Researchers found Cordyceps CI/CD flaws affecting 300+ repositories, enabling code execution, credential theft, and supply chain risks.

The CI/CD workflow weakness affects CI/CD platforms from Microsoft, Google, Apache, Cloudflare, and Python.

Cordyceps, a systemic class of exploitable CI/CD vulnerabilities, allows unauthenticated attackers to hijack developer workflows.