Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

github — Vulnerabilities & Security Advisories 149

Browse all 149 CVE security advisories affecting github. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GitHub operates as a cloud-based platform for version control and collaborative software development, primarily hosting Git repositories for millions of developers worldwide. Its extensive attack surface has historically exposed it to critical vulnerability classes, including remote code execution, cross-site scripting, and privilege escalation, often stemming from complex integrations and third-party dependencies. With 131 recorded CVEs, the platform has faced significant security challenges, most notably the 2021 incident where attackers compromised two-factor authentication tokens to access internal systems, leading to the theft of source code from major clients. These breaches underscore the risks associated with centralized code hosting and the potential for supply chain attacks. While GitHub employs rigorous security measures, its scale and role as infrastructure for global software development make it a high-value target, necessitating continuous vigilance against both external exploits and insider threats to maintain the integrity of the open-source ecosystem.

Found 46 results / 149 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2025-6600 GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Search API — GitHub Enterprise Server CWE-200 5.3AI Medium AI 2025-07-01
CVE-2025-3246 Markdown math block sanitization bypass allows privilege escalation and unauthorized workflow triggers — GitHub Enterprise Server CWE-79 5.4AI Medium AI 2025-04-17
CVE-2024-9539 GitHub Enterprise Server 安全漏洞 — GitHub Enterprise Server CWE-200 4.3AI Medium AI 2024-10-11
CVE-2024-8263 GitHub Enterprise Server 安全漏洞 — GitHub Enterprise Server CWE-269 9.1AI Critical AI 2024-09-23
CVE-2024-8770 GitHub Enterprise Server 安全漏洞 — GitHub Enterprise Server CWE-79 6.1AI Medium AI 2024-09-23
CVE-2024-6800 GitHub Enterprise Server 安全漏洞 — GitHub Enterprise Server CWE-347 9.8AI Critical AI 2024-08-20
CVE-2024-6337 Incorrect Authorization allows read access to issues in GitHub Enterprise Server — GitHub Enterprise Server CWE-863 4.3AI Medium AI 2024-08-20
CVE-2024-7711 GitHub Enterprise Server 安全漏洞 — GitHub Enterprise Server CWE-863 5.3AI Medium AI 2024-08-20
CVE-2024-6395 GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Deploy Keys — GitHub Enterprise Server CWE-200 5.3AI Medium AI 2024-07-16
CVE-2024-6336 Security misconfiguration was identified in GitHub Enterprise Server that allowed sensitive data exposure — GitHub Enterprise Server CWE-200 4.3AI Medium AI 2024-07-16
CVE-2024-5817 Improper authorization allows read access to issue content in GitHub Enterprise Server — GitHub Enterprise Server CWE-863 4.3AI Medium AI 2024-07-16
CVE-2024-5816 Improper authorization allows persistent access in GitHub Enterprise Server — GitHub Enterprise Server CWE-863 9.4AI Critical AI 2024-07-16
CVE-2024-5815 Cross Site Request Forgery was identified in GitHub Enterprise Server that allowed write in a user owned repository — GitHub Enterprise Server CWE-352 5.7AI Medium AI 2024-07-16
CVE-2024-5795 Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed resource exhaustion — GitHub Enterprise Server CWE-400 7.7 High 2024-07-16
CVE-2024-5566 Improper Privilege Management allows for access to unauthorized repository content during migration — GitHub Enterprise Server CWE-269 5.8 Medium 2024-07-16
CVE-2024-5746 GitHub Enterprise Server 安全漏洞 — GitHub Enterprise Server CWE-918 7.6 High 2024-06-20
CVE-2024-2443 Improper input validation vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console — GitHub Enterprise Server CWE-20 9.1 Critical 2024-03-20
CVE-2022-46257 Information disclosure in GitHub Enterprise Server leading to unauthorized viewing of private repository names — GitHub Enterprise Server CWE-200 6.5 - 2023-03-07
CVE-2023-22380 Path traversal in GitHub Enterprise Server leading to arbitrary file reading when building a GitHub Pages site — GitHub Enterprise Server CWE-22 6.5 - 2023-02-16
CVE-2022-23739 Incorrect authorization check in GitHub Enterprise Server leading to escalation of privileges in GraphQL API requests from GitHub Apps using scoped user-to-server tokens — GitHub Enterprise Server CWE-863 7.8 - 2023-01-17
CVE-2022-46258 Incorrect Authorization in GitHub Enterprise Server leads to Action Workflow modifications without Workflow Scope — GitHub Enterprise Server CWE-863 6.5 - 2023-01-09
CVE-2022-23741 Incorrect authorization in GitHub Enterprise Server token generation leading to full admin access — GitHub Enterprise Server CWE-863 7.2 - 2022-12-14
CVE-2022-46256 Path traversal in GitHub Enterprise Server leading to remote code execution in GitHub Pages — GitHub Enterprise Server CWE-22 8.8 - 2022-12-14
CVE-2022-46255 Improper Limitation of a Pathname to a Restricted Directory in GitHub Enterprise Server leading to RCE — GitHub Enterprise Server CWE-22 9.8 - 2022-12-14
CVE-2022-23737 Improper Privilege Management in GitHub Enterprise Server leading to page creation and deletion — GitHub Enterprise Server CWE-269 6.5 - 2022-12-01
CVE-2022-23740 Improper Neutralization of Argument Delimiters in a Command in GitHub Enterprise Server leading to Remote Code Execution — GitHub Enterprise Server CWE-88 8.8 - 2022-11-23
CVE-2022-23738 Incomplete cache verification issue in GitHub Enterprise Server leading to exposure of private repo files — GitHub Enterprise Server CWE-200 5.7 - 2022-11-01
CVE-2022-23734 Deserialization of Untrusted Data vulnerability in GitHub Enterprise Server leading to Remote Code Execution — GitHub Enterprise Server CWE-502 8.8 - 2022-10-19
CVE-2022-23733 Stored XSS vulnerability in GitHub Enterprise Server leading to injection of arbitrary attributes — GitHub Enterprise Server CWE-79 5.4 - 2022-08-02
CVE-2022-23732 Path traversal in GitHub Enterprise Server management console leading to a bypass of CSRF protections — GitHub Enterprise Server CWE-23 8.8 - 2022-04-05

This page lists every published CVE security advisory associated with github. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.