Skills
Wiz Discovers GitHub RCE via AI Reverse Engineering (CVE-2026-3854): First Critical Closed-Source Bug Found by AI, Cross-Tenant Access to Millions of Repos
Wiz Research used IDA MCP (AI-augmented reverse engineering) to discover CVE-2026-3854 (CVSS 8.7) in GitHub's internal X-Stat protocol — a semicolon injection in git push options enabling RCE as the git service user. On GitHub.com, researchers landed on shared storage nodes holding millions of public and private repos across organizations. Public disclosure was April 28; 88% of GitHub Enterprise Server instances remain unpatched.
Source
↳ Follow the thread