Sensitive Information Exposure in GitHub Enterprise Server by GitHub
CVE-2025-6600
What is CVE-2025-6600?
A vulnerability allowing the disclosure of private repository names was found in GitHub Enterprise Server, specifically affecting version 3.17. This issue arises when a user-to-server token with no scopes is exploited via the Search API endpoint. An attacker could leverage this vulnerability if a malicious GitHub App is installed by an organization administrator within their repositories. The vulnerability poses significant risks to organizational privacy and security, as it exposes sensitive information about repository structures. The issue was rectified in version 3.17.2 following a report through the GitHub Bug Bounty program.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GitHub Enterprise Server 3.17.0 <= 3.17.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved