logo

Git Push to Root: AI-Augmented Research Uncovers Critical GitHub RCE (CVE-2026-3854)

ID: fcb1b7af-160f-5305-9167-7901f763b068

STIX ID: report--fcb1b7af-160f-5305-9167-7901f763b068

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-28

Date Updated: 2026-04-29

Author: Ddos

...
...

Wiz Research disclosed CVE-2026-3854, a critical RCE in GitHub's internal git infrastructure where unsanitized semicolons in git push options let attackers inject fields into the X-Stat header and escape security controls; researchers achieved code execution on backend servers and access to repositories on multi-tenant storage, GitHub patched the public service quickly but many GHES instances remain vulnerable and must be upgraded.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.