CVE-2026-3854
CVSS 8.8 HIGH: an improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed… EPSS 40% (99th percentile).
Vulnerabilities · 139 days ago
A single authenticated git push could turn GitHub into a command-execution path. The standard response of treating this as a normal app bug misses the blast radius: on GitHub.com it exposed shared storage nodes, and on GitHub Enterprise Server it could lead to full server compromise and access to hosted repositories and internal secrets.
Wiz says it found CVE-2026-3854 in GitHub’s internal git protocol. GitHub mitigated GitHub.com within 6 hours and released patches for all supported GitHub Enterprise Server versions; Wiz says 88% of GHES instances were still vulnerable at publication.
The risk persists wherever GHES is exposed and unpatched. This is also a signal that AI-assisted review can surface critical flaws in closed-source infrastructure that conventional review missed.
CVSS 8.8 HIGH: an improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed… EPSS 40% (99th percentile).
4 sources covering this story
GitHub fixes RCE flaw that gave access to millions of private repos
In early March, GitHub patched a critical remote code execution vulnerability (CVE-2026-3854) that could have allowed attackers to access millions of private repositories.
Critical GitHub Vulnerability Exposed Millions of Repositories
The remote code execution flaw CVE-2026-3854 was found to impact GitHub.com and GitHub Enterprise Server.
Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push
CVE-2026-3854 (CVSS 8.7) enabled GitHub RCE via git push, risking cross-tenant access to millions of repositories.
GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog
A CVSS 8.7 vulnerability in GitHub Enterprise Server allows remote code execution.
Part of the PlainSec briefing for 2026-04-30