Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

github — Vulnerabilities & Security Advisories 149

Browse all 149 CVE security advisories affecting github. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GitHub operates as a cloud-based platform for version control and collaborative software development, primarily hosting Git repositories for millions of developers worldwide. Its extensive attack surface has historically exposed it to critical vulnerability classes, including remote code execution, cross-site scripting, and privilege escalation, often stemming from complex integrations and third-party dependencies. With 131 recorded CVEs, the platform has faced significant security challenges, most notably the 2021 incident where attackers compromised two-factor authentication tokens to access internal systems, leading to the theft of source code from major clients. These breaches underscore the risks associated with centralized code hosting and the potential for supply chain attacks. While GitHub employs rigorous security measures, its scale and role as infrastructure for global software development make it a high-value target, necessitating continuous vigilance against both external exploits and insider threats to maintain the integrity of the open-source ecosystem.

Found 80 results / 149Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2025-11892 DOM-based Cross-Site Scripting was identified in GitHub Enterprise Server Issues search allows privilege escalation and unauthorized workflow triggers — Enterprise ServerCWE-79 6.1 -2025-11-10
CVE-2025-8447 Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed read-only access — Enterprise ServerCWE-639 3.1AILowAI2025-08-26
CVE-2025-6981 Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized read-only access — Enterprise ServerCWE-863 7.5AIHighAI2025-07-15
CVE-2025-3509 Pre-Receive Hook Remote Code Execution vulnerability was identified in GitHub Enterprise Server that allowing Privilege Escalation — Enterprise ServerCWE-94 6.6AIMediumAI2025-04-17
CVE-2025-3124 Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized access to private repository names — Enterprise ServerCWE-862 4.3AIMediumAI2025-04-17
CVE-2024-10001 Code Injection Vulnerability in GitHub Enterprise Server Allows Arbitrary Code Execution via Message Handling — Enterprise ServerCWE-94 8.3 -2025-01-29
CVE-2025-23369 Improper Verification of Cryptographic Signature in GitHub Enterprise Server Allows Signature Spoofing by Improper Validation — Enterprise ServerCWE-347 7.5 -2025-01-21
CVE-2024-8810 Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed GitHub Apps to grant themselves write access — Enterprise ServerCWE-269 6.5AIMediumAI2024-11-07
CVE-2024-10824 Authorization Bypass Vulnerability was Identified in GitHub Enterprise Server that Allowed Unauthorized Internal Users to Access Secret Scanning Alert Data — Enterprise ServerCWE-862 4.3AIMediumAI2024-11-07
CVE-2024-10007 Pre-Receive Hook Path Collision Vulnerability in GitHub Enterprise Server Allowing Privilege Escalation — Enterprise ServerCWE-59 9.1AICriticalAI2024-11-07
CVE-2024-9487 An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed when the encrypted assertions feature was enabled — Enterprise ServerCWE-347 9.8AICriticalAI2024-10-10
CVE-2024-4985 GitHub Enterprise Server 安全漏洞 — Enterprise ServerCWE-303 9.8AICriticalAI2024-05-20
CVE-2024-2440 Race Condition was identified in GitHub Enterprise Server that allowed maintaining admin permissions — Enterprise ServerCWE-367 5.5 Medium2024-04-19
CVE-2024-3684 Improper Privilege Management was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console — Enterprise ServerCWE-88 8.0 High2024-04-19
CVE-2024-3646 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console — Enterprise ServerCWE-20 8.0 High2024-04-19
CVE-2024-2469 Remote Code Execution in GitHub Enterprise Server Allowed Administrators to gain SSH access to the appliance — Enterprise ServerCWE-20 8.0 High2024-03-20
CVE-2024-1908 Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed Privilege Escalation — Enterprise ServerCWE-269 6.3 Medium2024-02-29
CVE-2024-1482 Improper Authorization in GitHub Enterprise Server allowed unauthorized workflow execution — Enterprise ServerCWE-863 7.1 High2024-02-14
CVE-2024-1378 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console — Enterprise ServerCWE-20 9.1 Critical2024-02-13
CVE-2024-1374 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console — Enterprise ServerCWE-20 9.1 Critical2024-02-13
CVE-2024-1372 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console — Enterprise ServerCWE-20 9.1 Critical2024-02-13
CVE-2024-1369 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console — Enterprise ServerCWE-20 9.1 Critical2024-02-13
CVE-2024-1359 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console — Enterprise ServerCWE-20 9.1 Critical2024-02-13
CVE-2024-1355 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console — Enterprise ServerCWE-20 9.1 Critical2024-02-13
CVE-2024-1354 Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console — Enterprise ServerCWE-20 8.0 High2024-02-13
CVE-2024-1082 Path traversal vulnerability in GitHub Enterprise Server that allowed arbitrary file read with a specially crafted GitHub Pages artifact upload — Enterprise ServerCWE-22 6.3 Medium2024-02-13
CVE-2024-1084 GitHub Enterprise Server 安全漏洞 — Enterprise ServerCWE-79 6.5 Medium2024-02-13
CVE-2024-0507 Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise Server — Enterprise ServerCWE-20 6.5 Medium2024-01-16
CVE-2024-0200 Unsafe Reflection in Github Enterprise Server leading to Command Injection — Enterprise ServerCWE-470 7.2 High2024-01-16
CVE-2023-6847 Improper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository Data — Enterprise ServerCWE-287 7.5 High2023-12-21

This page lists every published CVE security advisory associated with github. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.