CVE-2025-11578
Last modified
CVE-2025-11578 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH access to the appliance by exploiting a symlink escape in pre-receive hook environments. By crafting a malicious repository and environment, an attacker could replace system binaries during hook cleanup and execute a payload that adds their own SSH key to the root user’s authorized keys—thereby granting themselves root SSH access to the server. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH access to the appliance by exploiting a symlink escape in pre-receive hook environments. By crafting a malicious repository and environment, an attacker could replace system binaries during hook cleanup and execute a payload that adds their own SSH key to the root user’s authorized keys—thereby granting themselves root SSH access to the server. To exploit this vulnerability, the attacker needed to have enterprise admin privileges. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.19, and was fixed in versions 3.14.20, 3.15.15, 3.16.11, 3.17.8, 3.18.2. This vulnerability was reported via the GitHub Bug Bounty program.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Github | Enterprise Server | >= 3.14.0, < 3.14.20 |
| Github | Enterprise Server | >= 3.15.0, < 3.15.15 |
| Github | Enterprise Server | >= 3.16.0, < 3.16.11 |
| Github | Enterprise Server | >= 3.17.0, < 3.17.8 |
| Github | Enterprise Server | >= 3.18.0, < 3.18.2 |
References
- https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.20Release Notes, Vendor Advisory
- https://docs.github.com/en/enterprise-server@3.15/admin/release-notes#3.15.15Release Notes, Vendor Advisory
- https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.11Release Notes, Vendor Advisory
- https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.8Release Notes, Vendor Advisory
- https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.2Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-11578?
How severe is CVE-2025-11578?
How do I fix CVE-2025-11578?
Are you affected by CVE-2025-11578?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
