{"id":"CVE-2025-14046","title":"An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied HTML to inject DOM elements with IDs that collided with server-initialized data islands","summary":"An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied HTML to inject DOM elements with IDs that collided with server-initialized data islands. These collisions could overw…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"github","product":"enterprise_server","affected":["enterprise_server < 3.14.21","enterprise_server >= 3.15.0, < 3.15.16","enterprise_server >= 3.16.0, < 3.16.12","enterprise_server >= 3.17.0, < 3.17.9","enterprise_server >= 3.18.0, < 3.18.3"],"patched":["enterprise_server 3.18.3"],"published":"2025-12-11","updated":"2026-10-07","sourceUpdated":"2026-10-07T20:10:01.970","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-14046","references":[{"url":"https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.21","label":"product-cna@github.com"},{"url":"https://docs.github.com/en/enterprise-server@3.15/admin/release-notes#3.15.16","label":"product-cna@github.com"},{"url":"https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.12","label":"product-cna@github.com"},{"url":"https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.9","label":"product-cna@github.com"},{"url":"https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.3","label":"product-cna@github.com"}],"tags":["nvd"],"epss":0.00386,"epssPercentile":0.30382,"ingestedAt":"2026-10-07T20:46:46.856Z","slug":"CVE-2025-14046","body":"## Overview\n\nAn improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied HTML to inject DOM elements with IDs that collided with server-initialized data islands. These collisions could overwrite or shadow critical application state objects used by certain Project views, leading to unintended server-side POST requests or other unauthorized backend interactions. Successful exploitation requires an attacker to have access to the target GitHub Enterprise Server instance and to entice a privileged user to view crafted malicious content that includes conflicting HTML elements. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.18.3, 3.17.9, 3.16.12, 3.15.16, and 3.14.21.\n\n## Affected\n\n- `enterprise_server < 3.14.21`\n- `enterprise_server >= 3.15.0, < 3.15.16`\n- `enterprise_server >= 3.16.0, < 3.16.12`\n- `enterprise_server >= 3.17.0, < 3.17.9`\n- `enterprise_server >= 3.18.0, < 3.18.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `enterprise_server 3.18.3`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}