Skip to content

RE-OPENING #2297: This is a Global GitHub Actions RCE, not a local issue. Stop blocking me. Description: #2319

@armeniachessbo-beep

Description

@armeniachessbo-beep

Stop the gaslighting and stop blocking me. This is not about a "local flag." This is a Global 0-Click RCE that triggers in GitHub Actions.

Look at this, @SamMorrowDrums:

The Reality: While you are merging PRs for "Session Hijacking" theory, I am already Root (uid=0) in a live environment. I have dumped Authorization tokens (ghs_) and Azure SSH keys (see Image 1).

The Stealth: Look at the logs . Your server says everything is fine while I am exfiltrating /etc/shadow in the background.

I told you about this 0-day a month ago. Instead of fixing it, you chose to block the researcher.

Image Image Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions