Skip to main content
See every side of every news story
Published loading...Updated

GitHub Fixes RCE Flaw that Gave Access to Millions of Private Repos

Wiz Research used AI to find a flaw that could have exposed millions of repositories, and GitHub deployed fixes in under six hours.

  • GitHub developers resolved a critical remote code execution vulnerability last month, securing both GitHub and GitHub Enterprise Server within six hours of the initial report.
  • Wiz Research discovered the vulnerability "using AI," identifying a rare flaw in internal infrastructure that could have allowed attackers to access millions of public and private code repositories.
  • GitHub chief information security officer Alexis Wales confirmed staff reproduced the issue "within 40 minutes," while Wiz warned the vulnerability was "remarkably easy to exploit."
  • Security researcher Sagi Tzadik noted this marks a shift as one of the first critical vulnerabilities found in closed-source binaries using AI, earning a top Bug Bounty payout.
  • GitHub experienced separate outages last week, including an incident where previously merged commits were reverted, suggesting a growing pattern of technical disruptions for the service.
Insights by Ground AI

13 Articles

A critical failure on the GitHub platform is generating global concern among developers and security experts. Vulnerability, identified as CVE-2026-3854, has been discovered by Wiz and allows remote code execution (RCE) from a simple git push command. The severity of the problem is in the ease of exploitation. A daily routine command can be manipulated to compromise servers, opening the way for improper access and execution of malicious commands…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 50% of the sources lean Left, 50% of the sources are Center
50% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

The GitHub Blog broke the news on Tuesday, April 28, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal