logo

Six years of the GitHub Security Bug Bounty program

ID: 5a9733fc-9941-5ed2-9140-592acfe34bfe

STIX ID: report--5a9733fc-9941-5ed2-9140-592acfe34bfe

Feed Name: HackerOne Blog

Threat Score
30/100

Date Published: 2023-09-11

Date Updated: 2026-06-11

...
...

GitHub’s 2019 Security Bug Bounty recap: the program surpassed $1M in payouts and accelerated response to submissions. Notable findings included an OAuth authorization bypass using cross-site HEAD requests and a Mercurial-import command injection that could lead to RCE; both were patched quickly with no evidence of exploitation. The post also describes scope expansion (Actions, Dependabot, mobile, LGTM), live-hacking events and private bounties, the Security Lab bounty program, and plans to assign CVEs for Enterprise Server issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.