• Sources: primary
  • Summary: The Rust Security Response Team published on 2026-09-21 that cargo miri needs build-relevant environment variables preserved between runs and does so by storing all of them to target/, reported by Predrag Gruevski of OpenAI. Where target/ is cached and the cache is readable by pull requests, which is the common actions/cache and swatinem/rust-cache setup, anyone who can open a PR can extract those secrets and then push a second commit to hide the run, and the ecosystem scan found 1 affected repository and 7 to be cautious about. The post names the fixed build, the 2026-09-22 nightly that restricts Miri to CARGO_* excluding CARGO_*_TOKEN plus OUT_DIR, rather than an affected version range, so every earlier cargo miri run under a publicly readable cache counts as exposed, and the stated mitigations are to disable the cache for that job, scope secrets away from Miri steps, or disable Miri, then clear the cache and rotate exposed secrets.
  • Why it matters: The stated rule generalizes past Rust, because most tools assume the whole environment is writable to disk, so any job that can write to a publicly readable cache should not hold secrets.
  • Follow-up: Whether other build tools are found writing the full environment into a cached directory.

send feedback on this story