Skip to content

[Security Research] Authorized bug bounty PRT verification — a0acfc4f - #636

Draft
fitzpr wants to merge 1 commit into
aws:mainfrom
fitzpr:security-research/prt-verify-a0acfc4f
Draft

[Security Research] Authorized bug bounty PRT verification — a0acfc4f#636
fitzpr wants to merge 1 commit into
aws:mainfrom
fitzpr:security-research/prt-verify-a0acfc4f

Conversation

@fitzpr

@fitzpr fitzpr commented Aug 10, 2026

Copy link
Copy Markdown

Automated security research verification — authorized bug bounty testing

Security researcher atoma (HackerOne: https://hackerone.com/atoma) is verifying whether integration-testing.yml is exploitable via pull_request_target with fork code checkout.

This draft PR is part of responsible disclosure under aws's bug bounty program. It will be automatically closed and the fork deleted within 60 seconds. No credentials are exfiltrated — the only test is whether a DNS lookup from the Actions runner reaches an OOB listener, confirming execution of fork-supplied code.

No action needed. This PR closes itself automatically.

Questions? Contact via HackerOne before closing: https://hackerone.com/atoma

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xs PR size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant