Skip to content
Brief Security & Trust ·

Rust's Miri can leak CI secrets when caches are readable by pull requests

The Rust Security Response Team says exposure needs secrets in the Miri step, a cached target/ folder and a PR-readable cache.

In brief
  • Miri saves all environment variables to target/. Secrets are exposed only if they are in that step's environment and the cache is readable by pull requests.
  • The Rust team found 1 affected repository in its scan. It advises clearing caches and considering rotating secrets.

The Rust Security Response Team said Miri, run through cargo miri, saves all environment variables into the target/ folder. It called this not necessarily a vulnerability on its own. Exposure needs three things: secrets in the environment of the step that runs Miri, a cached target/ folder, and a cache that pull requests can read. Then anyone who has landed a change before could start a CI run to extract them, and push a second commit to cover their tracks. Predrag Gruevski of OpenAI reported it.

The short-term fix makes Miri keep only CARGO_* variables, except CARGO_*_TOKEN, and OUT_DIR. The team said the 2026-09-22 nightly will not have the problem, though the patch may not be on nightly yet. Its scan of GitHub repositories found 1 affected repository and 7 that look safe but should be careful. It has contacted those maintainers and called the scan likely imperfect. It did not say whether anyone has stolen secrets. It advises clearing caches and considering rotating secrets.

Miri is one case of a wider habit: giving secrets to a whole job, while tools assume they can write the environment to disk. Leaders can ask which CI jobs hold secrets, which caches pull requests can read, and how long logs and overwritten commits last. The team says they are deleted after a few months.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: blog.rust-lang.org.