Executive brief
Act is a tool that runs GitHub Actions workflows locally. When a workflow uses artifact upload or download actions, act starts an HTTP backend service that is exposed to the network by default and lacks proper authentication. An attacker on the same network can forge credentials to read, modify, or delete artifacts from any running job, potentially exposing secrets, deployment credentials, and build outputs.
Technical details
The vulnerability involves multiple authentication failures in the Artifacts V4 backend. First, the validateRunIDV4 function in pkg/artifacts/artifacts_v4.go fails to validate that a caller-supplied workflow_run_backend_id belongs to the requester (the validation code is commented out). Second, signed URLs are protected by an HMAC with a hardcoded key (0xbadbeeef0) identical across all builds, and the signature is computed without length prefixes or delimiters, allowing forgery and collision attacks. Third, the --artifact-server-addr flag defaults to the outbound network address instead of localhost, exposing the backend to the network. Any network-adjacent client can invoke control-plane RPCs (CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeArtifact, DeleteArtifact) without credentials to access or manipulate artifacts of concurrent jobs.
Affected products
- nektos act prior to v0.2.90
Timeline
- 2026-08-24: disclosed