A timing race in JupyterLab's snapshot action can execute pull-request contributor code in a privileged CI job.
JupyterLab maintainer-tools, reusable GitHub Actions workflows used by software repositories to update pull-request snapshots.
After a maintainer approves a snapshot update, a contributor can push a malicious revision within the same one-second timestamp interval. The action treats it as unchanged and checks it out as the approved revision.
Detail and 2 sources
The checked-out code inherits the consuming job's secrets and authority. GitHub Security Lab tested the sequence against jupyter/notebook.
A patched action release exists, but consuming workflows can continue referencing the vulnerable release.