CVE-2026-15343
HIGHGitHub Enterprise Server < 3.22 - Dependabot Path Traversal
Title source: manualDescription
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including GitHub Actions workflow files under .github/workflows/ as the path validation did not check the effective path which the attacker could control through the dependency file's directory and symlink target. If the repository used a pull_request_target workflow or had auto-merge enabled, an injected workflow could execute with access to the repository's GitHub Actions secrets. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.3, 3.20.5, 3.19.9, 3.18.12, 3.17.18.
References (5)
Core 5
Core References
Release Notes release-notes
https://docs.github.com/en/[email protected]/admin/release-notes#3.17.18
Release Notes release-notes
https://docs.github.com/en/[email protected]/admin/release-notes#3.18.12
Release Notes release-notes
https://docs.github.com/en/[email protected]/admin/release-notes#3.19.9
Release Notes release-notes
https://docs.github.com/en/[email protected]/admin/release-notes#3.20.5
Release Notes release-notes
https://docs.github.com/en/[email protected]/admin/release-notes#3.21.3
Scores
CVSS v4
8.6
EPSS
0.0045
EPSS Percentile
36.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-22
Status
published
Products (5)
GitHub/Enterprise Server
3.17.0 - 3.17.17
GitHub/Enterprise Server
3.18.0 - 3.18.11
GitHub/Enterprise Server
3.19.0 - 3.19.8
GitHub/Enterprise Server
3.20.0 - 3.20.4
GitHub/Enterprise Server
3.21.0 - 3.21.2
Published
Jul 17, 2026
Tracked Since
Jul 17, 2026