DuckDuckGo CI/CD RCE: How a Single GitHub Workflow Could Have Backdoored Every DuckDuckGo Browser — Writeup Analysis
Some vulnerabilities are interesting because of their complexity. Others are terrifying because of their simplicity. The GitHub Actions RCE reported against DuckDuckGo in 2026 falls firmly in the second category: one misconfigured workflow file, zero required privileges beyond a free GitHub account, and a straight path from a forked pull request to a poisoned release shipped inside every…
The GitHub Actions Remote Code Execution (RCE) vulnerability discovered in 2026 affected DuckDuckGo's browser fleet. The flaw stemmed from a misconfigured GitHub Actions workflow file, .github/workflows/semver-label.yml. This workflow, responsible for labeling pull requests with semantic version labels, triggered without proper access controls or fork detection, granting attackers arbitrary code execution on DuckDuckGo's CI runners.
The attacker could exploit this by creating a forked pull request, injecting malicious code, and triggering the workflow to run the code in the context of DuckDuckGo's base repository, which possessed sensitive secrets. This led to a chain of events: the installation of the attacker-controlled code, its execution with full workflow permissions, and the exfiltration of critical secrets such as Anthropic API keys and GITHUB_TOKEN.
Once obtained, the attacker could manipulate the release pipeline, injecting poisoned releases across all platforms supported by DuckDuckGo's browsers, thereby compromising the entire browser fleet's integrity. The incident highlighted the dangers of misconfigured GitHub Actions triggers and underscored the importance of strict access controls and security best practices in CI/CD pipelines.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.