GitHub Security Lab

GitHub Security Lab

Securing the world's software, together

GitHub Security Lab

Securing the world's software, together

GitHub Security Lab’s mission is to inspire and enable the community to secure the open source software we all depend on.

Follow @GHSecurityLab

What we do

Find vulnerabilities

Find vulnerabilities

Our researchers find and report new vulnerabilities in the open source projects everyone relies on.

Educate the community

Educate the community

We share our research through proof-of-concepts, articles, tutorials, conferences and community events.

Amplify security research

Amplify security research

We scale the security research of our community by performing Variants Analysis for open source projects with CodeQL.

Notify the ecosystem

Notify the ecosystem

We curate a database of CVEs and security advisories to notify open source developers and maintainers.

Our principles

Empower others

Empower others

Make securing open source easy for developers and maintainers.

Foster collaboration

Foster collaboration

Build a community of security researchers to serve the global open source community.

Vulnerabilities we've disclosed so far

  • Quadratic complexity algorithm in cmark - CVE-2023-22486

  • Out-of-bounds read in cmark-gfm - CVE-2023-22485

  • Quadratic complexity algorithm in cmark - CVE-2023-22484

  • Quadratic complexity algorithms in cmark-gfm - CVE-2023-22483

  • SQL injection vulnerabilities in Owncloud Android app - CVE-2023-24804, CVE-2023-23948

shape

shape

by Security Lab researchers

260 since March 2020

Meet the team

Joseph Katsioloudes

Making security easy for developers

GitHub icon @jkcso twitter icon @jkcso

Nancy Gariché

Community Building as Secure Code

GitHub icon @nanzggits

Michael Stepankin

get shell or die trying.

GitHub icon @artsploit

Kevin Stubbings

Alright get out. From now on I'll do the memory managing around here.

GitHub icon @Kwstubbs

Peter Stöckli

Helping developers by breaking things.

GitHub icon @p- twitter icon @ulldma

Xavier René-Corail

3-legged race organizer: Building bridges between Dev and Sec

GitHub icon @xcorail twitter icon @xcorail

Ron Wochner

Breaker of things, fixer of some, curator of many.

GitHub icon @ronwoch

Shelby Cunningham

Security person with a dash of data privacy

GitHub icon @shelbyc
shape shape shape

mona puzzle

Join the effort

As a security researcher, your expertise is instrumental in securing the world’s software. Codify that knowledge as an expressive, executable, and repeatable CodeQL query that can be run on many codebases. Get rewarded for queries that have a positive impact on open source projects through our bounty program.

See our bounties

Our latest research

See all our articles