Securing the world's software, together
Securing the world's software, together
GitHub Security Lab’s mission is to inspire and enable the community to secure the open source software we all depend on.

What we do

Our researchers find and report new vulnerabilities in the open source projects everyone relies on.

We share our research through proof-of-concepts, articles, tutorials, conferences and community events.

We scale the security research of our community by performing Variants Analysis for open source projects with CodeQL.

We curate a database of CVEs and security advisories to notify open source developers and maintainers.
Our principles

Make securing open source easy for developers and maintainers.

Build a community of security researchers to serve the global open source community.
Vulnerabilities we've disclosed so far
-
Arbitrary Intent in WordPress for Android leads to read and write access
-
ReDoS (Regular Expression Denial of Service) in Dependency Parser
-
Use-after-free in alias memory of the Arm Mali gpu kernel driver - CVE-2022-20186
-
Arbitrary command execution through Apache Commons Configuration - CVE-2022-33980
-
Use After Free (UAF) in Qualcomm NPU driver - CVE-2022-22068
Meet the team
Catching up on all the hacking that I should have done in the 1990s
Join the effort
As a security researcher, your expertise is instrumental in securing the world’s software. Codify that knowledge as an expressive, executable, and repeatable CodeQL query that can be run on many codebases. Get rewarded for queries that have a positive impact on open source projects through our bounty program.
See our bounties