Python Software Foundation’s Black Tool Compromised by Cordyceps
The Python Software Foundation's Black tool was affected by the Cordyceps flaw, allowing a single pull request to execute attacker code and…
The Python Software Foundation's Black tool was affected by the Cordyceps flaw, allowing a single pull request to execute attacker code and…
Microsoft's Azure Sentinel was found to have a CI/CD workflow weakness that allowed unauthenticated attackers to run code and steal credentials via…
Google's AI Agent Development Kit (adk-samples) had a CI/CD vulnerability enabling attacker code execution and repository takeover via pull requests.
Apache Doris was vulnerable to zero-click CI/CD attacks that allowed code execution and credential theft through pull request comments.
Cloudflare Workers SDK had a CI/CD vulnerability where crafted branch names in pull requests could execute arbitrary commands on CI runners.
The Python Software Foundation's Black tool had a CI/CD flaw allowing pull requests to execute attacker code and steal automation tokens.