CVE-2026-15343

HIGH

GitHub Enterprise Server < 3.22 - Dependabot Path Traversal

Title source: manual
STIX 2.1

Description

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including GitHub Actions workflow files under .github/workflows/ as the path validation did not check the effective path which the attacker could control through the dependency file's directory and symlink target. If the repository used a pull_request_target workflow or had auto-merge enabled, an injected workflow could execute with access to the repository's GitHub Actions secrets. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.3, 3.20.5, 3.19.9, 3.18.12, 3.17.18.

Scores

CVSS v4 8.6
EPSS 0.0045
EPSS Percentile 36.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (5)
GitHub/Enterprise Server 3.17.0 - 3.17.17
GitHub/Enterprise Server 3.18.0 - 3.18.11
GitHub/Enterprise Server 3.19.0 - 3.19.8
GitHub/Enterprise Server 3.20.0 - 3.20.4
GitHub/Enterprise Server 3.21.0 - 3.21.2
Published Jul 17, 2026
Tracked Since Jul 17, 2026