Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GitHub Enhances Security by Blocking Risky Pwn Requests

GitHub Enhances Security by Blocking Risky Pwn Requests

Posted on June 23, 2026 By CWS

GitHub has taken significant steps to bolster software supply chain security by updating its popular ‘actions/checkout’ tool. This update is designed to block pwn request attacks that exploit the ‘pull_request_target’ workflow trigger, which can potentially run malicious code with full workflow privileges. The change, effective from June 18, 2026, automatically blocks common pwn request patterns, marking an essential move for safeguarding repositories.

New Security Measures for Actions/Checkout

The latest update to ‘actions/checkout’ ensures that fork pull request codes are not fetched in ‘pull_request_target’ and ‘workflow_run’ workflows, particularly when the triggering event is a ‘pull_request’. This measure is in place unless the ‘allow-unsafe-pr-checkout’ flag is explicitly set to ‘true’. The update will extend to all major supported versions on July 16, 2026, enhancing security across the platform.

These preventative measures are crucial as ‘pull_request_target’ workflows often run with elevated permissions, including access to secrets and write capabilities via the GITHUB_TOKEN. Such access poses significant security risks if exploited by malicious actors through untrusted fork pull requests.

Understanding the Risks of Pull Request Target

‘Pull_request_target’ is a trigger that executes workflows automatically when a pull request is opened or updated. This convenience comes with risks, as the workflow runs with the base repository’s access levels, potentially exposing sensitive information. GitHub’s documentation warns that executing untrusted code through this mechanism can lead to vulnerabilities, including cache poisoning and unauthorized access.

The risk is heightened when combined with ‘actions/checkout’, allowing attackers to submit harmful scripts that, if executed, could compromise the GITHUB_TOKEN and other critical data. This type of attack, known as a pwn request, has been exploited in recent software supply chain attacks, including breaches involving the Nx build system and other popular packages.

Guidance for Developers

To mitigate risks, developers are advised to carefully assess the necessity of using ‘pull_request_target’. If elevated permissions are not required, switching to ‘pull_request’ can reduce potential vulnerabilities. Developers should also restrict workflow permissions and ensure that user-controlled inputs do not result in executing untrusted code.

GitHub emphasizes that while this update is a protective measure, it is not a comprehensive solution. Workflows with significant privileges still require thorough reviews to ensure security. By implementing these changes, GitHub aims to provide a safer environment for developers, minimizing the threat of malicious exploits.

Overall, this update is a critical step in strengthening the security of the software supply chain on GitHub. Developers are encouraged to review their workflows and adopt best practices to protect their repositories from potential threats.

The Hacker News Tags:actions/checkout, cache poisoning, code execution, fork pull requests, GitHub, GITHUB_TOKEN, malicious code, pull_request_target, pwn requests, Repository, Security, software chain attacks, software supply chain, workflow permissions, Workflow Security

Post navigation

Previous Post: Hackers Exploit Tools for Network Persistence
Next Post: Carl Froggett: Dual Role as CISO and CIO at Deep Instinct

Related Posts

Why BAS Is Proof of Defense, Not Assumptions Why BAS Is Proof of Defense, Not Assumptions The Hacker News
Greatness PhaaS Enhances Device Code Phishing Tactics Greatness PhaaS Enhances Device Code Phishing Tactics The Hacker News
GitHub Actions Compromised to Steal CI/CD Credentials GitHub Actions Compromised to Steal CI/CD Credentials The Hacker News
Crypto-Mining Risks in Fortune 500 Cloud Systems Revealed Crypto-Mining Risks in Fortune 500 Cloud Systems Revealed The Hacker News
Researchers Uncover 20+ Configuration Risks, Including Five CVEs, in Salesforce Industry Cloud Researchers Uncover 20+ Configuration Risks, Including Five CVEs, in Salesforce Industry Cloud The Hacker News
ShowDoc Vulnerability CVE-2025-0520 Exploited in the Wild ShowDoc Vulnerability CVE-2025-0520 Exploited in the Wild The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Linux SCTP Vulnerability Risks Full Root Access
  • Critical WordPress Vulnerability Allows Remote Code Execution
  • Chrome Exploit Steals Gmail Codes to Hijack Accounts
  • Critical Flaws in Gemini CLI and Claude Code Exposed
  • Swiss Government SharePoint Servers Hacked, 200 Accounts Affected

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Linux SCTP Vulnerability Risks Full Root Access
  • Critical WordPress Vulnerability Allows Remote Code Execution
  • Chrome Exploit Steals Gmail Codes to Hijack Accounts
  • Critical Flaws in Gemini CLI and Claude Code Exposed
  • Swiss Government SharePoint Servers Hacked, 200 Accounts Affected

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark