Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push

2026-04-29T01:24:10Z617dd8c847effee1799d69a7ca07b5e21c4c9d08f389c9e7f4cfb63a1c25d307
active-exploitationcisacommand-injectioncredential-theftgithubhuggingfaceknown-exploited-vulnerabilitieslmdeploymalicious-extensionsphishingransomwareremote-code-executionssrfsupply-chain-attackuntrusted-deserializationwindowswiper

What happened

Multiple high‑impact vulnerabilities and active campaigns were reported: a critical GitHub command‑injection RCE (CVE-2026-3854) exploitable with a single git push; a critical unauthenticated LeRobot deserialization RCE (CVE-2026-25874); LMDeploy SSRF (CVE-2026-33626) actively exploited within hours of disclosure; and a Windows Shell flaw (CVE-2026-32202) confirmed exploited in the wild. The feed also highlights destructive VECT 2.0 ransomware/wiper behavior, ongoing supply‑chain compromises (Checkmarx incident with Bitwarden CLI compromise), large-scale malicious VS Code extensions (GlassWorm

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
617dd8c847effee1799d69a7ca07b5e21c4c9d08f389c9e7f4cfb63a1c25d307
Enrichment time
2026-04-29T01:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.