Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push
2026-04-29T01:24:10Z•617dd8c847effee1799d69a7ca07b5e21c4c9d08f389c9e7f4cfb63a1c25d307
active-exploitationcisacommand-injectioncredential-theftgithubhuggingfaceknown-exploited-vulnerabilitieslmdeploymalicious-extensionsphishingransomwareremote-code-executionssrfsupply-chain-attackuntrusted-deserializationwindowswiper
What happened
Multiple high‑impact vulnerabilities and active campaigns were reported: a critical GitHub command‑injection RCE (CVE-2026-3854) exploitable with a single git push; a critical unauthenticated LeRobot deserialization RCE (CVE-2026-25874); LMDeploy SSRF (CVE-2026-33626) actively exploited within hours of disclosure; and a Windows Shell flaw (CVE-2026-32202) confirmed exploited in the wild. The feed also highlights destructive VECT 2.0 ransomware/wiper behavior, ongoing supply‑chain compromises (Checkmarx incident with Bitwarden CLI compromise), large-scale malicious VS Code extensions (GlassWorm
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 617dd8c847effee1799d69a7ca07b5e21c4c9d08f389c9e7f4cfb63a1c25d307
- Enrichment time
- 2026-04-29T01:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.