Skip to content
Vulnerability intelligence

CVE-2026-3854: GitHub Enterprise Server remote code execution

A semicolon Git allowed, plus last-value-wins parsing, was the opening for CVE-2026-3854.

CVSS 8.7 2026