GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog
wiz.io · 2,452 words · saved by 4 readers
A CVSS 8.7 vulnerability in GitHub Enterprise Server allows remote code execution. Read the threat brief and find vulnerable GHES instances from Wiz.
Wiz Research uncovered a critical vulnerability (CVE-2026-3854) in GitHub's internal git infrastructure that could have affected both GitHub.com and GitHub Enterprise Server. By exploiting an injection flaw in GitHub's internal protocol, any authenticated user could execute arbitrary commands on GitHub's backend servers with a single git push command - using nothing but a standard git client. Notably, this is one of the first critical vulnerabilities discovered in closed-source binaries using AI, highlighting a shift in how these flaws are identified. Despite the complexity of the underlying s
saved by
related reading
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Security incident disclosure — July 2026huggingface.co
- AuditAgentauditagent.nethermind.io
- GitHub - Wikipediaen.wikipedia.org
- Ghostty Is Leaving GitHub – Mitchell Hashimotomitchellh.com
- Git at any scalecursor.com
- Why GitHub Actually Won | Butler's Logblog.gitbutler.com
- GitHub - GitGuardian/ggshield: Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret detection and security.github.com
- Code Storage by the Pierre Computer Companycode.storage
- Gitea Official Websiteabout.gitea.com
- All learning materials - detailed | Web Security Academyportswigger.net
- How to Manage GitHub Actions Secretsinfisical.com