Technology

Technology

Critical GitHub flaw (CVE-2026-3854) could enable RCE via a single git push

Apr 29, 2026 08:00

Security researchers reported a command-injection vulnerability in GitHub.com and GitHub Enterprise Server that could allow authenticated attackers with push access to trigger remote code execution. Teams should review access controls and apply vendor mitigations/patches as they become available.