Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push
ID: f0ec998c-7b3c-5269-ac2a-2909f3f9e8bd
STIX ID: report--f0ec998c-7b3c-5269-ac2a-2909f3f9e8bd
Feed Name: The Hacker News
Researchers disclosed CVE-2026-3854, a critical command-injection flaw (CVSS 8.7) in GitHub.com and GitHub Enterprise Server that allows an authenticated user with push access to achieve remote code execution by supplying crafted git push options. Wiz reported the issue and demonstrated an exploit chain that bypasses sandboxing to run arbitrary commands as the git user and enable cross-tenant exposure on shared storage; GitHub deployed a rapid fix to GitHub.com and released GHES patches (3.14.25, 3.15.20, 3.16.16, 3.17.13, 3.18.8, 3.19.4, 3.20.0 or later), and users are advised to update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
