CVE-2026-55563 Overview
CVE-2026-55563 affects Feast, the open source feature store for artificial intelligence (AI) and machine learning (ML) workloads. The flaw lives in the .github/workflows/pr_integration_tests.yml GitHub Actions workflow. The workflow uses pull_request_target with the synchronize event and preserves the ok-to-test, approved, or lgtm labels across newly pushed commits. A fork contributor can obtain approval for a benign revision, then push malicious code that executes with privileged secrets. The job exposes Google Cloud Platform (GCP), Amazon Web Services (AWS), and Snowflake credentials to attacker-controlled code. The issue is fixed in Feast version 0.65.0.
Critical Impact
Attackers can execute arbitrary code on GitHub Actions runners, steal cloud credentials, and pivot into GCP, AWS, and Snowflake environments.
Affected Products
- Feast versions prior to 0.65.0
- Feast CI/CD pipelines using pr_integration_tests.yml
- Downstream GCP, AWS, and Snowflake resources reachable from exposed workflow credentials
Discovery Timeline
- 2026-09-21 - CVE-2026-55563 published to the National Vulnerability Database (NVD)
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2026-55563
Vulnerability Analysis
The vulnerability is an Improper Authorization flaw [CWE-863] in a GitHub Actions workflow. The pr_integration_tests.yml workflow runs with pull_request_target, which executes in the context of the target repository and has access to repository secrets. The workflow gates execution on labels such as ok-to-test, approved, and lgtm. However, it does not remove those labels when a contributor pushes new commits via the synchronize event. A fork contributor can submit a benign pull request, obtain approval, then push malicious commits that inherit the trusted labels and run with privileged access.
Root Cause
The root cause is a stale-label authorization pattern. The workflow trusts persistent pull request labels as a proxy for code review, but the labels are not invalidated when the pull request head changes. The workflow additionally checks out and executes code from refs/pull/${{ github.event.pull_request.number }}/merge, which reflects the latest fork commit rather than the reviewed revision. Combined with pull_request_target, this allows fork code to run inside privileged make targets.
Attack Vector
An external contributor opens a benign pull request against the Feast repository. A maintainer applies ok-to-test, approved, or lgtm to authorize integration testing. The contributor then force-pushes malicious code to the same fork branch. The synchronize event fires, the labels remain in place, and the workflow executes the attacker-controlled merge ref with GCP, AWS, and Snowflake credentials in the environment. The attacker can exfiltrate the secrets, execute arbitrary commands on the runner, and pivot into cloud accounts. See the GitHub Security Advisory GHSA-2j2x-r73g-hrr5 for maintainer notes.
Detection Methods for CVE-2026-55563
Indicators of Compromise
- Workflow runs of pr_integration_tests.yml triggered by synchronize events on pull requests from forks after label assignment.
- Unexpected outbound network traffic from GitHub-hosted runners to attacker-controlled endpoints during integration test jobs.
- Access or usage of GCP, AWS, or Snowflake credentials from IP addresses associated with GitHub Actions runners outside normal CI windows.
Detection Strategies
- Audit GitHub Actions run history for pr_integration_tests.yml executions where the commit SHA changed after a ok-to-test, approved, or lgtm label was applied.
- Review cloud audit logs (GCP Cloud Audit Logs, AWS CloudTrail, Snowflake query history) for API calls originating from CI credentials during the exposure window.
- Inspect fork pull requests for force-push events that follow maintainer approval labels.
Monitoring Recommendations
- Enable branch protection and required review re-approval on label changes and new commits.
- Forward GitHub Actions and cloud provider audit logs to a centralized analytics platform for correlation.
- Alert on any CI job that reads secrets while checking out refs/pull/*/merge from an external fork.
How to Mitigate CVE-2026-55563
Immediate Actions Required
- Upgrade Feast to version 0.65.0 or later, which contains the workflow fix in commit 76192229.
- Rotate all GCP, AWS, and Snowflake credentials that were referenced by pr_integration_tests.yml.
- Review recent pull request activity for suspicious force-pushes after approval labels were applied.
Patch Information
The fix is available in Feast release v0.65.0. The remediation modifies the pull request integration test workflow to invalidate trust labels when new commits are pushed, preventing stale approval from authorizing attacker-controlled code.
Workarounds
- Deploy an external label-removal automation that strips ok-to-test, approved, and lgtm labels on every synchronize event for fork pull requests.
- Restrict privileged workflows to run only on commits authored by trusted maintainers or on non-fork branches.
- Move sensitive integration tests behind manual workflow_dispatch triggers instead of pull_request_target.
# Configuration example: remove trust labels on new fork commits
# .github/workflows/strip-labels.yml
name: Strip trust labels on sync
on:
pull_request_target:
types: [synchronize]
jobs:
strip:
runs-on: ubuntu-latest
steps:
- uses: actions/github-script@v7
with:
script: |
const labels = ['ok-to-test', 'approved', 'lgtm'];
for (const name of labels) {
try {
await github.rest.issues.removeLabel({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: context.payload.pull_request.number,
name
});
} catch (e) { /* label may not be present */ }
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.