Impact
A flaw in operator‑foundry allows external actors to call a third‑party reusable workflow that is granted overly permissive GitHub access tokens and Google Cloud Platform Workload Identity Federation credentials. By triggering this workflow on untrusted events without proper authorization checks, an attacker can obtain highly privileged access to both GitHub and cloud resources, potentially taking complete control. This vulnerability is categorized as an access‑control weakness (CWE‑269).
Affected Systems
The vulnerability affects the operator‑foundry GitHub action/repository that provides reusable workflows utilizing GITHUB_TOKEN and GCP WIF secrets. No specific version information is supplied, so any instance of operator‑foundry that offers the vulnerable workflow and accepts external triggers is at risk.
Risk and Exploitability
The CVSS score of 8.7 reflects a high severity, and while an EPSS score is not available, the absence of a KEV listing does not reduce the risk of exploitation. The likely attack vector is an untrusted‑triggerable event invoking the vulnerable workflow. With no obvious runtime checks, an attacker can leverage the over‑permissive tokens to access GitHub repositories and GCP projects, achieving data exfiltration or further lateral movement.
OpenCVE Enrichment