$25,000 GitHub pages RCE via YAML file - Bug Bounty Reports Explained

Опубликовано: 17 Апрель 2026
на канале: Bug Bounty Reports Explained
11,388
637

📧 Subscribe to BBRE Premium: https://bbre.dev/premium
✉️ Sign up for the mailing list: https://bbre.dev/nl
📣 Follow me on Twitter: https://bbre.dev/tw

This video is about an RCE vulnerability in Github pages. The report on hackerone was rewarded $25,000. The issue exploited a YAML file used to configure Jekyll website.

Report/blogpost:
https://devcraft.io/2020/10/20/github...
Reporter's twitter:
  / wcbowling  
His blog:
https://devcraft.io/

Follow me on twitter:
  / gregxsunday  

Opensnoop tool:
https://github.com/brendangregg/perf-...

Timestamps:
00:00 Intro
00:28 What is Github Pages?
00:56 What is Jekyll?
01:46 What is Kramdown?
02:17 The root cause of the vulnerability
03:34 Uploading our .rb file on the server
04:25 Winning the race condition
05:23 The fix, reward and outro

#rce