Hi 👋 we are the GitHub Security Lab. Find more information about us here:
Follow
GitHub Security Lab
@GHSecurityLab
GitHub Security Lab’s mission is to inspire and enable the community to secure the open source software we all depend on.
securitylab.github.comJoined October 2019
GitHub Security Lab’s Tweets
If you write a nice CodeQL query and propose it to the open source community, you can get not one, but TWO bounty rewards from the Security Lab. We're making changes to the Bug Slayer bug bounty program: securitylab.github.com/research/new-b
2
45
GHSL-2020-183: Arbitrary command injection in GitHub workflows of Checkstyle
2
5
GHSL-2021-099: ReDoS (Regular Expression Denial of Service) in Solidus - CVE-2021-43805
1
5
GHSL-2021-1045: Cross-Site Scripting (XSS) in jQuery MiniColors Plugin - CVE-2021-32850
2
2
GHSL-2021-1047: Cross-Site Scripting (XSS) in Mind-elixir - CVE-2021-32851
3
1
Topics to follow
Sign up to get Tweets about the Topics you follow in your Home timeline.
Carousel
GHSL-2021-1053: Path traversal in Grafana REST API - CVE-2021-43813, CVE-2021-43815
13
30
We know everyone is busy right now, so here's 3 minutes on how to prevent arbitrary file reads in our new #SecurityBites github.co/31S9sjb
7
13
Establish strong rules of engagement 📋
Make reporting actionable ☑️
Notify users 🔔
A guide to disclosing security vulnerabilities to #opensource projects with Nancy Gariché of
19
23
Learn how to define robust project security requirements in the new installment of our OWASP proactive controls series
16
53
PoC video for Ubuntu accountsservice CVE-2021-3939. It's not quick, but it gets you a root shell eventually. securitylab.github.com/research/ubunt
0:28
3.9K views
46
93
"Exploits are really the closest thing to magic spells we have in this world" according to Halvar Flake. demystifies an exploit of a double-free vulnerability in Ubuntu github.co/3pVse0G
1
67
248
GHSL-2021-113: ReDoS (Regular Expression Denial of Service) in JS Beautifier
1
6
Make sure the code you run is actually the code you wrote! Learn about preventing injection vulnerabilities in your code in this installment of #SecurityBites github.co/3oBFpEQ
11
29
GHSL-2021-122: ReDoS (Regular Expression Denial of Service) in Frappe
1
3
GHSL-2021-121: ReDoS (Regular Expression Denial of Service) in StreamAlert
1
1
GHSL-2021-117: ReDoS (Regular Expression Denial of Service) in python-ldap
2
2
GHSL-2021-115: ReDoS (Regular Expression Denial of Service) in Spyne
1
GHSL-2021-1032: Unauthorized repository modification or secrets exfiltration from a Pull Request in Solana GitHub workflow
1
4


