Code Execution Vulnerability in Feast Open Source Feature Store by Feast.dev
CVE-2026-55563
What is CVE-2026-55563?
The Feast open source feature store, prior to version 0.65.0, has a vulnerability in the GitHub Actions workflow that can lead to code execution and credential disclosure. This arises from the use of pull_request_target in the workflow, which allows a malicious contributor to execute their code with elevated privileges after gaining approval for a seemingly benign pull request update. As a result, sensitive credentials for GCP, AWS, and Snowflake can be exposed, potentially allowing unauthorized access to downstream cloud resources. While an external label-removal integration could provide some mitigation, this issue lacks built-in protections in the initial workflow configuration. The vulnerability has been addressed in version 0.65.0.
Affected Version(s)
feast < 0.65.0
