Reverse Engineering With AI Unearths High-Severity GitHub Bug
ID: 76df6548-277d-5ed7-a207-47580627607e
STIX ID: report--76df6548-277d-5ed7-a207-47580627607e
Feed Name: Dark Reading
Threat Score
GitHub disclosed CVE-2026-3854 — an 8.7 CVSS remote code execution flaw in GitHub Enterprise Server and related services where unsanitized git push options could be injected into internal metadata, enabling an attacker with push access to achieve RCE; Wiz used AI-assisted reverse-engineering to find and demonstrate the issue, GitHub has patched affected services and reported no evidence of exploitation, and Enterprise Server customers must upgrade to specified fixed versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
