GitHub
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 198 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 4, 2012 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites
Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths
Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configuration
GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace
'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows
An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositories
Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed arbitrary JavaScript execution via crafted Discussion titles in the Q&A category
Missing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via the Copilot pull request diff summary endpoint
UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screen
Monitor GitHub in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.