This page may contain stale information. Last updated: 2026-06-25
Definition
Cordyceps is a systemic class of exploitable CI/CD vulnerabilities in github-actions workflows discovered by novee-security in June 2026. Named after a parasitic fungus, it describes multi-step exploit chains where untrusted PR input crosses trust boundaries into high-privilege workflows.
Key Points
- Command injection, broken auth, artifact poisoning, cross-workflow privilege escalation
- Unauthenticated attackers with free GitHub accounts can hijack workflows
- 30,000 repo scan: 654 flagged, 300+ fully exploitable
- Affected: Azure Sentinel, Google ADK, Apache Doris, Cloudflare Workers SDK, Black formatter
- github actions/checkout v7 (June 18) is partial mitigation only