---
id: CVE-2025-14046
title: >-
  An improper neutralization of input vulnerability was identified in GitHub
  Enterprise Server that allowed user-supplied HTML to inject DOM elements with
  IDs that collided with server-initialized data islands
summary: >-
  An improper neutralization of input vulnerability was identified in GitHub
  Enterprise Server that allowed user-supplied HTML to inject DOM elements with
  IDs that collided with server-initialized data islands. These collisions could
  overw…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: github
product: enterprise_server
affected:
  - enterprise_server < 3.14.21
  - 'enterprise_server >= 3.15.0, < 3.15.16'
  - 'enterprise_server >= 3.16.0, < 3.16.12'
  - 'enterprise_server >= 3.17.0, < 3.17.9'
  - 'enterprise_server >= 3.18.0, < 3.18.3'
patched:
  - enterprise_server 3.18.3
published: '2025-12-11'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14046'
references:
  - url: >-
      https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.21
    label: product-cna@github.com
  - url: >-
      https://docs.github.com/en/enterprise-server@3.15/admin/release-notes#3.15.16
    label: product-cna@github.com
  - url: >-
      https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.12
    label: product-cna@github.com
  - url: >-
      https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.9
    label: product-cna@github.com
  - url: >-
      https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.3
    label: product-cna@github.com
tags:
  - nvd
epss: 0.00386
epssPercentile: 0.30382
ingestedAt: '2026-10-07T20:46:46.856Z'
---

## Overview

An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied HTML to inject DOM elements with IDs that collided with server-initialized data islands. These collisions could overwrite or shadow critical application state objects used by certain Project views, leading to unintended server-side POST requests or other unauthorized backend interactions. Successful exploitation requires an attacker to have access to the target GitHub Enterprise Server instance and to entice a privileged user to view crafted malicious content that includes conflicting HTML elements. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.18.3, 3.17.9, 3.16.12, 3.15.16, and 3.14.21.

## Affected

- `enterprise_server < 3.14.21`
- `enterprise_server >= 3.15.0, < 3.15.16`
- `enterprise_server >= 3.16.0, < 3.16.12`
- `enterprise_server >= 3.17.0, < 3.17.9`
- `enterprise_server >= 3.18.0, < 3.18.3`

## Remediation

Upgrade past the affected range:

- `enterprise_server 3.18.3`
