A command injection vulnerability in GitHub Enterprise Server’s git push pipeline allows any authenticated user with repository push access to execute arbitrary commands on the underlying instance using a single crafted git push.
Read more about Emerging Threat: (CVE-2026-3854) GitHub Enterprise Server RCE via Git Push Injection