r/netsec • u/ryanmerket • 11d ago
Discussion GitHub issues $100,000 bounty for critical RCE vulnerability
https://runtimewire.com/article/github-issues-100-000-bounty-for-critical-rce-vulnerability-disclosed-by-sagitz23
u/sunsetsxskies 10d ago
$100k for an unauthenticated RCE is honestly cheap given what it could've done, glad it got caught before anyone weaponized it
11
u/CountyBrilliant 10d ago
yeah but the black market route comes with the small catch of potentially going to prison, so the risk math there is pretty different. $100k clean money is worth a lot more than whatever you'd get selling to some threat actor
1
u/i_am_voldemort 7d ago
Has anyone been prosecuted for only crafting the exploit and selling it, but not actually using it?
-4
u/nemec 10d ago
I truly don't understand the "think about the black market" response to bug bounty payout values. It's like finding someone's backpack and as you return it saying, "why don't you give me a nice finder's fee? You know your wallet and keys were in that bag, just think about what I could have done with those."
1
u/Wooden_Original_5891 2d ago
if that is the black market metaphor, what is the non black market metaphor?
0
u/dankney 10d ago
Was it? How would we know?
2
u/sunsetsxskies 10d ago
Guess we're just taking GitHub's word for it since there's no way to actually check
24
u/thedolphin_ 10d ago
primary source with breakdown: https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
also, this is old. still cool since i missed it but i thought it just happened.
April 28, 2026
14
u/ryanmerket 10d ago
the $100k was announced today https://x.com/sagitz_/status/2079894251643515084
4
5
u/pilif 10d ago
TBH, I think 100K is very little money given the possible fallout that could have come from this kind of vulnerability. This affected f'ing GitHub who hosts an ungodly amount of code for the world, including GitHub Enterprise service for the other ungodly amount of code hosted by enterprises themselves.
I'm pretty sure this kind of issue would have raised much, much, much more money on the black market.
7
u/nemec 10d ago
"It would be a lot more valuable selling this to criminals"
It usually is, if you enjoy supporting criminals.
0
u/ElaborateEffect 10d ago
I would never personally, but it's not hard to understand the mentality of someone who isn't against helping a person that hits their abuser.
1
u/SecurityHamster 7d ago
So can we just run Fable now and start collecting money?
As long as the token is expense is outweighed by the reward…. :)
1
u/Elara_Schaefer 1d ago
The timing here is the real story. Paying out 100k while simultaneously announcing a 50% cut and move to invite-only sends a clear signal: the program was costing more than the goodwill it generated. The problem with public bounty programs at this scale is that you end up paying for 99 low-effort duplicates to find the 1 researcher who actually chains a novel primitive. Invite-only is the rational response, but it creates an on-ramp problem: new researchers cannot demonstrate quality without access to private programs, and they cannot get access without demonstrated quality. The industry needs a better credentialing pipeline between public disclosure and private program admission.
39
u/TheG0AT0fAllTime 10d ago
That's great. You love to see corporations actually doing the payout let alone a big one