Gbhackers GitHub Patches Critical RCE Vulnerability CVE-2026-3854
Article Content
- •CVE-2026-3854 allows RCE via a single malicious git push command.
- •88% of GitHub Enterprise Server instances were still vulnerable at public disclosure.
- •GitHub patched the vulnerability within six hours of its discovery.
A critical remote code execution vulnerability, tracked as CVE-2026-3854, was discovered in GitHub's internal git infrastructure, allowing authenticated users to execute arbitrary commands via a crafted git push command. The flaw, identified by Wiz researchers using AI, affects both GitHub.com and GitHub Enterprise Server, potentially exposing millions of repositories. GitHub's rapid response included patching the issue within six hours of disclosure on March 4, 2026. Despite the swift action, reports indicate that 88% of GitHub Enterprise Server instances remained vulnerable at the time of public disclosure. The vulnerability stems from improper sanitization of user-supplied push options, allowing command injection. GitHub has released patches for all affected versions, and no evidence of exploitation was found prior to the patch. The incident highlights significant security risks associated with internal protocols and user input handling.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (51)
Following this threat?
Track Wiz and CVE-2026-3854 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
GitHub CVE-2026-3854 Allows Remote Code Execution via Push Metadata Injection CVE-2026-3854 is a high-severity vulnerability in GitHub Enterprise Server's push pipeline, allowing authenticated users with push access to execute commands as the git service user. Attackers can inject semicolon-delimited fields into internal metadata through push options, overriding trusted configurations and…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…