Skip to content

GitHub security advisories

35 advisories across github-mcp-server, copilot-cli, GitHub

Company profile
Advisory
gh-aw: HTTPS egress allowlist bypass via TLS SNI domain fronting
GitHubHigh8.3Sep 23
GitHub Enterprise Server: cross-site scripting
Enterprise ServerHigh7.4Sep 22
GitHub Enterprise Server: server-side request forgery
Enterprise ServerCritical9.3Sep 22
GitHub Enterprise Server: insecure direct object reference
Enterprise ServerMedium6.0Sep 22
GitHub Enterprise Server: server-side request forgery
Enterprise ServerHigh7.7Sep 1
GitHub Enterprise Server: race condition
Enterprise ServerHigh7.7Sep 1
GitHub Enterprise Server: server-side request forgery
Enterprise ServerHigh8.2Sep 1
Arbitrary host filesystem & Docker-socket mounts via MCP server `mounts`
GitHubCritical9.6Aug 29
Safe-output artifacts may expose CI trigger tokens
GitHubCritical9.1Aug 27
gh-aw: github.event.* command injection via heredoc-blind template guardrails (MCP config, all engines)
GitHubHigh8.5Aug 25
GitHub: command injection
GitHubHigh8.5Aug 16
GitHub: improper authorization
GitHubHigh8.8Aug 16
gh-aw: safe-output validator forwards undeclared agent fields to the appliers (scope escape / mass assignment)
GitHubCritical9.1Aug 8
gh-aw: unauthenticated prompt-injection to code execution in the shipped ai-moderator workflow
GitHubMedium6.5Aug 7
command injection in compiled workflow via unsanitized `sandbox.mcp.env` exports
GitHubCritical9.6Aug 7
gh-aw: URL allowlist bypass via userinfo @ in the content sanitizer (exfiltration channel)
GitHubMedium6.8Aug 7
Safe-outputs config emitter: JSON injection via templated values despite env-var indirection
GitHubHigh8.5Aug 6
GitHub Enterprise Server: denial of service
Enterprise ServerMedium6.6Aug 5
GitHub Enterprise Server: path traversal
Enterprise ServerHigh8.8Aug 5
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
github-mcp-serverHigh7.5Jul 28
GitHub Enterprise Server: missing authorization
Enterprise ServerMedium5.3Jul 17
GitHub Enterprise Server: denial of service
Enterprise ServerMedium5.7Jul 17
GitHub Enterprise Server: path traversal
Enterprise ServerHigh8.6Jul 17
GitHub Enterprise Server: improper authorization
Enterprise ServerMedium5.3Jul 1
GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion
github-mcp-serverMedium6.0Jun 25
CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
GitHubMedium4.7Jun 3
GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor
copilot-cliHigh7.8May 11
GitHub Copilot CLI Dangerous Shell Expansion Patterns Enable Arbitrary Code Execution
copilot-cliHighMar 6
GitHub PAT written to debug artifacts
GitHubHighJan 24, 2025
Arbitrary File Overwrite in CodeQL versions less than 2.18.1
GitHubHighJul 25, 2024
Limited data exfiltration in CodeQL CLI
GitHubLow2.7Feb 22, 2024
### Impact The CodeQL runner tool
GitHubMedium4.4May 25, 2021
Limited header injection when using dynamic overrides with user input
GitHubMediumJan 22, 2020
Directive injection when using dynamic overrides with user input
GitHubMediumJan 22, 2020
Arbitrary code execution when opening a malicious workspace
GitHubHighNov 22, 2019
About GitHub

GitHub is a proprietary developer platform that allows developers to create, store, manage, and share their code. Popular games such as 2048 and Hextris have been known to be hosted on the platform.

Elsewhere on fru.dev: Paydays · Releases · Repos · Trending

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.