GitHub RCE Vulnerability CVE-2026-3854: Single Git Push Could Compromise Millions of Repos — 362 Points on HN
Wiz Research / Hacker News·high signal
Wiz Research disclosed CVE-2026-3854 (CVSS 8.7), a command injection flaw in GitHub's internal git protocol where any authenticated user could execute arbitrary commands on GitHub backend servers via a standard git push. The vulnerability in babeld's X-Stat header parsing enabled cross-tenant exposure, potentially allowing attackers to read millions of repositories. Notable: this is one of the first critical vulnerabilities discovered in closed-source binaries using AI. Fixed same day it was reported (March 4, 2026).