Coordinated Disclosure Timeline
- 2025-07-25: Reported using PVR: https://github.com/nf-core/tools/security/advisories/GHSA-p4vm-qh4p-2557
- 2025-09-02: Created a PR with the fix: https://github.com/nf-core/tools/pull/3744
- 2026-03-05: https://github.com/nf-core/tools/pull/3744 merged
- 2026-09-24: Created a second PR to fix mistakes in the original PR: https://github.com/nf-core/tools/pull/4480
Summary
The nf-core/tools project was vulnerable in its main version (commit https://github.com/nf-core/tools/commit/75e643ad2c62cdc8ecd39aa56c0c314efd4b13e4) because the changelog.yml workflow could run untrusted code.
Project
nf-core/tools
Tested Version
Latest main: https://github.com/nf-core/tools/commit/75e643ad2c62cdc8ecd39aa56c0c314efd4b13e4
Details
Execution of untrusted code in the changelog.yml workflow (GHSL-2025-080)
The changelog.yml workflow is triggered by either an issue comment or the creation of a new pull request:
name: Update CHANGELOG.md
on:
issue_comment:
types: [created]
pull_request_target:
types: [opened]
branches:
- dev
Either of those triggers could be activated by an attacker, and they cause the workflow to run with write permissions for the repository.
On line 37, the workflow checks out code from the pull request:
gh pr checkout $PR_NUMBER
And on line 55, executes it:
python ${GITHUB_WORKSPACE}/.github/workflows/changelog.py
Since the pull request can contain new code, this gives an attacker the ability to run arbitrary code. It would enable them to do things like pushing new commits to the main branch.
Impact
This issue may lead to full repository takeover.
CWEs
- CWE-829: “Inclusion of Functionality from Untrusted Control Sphere”
Credit
This issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse).
Contact
You can contact the GHSL team at securitylab@github.com, please include a reference to GHSL-2025-080 in any communication regarding this issue.