Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-15343— Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths

AI Predicted 8.8 Difficulty: Easy EPSS 0.45% · P37

Affected Version Matrix 5

VendorProductVersion RangeStatus
GitHubEnterprise Server3.17.0≤ 3.17.17affected
3.18.0≤ 3.18.11affected
3.19.0≤ 3.19.8affected
3.20.0≤ 3.20.4affected
3.21.0≤ 3.21.2affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-15343

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths
Source: CVE Program / CVE List V5
Vulnerability Description
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including GitHub Actions workflow files under .github/workflows/ as the path validation did not check the effective path which the attacker could control through the dependency file's directory and symlink target. If the repository used a pull_request_target workflow or had auto-merge enabled, an injected workflow could execute with access to the repository's GitHub Actions secrets. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.3, 3.20.5, 3.19.9, 3.18.12, 3.17.18.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5
Vulnerability Title
GitHub Enterprise Server 路径遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GitHub enterprise server是美国GitHub公司的一款一座企业级代码托管服务器。 GitHub Enterprise Server 3.22之前版本存在路径遍历漏洞,该漏洞源于路径验证未检查有效路径,可能导致在Dependabot更新器容器中具有代码执行权限的攻击者写入任意存储库路径,包括注入GitHub Actions工作流文件。以下版本受到影响:3.17.0版本至3.17.17版本、3.18.0版本至3.18.11版本、3.19.0版本至3.19.8版本、3.20.0版本至3.2
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
GitHubEnterprise Server 3.17.0 ~ 3.17.17 -

II. Public POCs for CVE-2026-15343

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-15343

登录查看更多情报信息。

Same Patch Batch · GitHub · 2026-07-17 · 4 CVEs total

CVE-2026-541634.7 MEDIUMsecure_headers: CSP directive injection via sandbox, plugin_types, and report_to when give
CVE-2026-15007Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via
CVE-2026-15783Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowe

IV. Related Vulnerabilities

V. Comments for CVE-2026-15343

No comments yet


Leave a comment