Root cause
GitHub identifies improper access control in cross-repository comparison (vendor-report; vendor-release). Access to one repository did not establish permission to disclose content from another contributing repository. The vendor describes prerequisites of existing repository access and prior knowledge of private-repository references; this was not described as unrestricted anonymous browsing. The conceptual failure is authorizing a derived view without preserving every source repository’s access boundary; implementation-level check placement is not disclosed.
Demonstrated impact
The vendor confirms limited code disclosure from an otherwise unauthorized repository (vendor-report; vendor-release). The public summary does not establish complete repository extraction, write access, account takeover, or exploitation in the wild; those outcomes must not be inferred from the broader report title.
Lessons for review
- Editorial design lesson: authorize every contributing source under the requesting actor before returning a combined or derived view.
- Editorial review objective: ensure that permission to access one repository never substitutes for permission to read another repository’s content.
- GitHub lists historical fixes in GHES 3.14.17, 3.15.12, 3.16.8 and 3.17.5 (vendor-report). These are historical remediation evidence, not current upgrade recommendations; the 3.17 documentation now marks that release series unsupported (vendor-release).
Award and evidence
One report award; cash receipt is unverified. USD is inferred from HackerOne’s platform-wide payment policy reviewed in October 2026, later than the August 2025 award; that context does not independently establish settlement.
Freshly read public GitHub summary and award/disclosure events in the cloud browser, plus GitHub release notes and HackerOne currency policy through web retrieval. Added bounded conceptual analysis without reproduction or testing.
- Public report content supplies a vendor summary, not implementation-level patch details or a complete demonstration transcript.
- GitHub.com deployment timing and exploitation-in-the-wild status are not established by the reviewed sources.
- Release availability, report resolution and detailed publication have different dates.
- Cash receipt is unverified; later platform-wide USD policy is contextual denomination evidence.
Recorded timeline
- Published
- 2025-09-23explicit · Detailed report disclosure event, activity-37054322.
- Public Disclosure
- 2025-08-25explicit · Vendor advisory in Enterprise Server 3.17.5 release notes preceded the detailed report.
- Reported
- 2025-05-03explicit
- Awarded
- 2025-08-26explicit
- Fixed
- 2025-08-25explicit · Public GHES 3.17.5 release. Report Resolved status is August 26; GitHub.com deployment timing is not established.
Sources and provenance
- GitHub HackerOne report 3124517 GitHub security team and furbreeze · reviewed 2026-10-03
- GitHub Enterprise Server 3.17.5 release notes GitHub · reviewed 2026-10-03
- Vulnerability Disclosure Standards: Bug Bounty payment denomination HackerOne · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.