CVE-2026-3854: one git push, full shell on GitHub's backend.
CVSS 8.7. Free account was enough.
Reported March 4, 2026. Patched in 6 hours. 88% of GHES still vulnerable at disclosure.
A thread.
CVE-2026-3854: one git push, full shell on GitHub's backend.
CVSS 8.7. Free account was enough.
Reported March 4, 2026. Patched in 6 hours. 88% of GHES still vulnerable at disclosure.
A thread.
The lesson.
No crypto bug. No exotic syscall. A missing sanitizer on a semicolon, where user input flowed into an internal header.
Closed binaries are no longer a defence.
Follow @DjangoWiz for more.
CVE-2026-3854: one git push, full shell on GitHub's backend.
CVSS 8.7. Free account was enough.
Reported March 4, 2026. Patched in 6 hours. 88% of GHES still vulnerable at disclosure.
A thread.
8/ What to do.
GHES: patch now. 88% of instances were still vulnerable at disclosure. Assume yours is until you check.
https://t.co/OkZXFgWf17 only: nothing required, but rotating long-lived personal access tokens is cheap insurance.
@iamrjknight@elonmusk I sincerely doubt Solomon was richer than Elon ๐
Do you know what 700billion dollars is?
You need to make 39,000 dollars every hour since the time of Jesus Christ till today to have 700 billion dollars .
That's 657 dollars per minute or 10.9 dollar per second. Since 0 BC