Earlier quoted context omitted.
Because it has the ability to write tests for the PR in question.
Then it should open a PR for those tests so it can go through the normal CI and review process.
How we exploited CodeRabbit: From simple PR to RCE and write access on 1M repos
41–50 of 244 posts
Re: How we exploited CodeRabbit: From simple PR to RCE and write access on 1M repos
#42No bounty was paid for this?
Re: How we exploited CodeRabbit: From simple PR to RCE and write access on 1M repos
#43hey, this is Howon from CodeRabbit here. we wish to note that this RCE was reported and fixed in January. it was entirely prospective and no customer data was affected. we have extensive sandboxing for basically any execution of anything now, including any and every tool and all generated code of any kind under the CodeRabbit umbrella. if you want to learn how CodeRabbit does the isolation, here's a blog post about h…
Re: How we exploited CodeRabbit: From simple PR to RCE and write access on 1M repos
#44Re: How we exploited CodeRabbit: From simple PR to RCE and write access on 1M repos
#45hey, this is Howon from CodeRabbit here. we wish to note that this RCE was reported and fixed in January. it was entirely prospective and no customer data was affected. we have extensive sandboxing for basically any execution of anything now, including any and every tool and all generated code of any kind under the CodeRabbit umbrella. if you want to learn how CodeRabbit does the isolation, here's a blog post about h…
Re: How we exploited CodeRabbit: From simple PR to RCE and write access on 1M repos
#46No bounty was paid for this?
First thing I looked for... this is an absolutely critical vulnerability that if exploited would have completely ruined their business. No bounty!?
If anything, they got paid in exposure.
Re: How we exploited CodeRabbit: From simple PR to RCE and write access on 1M repos
#47Re: How we exploited CodeRabbit: From simple PR to RCE and write access on 1M repos
#48Re: How we exploited CodeRabbit: From simple PR to RCE and write access on 1M repos
#49hey, this is Howon from CodeRabbit here. we wish to note that this RCE was reported and fixed in January. it was entirely prospective and no customer data was affected. we have extensive sandboxing for basically any execution of anything now, including any and every tool and all generated code of any kind under the CodeRabbit umbrella. if you want to learn how CodeRabbit does the isolation, here's a blog post about h…
In case you don't want to read through the PR
Re: How we exploited CodeRabbit: From simple PR to RCE and write access on 1M repos
#50hey, this is Howon from CodeRabbit here. we wish to note that this RCE was reported and fixed in January. it was entirely prospective and no customer data was affected. we have extensive sandboxing for basically any execution of anything now, including any and every tool and all generated code of any kind under the CodeRabbit umbrella. if you want to learn how CodeRabbit does the isolation, here's a blog post about h…
But do you still store your GH API private key in environment variables?