Web Hack List

Preliminary research

How We Exploited Qodo: From a PR Comment to RCE and an AWS Admin Key — Leaked Twice

AI-collected research leads through 2 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.

Traces pull-request comment options into Dynaconf dynamic-variable evaluation and uses `@json`, `@jinja` and `@format` transformations to bypass successive blocklists. A later include and documentation-path chain reaches the production GitHub App, leaks an AWS administrator key and achieves remote code execution.

Record

Researcher
Nils Amiet
Published by
Kudelski Security Research

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Nils Amiet, first published at the original source. Preserved copies are kept so the citation survives its host.