CVE-2025-11578High· 7.2▾ TwilightA privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH access to the appliance by exploiting a symlink escape in pre-receive hook environments. By c…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH access to the appliance by exploiting a symlink escape in pre-receive hook environments. By crafting a malicious repository and environment, an attacker could replace system binaries during hook cleanup and execute a payload that adds their own SSH key to the root user’s authorized keys—thereby granting themselves root SSH access to the server. To exploit this vulnerability, the attacker needed to have enterprise admin privileges. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.19, and was fixed in versions 3.14.20, 3.15.15, 3.16.11, 3.17.8, 3.18.2. This vulnerability was reported via the GitHub Bug Bounty program.
enterprise_server >= 3.14.0, < 3.14.20enterprise_server >= 3.15.0, < 3.15.15enterprise_server >= 3.16.0, < 3.16.11enterprise_server >= 3.17.0, < 3.17.8enterprise_server >= 3.18.0, < 3.18.2Upgrade past the affected range:
enterprise_server 3.18.2Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14046Medium· 6.1An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied HTML to inject DOM elements with IDs that collided with server-initialized data islands
CVE-2026-75101Medium· 6.5An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization
CVE-2026-77987Critical· 9.8A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server
CVE-2026-77912Medium· 5.4A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrot…
CVE-2026-18730High· 7.4A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled host
CVE-2026-19118High· 7.5A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution