
🚨High - act Artifacts V4 backend missing authorization and hardcoded HMAC key enables artifact takeover (CVE-2026-76847) nektos/act runs an HTTP Artifacts V4 backend for actions/*-artifact@v4 whose RPCs accept a caller-supplied workflow_run_backend_id with no ownership check (validateRunIDV4), and signs URLs with the hardcoded HMAC key 0xbadbeef0 over ambiguous input. When --artifact-server-addr is set to a non-loopback address, adjacent network clients can forge signatures and read, overwrite, or delete artifacts from any run. 👉Affected: nektos/act 0.2.81–0.2.89 | No fix yet — bind the artifact server to loopback and avoid actions/upload-artifact@v4 / download-artifact@v4 under act until patched
Post summary
The CVE-2026-76847 finds that nektos/act’s Artifacts V4 backend lacks authorization checks, using a hardcoded HMAC key that lets attackers take over artifacts; no fix yet but users should restrict the server to loopback and avoid artifact actions until patched.
