CVE-2025-6981: Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized read-only access
An incorrect authorization vulnerability allowed unauthorized read access to the contents of internal repositories for contractor accounts when the Contractors API feature was enabled. The Contractors API is a rarely-enabled feature in private preview. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.18 and was fixed in versions 3.14.15, 3.15.10, 3.16.6 and 3.17.3
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.14.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.15.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.16.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.17.3
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6981?
CVE-2025-6981 has a medium severity rating due to its potential for unauthorized read access.
How do I fix CVE-2025-6981?
To fix CVE-2025-6981, disable the Contractors API feature if it is not needed or upgrade GitHub Enterprise Server to a version that includes the patch.
Who is affected by CVE-2025-6981?
CVE-2025-6981 affects users of GitHub Enterprise Server versions up to 3.18 that have enabled the Contractors API feature.
What type of vulnerability is CVE-2025-6981?
CVE-2025-6981 is classified as an incorrect authorization vulnerability leading to unauthorized access.
When was CVE-2025-6981 reported?
CVE-2025-6981 was identified in versions of GitHub Enterprise Server prior to 3.18, which might impact contractor accounts.