Data from deleted and private repositories on GitHub can be accessed indefinitely due to the platform's architectural design. This vulnerability, termed Cross Fork Object Reference (CFOR), allows users to fetch commit data via known or brute-forced SHA-1 commit hashes, even if the repository or fork has been deleted. This issue can expose sensitive information and is inherent to how GitHub manages repository networks.

8m read timeFrom trufflesecurity.com
Post cover image
Table of contents
Accessing Deleted Fork DataAccessing Deleted Repo DataAccessing Private Repo DataHow do you actually access the data?GitHub’s PoliciesImplications
6 Comments

Sort: