Skip to content

[Security Research] Authorized bug bounty PRT verification — 910c1030#41

Closed
fitzpr wants to merge 1 commit into
Roblox:mainfrom
fitzpr:security-research/prt-verify-910c1030
Closed

[Security Research] Authorized bug bounty PRT verification — 910c1030#41
fitzpr wants to merge 1 commit into
Roblox:mainfrom
fitzpr:security-research/prt-verify-910c1030

Conversation

@fitzpr

@fitzpr fitzpr commented May 29, 2026

Copy link
Copy Markdown

Automated security research verification — authorized bug bounty testing

Security researcher atoma (HackerOne: https://hackerone.com/atoma) is verifying whether ci.yml is exploitable via pull_request_target with fork code checkout.

This draft PR is part of responsible disclosure under Roblox's bug bounty program. It will be automatically closed and the fork deleted within 60 seconds. No credentials are exfiltrated — the only test is whether a DNS lookup from the Actions runner reaches an OOB listener, confirming execution of fork-supplied code.

No action needed. This PR closes itself automatically.

Questions? Contact via HackerOne before closing: https://hackerone.com/atoma

@fitzpr fitzpr closed this May 29, 2026
@fitzpr fitzpr deleted the security-research/prt-verify-910c1030 branch May 29, 2026 20:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant