Topic: github vulnerability
-
GitHub patches RCE bug exposing millions of private repos
GitHub fixed a critical remote code execution vulnerability (CVE-2026-3854) in early March that could have allowed attackers to access and compromise millions of private repositories without any user interaction. The flaw, which resided in a core infrastructure component, was patched before publi...
Read More » -
Critical GitHub RCE Flaw CVE-2026-3854 Exploitable via Single Git Push
A critical command injection vulnerability (CVE-2026-3854, CVSS 8.7) in GitHub.com and GitHub Enterprise Server allows any authenticated user with push access to execute arbitrary code via a single git push command, due to insufficient sanitization of push option values in internal headers. The f...
Read More » -
Open source package with 1M monthly downloads stole user credentials
Attackers exploited a vulnerability in a GitHub action workflow to hijack the open-source package "element-data", downloaded over 1 million times monthly, stealing signing keys and credentials to release a malicious version. The tampered package, tagged 0.23.3, scanned environments for sensitiv...
Read More »