Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223839 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-77912PATCHED
GitHub · Enterprise Server

Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipeline

Description

A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrote quote characters in already-sanitized HTML without re-sanitizing the result. Crafted Markdown could abuse same-origin JavaScript gadgets to bypass Content Security Policy and gain control of the page DOM when viewed by another user. Successful exploitation could allow an attacker to read content visible to the victim, extract embedded CSRF tokens, perform state-changing actions as the victim, and exfiltrate data through same-origin writes. The payload could also propagate to repositories and organizations where the victim had write access. This vulnerability affected supported GitHub Enterprise Server releases in the 3.17, 3.18, 3.19, 3.20, 3.21, and 3.22 series and was fixed in versions 3.22.1, 3.21.6, 3.20.8, 3.19.12, 3.18.15, and 3.17.21. This vulnerability was reported via the GitHub Bug Bounty program.

Affected Products

VendorProductVersions
GitHubEnterprise Server3.17.0, 3.18.0, 3.19.0, 3.20.0, 3.21.0, 3.22.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftgithub enterprisecert_advisory90%

References

  • https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.21(release-notes)
  • https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.15(release-notes)
  • https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.12(release-notes)
  • https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.8(release-notes)
  • https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.6(release-notes)
  • https://docs.github.com/en/enterprise-server@3.22/admin/release-notes#3.22.1(release-notes)

Related News (2 articles)

Tier B
BSI Advisories4d ago
[NEU] [hoch] Microsoft GitHub Enterprise Server: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-77912 | GitHub Enterprise Server up to 3.22.0 Markdown Rendering cross site scripting
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV❌ No
Actively exploited❌ No
Patch available
3.17.*3.18.*3.19.*3.20.*3.21.*3.22.*
CWECWE-79
PublishedSep 22, 2026
Last enriched5d ago
Trending Score21
Source articles2
Independent2
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-77987
GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery
Trending: 27
NONECVE-2026-75101
Authorization bypass vulnerability in GitHub Enterprise Server allowed reading of private pull request diffs and patches via repository name collision
Trending: 17
NONECVE-2026-19118
Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution
Trending: 15
NONECVE-2026-76851
Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access from pre-receive hooks to internal services
Trending: 2
NONECVE-2026-18730
Server-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent bearer token
Trending: 2

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 22, 2026
Discovered by ZDM
Sep 22, 2026
Patch Available
Sep 23, 2026