PT-2025-17245 · Github · Github Enterprise Server

CVE-2025-3246

·

Published

2025-04-17

·

Updated

2025-10-01

CVSS v4.0

8.6

High

VectorAV:N/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions GitHub Enterprise Server version 3.16.1
Description An improper neutralization of input issue was identified in GitHub Enterprise Server, allowing cross-site scripting in GitHub Markdown that used $$..$$ math blocks. Exploitation required access to the target GitHub Enterprise Server instance and privileged user interaction with the malicious elements.
Recommendations For version 3.16.1, update to version 3.16.2 to resolve the issue. As a temporary workaround, consider restricting the use of $$..$$ math blocks in GitHub Markdown until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-05159
CVE-2025-3246

Affected Products

Github Enterprise Server