Junglewise Threat Intelligence

CVE-2026-77912: GitHub Enterprise Server stored XSS in Markdown rendering

CVE-2026-77912 · Severity: info · Published 2026-09-22

Technologies: GitHub Enterprise Server. Vendors: GitHub.

Executive brief

GitHub Enterprise Server contains a stored cross-site scripting (XSS) vulnerability in its Markdown rendering that allows authenticated users to inject malicious code. When another user views the affected content, an attacker can steal session tokens, impersonate the victim, and access data the victim can see. The vulnerability could allow attackers to compromise accounts and exfiltrate sensitive information across repositories and organizations.

Technical details

The vulnerability exists in the Markdown rendering pipeline, which rewrites quote characters in sanitized HTML without re-sanitizing the result, allowing injection of arbitrary HTML attributes. Authenticated attackers can craft Markdown payloads that abuse same-origin JavaScript gadgets to bypass Content Security Policy and gain DOM control. This requires viewing by another user (stored XSS) and enables reading victim-visible content, extracting CSRF tokens, and performing state-changing actions with victim privileges.

Affected products

  • GitHub Enterprise Server 3.17.0 to 3.17.20, 3.18.0 to 3.18.14, 3.19.0 to 3.19.11, 3.20.0 to 3.20.7, 3.21.0 to 3.21.5, 3.22.0

Timeline

  • 2026-09-22: disclosed
  • 2026-09-22: patched: Fixed in versions 3.22.1, 3.21.6, 3.20.8, 3.19.12, 3.18.15, 3.17.21

References

Related threats