PT-2026-97051 · Github · Github Enterprise Server
CVSS v4.0
7.4
High
| Vector | AV:N/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/AU:Y |
Name of the Vulnerable Software and Affected Versions
GitHub Enterprise Server versions 3.17 through 3.17.20
GitHub Enterprise Server versions 3.18 through 3.18.14
GitHub Enterprise Server versions 3.19 through 3.19.11
GitHub Enterprise Server versions 3.20 through 3.20.7
GitHub Enterprise Server versions 3.21 through 3.21.5
GitHub Enterprise Server versions 3.22 through 3.22.0
Description
A stored cross-site scripting (XSS) issue exists where an authenticated attacker can inject arbitrary HTML attributes into rendered Markdown. This occurs because the Markdown rendering pipeline rewrites quote characters in previously sanitized HTML without performing a second sanitization pass. By using crafted Markdown and same-origin JavaScript gadgets, an attacker can bypass the Content Security Policy (CSP) and control the page DOM. This could lead to the theft of content visible to the victim, extraction of embedded CSRF tokens, execution of state-changing actions, and data exfiltration. Additionally, the payload may propagate to organizations and repositories where the victim possesses write access.
Recommendations
Update to version 3.17.21
Update to version 3.18.15
Update to version 3.19.12
Update to version 3.20.8
Update to version 3.21.6
Update to version 3.22.1
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github Enterprise Server