CVE-2026-3854 (CVSS 8.7) enabled GitHub RCE via git push, risking cross-tenant access to millions of repositories.
A critical remote code execution flaw in GitHub allowed users to gain access to millions of repositories and compromise ...
GitHub’s engineering team developed a fix and deployed it just over an hour after identifying the root cause, protecting both ...
GitHub has fixed a critical remote code execution vulnerability, CVE-2026-3854, that allowed anyone with push access to execute arbitrary commands on its servers. While GitHub.com was patched within ...