Preliminary research
How We Exploited Qodo: From a PR Comment to RCE and an AWS Admin Key — Leaked Twice
AI-collected research leads through 2 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
Traces pull-request comment options into Dynaconf dynamic-variable evaluation and uses `@json`, `@jinja` and `@format` transformations to bypass successive blocklists. A later include and documentation-path chain reaches the production GitHub App, leaks an AWS administrator key and achieves remote code execution.
Record
- Researcher
- Nils Amiet
- Published by
- Kudelski Security Research
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Nils Amiet, first published at the original source. Preserved copies are kept so the citation survives its host.