Skip to content
GitHub CVE-2026-3854 Allows Remote Code Execution via Push Metadata Injection

GitHub CVE-2026-3854 Allows Remote Code Execution via Push Metadata Injection

First seen 7 Oct 2026, 06:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 07:28 UTC
  • •CVE-2026-3854 allows remote code execution via GitHub's push pipeline.
  • •Authenticated users can exploit this vulnerability to execute commands outside the sandbox.
  • •GitHub has released patched versions and recommends immediate upgrades.

CVE-2026-3854 is a high-severity vulnerability in GitHub Enterprise Server's push pipeline, allowing authenticated users with push access to execute commands as the git service user. Attackers can inject semicolon-delimited fields into internal metadata through push options, overriding trusted configurations and potentially exposing sensitive repository data. GitHub confirmed the vulnerability affects both GitHub Enterprise Server and GitHub.com, creating cross-tenant exposure risks. The flaw has a CVSS score of 8.7 and is classified as a remote code execution vulnerability. GitHub has identified patched versions and recommended administrators upgrade their installations. Security teams are advised to review historical push options for suspicious activity and rotate any potentially exposed secrets. The vulnerability was published on March 10, 2026, with a proof-of-concept released on April 29, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-03-10
CVE-2026-3854 published
GitHub disclosed a high-severity remote code execution vulnerability in its Enterprise Server push pipeline.
Mallory.Ai
2026-04-29
First public PoC released
A proof-of-concept for CVE-2026-3854 was made publicly available, demonstrating the exploit.
Seqrite
2026-10-06
GitHub identifies patched builds
GitHub announced patched versions GHES 3.14.25, 3.15.20, 3.16.16, 3.17.13, 3.18.7, 3.19.4, and 3.20.0 for affected installations.
Mallory.Ai

More articles in this cluster (3)

Following this threat?

Track CVE-2026-3854 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What versions of GitHub are affected?
GitHub Enterprise Server versions prior to the patched builds listed by GitHub are affected.
Is there a patch available?
Yes, GitHub has identified multiple patched versions and recommends upgrading immediately.
What should security teams do now?
Review historical push options for suspicious activity and rotate any potentially exposed secrets.