url-handler

1 article
Sort: New Top Best
clear filter
0
vulnerability

A path traversal vulnerability in GitHub Desktop's x-github-client:// URI scheme handler allowed arbitrary code execution on macOS by opening malicious application bundles from a cloned repository without user interaction or Gatekeeper validation. The vulnerability was patched in GitHub Desktop v1.3.4.

GitHub Desktop H1-702 HackerOne 0xacb zhuowei CVE-2018-1000559 github-desktop-poc
pwning.re · devanshbatham/Awesome-Bugbounty-Writeups · 5 hours ago · details