Junglewise Threat Intelligence

CVE-2026-55563: Feast insecure GitHub workflow allows credential exposure in CI/CD

CVE-2026-55563 · Severity: info · Published 2026-09-21

Executive brief

Feast, an open-source feature store for machine learning, had a misconfigured GitHub Actions workflow that allowed fork contributors to run arbitrary code with access to sensitive cloud credentials (GCP, AWS, Snowflake). An attacker could submit a benign pull request, get it approved, then push malicious code to the same PR to execute with privileged access and steal credentials. This vulnerability was fixed in version 0.65.0.

Technical details

The vulnerability exists in the pull_request_target workflow with the synchronize event, which preserved approval labels across new commits, allowing label reuse attacks. The vulnerable workflow exposed GCP, AWS, and Snowflake credentials to untrusted code executed through privileged make targets via refs/pull/${{ github.event.pull_request.number }}/merge. The fix removes the synchronize event handler to prevent code changes after approval from being automatically executed with retained privileges.

Affected products

  • Feast Feast before 0.65.0

Timeline

  • 2026-09-21: disclosed
  • 2026-07-20: patched: Fixed in version 0.65.0

References