Critical GitHub Vulnerability Exposed Millions of Repositories

2026-04-29T07:24:06Z867b34ab3cd6bdb6a6ccc91680f705049f9d737d50994bc14eca6a41edee61d4
CVE-2026-3854githubgithub enterprise serverpatchingrceremote code executionrepositoriessecurityweeksupply-chainvulnerability

What happened

A critical remote code execution vulnerability (CVE-2026-3854) was disclosed impacting GitHub.com and GitHub Enterprise Server, potentially exposing or enabling code execution across millions of repositories. The flaw has broad impact on hosted and enterprise instances and requires immediate remediation and mitigations from affected customers.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
867b34ab3cd6bdb6a6ccc91680f705049f9d737d50994bc14eca6a41edee61d4
Enrichment time
2026-04-29T07:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.