PT-2026-97051 · Github · Github Enterprise Server

·

CVE-2026-77912

·

Published

2026-09-22

·

Updated

2026-09-24

CVSS v4.0

7.4

High

VectorAV:N/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/AU:Y
Name of the Vulnerable Software and Affected Versions GitHub Enterprise Server versions 3.17 through 3.17.20 GitHub Enterprise Server versions 3.18 through 3.18.14 GitHub Enterprise Server versions 3.19 through 3.19.11 GitHub Enterprise Server versions 3.20 through 3.20.7 GitHub Enterprise Server versions 3.21 through 3.21.5 GitHub Enterprise Server versions 3.22 through 3.22.0
Description A stored cross-site scripting (XSS) issue exists where an authenticated attacker can inject arbitrary HTML attributes into rendered Markdown. This occurs because the Markdown rendering pipeline rewrites quote characters in previously sanitized HTML without performing a second sanitization pass. By using crafted Markdown and same-origin JavaScript gadgets, an attacker can bypass the Content Security Policy (CSP) and control the page DOM. This could lead to the theft of content visible to the victim, extraction of embedded CSRF tokens, execution of state-changing actions, and data exfiltration. Additionally, the payload may propagate to organizations and repositories where the victim possesses write access.
Recommendations Update to version 3.17.21 Update to version 3.18.15 Update to version 3.19.12 Update to version 3.20.8 Update to version 3.21.6 Update to version 3.22.1

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77912

Affected Products

Github Enterprise Server