malware.news GitHub CVE-2026-3854 Allows Remote Code Execution via Push Metadata Injection
Article Content
- •CVE-2026-3854 allows remote code execution via GitHub's push pipeline.
- •Authenticated users can exploit this vulnerability to execute commands outside the sandbox.
- •GitHub has released patched versions and recommends immediate upgrades.
CVE-2026-3854 is a high-severity vulnerability in GitHub Enterprise Server's push pipeline, allowing authenticated users with push access to execute commands as the git service user. Attackers can inject semicolon-delimited fields into internal metadata through push options, overriding trusted configurations and potentially exposing sensitive repository data. GitHub confirmed the vulnerability affects both GitHub Enterprise Server and GitHub.com, creating cross-tenant exposure risks. The flaw has a CVSS score of 8.7 and is classified as a remote code execution vulnerability. GitHub has identified patched versions and recommended administrators upgrade their installations. Security teams are advised to review historical push options for suspicious activity and rotate any potentially exposed secrets. The vulnerability was published on March 10, 2026, with a proof-of-concept released on April 29, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-3854 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What versions of GitHub are affected?
Is there a patch available?
What should security teams do now?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…