Image missing.
Weaponizing Dependabot: Pwn Request at its finest

created: June 6, 2025, 10:55 a.m. | updated: June 7, 2025, 12:14 p.m.

But in our Dependabot deputy confusion scenario, Dependabot has a very particular naming scheme for its branches (dependabot/<ecosystem>/...). So, you might think, "Phew, Dependabot deputy confusion is immune to injection Pwn Requests!" The @dependabot recreate: Comment @dependabot recreate on the original Dependabot Pull Request. Default Branch Swap: Change the default branch of your forked repository to this new payload-named branch. The @dependabot merge Command: Go to the original Dependabot PR and comment: @dependabot merge .

6 months, 1 week ago: Hacker News