CVE-2025-3246: Markdown math block sanitization bypass allows privilege escalation and unauthorized workflow triggers
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting in GitHub Markdown that used $$..$$ math blocks. Exploitation required access to the target GitHub Enterprise Server instance and privileged user interaction with the malicious elements. This vulnerability affected version 3.16.1 of GitHub Enterprise Server and was fixed in version 3.16.2. This vulnerability was reported via the GitHub Bug Bounty program.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3246?
CVE-2025-3246 is classified as a high severity cross-site scripting vulnerability.
How do I fix CVE-2025-3246?
To fix CVE-2025-3246, ensure that you update to the latest version of GitHub Enterprise Server that addresses this issue.
Who is affected by CVE-2025-3246?
Users of GitHub Enterprise Server with access to markdown rendering features are affected by CVE-2025-3246.
What type of vulnerability is CVE-2025-3246?
CVE-2025-3246 is an improper neutralization of input vulnerability that leads to cross-site scripting.
Is user interaction required for CVE-2025-3246 to be exploited?
Yes, exploitation of CVE-2025-3246 requires privileged user interaction within the affected GitHub Enterprise Server instance.