苹果测试工程师的日常
10:00 · 2026年4月29日 · 周三
https://fixupx.com/i/status/2049153195243372569
🧵
Thread • FixupX
sagitz (@sagitz_)
We achieved Remote Code Execution on GitHub - and got access to millions of repositories belonging to other users and organizations
🤯
All it took was a single `git push`
Here's how we did it (CVE-2026-3854)
🧵
⬇️
Home
Powered by
BroadcastChannel
&
Sepia