Improper Neutralization Vulnerability in GitHub Enterprise Server
CVE-2026-4821

8.1HIGH

Key Information:

Vendor

Github

Vendor
CVE Published:
21 April 2026

What is CVE-2026-4821?

An improper neutralization of special elements vulnerability exists within GitHub Enterprise Server, allowing authenticated Management Console administrators to execute arbitrary operating system commands. This risk arises from shell metacharacter injection in proxy configuration fields, such as http_proxy. Successful exploitation mandates both access to the GitHub Enterprise Server instance and administrator privileges in the Management Console. The vulnerability impacts all GitHub Enterprise Server versions prior to 3.21 and has been addressed in recent updates.

Affected Version(s)

Enterprise Server 3.20.0

Enterprise Server 3.20.0 < 3.20.1

Enterprise Server 3.19.0 <= 3.19.4

References

CVSS V4

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Seokchan Yoon
.