Full Report
CVE-2026-3854 exposed a critical trust-boundary failure in the GitHub Enterprise Server (GHES) push pipeline. A value supplied through a standard Git push option could be copied into internal, semicolon-delimited metadata and later interpreted as trusted configuration. For organizations that use GHES to host private source code, deployment credentials, and connections to internal development systems, the […] The post CVE-2026-3854: How Git Push Options Became an Internal Metadata Injection Primitive appeared first on Seqrite Labs.
Analysis Summary
# Vulnerability: GitHub Enterprise Server Internal Metadata Injection (RCE)
## CVE Details
- **CVE ID:** CVE-2026-3854
- **CVSS Score:** 8.7 (High) [CVSS 4.0]
- **CWE:** CWE-75 (Failure to Sanitize/Encode Special Characters in a Critical Control Element / Delimiter Confusion)
## Affected Systems
- **Products:** GitHub Enterprise Server (GHES)
- **Versions:**
- GHES 3.14.x (prior to 3.14.25)
- GHES 3.15.x (prior to 3.15.20)
- GHES 3.16.x (prior to 3.16.16)
- GHES 3.17.x (prior to 3.17.13)
- GHES 3.18.x (prior to 3.18.7)
- GHES 3.19.x (prior to 3.19.4)
- GHES 3.20.0 (and potentially others prior to current patched builds)
- **Configurations:** Systems where authenticated users have push access to at least one repository.
## Vulnerability Description
CVE-2026-3854 is a trust-boundary failure in the GHES push pipeline. When a user performs a `git push` with push options (`-o`), the server-side component `babeld` embeds these options into a semicolon-delimited internal metadata header called `X-Stat`.
Because GHES failed to neutralize semicolons within the user-supplied push options, an attacker could use the semicolon as a delimiter to inject new, unauthorized fields into the `X-Stat` metadata. Since the downstream parser (`gitrpcd`) followed a "last-write-wins" logic, the injected fields could override trusted server-side configurations. By overriding fields like `rails_env`, `custom_hooks_dir`, and `repo_pre_receive_hooks`, an attacker could bypass the security sandbox and execute arbitrary commands as the `git` service user.
## Exploitation
- **Status:** PoC described; vulnerability analyzed by third-party researchers (Seqrite/Wiz).
- **Complexity:** Medium (Requires knowledge of internal metadata field names).
- **Attack Vector:** Network (Authenticated Git Push).
- **Requirements:** Authenticated repository-level write access (push permissions).
## Impact
- **Confidentiality:** High (Access to private source code, configuration files, and internal secrets).
- **Integrity:** High (Ability to execute commands and modify server-side files).
- **Availability:** High (Potential for service disruption via command execution).
## Remediation
### Patches
GitHub has released the following minimum patched builds:
- GHES 3.14.25
- GHES 3.15.20
- GHES 3.16.16
- GHES 3.17.13
- GHES 3.18.7
- GHES 3.19.4
- GHES 3.20.0
### Workarounds
No specific configuration workaround is provided; **immediate upgrade to a patched version is the recommended mitigation.**
## Detection
- **Audit Log Analysis:** Search `/var/log/github-audit.log` for Git push operations that contain semicolons (`;`) within their push options.
- **Process Monitoring:** Inspect the server for unusual child processes spawned by the `git` service user, specifically those originating from the pre-receive hook stage.
- **File Integrity:** Monitor for unauthorized access to internal secrets or configuration files by the service user.
## References
- GitHub Blog: [https://github.blog/security/securing-the-git-push-pipeline-responding-to-a-critical-remote-code-execution-vulnerability/](https://github.blog/security/securing-the-git-push-pipeline-responding-to-a-critical-remote-code-execution-vulnerability/)
- Wiz Research: [https://www.wiz.io/blog/github-rce-vulnerability-cve-20-3854-technical-breakdown](https://www.wiz.io/blog/github-rce-vulnerability-cve-20-3854-technical-breakdown)
- Seqrite Labs: [https://www.seqrite.com/blog/cve-2026-3854-how-git-push-options-became-an-internal-metadata-injection-primitive/](https://www.seqrite.com/blog/cve-2026-3854-how-git-push-options-became-an-internal-metadata-injection-primitive/)