logo

Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push

ID: f0ec998c-7b3c-5269-ac2a-2909f3f9e8bd

STIX ID: report--f0ec998c-7b3c-5269-ac2a-2909f3f9e8bd

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed CVE-2026-3854, a critical command-injection flaw (CVSS 8.7) in GitHub.com and GitHub Enterprise Server that allows an authenticated user with push access to achieve remote code execution by supplying crafted git push options. Wiz reported the issue and demonstrated an exploit chain that bypasses sandboxing to run arbitrary commands as the git user and enable cross-tenant exposure on shared storage; GitHub deployed a rapid fix to GitHub.com and released GHES patches (3.14.25, 3.15.20, 3.16.16, 3.17.13, 3.18.8, 3.19.4, 3.20.0 or later), and users are advised to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.