This page may contain stale information. Last updated: 2026-06-25

Definition

Cordyceps is a systemic class of exploitable CI/CD vulnerabilities in github-actions workflows discovered by novee-security in June 2026. Named after a parasitic fungus, it describes multi-step exploit chains where untrusted PR input crosses trust boundaries into high-privilege workflows.

Key Points

  • Command injection, broken auth, artifact poisoning, cross-workflow privilege escalation
  • Unauthenticated attackers with free GitHub accounts can hijack workflows
  • 30,000 repo scan: 654 flagged, 300+ fully exploitable
  • Affected: Azure Sentinel, Google ADK, Apache Doris, Cloudflare Workers SDK, Black formatter
  • github actions/checkout v7 (June 18) is partial mitigation only

Sources