PT-2025-17245 · Github · Github Enterprise Server

Published

2025-04-17

·

Updated

2025-10-01

·

CVE-2025-3246

CVSS v4.0

8.6

High

VectorAV:N/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions GitHub Enterprise Server version 3.16.1
Description An improper neutralization of input issue was identified in GitHub Enterprise Server, allowing cross-site scripting in GitHub Markdown that used $$..$$ math blocks. Exploitation required access to the target GitHub Enterprise Server instance and privileged user interaction with the malicious elements.
Recommendations For version 3.16.1, update to version 3.16.2 to resolve the issue. As a temporary workaround, consider restricting the use of $$..$$ math blocks in GitHub Markdown until the update is applied.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-05159
CVE-2025-3246

Affected Products

Github Enterprise Server