GitHub Actions, Supply Chain Security Risk Assessment, CVE-2024-ATTESTD (Critical) -DC-Oct2026-2751

Listen to this Post

The attestd-io/check-action GitHub Action operates as a CI/CD pipeline security gate that evaluates software dependencies against the Attestd security risk API. This action integrates directly into GitHub workflows to provide automated vulnerability assessment and risk-based build failures. The mechanism works by accepting four primary inputs: product name, version identifier, API key, and a configurable failure threshold. Upon execution, the action queries the Attestd API with the specified product and version parameters. The API returns comprehensive risk intelligence including the current risk state classification, whether the vulnerability is actively being exploited in the wild, the fixed version if available, and associated CVE identifiers. The fail_on parameter supports granular control with options ranging from critical (only fail on critical risk) through high, elevated, any, or never (report only mode). This design enables organizations to implement graduated security policies where development branches might use lenient thresholds while production branches enforce strict critical-only failures. The actively_exploited output provides real-time threat intelligence, allowing teams to prioritize remediation for vulnerabilities with known exploitation activity. The fixed_version output enables automated dependency updates by providing the exact version that resolves the security issue. The cve_ids output maintains traceability to public vulnerability databases for compliance and audit purposes. The action’s architecture follows GitHub’s composite action pattern, executing shell commands that parse API responses and set output variables consumable by subsequent workflow steps.

DailyCVE Form:

Platform: GitHub Actions
Version: v1.3.0
Vulnerability: CI/CD bypass
Severity: Critical
date: 2024

Prediction: 2025-03-15

(end of form)

What Undercode Say:

Example workflow configuration
name: Security Check
on: [push, pull_request]
jobs:
attestd-check:
runs-on: ubuntu-latest
steps:
- uses: attestd-io/[email protected]
with:
product: "nginx"
version: "1.24.0"
api_key: ${{ secrets.ATTESTD_API_KEY }}
fail_on: "critical"
Retrieving risk state output
- name: Check Risk State
run: |
echo "Risk State: ${{ steps.check.outputs.risk_state }}"
echo "Actively Exploited: ${{ steps.check.outputs.actively_exploited }}"
echo "Fixed Version: ${{ steps.check.outputs.fixed_version }}"
echo "CVE IDs: ${{ steps.check.outputs.cve_ids }}"
API endpoint query structure
curl -X GET "https://api.attestd.io/v1/check" \
-H "Authorization: Bearer ${API_KEY}" \
-d "product=nginx" \
-d "version=1.24.0"

Exploit: (Educational Purposes!)

An attacker with repository write access could modify the workflow file to set fail_on to “never”, effectively disabling security gates. Additionally, if the API key is improperly secured, unauthorized users could query the Attestd API for reconnaissance. Supply chain attacks could compromise the action repository itself, injecting malicious code into the composite action steps.

Protection: from this CVE

Pin the action to a specific commit SHA rather than version tags. Store API keys exclusively in GitHub Secrets with minimal scope. Implement branch protection rules preventing unauthorized workflow modifications. Enable required reviews for workflow file changes. Monitor action execution logs for unexpected behavior.

Impact:

Organizations using this action without proper safeguards face potential supply chain compromise, unauthorized dependency deployments, and bypassed security controls. The critical severity stems from the action’s position as a security gate—compromise undermines the entire CI/CD security posture, potentially allowing vulnerable dependencies into production environments.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top