Gbhackers Cordyceps Vulnerability Exposes Thousands of Code Repositories to Attacks
Article Content
- •Cordyceps vulnerability allows unauthenticated attackers to exploit Git workflows.
- •Over 300 repositories confirmed fully exploitable, affecting major platforms like Microsoft and Google.
- •Immediate action is required to secure CI/CD workflows against this systemic flaw.
A newly identified supply chain vulnerability named 'Cordyceps' affects CI/CD workflows across major platforms, allowing unauthenticated attackers to exploit Git-based repositories. Novee's research flagged 654 vulnerable repositories, with over 300 confirmed as fully exploitable. The vulnerability arises from insecure workflow compositions, enabling command injection, credential theft, and privilege escalation. Affected systems include Microsoft's Azure Sentinel, Google's AI Agent Development Kit, Apache's Doris, Cloudflare's Workers SDK, and the Python Software Foundation's Black project. Major companies have confirmed the vulnerability and implemented fixes, but the potential impact could extend to millions of repositories. The flaw's systemic nature highlights the need for enhanced security measures in CI/CD configurations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (13)
Following this threat?
Track Dropping Elephant and Cloudflare in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…