GitHub Security Lab
Securing the world's software, together
GitHub Security Lab
Securing the world's software, together
GitHub Security Lab’s mission is to inspire and enable the community to secure the open source software we all depend on.

What we do
![]()
Find vulnerabilities
Our researchers find and report new vulnerabilities in the open source projects everyone relies on.
![]()
Educate the community
We share our research through proof-of-concepts, articles, tutorials, conferences and community events.
![]()
Amplify security research
We scale the security research of our community by performing Variants Analysis for open source projects with CodeQL.
![]()
Notify the ecosystem
We curate a database of CVEs and security advisories to notify open source developers and maintainers.
Our principles
![]()
Empower others
Make securing open source easy for developers and maintainers.
![]()
Foster collaboration
Build a community of security researchers to serve the global open source community.
Vulnerabilities we've disclosed so far
-
Quadratic complexity algorithm in cmark - CVE-2023-22486
-
Out-of-bounds read in cmark-gfm - CVE-2023-22485
-
Quadratic complexity algorithm in cmark - CVE-2023-22484
-
Quadratic complexity algorithms in cmark-gfm - CVE-2023-22483
-
SQL injection vulnerabilities in Owncloud Android app - CVE-2023-24804, CVE-2023-23948
by Security Lab researchers
260 since March 2020
Meet the team
Join the effort
As a security researcher, your expertise is instrumental in securing the world’s software. Codify that knowledge as an expressive, executable, and repeatable CodeQL query that can be run on many codebases. Get rewarded for queries that have a positive impact on open source projects through our bounty program.