Root cause
One API path omitted the pull-request-author entitlement required to change collaboration consent.
Demonstrated impact
A base-repository maintainer could gain unauthorized write access to a contributor branch.
Lessons for review
- Keep collaboration consent separate from ordinary metadata privileges.
- Enforce identical ownership rules across API implementations.
Award and evidence
USD 10,000Bug Bounty · Researcher Reported
Separate report and award, initially marked duplicate then reopened after its distinct fix requirement was confirmed.
Primary public source read; individual award and source provenance verified. No target testing or exploit reproduction performed.
- Award remains researcher-reported; vendor release notes corroborate the distinct CVE and remediation.
Recorded timeline
- Published
- 2021-03-10explicit
- Reported
- 2021-01-24explicit
- Awarded
- 2021-03-02explicit
- Fixed
- 2021-01-28explicit · github.com deployment; Enterprise Server releases followed March 2, 2021.
Sources and provenance
- Messing with GitHub’s fork collaboration for fun and profit Teddy Katz · reviewed 2026-10-02
- GitHub Enterprise Server 3.0.1 security fixes GitHub · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.