CVE-2026-3854 (CVSS 8.7) enabled GitHub RCE via git push, risking cross-tenant access to millions of repositories.
A design choice in the MCP SDKs allows remote code execution across the AI supply chain.
A flaw in Cursor’s AI agent lets malicious repositories trigger arbitrary code execution through routine Git operations, now ...
A critical remote code execution flaw in GitHub allowed users to gain access to millions of repositories and compromise ...
CVE-2026-5752 CVSS 9.3 flaw in Terrarium enables root code execution via Pyodide prototype traversal, risking container ...
The now‑patched flaw allowed authenticated users to execute arbitrary code via crafted git push requests, affecting ...
Wiz discovered a critical remote code execution vulnerability in GitHub that exposed millions of repositories.
Microsoft-owned open source code hosting platform GitHub has acknowledged and patched a critical vulnerability that allowed ...