
GitHub's repository architecture allows access to deleted and private repositories, making it an enormous attack vector for organizations that use the platform. The Cross Fork Object Reference (CFOR) vulnerability allows users to access sensitive data from other forks, including deleted and private repositories, by using commit hashes that can be easily discovered.