Root cause
Externally controlled method selection was insufficiently restricted to intended operations. The researcher traces this unsafe reflection to a boundary where selection data acquired internal application authority; the GHES advisory corroborates the weakness class. Authentication and organization ownership limited reachability but did not make unrestricted operation selection safe.
Demonstrated impact
GitHub confirms production-container credential exposure and assessed with high confidence that the issue had not been previously exploited and impact was isolated to the researcher. The researcher separately reports GHES code-execution potential; GitHub's GHES advisory corroborates that impact class and requires an authenticated organization-owner account. These sources do not establish code execution on GitHub.com. No secret values or private victim data are retained.
Lessons for review
- Constrain dynamic operation selection to an explicit permitted set, with authorization for the selected operation rather than relying only on the caller's authenticated role.
- Minimize secrets available to each process and define narrow response-data contracts so an unexpected internal result cannot disclose ambient credentials.
- Treat credential exposure as requiring coordinated rotation and dependency review; design recovery procedures that limit disruption.
- For 2026 framework reviews, assess input-to-operation authority separately from input format and keep hosted-service observations distinct from self-managed deployment impact.
Award and evidence
One vendor-reported paid reward linked to this incident, not a program ceiling or total. USD is a contextual inference: the award source uses $ only. GitHub's January 9, 2017 program article, updated June 25, 2021, explicitly uses USD; HackerOne's guidelines version 1.3, updated July 27, 2026, also specify USD. These earlier program-wide and later platform-wide statements are not contemporaneous 2023 payment evidence and do not independently prove this award's currency or settlement. No conflicting denomination was found in the reviewed sources. The retrospective establishes the amount and payment year; no separate award is inferred for the follow-up GHES impact.
Read six public primary sources. Followed the vendor retrospective's single-reward link to the incident notice, reconciled its researcher credit with the linked researcher account and GHES advisory, and separately checked contextual denomination evidence. Promoted the prior 'GitHub highest single award in 2023' candidate after resolving technical attribution and contextual-currency gaps. No target interaction or exploit reproduction.
- Payment is vendor-reported, not an independently audited bank transfer. Exact award-decision and payment days are unknown.
- USD denomination is contextual inference from non-contemporaneous official evidence; neither currency-context source establishes the individual amount or settlement.
- The researcher describes the GHES execution-impact extension separately from the GitHub.com credential-exposure observation. The precise GHES demonstration and implementation details are not independently verified here.
- GitHub's assessment of no earlier exploitation is the vendor's investigation conclusion, not an independent guarantee.
- The record summarizes a patched historical case; review in 2026 does not imply current exposure or grant testing authorization.
Recorded timeline
- Published
- 2024-05-06explicit · Detailed researcher publication and coordinated technical disclosure.
- Public Disclosure
- 2024-01-16explicit · Vendor incident notice; distinct from the later detailed researcher publication.
- Reported
- 2023-12-26explicit · Initial report. The researcher timeline separately dates the GHES execution-impact follow-up to December 28, 2023.
- Fixed
- 2023-12-26explicit · GitHub.com fix only. The vendor incident notice and GHES release notes date GHES patches to January 16, 2024.
- Paid
- 2023explicit · Vendor explicitly says the single reward was paid in 2023; exact payment day and independent settlement evidence are unavailable.
- Award Announced
- 2024-06-11explicit · Publication date of the reviewed award retrospective, updated July 23, 2024; the earliest announcement date is not established.
- Mitigated
- 2023-12-26explicit · Credential rotation began after the GitHub.com fix; this is not a rotation-completion date.
Sources and provenance
- GitHub.com's Environment Variables & GHES Shell Ngo Wei Lin (Creastery) · reviewed 2026-10-04
- 10 years of the GitHub Security Bug Bounty Program Jill Moné-Corallo / GitHub · reviewed 2026-10-04
- Rotating credentials for GitHub.com and new GHES patches Jacob DePriest / GitHub · reviewed 2026-10-04
- GitHub Enterprise Server 3.11.3 release notes GitHub · reviewed 2026-10-04
- Bug Bounty anniversary promotion: bigger bounties in January and February Neil Matatall / GitHub · reviewed 2026-10-04
- Vulnerability Disclosure Guidelines (Vulnerability Disclosure Standards) HackerOne · reviewed 2026-10-04
Record reviewed 2026-10-04. Snapshot d5550c789111. Open the complete JSON contract.