Root cause
Object validation differed between creation and mutation; automation relied on a branch-type invariant that was not consistently enforced.
Demonstrated impact
Repository secrets and write authority could become available to an unauthorized workflow.
Lessons for review
- Enforce security invariants at every mutation and at their privileged consumers.
- Keep repository secrets confined to explicitly trusted execution contexts.
Award and evidence
Single finding; the later 2022 follow-up earned USD 7,500 and is excluded.
Primary public source read; individual award and source provenance verified. No target testing or exploit reproduction performed.
- Award is reported by the cited source; cash settlement is not independently audited.
Recorded timeline
- Published
- 2021-03-17explicit
- Reported
- 2021-02-04explicit
- Awarded
- 2021-03-03explicit
- Fixed
- 2021-03-02explicit · GitHub Enterprise Server 3.0.1 release; github.com was fixed earlier in February, without an exact final timestamp in the source.
Sources and provenance
- Stealing arbitrary GitHub Actions secrets Teddy Katz · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.