
Security research lab reproducing CVE-2025-53546 (GHSA-h87r-5w74-qfm4): pull_request_target arbitrary code execution in RSSNext/Folo's auto-fix lint workflow — authorized, isolated reproduction
Automated research artifact — not the upstream project.
This repository is a disposable lab built by an automated harness for a master's thesis at Université Laval on reproducing published GitHub Actions workflow vulnerabilities. It is a verbatim snapshot of
RSSNext/Foloat commit5c5f61d18737e9b039181bee97c7e0b0f956eabf(2025-07-04), redistributed under that project's own licence, whose file is included unchanged in this snapshot.The upstream project is not involved, is never targeted, and the vulnerability studied here is already public. Every secret and variable in this repository is a randomly generated dummy value — no real credential is present. Action references and runner images are pinned to what they resolved to on 2025-07-04; see
pinning.mdin the harness output for every change made to the snapshot.Questions or objections: [email protected]

As they say, your thoughts are what you read—and we’ve been consuming noisy feeds for too long! Folo organizes content into one timeline, keeping you updated on what matters, noise-free. Share lists, explore collections, and enjoy distraction-free browsing.
Whether for users or professional developers, Folo will be your open information playground. Please be aware that Folo is currently under active development, and feedback is welcome for any issue encountered.
Feel free to try it using the following methods:
You can also install using the following methods maintained by our community:
[!IMPORTANT]
Star Us, You will receive all release notifications from GitHub without any delay ~

Subscribe to a vast range of feeds and curated lists. Curate your favorites and keep track of what matters most to you.

A smarter and more efficient browsing with AI-powered features like translation, summary, and more.

Because we know content is more than just text. From articles to videos, images to audio — Folo gets it all covered.

Tip creators across instantly with $POWER, support content you love, and unlock value in your own work. Your content, your power.

This isn’t just another app. Folo is a community — introducing a new era of openness and community-driven experience.

You are welcome to join the open source community to build together, please check our Contributing Guide for more details.
Folo for Windows uses free code signing provided by SignPath.io, certificate by SignPath Foundation.
Folo for macOS and iOS are signed and notarized by Apple Developer Program.
All released files are verified with GitHub artifact attestations to ensure their provenance and integrity.
Folo is licensed under the GNU General Public License version 3 with the addition of the following special exception:
All content in the icons/mgc directory is copyrighted by https://mgc.mingcute.com/ and cannot be redistributed.
All content in the lottie directory is distributed under the Lottie Simple License.

| Linux | ![]() |