vulns.co
/
GKData.io MCP

AZAuthorization and tenant boundaries · 2 min read

GitHub OAuth consent failed across request-method semantics

A USD 25,000 researcher-reported award illustrates how differing framework and controller assumptions can remove an OAuth consent boundary.

Read the primary source AZAuthorization and tenant boundariesReviewed 2026-10-02

Root cause

The researcher compared the consent screen’s intended state change with routing and controller logic. The framework accepted a wider set of request semantics than the controller expected. Application logic treated the unexpected case as permission to grant access, even though the usual consent safeguards did not apply. The failed invariant was that every new grant required the user’s explicit, validated approval.

Demonstrated impact

The researcher reports that a user visiting a malicious website could unintentionally grant an application access to read or modify private GitHub data. This demonstrates unauthorized delegated access, rather than evidence that the attacker learned the account password or that all unrelated account controls failed.

Lessons for review

  • Require positive validation of the intended state-changing operation; reject unrecognized alternatives rather than defaulting to a privileged action.
  • Model framework routing, request interpretation and consent enforcement as separate layers whose assumptions must agree.
  • Verify that consent and request-integrity checks remain attached to every path that creates a grant.
  • The source dates the production fix and later Enterprise releases, but does not document the exact patch here; these lessons are defensive recommendations.

Award and evidence

USD 25,000Bug Bounty · Researcher Reported

Individual report; production fix date is for github.com, with enterprise releases following June 26.

Re-read the researcher’s intended-consent model, framework/controller distinction, impact and remediation timeline. Expanded the original explanation while omitting the triggering request and reproduction details.

  • Researcher-reported award; cash settlement is not independently audited.
  • The reported impact requires user interaction. Exact vendor patch implementation and evidence of real-world abuse are not supplied.

Recorded timeline

Published
2019-11-05explicit
Reported
2019-06-19explicit
Awarded
2019-06-26explicit
Fixed
2019-06-20explicit

Related visual models

Sources and provenance

  1. Bypassing GitHub’s OAuth flow Teddy Katz · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software