Bug Bounty

HackerOne Bug Bounty Disclosure: improper-handling-of-null-bytes-in-github-actions-runner-allows-an-attacker-to-set-arbitrary-environment-variablesbyryotak

Programme HackerOne GitHub GitHub Submitted by ryotak ryotak Report Improper handling of null bytes in GitHub Actions Runner allows an...

HackerOne Bug Bounty Disclosure: desktop-client-can-be-tricked-into-opening/executing-local-files-when-clicking-a-nc://open/-linkbylukasreschke

Programme HackerOne Nextcloud Nextcloud Submitted by lukasreschke lukasreschke Report Desktop client can be tricked into opening/executing local files when clicking...