PT-2025-50649 · Github · Github Enterprise Server
Published
2025-12-11
·
Updated
2025-12-13
·
CVE-2025-14046
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
GitHub Enterprise Server versions prior to 3.18.3
GitHub Enterprise Server versions prior to 3.17.9
GitHub Enterprise Server versions prior to 3.16.12
GitHub Enterprise Server versions prior to 3.15.16
GitHub Enterprise Server versions prior to 3.14.21
Description
An improper neutralization of input issue exists in GitHub Enterprise Server. This allows user-supplied HTML to inject DOM elements with IDs that conflict with server-initialized data islands. These conflicts can overwrite or shadow critical application state objects used by certain Project views, potentially leading to unintended server-side POST requests or other unauthorized backend interactions. Exploitation requires an attacker to have access to the target GitHub Enterprise Server instance and to convince a privileged user to view crafted malicious content containing conflicting HTML elements.
Recommendations
Update GitHub Enterprise Server to version 3.18.3 or later.
Update GitHub Enterprise Server to version 3.17.9 or later.
Update GitHub Enterprise Server to version 3.16.12 or later.
Update GitHub Enterprise Server to version 3.15.16 or later.
Update GitHub Enterprise Server to version 3.14.21 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github Enterprise Server