CVE-2026-3854: GitHub RCE via a Single Git Push — What You Need to Know
Technical root cause of the command injection flaw in GitHub's internal git infrastructure allowing remote code execution via a single git push.
CVE-2026-3854
Severity: CVSS 8.7
Status: Disclosed by Wiz Research
Target Component: GitHub internal Git backend
This article is part of our Week of May 7, 2026 Security Roundup.
Wiz Research disclosed CVE-2026-3854 on April 28, 2026 — a command injection vulnerability in GitHub's internal git infrastructure that allowed any authenticated user with push access to a repository to achieve remote code execution on GitHub's backend servers with a single git push command. CVSS score: 8.7.
GitHub patched GitHub.com within two hours of receiving the report on March 4, 2026. GitHub Enterprise Server patches were released on March 10. Public disclosure came April 28.
Root Cause: Internal Header Injection
GitHub's git push pipeline passes data through multiple internal services written in different languages. User-supplied push option values were not sanitized before being included in internal service headers. The internal header format used a delimiter character that could also appear in attacker-controlled push option values.
By crafting a push option containing the delimiter, an attacker could inject additional metadata fields into the internal header, which downstream services interpreted as legitimate protocol data — leading to command execution on shared storage nodes.
# The vulnerability — push option values flow unsanitized into internal headers
git push origin main \
-o <crafted-value-containing-internal-delimiter>
# No special tooling required — standard git client is sufficient
# Only requirement: authenticated user with push access to any repositoryScope of Impact
The vulnerability affected GitHub.com (patched March 4, 2026, within 2 hours of report), GitHub Enterprise Cloud and GitHub Enterprise Cloud with Data Residency, GitHub Enterprise Cloud with Enterprise Managed Users, and GitHub Enterprise Server versions prior to 3.14.25, 3.15.20, 3.16.16, 3.17.13, 3.18.8, 3.19.4, and 3.20.0.
Why This Matters Beyond the Patch
This is one of the first publicly documented critical vulnerabilities in closed-source binaries discovered using AI-assisted analysis, according to Wiz. The technique — using AI to analyze compiled code without source access — signals a meaningful shift in how vulnerability research will be conducted. Expect more discoveries of this type across other large platforms' closed-source infrastructure.
The attack vector is also worth internalizing: the complexity isn't in the exploit itself — a standard git push with a crafted option is trivial to execute. The complexity was in finding the injection point in a multi-language internal protocol. Once found, exploitation required no special tools, no elevated privileges, and no user interaction beyond having push access to any repository.
Remediation for GitHub Enterprise Server
# Check your GHES version
ghes version
# Required minimum patch versions:
# 3.14.x -> upgrade to 3.14.25 or later
# 3.15.x -> upgrade to 3.15.20 or later
# 3.16.x -> upgrade to 3.16.16 or later
# 3.17.x -> upgrade to 3.17.13 or later
# 3.18.x -> upgrade to 3.18.8 or later
# 3.19.x -> upgrade to 3.19.4 or later
# 3.20.x -> upgrade to 3.20.0 or laterGitHub.com users are already patched. If you are running GitHub Enterprise Server on an unpatched version, treat this as urgent — push access to any repository on your instance is sufficient to exploit this.
References: Wiz Research disclosure | GitHub Security Advisory | The Hacker News | Security Affairs