Root cause
Permission checks differed between creation and modification of the same collaboration setting.
Demonstrated impact
An unauthorized user could obtain write access to affected public forks.
Lessons for review
- Centralize entitlement checks across mutation paths.
- Verify that only an authorized owner can grant collaboration privileges.
Award and evidence
USD 20,000Bug Bounty · Researcher Reported
First report only; the separately awarded CVE-2021-22863 is a different record.
Primary public source read; individual award and source provenance verified. No target testing or exploit reproduction performed.
- Award is reported by the cited source; cash settlement is not independently audited.
Recorded timeline
- Published
- 2021-03-10explicit
- Reported
- 2021-01-22explicit
- Awarded
- 2021-03-02explicit
- Fixed
- 2021-01-27explicit · github.com deployment; Enterprise Server releases followed March 2, 2021.
Sources and provenance
- Messing with GitHub’s fork collaboration for fun and profit Teddy Katz · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.