PT-2025-27576 · Github · Github Enterprise Server

Ammar Bandukwala

+1

·

Published

2025-07-01

·

Updated

2025-09-05

·

CVE-2025-6600

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: GitHub Enterprise Server version 3.17
Description: An exposure of sensitive information issue was identified that could allow an attacker to disclose the names of private repositories within an organization. This issue could be exploited by leveraging a user-to-server token with no scopes via the "Search API" endpoint. Successful exploitation required an organization administrator to install a malicious GitHub App in the organization’s repositories.
Recommendations: For GitHub Enterprise Server version 3.17, update to version 3.17.2 to resolve the issue. As a temporary workaround, consider restricting the installation of GitHub Apps to trusted sources until the update is applied. Restrict access to the Search API endpoint to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-6600

Affected Products

Github Enterprise Server