GitHub Restructures Its Bug Bounty Program After Being Overwhelmed by AI Alphabet Soup

Despite the valuable assistance AI provides, please do not confuse speed with haste.

In mid-May, GitHub signaled to participants in its public bug bounty program. Behind the scene was a flood of low-quality submissions, essentially for two reasons. First, because they fell outside the scope. Second, due to a lack of proof of real impact.

In this context, GitHub said it would apply stricter scrutiny to the presence of functional PoCs. More broadly, it reminded that, AI-assisted or not, any find should be validated before submission. While ensuring reports are concise and well-structured (problem summary, steps to reproduce, impact statement).

Read also: GitHub Actions becomes a channel for prompt injection

This reminder was accompanied by another one about shared responsibility. GitHub revisited attacks involving an “explicit user engagement.” It cited, among other things, the cloning of a malicious repository and the use of AI to analyze insecure code. In broad terms: these scenarios are generally not considered bypassing its security controls.

GitHub also announced the end of monetary rewards for reports that do not demonstrate meaningful impact but still enable code or documentation fixes. Their authors may now be eligible only for goodies.

Reward thresholds largely maintained… for VIPs

A new step in the restructuring of the bug bounty program has been crossed. It includes a revamp of the invitation-only VIP program*. Eligibility criterion: the number of validated reports. At minimum:

  • 1 for a critical vulnerability
  • 2 for important vulnerabilities
  • 4 for medium-severity vulnerabilities
  • 7 for low-severity vulnerabilities

Beyond a promise of a “tighter” relationship with GitHub’s security teams, VIPs can expect higher rewards. The caps are set at:

  • 1000 $ for a low-severity vulnerability
  • 7500 $ for a medium-severity vulnerability
  • 20 000 $ for a high-severity vulnerability
  • 30 000 $ for critical findings

These caps remain indicative. GitHub reserves the right to adjust rewards based on the discoveries. The same goes for non-VIPs… who, on paper, stand to lose out.

Old caps New caps
Low 2000 $ 250 $
Medium 10 000 $ 2000 $
High 20 000 $ 5000 $
Critical 30 000 $ 10 000 $

GitHub doesn’t hide it: it trims the rewards for the public bug bounty in order to be able to grant higher sums to VIPs.

GitHub will now use the HackerOne reputation score

Another novelty: the activation of the HackerOne reputation signal. This reputation metric, if not reached, limits the number of submissions allowed: 4 per program for new members (fewer than 5 resolved reports), 8 for veterans (more than 5 resolved reports). The requirement will take effect by July 27, 2026.

Severity level Examples of vulnerabilities
Critical – Arbitrary command execution on a production server
– Arbitrary SQL query execution on a production database
– Access to internal production systems
– Access to another user’s data in GitHub Actions
High – Bypassing authorization logic to exceed a colleague’s access rights
– Discovery of sensitive user or GitHub data in a publicly accessible resource
– Deletion of a repository or a package that should be inaccessible
– Transmitting credentials from a client application to an unexpected server
Medium – Disclosing issue titles in private repositories
– Compromising the integrity of a package
– Injecting content on GitHub.com without bypassing Content Security Policy or exploiting another user’s session
Low – Triggering exceptions that could affect many users
– Exfiltrating credentials in logs
– Enabling a feature in early access for a user without their consent

* There was already an invitation-only VIP program. It granted access to a dedicated Slack channel, exclusive goodies, and early-access features. But it did not offer higher rewards. To be eligible, one had to have earned at least $20,000 from the bug bounty and have submitted at least 2 reports in the last two years.

Dawn Liphardt

Dawn Liphardt

I'm Dawn Liphardt, the founder and lead writer of this publication. With a background in philosophy and a deep interest in the social impact of technology, I started this platform to explore how innovation shapes — and sometimes disrupts — the world we live in. My work focuses on critical, human-centered storytelling at the frontier of artificial intelligence and emerging tech.