Critical GitHub.com and Enterprise Server RCE Vulnerability Enables Full Server Compromise
ID: c70e4551-5b76-56ce-992e-e793a1853a40
STIX ID: report--c70e4551-5b76-56ce-992e-e793a1853a40
Feed Name: cybersecurityNews.com
**CVE-2026-3854 — GitHub internal git proxy RCE:** Wiz researchers discovered a critical remote code execution vulnerability in GitHub's internal `babeld`/`gitrpcd` pipeline that allows authenticated users to inject semicolon-delimited fields via `git push -o` push options, override security-critical headers (e.g., `rails_env`, `custom_hooks_dir`, `repo_pre_receive_hooks`), and chain them to execute arbitrary binaries as the `git` service user; the flaw impacted GitHub Enterprise Server (full server takeover) and GitHub.com (cross-tenant repo exposure) but GitHub patched GitHub.com within hours and released GHES fixes while advising administrators to audit push option entries in logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
