vulns.co
/
GKData.io MCP

Wiz Research · 2 min read

GitHub internal metadata: preserve the boundary between user data and service authority

Wiz's CVE-2026-3854 research examines a data-to-authority boundary in GitHub's backend. User-controlled operation metadata reached downstream services as trusted configuration. Code execution was demonstrated on Enterprise Server and hosted infrastructure. Wiz bounded cross-tenant content validation to its own accounts; broader repository exposure was a capability inference, not demonstrated theft of customer content.

Open the reference Research PaperReviewed 2026-10-03

How to use this reference

Editorial lessons: preserve provenance when internal services exchange mixed-trust data, keep policy decisions independent of user-controlled metadata, and remove environment-inappropriate execution paths. GitHub confirms input sanitization and removal of unnecessary code paths as remediation. Review the vendor's maintained release guidance rather than treating a researcher version table as definitive.

Before reading

  • Familiarity with service-to-service trust boundaries
  • Basic authorization and serialization concepts

Context and limits

  • Technical precondition: an authenticated user needed repository push permission (vendor). Learning prerequisites above are editorial.
  • Wiz reports controlled cross-tenant validation with its own accounts and says it did not access other tenants' repository contents. GitHub's investigation attributes observed activity to the researchers and reports no customer-data access, modification or exfiltration.
  • Wiz dates reporting and hosted remediation to March 4, 2026, Enterprise Server patch release to March 10, and disclosure to April 28. GitHub corroborates hosted remediation on March 4; its article was updated April 29.
  • Remediation-version disagreement: Wiz lists 3.19.3 among fixed versions, while GitHub's updated guidance recommends 3.19.4 or later and newer patch levels across other branches. The difference is preserved rather than resolved by inference; no independent patch verification was performed.
  • The exact award amount and payment settlement are undisclosed in the reviewed articles. This educational resource does not qualify or promote the existing award-report candidate.

Sources and provenance

  1. Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854) Wiz Research · reviewed 2026-10-03
  2. Securing the git push pipeline: Responding to a critical remote code execution vulnerability GitHub · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software