vulns.co
/
GKData.io MCP

AZAuthorization and tenant boundaries · 1 min read

GitHub GraphQL collaboration changes lacked author consent

The second fork-collaboration report received its own USD 10,000 award.

Read the primary source AZAuthorization and tenant boundariesReviewed 2026-10-02

Root cause

One API path omitted the pull-request-author entitlement required to change collaboration consent.

Demonstrated impact

A base-repository maintainer could gain unauthorized write access to a contributor branch.

Lessons for review

  • Keep collaboration consent separate from ordinary metadata privileges.
  • Enforce identical ownership rules across API implementations.

Award and evidence

USD 10,000Bug Bounty · Researcher Reported

Separate report and award, initially marked duplicate then reopened after its distinct fix requirement was confirmed.

Primary public source read; individual award and source provenance verified. No target testing or exploit reproduction performed.

  • Award remains researcher-reported; vendor release notes corroborate the distinct CVE and remediation.

Recorded timeline

Published
2021-03-10explicit
Reported
2021-01-24explicit
Awarded
2021-03-02explicit
Fixed
2021-01-28explicit · github.com deployment; Enterprise Server releases followed March 2, 2021.

Sources and provenance

  1. Messing with GitHub’s fork collaboration for fun and profit Teddy Katz · reviewed 2026-10-02
  2. GitHub Enterprise Server 3.0.1 security fixes GitHub · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software