LIVE · cybersecurity feed
Live wire
vendor

Github

6 CVEs published in the last four months and 12 stories. Exploited flaws first.

Critical1
High5
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-175569.1criticalenterprise serverA path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker31d ago
CVE-2026-93128.2highenterprise serverA server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unaut102d ago
CVE-2026-450337.8highcopilot-cliGitHub Copilot CLI brings AI-powered coding assistance directly to your command line.115d ago
CVE-2026-474277.5highmcp serverGitHub MCP Server is GitHub's official MCP Server.39d ago
CVE-2026-159967.5highenterprise serverA denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attac31d ago
CVE-2026-485017.4highcliGitHub CLI (gh) is GitHub’s official command line tool.99d ago

Filter the full tracker by Github

Our coverage of Github

vulnerability

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. The post In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug appeared first on SecurityWeek.

vulnerabilitycritical

Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed

The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher

snowflakehigh

Snowflake GitHub Actions Flaw Allows Command Injection

Researchers have identified a vulnerability in Snowflake's GitHub Actions workflows, specifically within the snowflakedb/snowflake-connector-net repository. A specially crafted GitHub issue could exploit this flaw to execute commands within a workflow, potentially exposing internal Jira credentials.

security

Microsoft confirms GitHub is down worldwide

GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. [...]

patch

Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

Audit logs found no unexpected visitors, but release verification still needs an update

malware

GitHub Dependabot malware alerts now cover eight ecosystems

GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. GitHub’s Advisory Database now ingests malware reports from OpenSSF’s malicious-packages repository, a public feed in OSV format that launch

CVE-2026-12537critical

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

Researchers discovered vulnerabilities in Anthropic's Claude Code and Google's Gemini CLI that allowed unprivileged attackers to execute code on CI runners. The flaws, which have been patched and assigned CVEs, involved issues with command validation and container launching. A separate finding related to OpenAI's Codex also allowed for the hijacking of agent runs, though OpenAI considers its sandbox to have behaved as documented.

malware

FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. [...]

vulnerabilityhigh

'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows

A vulnerability dubbed GitLost leaks private data from GitHub Agentic Workflows. An unauthenticated attacker can craft a public GitHub Issue to silently exfiltrate data from private repositories.

vulnerabilityhigh

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

Noma Security demonstrated that a public GitHub Issue can trick GitHub Agentic Workflows into leaking private repository data. A seemingly innocuous issue on a public repo can be crafted to exfiltrate private contents.

github actions

The GitHub Actions Attack Pattern Your CI Security Scanners Miss

ActiveState detailed a GitHub Actions attack pattern that often bypasses traditional CI security scanners. The analysis explains how these attack chains evade detection and how to better govern CI/CD pipelines.

breach

CISA Admin Leaked AWS GovCloud Keys on Github

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of inte