Urgent.News

What's breaking now, across thousands of outlets.

Tech

DuckDuckGo CI/CD RCE: How a Single GitHub Workflow Could Have Backdoored Every DuckDuckGo Browser — Writeup Analysis

Some vulnerabilities are interesting because of their complexity. Others are terrifying because of their simplicity. The GitHub Actions RCE reported against DuckDuckGo in 2026 falls firmly in the second category: one misconfigured workflow file, zero required privileges beyond a free GitHub account, and a straight path from a forked pull request to a poisoned release shipped inside every…

The GitHub Actions Remote Code Execution (RCE) vulnerability discovered in 2026 affected DuckDuckGo's browser fleet. The flaw stemmed from a misconfigured GitHub Actions workflow file, .github/workflows/semver-label.yml. This workflow, responsible for labeling pull requests with semantic version labels, triggered without proper access controls or fork detection, granting attackers arbitrary code execution on DuckDuckGo's CI runners.

The attacker could exploit this by creating a forked pull request, injecting malicious code, and triggering the workflow to run the code in the context of DuckDuckGo's base repository, which possessed sensitive secrets. This led to a chain of events: the installation of the attacker-controlled code, its execution with full workflow permissions, and the exfiltration of critical secrets such as Anthropic API keys and GITHUB_TOKEN.

Once obtained, the attacker could manipulate the release pipeline, injecting poisoned releases across all platforms supported by DuckDuckGo's browsers, thereby compromising the entire browser fleet's integrity. The incident highlighted the dangers of misconfigured GitHub Actions triggers and underscored the importance of strict access controls and security best practices in CI/CD pipelines.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Grass Pass: Photograph to Unlock Reddit

This is a submission for the Hacktoberfest Open-Source AI Challenge Week 1: Touch Grass What I Built Grass Pass is a Chromium extension (Chrome, Edge, Brave) that blocks the sites you doomscroll on.

More from Sunday 11 October →