litgpt icon indicating copy to clipboard operation
litgpt copied to clipboard

Secrets exfiltration vulnerability

Open darryk10 opened this issue 9 months ago • 0 comments

Hi, We found a critical vulnerability in one of the CI workflows in this repo. We already submitted a GHSA to securely disclose all the information and the POC to reproduce the issue. The repository is still vulnerable, and exploiting the vulnerability, an attacker could exfiltrate secrets and a highly privileged GITHUB_TOKEN to revert the overall repo.

Let me know if we can provide any other information to fix it.

darryk10 avatar Jul 07 '25 14:07 darryk10