
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14046 is an improper input neutralization vulnerability (CWE-79/XSS) in GitHub Enterprise Server (GHES) that allows user-supplied HTML to inject DOM elements with IDs that collide with server-initialized data islands. These collisions can overwrite or shadow critical application state objects used by certain Project views, potentially leading to unintended server-side POST requests or other unauthorized backend interactions. The vulnerability affects all GHES versions prior to 3.14.21, 3.15.16, 3.16.12, 3.17.9, and 3.18.3. It was disclosed on December 11, 2025, with a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 8.6 (High) (Feedly, GHES 3.18 Release Notes).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-site Scripting), specifically a DOM-based variant where user-controlled HTML is rendered without sufficient sanitization. The attack mechanism involves an attacker injecting HTML elements with IDs that match server-initialized JavaScript data islands — structured data objects embedded in the page by the server to initialize application state for Project views. When a crafted page is loaded by a victim, the attacker-supplied DOM element shadows or overwrites the legitimate data island, causing the application to use attacker-controlled state, which can trigger unintended server-side POST requests or other unauthorized backend interactions. Exploitation requires the attacker to have access to the GHES instance and to socially engineer a privileged user into viewing the malicious content (Feedly).
Successful exploitation can result in high confidentiality and integrity impacts against the vulnerable system, as reflected in the CVSS v4.0 scoring (VC:H, VI:H). An attacker who tricks a privileged user into viewing crafted content could cause unauthorized server-side POST requests to be issued on behalf of that user, potentially modifying project data or triggering other privileged backend operations. Availability is not directly impacted, and the attack scope is limited to the GHES instance itself rather than enabling broad lateral movement (Feedly).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.051% (0.000510), indicating a very low probability of exploitation in the near term. Exploitation requires both access to the GHES instance and successful social engineering of a privileged user, which raises the practical bar for attackers.
id attributes matching the names of server-initialized JavaScript data islands used by GHES Project views.<script type="application/json" id="..."> or similar patterns).<div id="[target-data-island-id]">...</div> or similar, designed to shadow or overwrite the legitimate server-initialized state object when the page is rendered.id attributes that match known GHES data island identifiers.GitHub has released patched versions of GHES that address this vulnerability. Administrators should upgrade to one of the following fixed versions as soon as possible: 3.14.21, 3.15.16, 3.16.12, 3.17.9, or 3.18.3 (GHES 3.18 Release Notes, GHES 3.17 Release Notes). As interim mitigations, administrators should restrict access to the GHES instance to trusted users only, apply the principle of least privilege, and educate privileged users to be cautious about viewing content from untrusted sources. No configuration-based workaround is documented by GitHub for this specific vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."