Github
30 known vulnerabilities
Top Products
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to de
GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token
A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated att
A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to r
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gai
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization h
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenti
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker t
`gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified i
GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulne
A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page th
A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that a
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to
An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attack
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker t
An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server
An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacke
An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to byp
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin acc
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user w
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed DOM-based cros
An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an
An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed a user with read access
The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution thro
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to merge th
A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to upload unau
An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects t
An Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server
Frequently Asked Questions
How many CVEs affect Github?
Github has 30 CVE records in our database, including 4 critical and 10 high severity vulnerabilities.
What are the most severe Github vulnerabilities?
Github has 4 critical severity (CVSS 9.0+) and 10 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Github vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Github products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Github Vulnerabilities
CyberStrike scans your infrastructure for Github vulnerabilities and provides real-time remediation guidance.
Get Started