GitHub Pages is our static site hosting service designed to host your personal, organization, or project pages directly from a GitHub repository. It uses the Jekyll static site generator and officially supported themes are developed in the pages-themes organization. GitHub Pages support custom domains and can be secured with HTTPS.
More information is available at https://pages.github.com
GitHub users are responsible for the content hosted on GitHub Pages sites. Any vulnerabilities in user content do not affect the security of GitHub.com or its users. We recommend that you report this issue to the owner of this GitHub Pages site.
Subdomain takeovers on GitHub Pages are a known issue that does not present a significant security risk. We are aware of the risks associated with DNS records pointing to GitHub Pages without an intended repository being configured to use the domain. If you have had your domain taken over, please reach out to Support for help reclaiming it.
A Pages build runs the repository’s own configuration and theme, so a user who can push to the repository can influence what the build does. That is the point of the feature. An eligible report shows a build reaching outside its own boundary: another repository’s source, another customer’s build, credentials belonging to GitHub, or the internal network. Show what you reached, not just that your code ran.
Custom domain verification proves that a domain owner intends to point at a particular account. It does not prevent anyone from setting a CNAME file in their own repository, and an unverified domain that nobody has claimed is not a vulnerability by itself.