CVE-2025-14046: 
GitHub Enterprise Server vulnerability analysis and mitigation

Overview

CVE-2025-14046 is an improper input neutralization vulnerability (CWE-79/XSS) in GitHub Enterprise Server (GHES) that allows user-supplied HTML to inject DOM elements with IDs that collide with server-initialized data islands. These collisions can overwrite or shadow critical application state objects used by certain Project views, potentially leading to unintended server-side POST requests or other unauthorized backend interactions. The vulnerability affects all GHES versions prior to 3.14.21, 3.15.16, 3.16.12, 3.17.9, and 3.18.3. It was disclosed on December 11, 2025, with a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 8.6 (High) (Feedly, GHES 3.18 Release Notes).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-site Scripting), specifically a DOM-based variant where user-controlled HTML is rendered without sufficient sanitization. The attack mechanism involves an attacker injecting HTML elements with IDs that match server-initialized JavaScript data islands — structured data objects embedded in the page by the server to initialize application state for Project views. When a crafted page is loaded by a victim, the attacker-supplied DOM element shadows or overwrites the legitimate data island, causing the application to use attacker-controlled state, which can trigger unintended server-side POST requests or other unauthorized backend interactions. Exploitation requires the attacker to have access to the GHES instance and to socially engineer a privileged user into viewing the malicious content (Feedly).

Impact

Successful exploitation can result in high confidentiality and integrity impacts against the vulnerable system, as reflected in the CVSS v4.0 scoring (VC:H, VI:H). An attacker who tricks a privileged user into viewing crafted content could cause unauthorized server-side POST requests to be issued on behalf of that user, potentially modifying project data or triggering other privileged backend operations. Availability is not directly impacted, and the attack scope is limited to the GHES instance itself rather than enabling broad lateral movement (Feedly).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.051% (0.000510), indicating a very low probability of exploitation in the near term. Exploitation requires both access to the GHES instance and successful social engineering of a privileged user, which raises the practical bar for attackers.

Exploitation steps

  1. Gain access to the GHES instance: The attacker must have at least basic user-level access to the target GitHub Enterprise Server instance.
  2. Craft malicious HTML content: Create content (e.g., in an issue, comment, project description, or other user-controlled field) that includes HTML elements with id attributes matching the names of server-initialized JavaScript data islands used by GHES Project views.
  3. Identify target data island IDs: Analyze the GHES Project view page source to identify the specific element IDs used by server-initialized data objects (e.g., JSON blobs embedded in <script type="application/json" id="..."> or similar patterns).
  4. Inject conflicting DOM elements: Submit crafted HTML containing elements like <div id="[target-data-island-id]">...</div> or similar, designed to shadow or overwrite the legitimate server-initialized state object when the page is rendered.
  5. Entice a privileged user to view the content: Use phishing, direct messaging, or other social engineering to get a privileged user (e.g., organization owner or admin) to navigate to the page containing the malicious content.
  6. Trigger unauthorized backend interaction: When the privileged user loads the page, the application reads the attacker-controlled DOM element instead of the legitimate data island, causing the application to issue unintended server-side POST requests or other backend interactions with the victim's session credentials (Feedly).

Indicators of compromise

  • Logs: Unexpected or anomalous POST requests to GHES Project-related API endpoints originating from privileged user sessions, particularly those not correlated with known user actions in the audit log.
  • Logs: Audit log entries showing project state modifications or backend interactions that the privileged user did not intentionally initiate.
  • Network: Unusual server-side POST requests to internal GHES project endpoints triggered immediately after a privileged user views a specific page or content item.
  • Application: User-generated content (issues, comments, project descriptions) containing HTML elements with id attributes that match known GHES data island identifiers.

Mitigation and workarounds

GitHub has released patched versions of GHES that address this vulnerability. Administrators should upgrade to one of the following fixed versions as soon as possible: 3.14.21, 3.15.16, 3.16.12, 3.17.9, or 3.18.3 (GHES 3.18 Release Notes, GHES 3.17 Release Notes). As interim mitigations, administrators should restrict access to the GHES instance to trusted users only, apply the principle of least privilege, and educate privileged users to be cautious about viewing content from untrusted sources. No configuration-based workaround is documented by GitHub for this specific vulnerability.

Additional resources


Source: This report was generated using AI

Related GitHub Enterprise Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77987CRITICAL9.3
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 22, 2026
CVE-2026-76851HIGH7.7
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 01, 2026
CVE-2026-19118HIGH7.7
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 01, 2026
CVE-2026-77912HIGH7.4
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 22, 2026
CVE-2026-75101MEDIUM6
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management