T05 · Unauthorized Access and Privilege Escalation
- Location
PUBLISH_GUIDE.md:12- Finding
Excessively Privileged GitHub Personal Access Token Instructions
- Content
View full analysis
Vulnerability Details
File Location:
PUBLISH_GUIDE.md, lines 12-20
Vulnerability Type: Excessive credential permissions and violation of least privilege
Risk Level: MediumVulnerable Code Snippet
The guide instructs users to generate a classic GitHub token with the following permissions:
text Generate new token (classic) Permissions: - repo (Full control of private repositories) - read:org (Read organization and team membership) Generate token Copy the token immediately because it is displayed only once.Technical Analysis
The documented operation is publishing a single public repository. It does not require a classic personal access token with full control over every private repository accessible by the user. Organization membership access is also not shown to be necessary.
Classic tokens using the
reposcope provide broad access that is not restricted to the project being published. If the token is exposed through shell history, Git credential storage, terminal logging, malware, a compromised credential helper, or another local process, an attacker may use it against unrelated repositories.The
read:orgpermission additionally exposes organization and team membership information. This can assist reconnaissance and targeted attacks even if the organization data is not directly modified.Attack Path
- A user follows the publishing guide and creates a classic personal access token.
- The user grants the recommended
repoandread:orgscopes. - The token is entered during Git authentication and may be retained by a credential helper or exposed to a compromised local process.
- An attacker extracts the token from the affected environment.
- The attacker authenticates to GitHub using the token.
- The attacker accesses or modifies unrelated private repositories available to the victim and enumerates organization membership data.
- Depending on the victim's r ...[truncated 683 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the classic PAT instructions with a fine-grained personal access token.
- Restrict the token to the single target repository.
- Grant only the minimum repository permissions required to push content, such as narrowly scoped Contents write access.
- Remove
read:orgunless a documented publishing operation specifically requires it. - Configure a short expiration period and require token rotation.
- Prefer
gh auth loginor an approved Git credential manager rather than manually handling tokens as passwords. - Warn users not to place tokens in repository files, command-line arguments, shell history, or plaintext configuration.
- Document immediate revocation procedures for suspected exposure.
- Where practical, use a dedicated publishing workflow with environment protection and repository-scoped credentials.
