GitHub disclosed a bug submitted by legit-security: https://hackerone.com/reports/1619604 – Bounty: $4000 [Source]