Preliminary research
GitHub RCE Vulnerability: CVE-2026-3854
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Traces Git push-option delimiters into trusted metadata passed between GitHub services. Following the overwritten fields through their consumers reveals environment and sandbox changes, activation of pre-receive hooks and a traversable hook path, connecting a parsing boundary to server-side execution.
Record
- Researcher
- Sagi Tzadik
- Published by
- Wiz Research
- Date
- Topic
- Server
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Sagi Tzadik, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .