Skip to content
Exploitation of GitHub Actions via pull_request_target Trigger

Exploitation of GitHub Actions via pull_request_target Trigger

First seen 11 May 2026, 03:32 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 12, 2026 at 03:14 UTC
  • The pull_request_target trigger in GitHub Actions allows elevated access to repository secrets.
  • A campaign by hackerbot-claw exploited this vulnerability, targeting high-profile repositories.
  • Despite GitHub's mitigations, misconfigurations remain common, posing ongoing risks.

A targeted campaign exploiting GitHub Actions' pull_request_target trigger was identified, allowing attackers to execute malicious code with elevated privileges. This vulnerability has been documented since 2021 but continues to be misconfigured in many repositories. The hackerbot-claw account scanned public repositories for these misconfigurations, submitting malicious pull requests to high-profile targets, including Microsoft and DataDog projects. Between February 21 and March 2, 2026, this campaign demonstrated the feasibility of such attacks at scale. GitHub has implemented platform-level mitigations, but many users still rely on insecure configurations. The ongoing prt-scan campaign indicates that this attack vector is evolving and may become accessible to a broader range of actors. Security professionals are urged to review their GitHub Actions configurations to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 132d ago How this analysis works

Timeline

2021-01-01
Vulnerability documented by GitHub Security Lab
The term 'pwn request' was coined to describe vulnerabilities associated with pull_request_target triggers.
labs.cloudsecurityalliance.org
2026-02-21
Targeted scanning campaign begins
The hackerbot-claw account started scanning public repositories for exploitable pull_request_target workflows.
labs.cloudsecurityalliance.org
2026-03-02
Malicious pull requests submitted
Hackerbot-claw submitted malicious pull requests to high-profile repositories, including those linked to Microsoft.
labs.cloudsecurityalliance.org
2026-03-11
Subsequent waves of activity observed
Wiz Research reconstructed six waves of activity attributed to a single threat actor, refining their targeting and tooling.
labs.cloudsecurityalliance.org
2026-05-11
Security checklist published
Aikido.Dev published a checklist to help users secure their GitHub Actions workflows against known vulnerabilities.
Aikido.Dev

More articles in this cluster (5)

Following this threat?

Track Cloud Native Computing Foundation in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed