OCTOBER 4, 2026
Live Feed
Back to database
Case File

CVE-2026-77912

MEDIUM · CVSS 5.4 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-04

CyberRota Analysis

AI-Generated

A stored cross-site scripting (XSS) vulnerability in GitHub Enterprise Server allows authenticated attackers to inject malicious HTML into rendered Markdown, compromising the security of the page DOM for other users. This could enable attackers to read sensitive content, extract CSRF tokens, and perform unauthorized actions on behalf of victims. Organizations using affected versions (3.17 to 3.22) should prioritize patching to mitigate potential data exfiltration and unauthorized access risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77912
Severity
MEDIUM
CVSS
5.4
EPSS
0.21%
Java GitHub

Original NVD Description

A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrote quote characters in already-sanitized HTML without re-sanitizing the result. Crafted Markdown could abuse same-origin JavaScript gadgets to bypass Content Security Policy and gain control of the page DOM when viewed by another user. Successful exploitation could allow an attacker to read content visible to the victim, extract embedded CSRF tokens, perform state-changing actions as the victim, and exfiltrate data through same-origin writes. The payload could also propagate to repositories and organizations where the victim had write access. This vulnerability affected supported GitHub Enterprise Server releases in the 3.17, 3.18, 3.19, 3.20, 3.21, and 3.22 series and was fixed in versions 3.22.1, 3.21.6, 3.20.8, 3.19.12, 3.18.15, and 3.17.21. This vulnerability was reported via the GitHub Bug Bounty program.

Related CVEs

Other vulnerabilities affecting the same vendor(s)