Where
-Infinity
0

GitHub GitHub Enterprise ServerMissing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites

Risk 26
Severity
5.3
First published (updated )

GitHub GitHub Enterprise ServerPath traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths

Risk 62
Severity
8.6
First published (updated )

GitHub GitHub Enterprise ServerDenial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configuration

Risk 36
Severity
5.7
First published (updated )

GitHub GitHub CLI (gh)GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace

Risk 29
Severity
4.4
First published (updated )

Dark Reading'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

GitHub Enterprise ServerAn incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositories

Risk 26
Severity
5.3
First published (updated )

GitHub Enterprise ServerStored cross-site scripting vulnerability in GitHub Enterprise Server allowed arbitrary JavaScript execution via crafted Discussion titles in the Q&A category

Risk 55
Severity
6.3
First published (updated )

GitHub Enterprise ServerMissing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via the Copilot pull request diff summary endpoint

Risk 27
Severity
6
EPSS
0.26%
First published (updated )

GitHub Enterprise ServerUI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screen

Risk 30
Severity
4.8
EPSS
0.21%
First published (updated )

GitHub GitHub CopilotGitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval…

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/cli/cli/v2GitHub CLI tokens leak via `gh attestation` commands

Risk 66
Severity
9.1
First published (updated )

GitHub Enterprise ServerServer-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpoint

Risk 57
Severity
9.2
EPSS
6.55%
First published (updated )

GitHub Enterprise ServerServer-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL Endpoint

Risk 41
Severity
7
EPSS
0.39%
First published (updated )

GitHub GitHub CLIgh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection

Risk 19
Severity
3.5
First published (updated )

Microsoft Visual Studio CodeGitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability

Risk 77
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/@github/copilotGitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor

Risk 73
Severity
8.5
First published (updated )

Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)

First published (updated )
Social
reddit

GitHub Enterprise ServerReflected HTML injection vulnerability in GitHub Enterprise Server Management Console login page allowed credential theft

Risk 27
Severity
5.9
EPSS
0.03%
First published (updated )

GitHub Enterprise ServerServer-side request forgery vulnerability in GitHub Enterprise Server notebook viewer via URL parser confusion

Risk 61
Severity
7.9
EPSS
0.06%
First published (updated )

GitHub Enterprise ServerDenial of service vulnerability in GitHub Enterprise Server allowed service disruption via unauthenticated API endpoint

Risk 31
Severity
6.3
EPSS
0.06%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

GitHub Enterprise ServerAuthentication bypass vulnerability in GitHub Enterprise Server allowed creation of local user accounts bypassing the configured external identity provider

Risk 28
Severity
6.3
EPSS
0.14%
First published (updated )

Dark ReadingReverse Engineering With AI Unearths High-Severity GitHub Bug

First published (updated )

BleepingComputerGitHub fixes RCE flaw that gave access to millions of private repos

First published (updated )

GitHub Enterprise ServerImproper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise Server

Risk 49
Severity
7.2
EPSS
0.02%
First published (updated )

GitHub Enterprise ServerAuthorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewers

Risk 26
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

GitHub Enterprise ServerImproper authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository names via mobile upload policy API

Risk 19
Severity
5.3
EPSS
0.06%
First published (updated )

GitHub Enterprise ServerIncorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypass

Risk 77
Severity
7.5
First published (updated )

GitHub Enterprise ServerProxy configuration command injection vulnerability found in GitHub Enterprise Server Management Console configuration API

Risk 38
Severity
8.1
First published (updated )

GitHub Enterprise ServerServer-Side Request Forgery in GitHub Enterprise Server allowed extraction of sensitive environment variables via timing side-channel attack

Risk 49
Severity
8.9
EPSS
0.07%
First published (updated )

GitHub Enterprise ServerIncorrect Authorization in GitHub Enterprise Server allows access to issue and commit search results without repo scope

Risk 19
Severity
5.3
EPSS
0.02%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203