Code Execution Vulnerability in Feast Open Source Feature Store by Feast.dev
CVE-2026-55563

8.9HIGH

Key Information:

Vendor

Feast-dev

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-55563?

The Feast open source feature store, prior to version 0.65.0, has a vulnerability in the GitHub Actions workflow that can lead to code execution and credential disclosure. This arises from the use of pull_request_target in the workflow, which allows a malicious contributor to execute their code with elevated privileges after gaining approval for a seemingly benign pull request update. As a result, sensitive credentials for GCP, AWS, and Snowflake can be exposed, potentially allowing unauthorized access to downstream cloud resources. While an external label-removal integration could provide some mitigation, this issue lacks built-in protections in the initial workflow configuration. The vulnerability has been addressed in version 0.65.0.

Affected Version(s)

feast < 0.65.0

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.