Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Critical GitHub Vulnerability Exposed Millions of Repositories
    Cybersecurity

    Critical GitHub Vulnerability Exposed Millions of Repositories

    adminBy adminApril 29, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    GitHub vulnerability
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Researchers at cloud security giant Wiz discovered a critical remote code execution vulnerability in GitHub that exposed millions of repositories.

    The vulnerability, tracked as CVE-2026-3854, affected the code-hosting platform’s internal Git infrastructure. It impacted both GitHub Enterprise Server and GitHub.com.

    “By exploiting an injection flaw in GitHub’s internal protocol, any authenticated user could execute arbitrary commands on GitHub’s backend servers with a single git push command – using nothing but a standard git client,” Wiz explained.

    According to the security firm, which discovered the issue using AI, exploitation is easy. 

    In the case of GitHub Enterprise Server, an attacker can exploit the vulnerability to fully compromise the server and gain access to all repositories and internal secrets.

    The impact was even greater on GitHub.com, where CVE-2026-3854 could have been exploited for remote code execution on shared storage nodes.

    Advertisement. Scroll to continue reading.

    “On GitHub.com, this vulnerability allowed remote code execution on shared storage nodes. We confirmed that millions of public and private repositories belonging to other users and organizations were accessible on the affected nodes,” Wiz said.

    While the authentication requirement may appear to mitigate the risk, GitHub explained that any user with push access to a repository, including one they created, could exploit the vulnerability to execute arbitrary commands on the server. 

    GitHub quickly addressed the vulnerability. The company has conducted a forensic investigation and determined that it has not been exploited in the wild. 

    In addition to GitHub.com and GitHub Enterprise Server, the security hole affected GitHub Enterprise Cloud, GitHub Enterprise Cloud with Data Residency, and GitHub Enterprise Cloud with Enterprise Managed Users.

    The vulnerability was reported to GitHub on March 4, and a fix was deployed to GitHub.com on the same day. 

    A patch for Enterprise Server was made available on March 10. However, Wiz reported on Tuesday that 88% of Enterprise Server instances had not yet been updated to a patched version.

    The technical details of CVE-2026-3854 have been disclosed by Wiz, and GitHub has described the actions it has taken and its process for handling such vulnerabilities. 

    Related: Claude Code, Gemini CLI, GitHub Copilot Agents Vulnerable to Prompt Injection via Comments

    Related: Critical Vulnerability in OpenAI Codex Allowed GitHub Token Compromise

    Related: GitHub Issues Abused in Copilot Attack Leading to Repository Takeover

    Critical Exposed GitHub Millions Repositories vulnerability
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleShare of Voice Tools for Growing Companies
    Next Article Google Tests ‘Ask YouTube’ Conversational Search Experiment
    admin
    • Website

    Related Posts

    NSA Chief During Snowden Affair 13 Years Later

    April 29, 2026

    Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign

    April 29, 2026

    Police arrest 10 suspected members of Black Axe cybercrime gang

    April 29, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Google Tests ‘Ask YouTube’ Conversational Search Experiment

    April 29, 2026

    Critical GitHub Vulnerability Exposed Millions of Repositories

    April 29, 2026

    Share of Voice Tools for Growing Companies

    April 29, 2026

    NSA Chief During Snowden Affair 13 Years Later

    April 29, 2026
    Categories
    • Blogging (69)
    • Cybersecurity (1,570)
    • Privacy & Online Earning (187)
    • SEO & Digital Marketing (965)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (249)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Google Tests ‘Ask YouTube’ Conversational Search Experiment

    April 29, 2026

    Critical GitHub Vulnerability Exposed Millions of Repositories

    April 29, 2026

    Share of Voice Tools for Growing Companies

    April 29, 2026
    Most Popular
    • Google Tests ‘Ask YouTube’ Conversational Search Experiment
    • Critical GitHub Vulnerability Exposed Millions of Repositories
    • Share of Voice Tools for Growing Companies
    • NSA Chief During Snowden Affair 13 Years Later
    • Why more content is no longer a reliable way to grow SEO
    • Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign
    • Police arrest 10 suspected members of Black Axe cybercrime gang
    • OpenAI Crawl Activity Tripled Since GPT-5, Data Shows
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.