Skip to content

CVE Consideration Request – GitHub Actions Workflow RCE Vulnerability in Apache Beam #38926

@rishiarora123

Description

@rishiarora123

What happened?

Background

This issue is related to HackerOne Report #3763942, titled:

GitHub Actions CI/CD Injection Leads To RCE — anthropics/beam

The report was submitted to Anthropic on May 27, 2026 and was subsequently resolved through their vulnerability disclosure process.

According to Anthropic's response:

"CVE assignment for the underlying workflow pattern in the upstream project would be the Apache Beam project's decision, made through their own security and advisory process."

As a result, we are requesting a review of the upstream Apache Beam implementation to determine whether the affected workflow pattern existed in Apache Beam and whether it qualifies for a security advisory and/or CVE assignment.

Researchers

Please let us know if any additional information, proof-of-concept details, workflow references, commit history, remediation details, or supporting documentation are required.

Image Image

Issue Priority

Priority: 1 (data loss / total loss of function)

Issue Components

  • Component: Python SDK
  • Component: Java SDK
  • Component: Go SDK
  • Component: Typescript SDK
  • Component: IO connector
  • Component: Beam YAML
  • Component: Beam examples
  • Component: Beam playground
  • Component: Beam katas
  • Component: Website
  • Component: Infrastructure
  • Component: Spark Runner
  • Component: Flink Runner
  • Component: Prism Runner
  • Component: Twister2 Runner
  • Component: Hazelcast Jet Runner
  • Component: Google Cloud Dataflow Runner

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions