All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Critical RCE vulnerability CVE-2026-3854 discovered in GitHub's internal git infrastructure

By

Sagi Tzadik

1mo ago· 11 min readenNews

Summary

Wiz Research discovered a critical vulnerability (CVE-2026-3854) in GitHub's internal git infrastructure affecting both GitHub.com and GitHub Enterprise Server. The flaw allowed any authenticated user to execute arbitrary commands on GitHub's backend servers through a single git push command using a standard git client, by exploiting an injection flaw in GitHub's internal protocol. Notably, this is one of the first critical vulnerabilities discovered in closed-source binaries using AI, marking a shift in vulnerability identification methods.

Key quotes

· 3 pulled
Wiz Research uncovered a critical vulnerability (CVE-2026-3854) in GitHub's internal git infrastructure that could have affected both GitHub.com and GitHub Enterprise Server.
By exploiting an injection flaw in GitHub's internal protocol, any authenticated user could execute arbitrary commands on GitHub's backend servers with a single git push command - using nothing but a standard git client.
Notably, this is one of the first critical vulnerabilities discovered in closed-source binaries using AI, highlighting a shift in how these flaws are identified.
Snippet from the RSS feed
Details on CVE-2026-3854: A critical flaw in GitHub’s internal git infrastructure enabling RCE on GitHub.com and GitHub Enterprise Server.

You might also wanna read