CVE-2026-3854
CVSS 8.8 HIGH: an improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed… EPSS 40% (99th percentile).
Vulnerabilities & Exploits · Zero-Day Exploit
A single authenticated git push could turn GitHub into a command-execution path. The standard response of treating this as a normal app bug misses the blast radius: on GitHub.com it exposed shared storage nodes, and on GitHub Enterprise Server it could lead to full server compromise and access to hosted repositories and internal secrets.
Wiz says it found CVE-2026-3854 in GitHub’s internal git protocol. GitHub mitigated GitHub.com within 6 hours and released patches for all supported GitHub Enterprise Server versions; Wiz says 88% of GHES instances were still vulnerable at publication.
The risk persists wherever GHES is exposed and unpatched. This is also a signal that AI-assisted review can surface critical flaws in closed-source infrastructure that conventional review missed.
4 sources · Apr 29
CVSS 8.8 HIGH: an improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed… EPSS 40% (99th percentile).
BleepingComputer
GitHub fixes RCE flaw that gave access to millions of private repos
In early March, GitHub patched a critical remote code execution vulnerability (CVE-2026-3854) that could have allowed attackers to access millions of private repositories.
originalSecurityWeek
Critical GitHub Vulnerability Exposed Millions of Repositories
The remote code execution flaw CVE-2026-3854 was found to impact GitHub.com and GitHub Enterprise Server.
originalThe Hacker News
Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push
CVE-2026-3854 (CVSS 8.7) enabled GitHub RCE via git push, risking cross-tenant access to millions of repositories.
originalPart of the PlainSec briefing for 2026-04-29
Every edition of this story: GitHub Internal Protocol Flaw Exposes Entire Repos