Skip to main content
Vulnerability Database/CVE-2026-55563

CVE-2026-55563: Feast Feature Store RCE Vulnerability

CVE-2026-55563 is a remote code execution vulnerability in Feast feature store that allows attackers to execute arbitrary code and access cloud credentials. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-55563 Overview

CVE-2026-55563 affects Feast, the open source feature store for artificial intelligence (AI) and machine learning (ML) workloads. The flaw lives in the .github/workflows/pr_integration_tests.yml GitHub Actions workflow. The workflow uses pull_request_target with the synchronize event and preserves the ok-to-test, approved, or lgtm labels across newly pushed commits. A fork contributor can obtain approval for a benign revision, then push malicious code that executes with privileged secrets. The job exposes Google Cloud Platform (GCP), Amazon Web Services (AWS), and Snowflake credentials to attacker-controlled code. The issue is fixed in Feast version 0.65.0.

Critical Impact

Attackers can execute arbitrary code on GitHub Actions runners, steal cloud credentials, and pivot into GCP, AWS, and Snowflake environments.

Affected Products

  • Feast versions prior to 0.65.0
  • Feast CI/CD pipelines using pr_integration_tests.yml
  • Downstream GCP, AWS, and Snowflake resources reachable from exposed workflow credentials

Discovery Timeline

  • 2026-09-21 - CVE-2026-55563 published to the National Vulnerability Database (NVD)
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-55563

Vulnerability Analysis

The vulnerability is an Improper Authorization flaw [CWE-863] in a GitHub Actions workflow. The pr_integration_tests.yml workflow runs with pull_request_target, which executes in the context of the target repository and has access to repository secrets. The workflow gates execution on labels such as ok-to-test, approved, and lgtm. However, it does not remove those labels when a contributor pushes new commits via the synchronize event. A fork contributor can submit a benign pull request, obtain approval, then push malicious commits that inherit the trusted labels and run with privileged access.

Root Cause

The root cause is a stale-label authorization pattern. The workflow trusts persistent pull request labels as a proxy for code review, but the labels are not invalidated when the pull request head changes. The workflow additionally checks out and executes code from refs/pull/${{ github.event.pull_request.number }}/merge, which reflects the latest fork commit rather than the reviewed revision. Combined with pull_request_target, this allows fork code to run inside privileged make targets.

Attack Vector

An external contributor opens a benign pull request against the Feast repository. A maintainer applies ok-to-test, approved, or lgtm to authorize integration testing. The contributor then force-pushes malicious code to the same fork branch. The synchronize event fires, the labels remain in place, and the workflow executes the attacker-controlled merge ref with GCP, AWS, and Snowflake credentials in the environment. The attacker can exfiltrate the secrets, execute arbitrary commands on the runner, and pivot into cloud accounts. See the GitHub Security Advisory GHSA-2j2x-r73g-hrr5 for maintainer notes.

Detection Methods for CVE-2026-55563

Indicators of Compromise

  • Workflow runs of pr_integration_tests.yml triggered by synchronize events on pull requests from forks after label assignment.
  • Unexpected outbound network traffic from GitHub-hosted runners to attacker-controlled endpoints during integration test jobs.
  • Access or usage of GCP, AWS, or Snowflake credentials from IP addresses associated with GitHub Actions runners outside normal CI windows.

Detection Strategies

  • Audit GitHub Actions run history for pr_integration_tests.yml executions where the commit SHA changed after a ok-to-test, approved, or lgtm label was applied.
  • Review cloud audit logs (GCP Cloud Audit Logs, AWS CloudTrail, Snowflake query history) for API calls originating from CI credentials during the exposure window.
  • Inspect fork pull requests for force-push events that follow maintainer approval labels.

Monitoring Recommendations

  • Enable branch protection and required review re-approval on label changes and new commits.
  • Forward GitHub Actions and cloud provider audit logs to a centralized analytics platform for correlation.
  • Alert on any CI job that reads secrets while checking out refs/pull/*/merge from an external fork.

How to Mitigate CVE-2026-55563

Immediate Actions Required

  • Upgrade Feast to version 0.65.0 or later, which contains the workflow fix in commit 76192229.
  • Rotate all GCP, AWS, and Snowflake credentials that were referenced by pr_integration_tests.yml.
  • Review recent pull request activity for suspicious force-pushes after approval labels were applied.

Patch Information

The fix is available in Feast release v0.65.0. The remediation modifies the pull request integration test workflow to invalidate trust labels when new commits are pushed, preventing stale approval from authorizing attacker-controlled code.

Workarounds

  • Deploy an external label-removal automation that strips ok-to-test, approved, and lgtm labels on every synchronize event for fork pull requests.
  • Restrict privileged workflows to run only on commits authored by trusted maintainers or on non-fork branches.
  • Move sensitive integration tests behind manual workflow_dispatch triggers instead of pull_request_target.
bash
# Configuration example: remove trust labels on new fork commits
# .github/workflows/strip-labels.yml
name: Strip trust labels on sync
on:
  pull_request_target:
    types: [synchronize]
jobs:
  strip:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/github-script@v7
        with:
          script: |
            const labels = ['ok-to-test', 'approved', 'lgtm'];
            for (const name of labels) {
              try {
                await github.rest.issues.removeLabel({
                  owner: context.repo.owner,
                  repo: context.repo.repo,
                  issue_number: context.payload.pull_request.number,
                  name
                });
              } catch (e) { /* label may not be present */ }
            }

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.