Skip to content
GitHub Actions Enhances Security Against 'Pwn Request' Attacks

GitHub Actions Enhances Security Against 'Pwn Request' Attacks

First seen 22 Jun 2026, 11:37 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 23, 2026 at 10:55 UTC
  • GitHub's actions/checkout v7 blocks unsafe workflows from untrusted forks.
  • The update addresses long-standing vulnerabilities exploited in pwn request attacks.
  • Developers can opt out of restrictions, but this is discouraged to maintain security.

GitHub has released actions/checkout v7 to mitigate vulnerabilities associated with the pull_request_target workflow trigger, which has been exploited in 'pwn request' attacks. This update, announced on June 18, 2026, blocks workflows that attempt to fetch untrusted code from forked repositories, thereby preventing unauthorized access to sensitive resources. The changes will be backported to all supported major versions starting July 16, 2026. Developers can opt out of these restrictions but are discouraged from doing so. The update aims to enhance security by default, addressing a long-standing issue that has led to multiple compromises in software supply chains. GitHub acknowledges that while this update significantly reduces risk, it does not eliminate all forms of exploitation related to pwn requests. The changes come in response to a surge in cyberattacks targeting developer environments, including recent incidents attributed to the TeamPCP hacking group.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 90d ago How this analysis works

Timeline

2026-06-18
GitHub announces actions/checkout v7 release
The update introduces security measures to block pwn request attacks by restricting workflows triggered by pull_request_target.
Gbhackers
2026-06-22
GitHub Actions security update reported widely
Multiple cybersecurity outlets reported on GitHub's actions/checkout v7 and its implications for developers and security.
Csoonline
2026-07-16
Backporting of security features begins
GitHub will backport the new security defaults to all supported major versions of actions/checkout.
Gbhackers

More articles in this cluster (12)

Following this threat?

Track Miasma and Qnap in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed