
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-77912 is a stored cross-site scripting (XSS) vulnerability in GitHub Enterprise Server (GHES) that allows an authenticated attacker to inject arbitrary HTML attributes into Markdown-rendered pages. The root cause is that the Markdown rendering pipeline rewrites quote characters in already-sanitized HTML without re-sanitizing the result, enabling crafted Markdown to bypass Content Security Policy via same-origin JavaScript gadgets. Affected versions span the 3.17, 3.18, 3.19, 3.20, 3.21, and 3.22 series; fixed versions are 3.17.21, 3.18.15, 3.19.12, 3.20.8, 3.21.6, and 3.22.1. The vulnerability was disclosed on September 22, 2026, and reported via the GitHub Bug Bounty program. It carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 7.4 (High) (GitHub Advisory, GHES 3.17 Release Notes).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting). The flaw exists in the Markdown rendering pipeline: when processing Markdown content, the pipeline first sanitizes HTML, but then rewrites quote characters in the sanitized output without performing a second sanitization pass. This allows an attacker to craft Markdown that, after the quote-rewriting step, introduces unsanitized HTML attributes into the rendered page. By abusing same-origin JavaScript gadgets already present on the page, the injected attributes can execute arbitrary JavaScript in the victim's browser, effectively bypassing the instance's Content Security Policy. Exploitation requires the attacker to be authenticated and to post crafted Markdown content (e.g., an issue comment, README, or wiki page) that a victim user subsequently views (GitHub Advisory, GHES 3.19 Release Notes).
Successful exploitation allows the attacker to read all content visible to the victim user, extract embedded CSRF tokens, and perform state-changing actions (such as creating repositories, modifying settings, or pushing code) on behalf of the victim. Exfiltrated data can be sent to attacker-controlled infrastructure via same-origin writes. Critically, the XSS payload can self-propagate to any repository or organization where the victim has write access, amplifying the blast radius beyond the initial injection point and enabling lateral movement across the enterprise (GitHub Advisory, GHES 3.20 Release Notes).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.45%, indicating a low near-term exploitation probability. No threat actor attribution has been reported. The NVD SSVC assessment classifies exploitation as "none" and automatable as "no," though the CVSS v4.0 vector marks the vulnerability as automatable (AU:Y), reflecting the potential for scripted payload propagation once initial access is established.
onerror or onmouseover) into the rendered HTML. The payload exploits the fact that quote characters are rewritten post-sanitization without re-sanitization.<script> tag, thereby bypassing CSP.onerror=, onmouseover=, encoded quote sequences) from a single user account targeting high-privilege users.GitHub has released patched versions addressing the Markdown sanitization flaw for all affected release series: 3.17.21, 3.18.15, 3.19.12, 3.20.8, 3.21.6, and 3.22.1. Administrators should upgrade to the appropriate patched version as the primary remediation (GHES 3.17 Release Notes, GHES 3.18 Release Notes). Until patching is possible, limit the ability to create or edit Markdown content (issues, PRs, wikis, READMEs) to trusted users only, and review audit logs for suspicious Markdown content creation or modification. Administrators should also monitor for unexpected state-changing actions performed by high-privilege accounts.
Security news outlet SecurityOnline.info covered the batch of GHES vulnerabilities disclosed on September 22, 2026, including CVE-2026-77912, noting the range of severity across the release (SecurityOnline). UnderCode News highlighted the broader GHES security release, focusing on the critical SSRF-to-RCE vulnerability (CVE-2026-77987) disclosed in the same patch batch, with CVE-2026-77912 noted as part of the same advisory (UnderCode News). No significant independent researcher commentary or social media discussion specific to CVE-2026-77912 has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."