GHSA-g7mm-9vx7-jm7h

Suggest an improvement
Source
https://github.com/advisories/GHSA-g7mm-9vx7-jm7h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-g7mm-9vx7-jm7h/GHSA-g7mm-9vx7-jm7h.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g7mm-9vx7-jm7h
Aliases
Published
2026-07-14T19:00:29Z
Modified
2026-07-21T19:19:07Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation
Details

Impact

A vulnerability in Woodpecker CI's gRPC layer allowed any authenticated agent to impersonate any other agent on the same server by injecting a forged agent_id value into outgoing gRPC metadata. The server correctly verified the JWT token but then discarded the verified agent identity in favor of the client-supplied value.

Patches

Direct patch: https://github.com/woodpecker-ci/woodpecker/pull/6567 Later proper fix: https://github.com/woodpecker-ci/woodpecker/pull/6569

Workarounds

Disable org agents (WOODPECKER_DISABLE_USER_AGENT_REGISTRATION=true) and delete existing ones

Resources

Public ref: https://github.com/woodpecker-ci/woodpecker/issues/6541 Private com: https://github.com/woodpecker-ci/woodpecker-security/issues/21

Database specific
{
    "cwe_ids":  [
        "CWE-290",
        "CWE-639"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-14T19:00:29Z",
    "nvd_published_at":  "2026-06-18T14:17:29Z",
    "severity":  "HIGH"
}
References

Affected packages

Go / go.woodpecker-ci.org/woodpecker/v3

Package

Name
go.woodpecker-ci.org/woodpecker/v3
View open source insights on deps.dev
Purl
pkg:golang/go.woodpecker-ci.org/woodpecker/v3

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0
Fixed
3.14.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-g7mm-9vx7-jm7h/GHSA-g7mm-9vx7-jm7h.json"