GitHub Internal Protocol Flaw Exposes Entire Repos

A single authenticated git push could turn GitHub into a command-execution path. The standard response of treating this as a normal app bug misses the blast radius: on GitHub.com it exposed shared storage nodes, and on GitHub Enterprise Server it could lead to full server compromise and access to hosted repositories and internal secrets. Wiz says it found CVE-2026-3854 in GitHub’s internal git protocol. GitHub mitigated GitHub.com within 6 hours and released patches for all supported GitHub Enterprise Server versions; Wiz says 88% of GHES instances were still vulnerable at publication. The risk persists wherever GHES is exposed and unpatched. This is also a signal that AI-assisted review can surface critical flaws in closed-source infrastructure that conventional review missed.

Part of the PlainSec briefing for 2026-04-30

Sources