Executive brief
Atlantis is a tool that automates Terraform pull requests using GitHub App integration. The /github-app/setup endpoint fails to require authentication, allowing anyone on the network to access sensitive GitHub App credentials including RSA private keys and webhook secrets. An attacker exploiting this vulnerability could forge webhook payloads, create installation tokens, and gain unauthorized access to integrated repositories.
Technical details
The vulnerability is an authentication bypass in the /github-app/setup endpoint of Atlantis through version 0.47.1. The endpoint fails to enforce authentication checks before exposing GitHub App configuration details, including the RSA private key and webhook secret used for GitHub integration. An unauthenticated attacker with network access to the Atlantis server can intercept or observe the GitHub redirect during setup to extract these credentials. Once obtained, the attacker can mint installation tokens and forge webhook payloads, enabling unauthorized access to repositories and CI/CD pipeline manipulation. The vulnerability requires network access to the endpoint but no prior authentication or user interaction.
Affected products
- Runatlantis Atlantis through 0.47.1
Timeline
- 2026-08-28: disclosed