« Volver al listado

CVE-2026-15343

Estado: AplazadaAlta (8.6)—

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including GitHub Actions workflow files under .github/workflows/ as the path validation did not check the effective path which the attacker could control through the dependency file's directory and symlink target. If the repository used a pull_request_target workflow or had auto-merge enabled, an injected workflow could execute with access to the repository's GitHub Actions secrets. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.3, 3.20.5, 3.19.9, 3.18.12, 3.17.18.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso remoto como usuario autenticado (PR:L) en servicio de red (GitHub Actions). Path traversal para inyectar workflows maliciosos que se ejecutan con secretos del repositorio, logrando ejecución de código y acceso a datos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-15343",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-15343",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-17T16:31:35.938532Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "product-cna@github.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.6,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "product-cna@github.com",
      "affectedData": [
        {
          "vendor": "GitHub",
          "product": "Enterprise Server",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "3.17.18",
                  "status": "unaffected"
                }
              ],
              "version": "3.17.0",
              "versionType": "semver",
              "lessThanOrEqual": "3.17.17"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "3.18.12",
                  "status": "unaffected"
                }
              ],
              "version": "3.18.0",
              "versionType": "semver",
              "lessThanOrEqual": "3.18.11"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "3.19.9",
                  "status": "unaffected"
                }
              ],
              "version": "3.19.0",
              "versionType": "semver",
              "lessThanOrEqual": "3.19.8"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "3.20.5",
                  "status": "unaffected"
                }
              ],
              "version": "3.20.0",
              "versionType": "semver",
              "lessThanOrEqual": "3.20.4"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "3.21.3",
                  "status": "unaffected"
                }
              ],
              "version": "3.21.0",
              "versionType": "semver",
              "lessThanOrEqual": "3.21.2"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-07-17T16:17:13.917",
  "references": [
    {
      "url": "https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.18",
      "source": "product-cna@github.com"
    },
    {
      "url": "https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.12",
      "source": "product-cna@github.com"
    },
    {
      "url": "https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.9",
      "source": "product-cna@github.com"
    },
    {
      "url": "https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.5",
      "source": "product-cna@github.com"
    },
    {
      "url": "https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.3",
      "source": "product-cna@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "product-cna@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including GitHub Actions workflow files under .github/workflows/ as the path validation did not check the effective path which the attacker could control through the dependency file's directory and symlink target. If the repository used a pull_request_target workflow or had auto-merge enabled, an injected workflow could execute with access to the repository's GitHub Actions secrets. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.3, 3.20.5, 3.19.9, 3.18.12, 3.17.18."
    }
  ],
  "lastModified": "2026-07-17T18:11:59.263",
  "sourceIdentifier": "product-cna@github.com"
}