CVE Tools

Securing the git push pipeline: Responding to a critical remote code execution vulnerability

GitHub Security LabBy Alexis Wales5 min read

Patchgithub.comGitHub Enterprise Server
Read at GitHub Security Lab

Below is the opening; the full story is at GitHub Security Lab.

From GitHub Security Lab

On March 4, 2026, we received a vulnerability report through our Bug Bounty program from researchers at Wiz describing a critical remote code execution vulnerability affecting github.com, GitHub Enterprise Cloud, GitHub Enterprise Cloud with Data Residency, GitHub Enterprise Cloud with Enterprise Managed Users, and GitHub Enterprise Server.…

Continue at GitHub Security Lab

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store