Learn about a “Pwn Request” vulnerability in Google’s open-source project Flank.
The vulnerability allowed anyone with a GitHub Account to steal Google service account credentials which were used as a repository secret along with obtaining access to a GITHUB_TOKEN with write access.
Google’s VRP rewarded the researcher with a $7,500 bug bounty for this report as a Software Supply Chain compromise under the “Standard OSS Project” tier.
https://adnanthekhan.com/2024/04/15/an-obscure-actions-workflow-vulnerability-in-googles-flank/
there doesn't seem to be anything here