Loading…
7-9 October, 2026
Prague, Czechia
View More Details & Registration
Important Note: Timing of sessions and room locations are subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.



Friday October 9, 2026 11:15 - 11:25 CEST
A pull_request_target trigger plus ref: ${{ github.event.pull_request.head.sha }} in a checkout step. That combination lets any external contributor run arbitrary code with your repository's secrets and write token. This is the "pwn request" pattern, and it's in production workflows across some of the most popular open-source projects on GitHub.

I'll use a real finding (a CRITICAL-severity pwn request I discovered and privately disclosed in an Apache project) to explain how the attack works: what pull_request_target does differently from pull_request, why adding permissions: read-all doesn't protect you, and why the attacker needs nothing beyond opening a pull request.

Then I'll show the three mitigations that work: splitting into unprivileged build and privileged post-processing steps, using persist-credentials: false, and gating on the head repo matching the base.
Speakers
avatar for Arpit Jain

Arpit Jain

Security Researcher, Self Employed
Supply-chain security researcher focused on CI/CD pipeline vulnerabilities. Audits GitHub Actions workflows across CNCF, sigstore/SLSA, OpenSSF, and US federal government orgs (cisagov, GSA) for exploitable patterns: pwn requests, unpinned actions, token-scope misconfigurations. Has... Read More →
Friday October 9, 2026 11:15 - 11:25 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link