Cordyceps Vulnerability Exposes Thousands of Code Repositories to Attacks

Cordyceps Vulnerability Exposes Thousands of Code Repositories to Attacks

First seen 23 Jun 2026, 17:06 UTC CybersecuritynewsGbhackersDarkreadingThehackernewsPanewslab+7 84% similarity 72.0

Article Content

Browse articles
ThreatCluster

A newly identified supply chain vulnerability named 'Cordyceps' affects CI/CD workflows across major platforms, allowing unauthenticated attackers to exploit Git-based repositories. Novee's research flagged 654 vulnerable repositories, with over 300 confirmed as fully exploitable. The vulnerability arises from insecure workflow compositions, enabling command injection, credential theft, and privilege escalation. Affected systems include Microsoft's Azure Sentinel, Google's AI Agent Development Kit, Apache's Doris, Cloudflare's Workers SDK, and the Python Software Foundation's Black project. Major companies have confirmed the vulnerability and implemented fixes, but the potential impact could extend to millions of repositories. The flaw's systemic nature highlights the need for enhanced security measures in CI/CD configurations.

Key Points: • Cordyceps vulnerability allows unauthenticated attackers to exploit Git workflows. • Over 300 repositories confirmed fully exploitable, affecting major platforms like Microsoft and Google. • Immediate action is required to secure CI/CD workflows against this systemic flaw.

ThreatCluster AI How this analysis works

Timeline

2026-06-23
Cordyceps vulnerability disclosed
Novee published findings on a critical CI/CD vulnerability affecting thousands of repositories, enabling unauthenticated access.
Darkreading
2026-06-23
Vulnerable repositories identified
Novee scanned 30,000 repositories, flagging 654 as vulnerable and confirming over 300 as fully exploitable.
Gbhackers
2026-06-23
Major companies confirm impact
Microsoft and Google confirmed their systems were affected, while Cloudflare and Apache applied fixes.
Darkreading

Community

Browse all →