Skip to content

Add topic: security-research#5135

Closed
orihamama wants to merge 1 commit intogithub:mainfrom
orihamama:security-poc-gh006
Closed

Add topic: security-research#5135
orihamama wants to merge 1 commit intogithub:mainfrom
orihamama:security-poc-gh006

Conversation

@orihamama
Copy link
Copy Markdown

Adding a new topic for security research resources.

This demonstrates that the lint.yml workflow using pull_request_target
checks out attacker-controlled code and runs bundle install, which
evaluates the Gemfile as Ruby code — enabling arbitrary code execution.

Informational only — no destructive actions.
@orihamama orihamama requested a review from a team as a code owner April 26, 2026 18:08
@orihamama
Copy link
Copy Markdown
Author

Closing — this was an authorized security test under the GitHub Bug Bounty program. Report will be submitted via HackerOne.

@orihamama orihamama closed this Apr 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant