Coordinated Disclosure Timeline

Summary

The nf-core/tools project was vulnerable in its main version (commit https://github.com/nf-core/tools/commit/75e643ad2c62cdc8ecd39aa56c0c314efd4b13e4) because the update-textual-snapshots.yml workflow could run untrusted code.

Project

nf-core/tools

Tested Version

Latest main: https://github.com/nf-core/tools/commit/75e643ad2c62cdc8ecd39aa56c0c314efd4b13e4

Details

Execution of untrusted code in the update-textual-snapshots.yml workflow (GHSL-2025-078)

Note: this vulnerability was found by code scanning, but we have verified (human review) that it’s a true positive result.

The update-textual-snapshots.yml workflow is triggered by an issue comment:

name: Update Textual snapshots from a comment
on:
  issue_comment:
    types: [created]

Issue comments can be added by anybody, so an attacker can trigger this workflow by first creating a pull request, then adding a comment with the following body:

@nf-core-bot update snapshots

On line 29, the workflow checks out code from the pull request:

      - name: Checkout Pull Request
        run: gh pr checkout ${{ github.event.issue.number }}
        env:
          GITHUB_TOKEN: ${{ secrets.nf_core_bot_auth_token }}

And, on line 46, executes it:

      - name: Run pytest to update snapshots
        id: pytest
        run: |
          python3 -m pytest tests/pipelines/test_create_app.py --snapshot-update --color=yes --durations=0 -n auto
        continue-on-error: true

Since the pull request can contain new code, this gives an attacker the ability to run arbitrary code. It would enable them to do things like pushing new commits to the main branch.

Impact

This issue may lead to full repository takeover.

CWEs

Credit

This issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse).

Contact

You can contact the GHSL team at securitylab@github.com, please include a reference to GHSL-2025-078 in any communication regarding this issue.