Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

GitHub — Vulnerabilities & Security Advisories 135

Browse all 135 CVE security advisories affecting GitHub. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GitHub operates as a cloud-based platform for version control and collaborative software development, primarily hosting Git repositories for millions of developers worldwide. Its extensive attack surface has historically exposed it to critical vulnerability classes, including remote code execution, cross-site scripting, and privilege escalation, often stemming from complex integrations and third-party dependencies. With 131 recorded CVEs, the platform has faced significant security challenges, most notably the 2021 incident where attackers compromised two-factor authentication tokens to access internal systems, leading to the theft of source code from major clients. These breaches underscore the risks associated with centralized code hosting and the potential for supply chain attacks. While GitHub employs rigorous security measures, its scale and role as infrastructure for global software development make it a high-value target, necessitating continuous vigilance against both external exploits and insider threats to maintain the integrity of the open-source ecosystem.

CVE IDTitleCVSSSeverityPublished
CVE-2021-37700 Clipboard-based DOM-XSS — paste-markdownCWE-79 6.5 Medium2021-08-12
CVE-2021-22867 Unsafe configuration options in GitHub Pages leading to path traversal on GitHub Enterprise Server — GitHub Enterprise ServerCWE-77 6.5 -2021-07-14
CVE-2021-32638 CodeQL runner: Command-line options that make GitHub access tokens visible to other processes are now deprecated — codeql-actionCWE-200 4.4 Medium2021-05-25
CVE-2021-22866 UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to user resources — GitHub Enterprise ServerCWE-451 8.8 -2021-05-14
CVE-2021-22865 Improper access control in GitHub Enterprise Server leading to unauthorized read access to private repository metadata — GitHub Enterprise ServerCWE-285 4.3 -2021-04-02
CVE-2021-22864 Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server — GitHub Enterprise ServerCWE-77 8.8 -2021-03-23
CVE-2021-22863 Improper access control in GitHub Enterprise Server leading to unauthorized changes to maintainer permissions on pull requests — GitHub Enterprise ServerCWE-285 8.1 -2021-03-03
CVE-2021-22862 Improper access control in GitHub Enterprise Server leading to the disclosure of Actions secrets to forks — GitHub Enterprise ServerCWE-285 6.5 -2021-03-03
CVE-2020-10519 Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server — GitHub Enterprise ServerCWE-77 8.8 -2021-03-03
CVE-2021-22861 Improper access control in GitHub Enterprise Server leading to unauthorized write access to forkable repositories — GitHub Enterprise ServerCWE-285 4.3 -2021-03-03
CVE-2020-10517 Improper access control in GitHub Enterprise Server leading to the enumeration of private repository names — GitHub Enterprise ServerCWE-285 4.3 -2020-08-27
CVE-2020-10518 Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server — GitHub Enterprise ServerCWE-77 8.8 -2020-08-27
CVE-2020-5238 Denial of service in table parsing in cmark-gfm — cmark-gfmCWE-20 6.5 Medium2020-07-01
CVE-2020-10516 Improper access control in GitHub Enterprise Server leading to privilege escalation of organization member — GitHub Enterprise ServerCWE-285 8.8 -2020-06-03
CVE-2019-16765 Microsoft Visual Studio Code 输入验证错误漏洞 — vscode-codeqlCWE-250 7.4 High2019-11-25

This page lists every published CVE security advisory associated with GitHub. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.