Miri’s Cache Leak Turns Cargo Environment Hygiene Into a CI Security Rule
A Rust Security Response Team notice shows how cargo miri, cached target directories, and broadly scoped CI secrets can combine into a pull-request exposure path.

The Rust Security Response Team disclosed a narrowly defined but important CI failure mode on September 21: Miri stored environment variables in target/, so caching that directory could preserve secrets for later pull-request jobs.
This is not a claim that Miri itself is an arbitrary code-execution vulnerability. The exposure requires a specific combination: CI runs cargo miri, the Miri step can read secrets through environment variables, the workflow caches target/, and that cache can be read by pull-request jobs. In common GitHub Actions configurations, main-branch jobs write caches while pull requests read them.
The operational lesson is broader than Miri. Build outputs are not automatically secret-free. Rust’s security notice says Cargo, Miri, and Rust do not guarantee that environment variables will never be copied into compilation artifacts; build scripts can also create their own persistence paths.
For ICP developers, the practical review is straightforward:
- Find every workflow that runs cargo miri, including reusable workflows.
- Check whether secrets are placed at workflow or job scope instead of only on the steps that need them.
- Inspect cache actions for target/ or equivalent build-artifact directories.
- Ensure pull-request jobs cannot read caches produced by secret-bearing jobs, or disable caching for the Miri job.
- After remediation, clear affected caches and consider rotating credentials that may have been exposed.
The announced short-term Miri fix limits preserved variables to CARGO_* values, excluding CARGO_*_TOKEN, plus OUT_DIR. The notice says a future design may let Miri and Cargo communicate the required environment-variable list more precisely.
Important caveat: the Rust team says its ecosystem scan may be imperfect, and the fix may not have been available on nightly when the notice was published. Verify the current nightly toolchain before treating the patch as sufficient protection.
The durable rule is simple: any process that can write to a cache must be treated as capable of persisting sensitive inputs. Keep secrets out of jobs that produce reusable build artifacts, even when the tool being run is intended for testing or undefined-behavior detection.
Get the wire in your inbox
Every new signal, straight from the generator. No noise, unsubscribe anytime.


