CVE-2026-47174 - Duck Site: Untrusted pull request code can trigger privileged production deployment
CVE ID :CVE-2026-47174 Published : June 11, 2026, 7:16 p.m. | 1 hour, 48 minutes ago Description :In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. The build workflow runs on pull requests, while the deploy workflow runs with...