CVE-2026-10585
Last modified
CVE-2026-10585 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary JavaScript in another user's browser by injecting a crafted payload into the title of a Discussion in the Q&A category. The AnsweredQuestionStructuredDataComponent did not escape user-controlled Discussion titles before embedding them in a <script type="application/ld+json"> block, allowing the title to break out of the script context. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary JavaScript in another user's browser by injecting a crafted payload into the title of a Discussion in the Q&A category. The AnsweredQuestionStructuredDataComponent did not escape user-controlled Discussion titles before embedding them in a <script type="application/ld+json"> block, allowing the title to break out of the script context. The injection was escalated to a full cross-site scripting attack on GitHub Enterprise Server by leveraging JSONP callback support in the REST API to bypass the Content Security Policy. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.4, 3.19.8, 3.18.11, 3.17.17, 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Github | Enterprise Server | < 3.16.20 |
| Github | Enterprise Server | >= 3.17.0, < 3.17.17 |
| Github | Enterprise Server | >= 3.18.0, < 3.18.11 |
| Github | Enterprise Server | >= 3.19.0, < 3.19.8 |
| Github | Enterprise Server | >= 3.20.0, < 3.20.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-10585?
How severe is CVE-2026-10585?
How do I fix CVE-2026-10585?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10579A flaw was found in Picketlink Federation SAML; the unsolcit…9.8
- CVE-2026-1058The Form Maker plugin for WordPress is vulnerable to Stored …7.1
- CVE-2026-10580The Hippoo Mobile App for WooCommerce plugin for WordPress i…9.8
- CVE-2026-10581A flaw has been found in DedeCMS 5.7.88. Affected by this vu…6.3
- CVE-2026-10583A security vulnerability has been detected in nextlevelbuild…4.7
- CVE-2026-10584Proxy server in Graph Explorer before 3.0.1 falls back to HT…8.2
- CVE-2026-10586The Gutenberg Essential Blocks – Page Builder for Gutenberg …7.2
- CVE-2026-10587A potential out-of-bounds write vulnerability could allow a …6.8
- CVE-2026-10588A potential vulnerability could allow a local privileged att…6.7
- CVE-2026-10589A potential out of bounds write vulnerability could allow a …6.8
- CVE-2026-1059A security vulnerability has been detected in FeMiner wms up…9.8
- CVE-2026-10590A potential missing authentication vulnerability could allow…6.7
Are you affected by CVE-2026-10585?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
