Woodpecker's custom workspace allow to overwrite plugin entrypoint executable
The server allow to create any user who can trigger a pipeline run malicious workflows: Those workflows can either lead to a host takeover that runs the agent executing the workflow. Or allow to extract the secrets who would be normally provided to the plugins who's entrypoint are overwritten.