CVE-2026-77912: 
GitHub Enterprise Server vulnerability analysis and mitigation

Overview

CVE-2026-77912 is a stored cross-site scripting (XSS) vulnerability in GitHub Enterprise Server (GHES) that allows an authenticated attacker to inject arbitrary HTML attributes into Markdown-rendered pages. The root cause is that the Markdown rendering pipeline rewrites quote characters in already-sanitized HTML without re-sanitizing the result, enabling crafted Markdown to bypass Content Security Policy via same-origin JavaScript gadgets. Affected versions span the 3.17, 3.18, 3.19, 3.20, 3.21, and 3.22 series; fixed versions are 3.17.21, 3.18.15, 3.19.12, 3.20.8, 3.21.6, and 3.22.1. The vulnerability was disclosed on September 22, 2026, and reported via the GitHub Bug Bounty program. It carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 7.4 (High) (GitHub Advisory, GHES 3.17 Release Notes).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting). The flaw exists in the Markdown rendering pipeline: when processing Markdown content, the pipeline first sanitizes HTML, but then rewrites quote characters in the sanitized output without performing a second sanitization pass. This allows an attacker to craft Markdown that, after the quote-rewriting step, introduces unsanitized HTML attributes into the rendered page. By abusing same-origin JavaScript gadgets already present on the page, the injected attributes can execute arbitrary JavaScript in the victim's browser, effectively bypassing the instance's Content Security Policy. Exploitation requires the attacker to be authenticated and to post crafted Markdown content (e.g., an issue comment, README, or wiki page) that a victim user subsequently views (GitHub Advisory, GHES 3.19 Release Notes).

Impact

Successful exploitation allows the attacker to read all content visible to the victim user, extract embedded CSRF tokens, and perform state-changing actions (such as creating repositories, modifying settings, or pushing code) on behalf of the victim. Exfiltrated data can be sent to attacker-controlled infrastructure via same-origin writes. Critically, the XSS payload can self-propagate to any repository or organization where the victim has write access, amplifying the blast radius beyond the initial injection point and enabling lateral movement across the enterprise (GitHub Advisory, GHES 3.20 Release Notes).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.45%, indicating a low near-term exploitation probability. No threat actor attribution has been reported. The NVD SSVC assessment classifies exploitation as "none" and automatable as "no," though the CVSS v4.0 vector marks the vulnerability as automatable (AU:Y), reflecting the potential for scripted payload propagation once initial access is established.

Exploitation steps

  1. Gain authenticated access: Obtain any valid user account on the target GitHub Enterprise Server instance (e.g., via credential theft, social engineering, or a low-privilege account).
  2. Identify a Markdown-rendering surface: Locate a location where Markdown is rendered and visible to a high-privilege target user — such as an issue comment, pull request description, wiki page, or README in a shared repository.
  3. Craft malicious Markdown: Construct a Markdown payload that, after the rendering pipeline's quote-rewriting step, introduces an unsanitized HTML attribute (e.g., an event handler like onerror or onmouseover) into the rendered HTML. The payload exploits the fact that quote characters are rewritten post-sanitization without re-sanitization.
  4. Embed a same-origin JavaScript gadget: Reference an existing JavaScript function or object already loaded on the GHES page (a "gadget") to execute arbitrary code without needing to inject a <script> tag, thereby bypassing CSP.
  5. Deliver the payload to the victim: Post the crafted Markdown content in a location the target user will view (e.g., mention them in an issue, submit a PR to their repository).
  6. Harvest victim session data: When the victim views the page, the injected JavaScript executes in their browser, extracting CSRF tokens, session cookies (if accessible), or other sensitive data and exfiltrating it to an attacker-controlled endpoint via same-origin requests.
  7. Perform actions as the victim: Use extracted CSRF tokens to perform state-changing actions (e.g., adding SSH keys, modifying repository settings, pushing malicious code) as the victim user.
  8. Propagate the payload: If the victim has write access to other repositories or organizations, inject the same payload there to further spread the attack (GitHub Advisory, GHES 3.21 Release Notes).

Indicators of compromise

  • Logs: GHES audit log entries showing unexpected issue comments, pull request descriptions, wiki edits, or README modifications containing unusual HTML attribute patterns (e.g., onerror=, onmouseover=, encoded quote sequences) from a single user account targeting high-privilege users.
  • Logs: Audit log entries recording state-changing actions (SSH key additions, repository setting changes, organization membership changes) performed by a user shortly after viewing a Markdown-rendered page, potentially indicating CSRF token abuse.
  • Network: Outbound HTTP/HTTPS requests from the GHES instance or from victim user browsers to unexpected external domains, particularly those carrying encoded token or session data in query parameters or request bodies.
  • File System / Repository: Unexpected commits, file modifications, or webhook additions in repositories where the victim had write access, especially if the commit author or actor differs from the expected contributor.
  • Application: Unusual patterns in GHES web logs showing the same Markdown content being rendered repeatedly across multiple user sessions, or a spike in requests to Markdown-rendering endpoints from a single source account.

Mitigation and workarounds

GitHub has released patched versions addressing the Markdown sanitization flaw for all affected release series: 3.17.21, 3.18.15, 3.19.12, 3.20.8, 3.21.6, and 3.22.1. Administrators should upgrade to the appropriate patched version as the primary remediation (GHES 3.17 Release Notes, GHES 3.18 Release Notes). Until patching is possible, limit the ability to create or edit Markdown content (issues, PRs, wikis, READMEs) to trusted users only, and review audit logs for suspicious Markdown content creation or modification. Administrators should also monitor for unexpected state-changing actions performed by high-privilege accounts.

Community reactions

Security news outlet SecurityOnline.info covered the batch of GHES vulnerabilities disclosed on September 22, 2026, including CVE-2026-77912, noting the range of severity across the release (SecurityOnline). UnderCode News highlighted the broader GHES security release, focusing on the critical SSRF-to-RCE vulnerability (CVE-2026-77987) disclosed in the same patch batch, with CVE-2026-77912 noted as part of the same advisory (UnderCode News). No significant independent researcher commentary or social media discussion specific to CVE-2026-77912 has been identified beyond standard vulnerability database aggregation.

Additional resources


Source: This report was generated using AI

Related GitHub Enterprise Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77987CRITICAL9.3
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 22, 2026
CVE-2026-76851HIGH7.7
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 01, 2026
CVE-2026-19118HIGH7.7
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 01, 2026
CVE-2026-77912HIGH7.4
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 22, 2026
CVE-2026-75101MEDIUM6
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management