GEOSERVER’S Cloud project fixed a critical flaw in its GitHub Actions workflow that could have allowed an outside contributor to run code on the build runner and exfiltrate repository secrets. The issue resided in the geoserver-cloud repository’s CI pipeline, not in the GeoServer software itself, and leveraged the pull_request_target trigger to operate with the repository’s own permissions and secrets.
In practice, this meant that a fork’s PR could trigger code execution in a privileged context, potentially exposing tokens and credentials with write access. The maintainers note the risk as a classic supply‑chain concern, even though no exploitation was observed.
Affected were the main and release/2.28.x branches of the geoserver-cloud repository. There was no assigned CVE for the flaw, and the team’s review found no evidence of abuse; they also reported that release downloads are built on a separate server, not via GitHub Actions. To remediate, GeoServer rewrote the workflow following the GitHub Security Lab “Preventing pwn requests” pattern and deleted the vulnerable file from all branches, while rotating secrets.
Users of GeoServer do not need to patch their installations, but projects using pull_request_target should audit their own workflows for similar vulnerability patterns. The article emphasises that CISA KEV is not the sole exploitation signal, and notes the broader importance of securing CI/CD pipelines to prevent supply‑chain compromises.