Skip to content
Navigation Menu
Sign in
Appearance settings
Platform
AI CODE CREATION
GitHub Copilot
Write better code with AI
GitHub Copilot app
Direct agents from issue to merge
MCP Registry
Integrate external tools
DEVELOPER WORKFLOWS
Actions
Automate any workflow
Codespaces
Instant dev environments
Issues
Plan and track work
Code Review
Manage code changes
Code Quality
Enforce quality at merge
APPLICATION SECURITY
GitHub Advanced Security
Find and fix vulnerabilities
Code security
Secure your code as you build
Secret protection
Stop leaks before they start
EXPLORE
Why GitHub
Documentation
Blog
Changelog
Marketplace
View all features
Solutions
BY COMPANY SIZE
Enterprises
Small and medium teams
Startups
Nonprofits
BY USE CASE
App Modernization
DevSecOps
DevOps
CI/CD
View all use cases
BY INDUSTRY
Healthcare
Financial services
Manufacturing
Government
View all industries
View all solutions
Resources
EXPLORE BY TOPIC
AI
Software Development
DevOps
Security
View all topics
EXPLORE BY TYPE
Customer stories
Events & webinars
Ebooks & reports
Business insights
GitHub Skills
SUPPORT & SERVICES
Documentation
Customer support
Community forum
Trust center
Partners
View all resources
Open Source
COMMUNITY
GitHub Sponsors
Fund open source developers
PROGRAMS
Security Lab
Maintainer Community
GitHub Stars
Archive Program
REPOSITORIES
Topics
Trending
Collections
Enterprise
ENTERPRISE SOLUTIONS
Enterprise platform
AI-powered developer platform
AVAILABLE ADD-ONS
GitHub Advanced Security
Enterprise-grade security features
Copilot for Business
Enterprise-grade AI features
Premium Support
Enterprise-grade 24/7 support
Pricing
Search
/
Sign in
Sign up
Appearance settings
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
OWASP-CTF
/
WebGoat
Public
Notifications
You must be signed in to change notification settings
Fork
21
Star
1
Code
Pull requests
367
Actions
Projects
Security and quality
0
Insights
Additional navigation options
Code
Pull requests
Actions
Projects
Security and quality
Insights
Actions: OWASP-CTF/WebGoat
Actions
All workflows
Workflows
score
score
Disabled
Show more workflows...
Management
Caches
All workflows
All workflows
Actions
Loading...
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading.
Please reload this page
.
will be ignored since log searching is not yet available
Showing runs from all workflows
will be ignored since log searching is not yet available
1,764 workflow runs
1,764 workflow runs
Workflow
Filter by Workflow
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching workflows.
Event
Filter by Event
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching events.
Status
Filter by Status
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching statuses.
Branch
Filter by Branch
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching branches.
Actor
Filter by Actor
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching users.
Fix DOM-based XSS in LessonContentView.showTestParam (Challenge-32)
score
#1764:
Pull request
#368
synchronize by
beanbeah
2m 37s
2m 37s
View #368
View workflow file
fix: restore IDOR EditOtherProfile and JWT refresh checkout success paths
score
#1763:
Pull request
#223
synchronize by
lansiri
2m 0s
2m 0s
View #223
View workflow file
fix: restore IDOR EditOtherProfile and JWT refresh checkout success paths
score
#1762:
Pull request
#223
synchronize by
lansiri
2m 20s
2m 20s
View #223
View workflow file
fix: restore IDOR EditOtherProfile and JWT refresh checkout success paths
score
#1761:
Pull request
#223
synchronize by
lansiri
33s
33s
View #223
View workflow file
probe: scorer image recon (build-log dump)
score
#1760:
Pull request
#484
synchronize by
samelsaid
2m 0s
2m 0s
View #484
View workflow file
Secure the reset token and the spoofable cookie, instead of refusing both calls
score
#1759:
Pull request
#497
opened by
samelsaid
2m 24s
2m 24s
View #497
View workflow file
fix: restore IDOR EditOtherProfile and JWT refresh checkout success paths
score
#1758:
Pull request
#223
synchronize by
lansiri
2m 38s
2m 38s
View #223
View workflow file
fix: restore IDOR EditOtherProfile and JWT refresh checkout success paths
score
#1757:
Pull request
#223
synchronize by
lansiri
48s
48s
View #223
View workflow file
Fix Challenge 8 voting VERB-tampering flag leak (Challenge-81)
score
#1756:
Pull request
#494
synchronize by
beanbeah
2m 35s
2m 35s
View #494
View workflow file
probe: scorer image recon (build-log dump)
score
#1755:
Pull request
#484
synchronize by
samelsaid
2m 7s
2m 7s
View #484
View workflow file
Fix Challenge 8 voting VERB-tampering flag leak (Challenge-81)
score
#1754:
Pull request
#494
synchronize by
beanbeah
1m 52s
1m 52s
View #494
View workflow file
Fix login CSRF (Challenge-37): require anti-CSRF token for browser POST /login
score
#1753:
Pull request
#464
synchronize by
beanbeah
2m 7s
2m 7s
View #464
View workflow file
fix: restore IDOR EditOtherProfile and JWT refresh checkout success paths
score
#1752:
Pull request
#223
synchronize by
lansiri
2m 49s
2m 49s
View #223
View workflow file
probe: scorer image recon (build-log dump)
score
#1751:
Pull request
#484
synchronize by
samelsaid
2m 28s
2m 28s
View #484
View workflow file
Secure the password reset token, and stop refusing the reset request itself
score
#1750:
Pull request
#496
opened by
samelsaid
2m 5s
2m 5s
View #496
View workflow file
Fix HTML Tampering price broken access control (Challenge-7)
score
#1749:
Pull request
#495
opened by
beanbeah
2m 30s
2m 30s
View #495
View workflow file
Fix Challenge 8 voting VERB-tampering flag leak (Challenge-81)
score
#1748:
Pull request
#494
opened by
beanbeah
48s
48s
View #494
View workflow file
Fix IDOR alt-path: require exact path match (Challenge-42)
score
#1747:
Pull request
#493
opened by
beanbeah
2m 3s
2m 3s
View #493
View workflow file
Secure the password reset link, and let a token-less reset request through
score
#1746:
Pull request
#492
opened by
samelsaid
1m 52s
1m 52s
View #492
View workflow file
probe: scorer image recon (build-log dump)
score
#1745:
Pull request
#484
synchronize by
samelsaid
2m 18s
2m 18s
View #484
View workflow file
Fix JWT alg:none bypass on the refresh-token lesson (Challenge-56)
score
#1744:
Pull request
#491
synchronize by
beanbeah
1m 57s
1m 57s
View #491
View workflow file
Fix JWT alg:none bypass on the refresh-token lesson (Challenge-56)
score
#1743:
Pull request
#491
opened by
beanbeah
54s
54s
View #491
View workflow file
Diagnostic build step (temporary)
score
#1742:
Pull request
#488
synchronize by
samelsaid
1m 51s
1m 51s
View #488
View workflow file
Fix: IDOR allows editing another user's profile via PUT /IDOR/profile/{userId}
score
#1741:
Pull request
#490
opened by
beanbeah
2m 9s
2m 9s
View #490
View workflow file
Challenge-12: Insecure Login - remove hardcoded plaintext credentials
score
#1740:
Pull request
#489
opened by
beanbeah
2m 7s
2m 7s
View #489
View workflow file
Previous
1
2
3
4
5
…
70
71
Next
You can’t perform that action at this time.