Vulnerabilities & Exploits · Zero-Day Exploit

GitHub Internal Protocol Flaw Exposes Entire Repos

A single authenticated git push could turn GitHub into a command-execution path. The standard response of treating this as a normal app bug misses the blast radius: on GitHub.com it exposed shared storage nodes, and on GitHub Enterprise Server it could lead to full server compromise and access to hosted repositories and internal secrets.

Wiz says it found CVE-2026-3854 in GitHub’s internal git protocol. GitHub mitigated GitHub.com within 6 hours and released patches for all supported GitHub Enterprise Server versions; Wiz says 88% of GHES instances were still vulnerable at publication.

The risk persists wherever GHES is exposed and unpatched. This is also a signal that AI-assisted review can surface critical flaws in closed-source infrastructure that conventional review missed.

4 sources · Apr 29

CVE-2026-3854

NVD KEV

CVSS 8.8 HIGH: an improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed… EPSS 40% (99th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-04-29

Every edition of this story: GitHub Internal Protocol Flaw Exposes Entire Repos

More from today