
Abdullah Kareem@CyberKareem
Patch
New one on the board: CVE-2026-59185. Found an IDOR in http://identrail.com where you could claim someone else's GitHub App install just by sending its id. server never checked ownership. Fixed + credited. #appsec #research #infosec https://t.co/IsUHJTv4aK
Post summary
A new CVE (CVE‑2026‑59185) was discovered as an IDOR on identrail.com that enabled impersonation of GitHub App installs by ID; the flaw has been resolved and credited.
0000095
236 followersView on X
