Coordinated Disclosure Timeline

Summary

The nf-core/tools project was vulnerable in its main version (commit https://github.com/nf-core/tools/commit/75e643ad2c62cdc8ecd39aa56c0c314efd4b13e4) because the changelog.yml workflow could run untrusted code.

Project

nf-core/tools

Tested Version

Latest main: https://github.com/nf-core/tools/commit/75e643ad2c62cdc8ecd39aa56c0c314efd4b13e4

Details

Execution of untrusted code in the changelog.yml workflow (GHSL-2025-080)

The changelog.yml workflow is triggered by either an issue comment or the creation of a new pull request:

name: Update CHANGELOG.md
on:
  issue_comment:
    types: [created]
  pull_request_target:
    types: [opened]
    branches:
      - dev

Either of those triggers could be activated by an attacker, and they cause the workflow to run with write permissions for the repository.

On line 37, the workflow checks out code from the pull request:

          gh pr checkout $PR_NUMBER

And on line 55, executes it:

          python ${GITHUB_WORKSPACE}/.github/workflows/changelog.py

Since the pull request can contain new code, this gives an attacker the ability to run arbitrary code. It would enable them to do things like pushing new commits to the main branch.

Impact

This issue may lead to full repository takeover.

CWEs

Credit

This issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse).

Contact

You can contact the GHSL team at securitylab@github.com, please include a reference to GHSL-2025-080 in any communication regarding this issue.