CVE-2026-3854 exposed a critical trust-boundary failure in the GitHub Enterprise Server (GHES) push pipeline. A value supplied through a standard Git push option could be copied into internal, semicolon-delimited metadata and later interpreted as trusted configuration. For organizations that use GHES to host private source code, deployment credentials, and connections to internal development systems, the […] The post CVE-2026-3854: How Git Push Options Became an Internal Metadata Injection Primitive appeared first on Seqrite Labs.