GHSL-2025-078: Untrusted pull request code execution in the nf-core/tools snapshot workflow
Published Oct 1, 2026
·Updated
The nf-core/tools update-textual-snapshots workflow could execute untrusted pull request code in a privileged GitHub Actions context.
Affected Software
1 affected component
nf-core tools
Event History
Oct 1, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
Which repositories are exposed to this issue?
Repositories using the nf-core/tools update-textual-snapshots workflow are exposed when that workflow runs in a privileged GitHub Actions context.
2
What does an attacker need to exploit it?
An attacker needs to cause untrusted pull request code to be processed by the affected workflow. The provided information does not specify additional prerequisites.