PT-2026-96146 · Feast · Feast

CVE-2026-55563

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

8.9

High

VectorAV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Feast versions prior to 0.65.0
Description The .github/workflows/pr integration tests.yml workflow uses pull request target with the synchronize event and preserves ok-to-test, approved, or lgtm labels across newly pushed commits. This allows a fork contributor to obtain approval for a benign revision and subsequently execute modified code from refs/pull/${{ github.event.pull request.number }}/merge via privileged make targets. This flaw exposes GCP, AWS, and Snowflake credentials, potentially leading to runner code execution, credential disclosure, and unauthorized access to downstream cloud resources.
Recommendations Update to version 0.65.0.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55563
GHSA-2J2X-R73G-HRR5

Affected Products

Feast