GitHub disclosed and patched CVE-2026-3854, a critical command-injection flaw in its git push pipeline that allowed an authenticated user with repository push access to trigger remote code execution using a single crafted push. Wiz reported the bug on March 4, and GitHub said it reproduced the issue within about 40 minutes and deployed a fix to GitHub.com within roughly two hours, later publishing patches for supported GitHub Enterprise Server releases including 3.14.24, 3.15.19, 3.16.15, 3.17.12, 3.18.6, and 3.19.3. The vulnerability stemmed from unsanitized user-supplied push option values being inserted into internal X-Stat headers, enabling attackers to inject trusted metadata, bypass sandboxing, and execute commands as the git service user.
Researchers said the flaw could have led to full server compromise on GitHub Enterprise Server and, on GitHub.com, code execution on shared storage infrastructure where millions of repositories were accessible to the git service account, creating potential cross-tenant exposure. GitHub said forensic analysis and telemetry found no evidence of malicious exploitation and no indication that customer data was accessed, modified, or exfiltrated, but urged Enterprise Server administrators to upgrade immediately and review logs for suspicious push activity. Wiz described the bug as easy to exploit and highlighted its use of AI-assisted reverse engineering tools, including IDA MCP, to uncover the issue in GitHub’s closed-source components.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Wiz published its research on CVE-2026-3854, explaining how unsanitized git push options were copied into internal X-Stat headers and enabled remote code execution. The disclosure described impact on GitHub.com shared storage nodes and potential full compromise of GitHub Enterprise Server.
GitHub publicly disclosed CVE-2026-3854, a critical git push pipeline command injection issue affecting GitHub.com and GitHub Enterprise Server. It released patched GHES versions across supported release lines and advised administrators to upgrade immediately.
ZDI publicly disclosed the OpenAI Codex sandbox escape as advisory ZDI-26-305, describing insufficient isolation in the JavaScript execution environment. ZDI said OpenAI had reproduced the behavior but considered it out of scope for its bug bounty program and not part of Codex's default product surface.
Xen.org released Xen Security Advisory 489 for five RBAC-related XAPI vulnerabilities: CVE-2026-23559, CVE-2026-23560, CVE-2026-23561, CVE-2026-23562, and CVE-2026-42486. The advisory said the XAPI team validated 5 real vulnerabilities out of the 89 public claims and recommended disabling lower-privileged RBAC roles until fixes are applied.
A researcher published an independent audit disclosing 89 claimed exploitable vulnerabilities in XAPI used by Citrix XenServer/Hypervisor and XCP-ng. The disclosure said the issues stemmed from architectural failures in unvalidated Map(String,String) fields and included extensive proof-of-concept and detection materials.
After receiving Wiz's report, GitHub reproduced the issue within about 40 minutes, identified the root cause the same day, and deployed a fix to GitHub.com in under two hours. GitHub later said forensic analysis found no evidence of exploitation or customer data compromise.
Wiz reported a command injection vulnerability later assigned CVE-2026-3854 to GitHub through the bug bounty program. The flaw allowed an authenticated user with push access to achieve remote code execution via crafted git push options.
Trend Micro's Zero Day Initiative reported a Codex sandbox escape vulnerability, later tracked as ZDI-26-305 / ZDI-CAN-29475, to OpenAI. The flaw allowed code execution as the current user when processing a repository containing malicious JavaScript.
Citrix issued a September 2024 security update for XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR addressing CVE-2024-45817 and net-snmp flaws CVE-2022-24805 and CVE-2022-24809. Citrix recommended restricting management interface access and upgrading affected systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethecyberexpress.com
Open sourcecsirt.sk
Open sourcetheregister.com
Open sourcereddit.com
Open sourcezerodayinitiative.com
Open sourcecve.org
Open sourcerunzero.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.