Junglewise Threat Intelligence

CVE-2026-10585: GitHub Enterprise Server stored XSS in Discussion titles

CVE-2026-10585 · Severity: info · CVSS 6.3 · Published 2026-06-30

Technologies: GitHub Enterprise Server. Vendors: GitHub.

Executive brief

A security vulnerability in GitHub Enterprise Server could allow an attacker to execute malicious code in the web browsers of other users. By creating a specially crafted Discussion title in the Q&A category, an attacker could potentially steal session information or perform actions on behalf of other users who view the discussion. This issue affects organizations using self-hosted GitHub Enterprise Server instances.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the AnsweredQuestionStructuredDataComponent of GitHub Enterprise Server. The component fails to properly escape user-controlled Discussion titles before embedding them into a JSON-LD script block (<script type="application/ld+json">), allowing an attacker to break out of the script context. An authenticated attacker can achieve full XSS by leveraging JSONP callback support in the REST API to bypass the application's Content Security Policy (CSP). The vulnerability is fixed in versions 3.20.4, 3.19.8, 3.18.11, and 3.17.17.

Affected products

  • GitHub Enterprise Server < 3.21, fixed in 3.20.4, 3.19.8, 3.18.11, 3.17.17

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: disclosed

References