A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrote quote characters in a
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GitHub | Enterprise Server | 3.17.0 ~ 3.17.* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77987 | 9.3 CRITICAL | GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery |
| CVE-2026-75101 | 6.0 MEDIUM | Authorization bypass vulnerability in GitHub Enterprise Server allowed reading of private |
No comments yet