VYPR
Important severity8.7NVD Advisory· Published Sep 8, 2026

operator-foundry: operator-foundry: Over-permissive GITHUB_TOKEN and GCP WIF secrets granted to third-party reusable workflow on untrusted-triggerable events

CVE-2026-87049

Description

operator-foundry: operator-foundry: Over-permissive GITHUB_TOKEN and GCP WIF secrets granted to third-party reusable workflow on untrusted-triggerable events

Affected products

1

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.