GHSL-2025-080: Untrusted pull request code execution in the nf-core/tools changelog workflow
Published Oct 1, 2026
·Updated
The nf-core/tools changelog workflow could execute untrusted pull request code in a privileged GitHub Actions context.
Affected Software
1 affected component
nf-core tools
Event History
Oct 1, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What attacker-controlled input is involved?
The affected workflow could execute code from an untrusted pull request. The available information does not identify a specific file, event trigger, or required pull request permission level.