Executive brief
GitHub Enterprise Server contains a stored cross-site scripting (XSS) vulnerability in its Markdown rendering that allows authenticated users to inject malicious code. When another user views the affected content, an attacker can steal session tokens, impersonate the victim, and access data the victim can see. The vulnerability could allow attackers to compromise accounts and exfiltrate sensitive information across repositories and organizations.
Technical details
The vulnerability exists in the Markdown rendering pipeline, which rewrites quote characters in sanitized HTML without re-sanitizing the result, allowing injection of arbitrary HTML attributes. Authenticated attackers can craft Markdown payloads that abuse same-origin JavaScript gadgets to bypass Content Security Policy and gain DOM control. This requires viewing by another user (stored XSS) and enables reading victim-visible content, extracting CSRF tokens, and performing state-changing actions with victim privileges.
Affected products
- GitHub Enterprise Server 3.17.0 to 3.17.20, 3.18.0 to 3.18.14, 3.19.0 to 3.19.11, 3.20.0 to 3.20.7, 3.21.0 to 3.21.5, 3.22.0
Timeline
- 2026-09-22: disclosed
- 2026-09-22: patched: Fixed in versions 3.22.1, 3.21.6, 3.20.8, 3.19.12, 3.18.15, 3.17.21