vulns.co
/
GKData.io MCP

AZAuthorization and tenant boundaries · 1 min read

GitHub fork collaboration applied inconsistent authorization

The first fork-collaboration finding in this article earned USD 20,000.

Read the primary source AZAuthorization and tenant boundariesReviewed 2026-10-02

Root cause

Permission checks differed between creation and modification of the same collaboration setting.

Demonstrated impact

An unauthorized user could obtain write access to affected public forks.

Lessons for review

  • Centralize entitlement checks across mutation paths.
  • Verify that only an authorized owner can grant collaboration privileges.

Award and evidence

USD 20,000Bug Bounty · Researcher Reported

First report only; the separately awarded CVE-2021-22863 is a different record.

Primary public source read; individual award and source provenance verified. No target testing or exploit reproduction performed.

  • Award is reported by the cited source; cash settlement is not independently audited.

Recorded timeline

Published
2021-03-10explicit
Reported
2021-01-22explicit
Awarded
2021-03-02explicit
Fixed
2021-01-27explicit · github.com deployment; Enterprise Server releases followed March 2, 2021.

Sources and provenance

  1. Messing with GitHub’s fork collaboration for fun and profit Teddy Katz · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software