WhisperX tag archive

#pwn-request

This page collects WhisperX intelligence signals tagged #pwn-request. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-05-02 14:54:06 · GitHub Issues

1. Ruff GitHub Actions Workflow Exposes Write Token to Fork Pull Requests — Code Execution Risk

A GitHub Actions workflow in the Ruff repository contains a security flaw that allows any user with fork pull request access to execute arbitrary code inside a runner holding a write-scoped `GITHUB_TOKEN`. The vulnerability, classified under CWE-77 (Improper Neutralization of Special Elements used in a Command), reside...