A misconfiguration in Amazon Web Services (AWS) CodeBuild could allow the cloud service provider's own GitHub repositories , including the AWS JavaScript SDK , to be fully taken over . The vulnerability was dubbed CodeBreach by cloud security firm Wiz . The issue was patched by AWS in September 2025, following a responsible disclosure on August 25, 2025.

“By exploiting CodeBreach, attackers could inject malicious code to cause a platform-level breach, potentially affecting not only the countless applications that depend on the SDK, but also the Console itself, threatening every AWS account,” researchers Yuval Avrahami and Nir Ohfeld said.
The vulnerability, as Wiz noted, is the result of a weakness in continuous integration (CI) pipelines and could allow unauthenticated attackers to compromise the build environment, leak credentials such as GitHub admin tokens, and then use them to push malicious changes to the compromised repository – creating a route for supply chain attacks.
See also: Windows Remote Assistance: Vulnerability allows MOTW bypass
In other words, the issue undermines the webhook filters that AWS introduced to ensure that only certain events trigger a CI build. For example, AWS CodeBuild can be configured so that a build is triggered only when code changes are made to a specific branch or when a GitHub account or GitHub Enterprise Server ID (also known as ACTOR_ID or actor ID) matches a regular expression pattern. These filters are used to protect against untrusted pull requests.
AWS CodeBuild: Which GitHub repositories are affected by the CodeBreach vulnerability
The misconfiguration affected the following open source GitHub repositories managed by AWS, which are configured to perform builds on pull requests:
- aws-sdk-js-v3
- aws-lc
- amazon-corretto-crypto-provider
- awslabs/open-data-registry

The four projects that implemented an ACTOR_IDsuffered from a fatal flaw in that they failed to include two characters – the start ^ and end $ anchors – necessary to yield an exact regular expression (regex) match. Instead, the regex pattern allowed any GitHub user ID that was a superstring of an approved ID (e.g. 755743) to bypass the filter and trigger the build.
See also: Vulnerability in Microsoft SQL Server allows elevation of privilege
Because GitHub assigns numeric user IDs sequentially, Wiz said she was able to predict that new user IDs (currently 9-digit) could “block” a trusted maintainer’s six-digit ID about every five days. This knowledge, combined with using GitHub Apps to automate app creation (which, in turn, creates a corresponding bot user), made it possible to create a target ID (e.g. 226755743) that would trigger hundreds of new bot user registrations.
Armed with the actor ID, an attacker can now trigger a build and obtain the GitHub credentials of the aws-sdk-js-v3 CodeBuild project, a Personal Access Token (PAT) belonging to the user aws-sdk-js-automation, which has full admin rights on the repository.
The attacker can leverage this increased access to push code directly to the master branch, approve pull requests , and export repository secrets, ultimately paving the way for supply chain attacks.
“The above regular expressions configured for AWS CodeBuild webhook filters to restrict trusted actor IDs were insufficient, allowing a compromised actor ID to gain administrator privileges for the affected repositories,” AWS said in an advisory.
“We can confirm that these were specific project misconfigurations in the webhook actor ID filters for these repositories and not an issue in the CodeBuild service itself“.
See also: Vulnerability in Palo Alto Networks firewall allows DoS attacks
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Protection
Amazon also said it had fixed the issues, along with implementing additional measures such as credential rotations and steps to secure build processes that contain GitHub tokens or any other credentials in memory. It further emphasized that it had found no evidence that CodeBreach had been exploited by cybercriminals.
To mitigate such risks, untrusted contributions should not trigger privileged CI/CD pipelines by enabling the new Pull Request Comment Approval build gate. It is also necessary to use CodeBuild-hosted runners to manage build triggers via GitHub workflows, ensure that regex patterns in webhook filters are anchored, create a unique PAT for each CodeBuild project, limit the PAT's permissions to the minimum required, and use a dedicated, unprivileged GitHub account for CodeBuild integration.
