{"id":18396,"date":"2026-08-13T01:07:14","date_gmt":"2026-08-12T18:07:14","guid":{"rendered":"https:\/\/droneth.or.th\/?p=18396"},"modified":"2026-08-13T01:07:14","modified_gmt":"2026-08-12T18:07:14","slug":"github-rce-cve-2026-3854-git-push-command-injection","status":"publish","type":"post","link":"https:\/\/droneth.or.th\/ja\/github-rce-cve-2026-3854-git-push-command-injection\/","title":{"rendered":"GitHub RCE CVE-2026-3854: \u0e40\u0e21\u0e37\u0e48\u0e2d git push \u0e04\u0e23\u0e31\u0e49\u0e07\u0e40\u0e14\u0e35\u0e22\u0e27\u0e23\u0e31\u0e19\u0e42\u0e04\u0e49\u0e14\u0e1a\u0e19\u0e40\u0e0b\u0e34\u0e23\u0e4c\u0e1f\u0e40\u0e27\u0e2d\u0e23\u0e4c\u0e44\u0e14\u0e49"},"content":{"rendered":"<p>\u0e19\u0e31\u0e01\u0e27\u0e34\u0e08\u0e31\u0e22 Wiz \u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22 <strong>CVE-2026-3854<\/strong> \u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48 command injection \u0e43\u0e19 GitHub push pipeline \u0e17\u0e35\u0e48\u0e17\u0e33\u0e43\u0e2b\u0e49\u0e1c\u0e39\u0e49\u0e43\u0e0a\u0e49\u0e0b\u0e36\u0e48\u0e07\u0e21\u0e35\u0e2a\u0e34\u0e17\u0e18\u0e34\u0e4c push \u0e44\u0e1b\u0e22\u0e31\u0e07 repository \u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e17\u0e33\u0e43\u0e2b\u0e49\u0e04\u0e33\u0e2a\u0e31\u0e48\u0e07\u0e17\u0e35\u0e48\u0e04\u0e27\u0e1a\u0e04\u0e38\u0e21\u0e44\u0e14\u0e49\u0e44\u0e1b\u0e23\u0e31\u0e19\u0e1a\u0e19 infrastructure \u0e1d\u0e31\u0e48\u0e07\u0e40\u0e0b\u0e34\u0e23\u0e4c\u0e1f\u0e40\u0e27\u0e2d\u0e23\u0e4c \u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e21\u0e35\u0e04\u0e30\u0e41\u0e19\u0e19 CVSS 8.7 \u0e41\u0e25\u0e30\u0e21\u0e35\u0e1c\u0e25\u0e17\u0e31\u0e49\u0e07 GitHub.com \u0e01\u0e48\u0e2d\u0e19\u0e41\u0e01\u0e49\u0e44\u0e02\u0e41\u0e25\u0e30 GitHub Enterprise Server (GHES) \u0e23\u0e38\u0e48\u0e19\u0e17\u0e35\u0e48\u0e44\u0e14\u0e49\u0e23\u0e31\u0e1a\u0e1c\u0e25\u0e01\u0e23\u0e30\u0e17\u0e1a<\/p>\n<p>\u0e04\u0e33\u0e27\u0e48\u0e32 \u201cRCE \u0e14\u0e49\u0e27\u0e22 git push \u0e04\u0e23\u0e31\u0e49\u0e07\u0e40\u0e14\u0e35\u0e22\u0e27\u201d \u0e1f\u0e31\u0e07\u0e40\u0e2b\u0e21\u0e37\u0e2d\u0e19\u0e43\u0e04\u0e23\u0e01\u0e47\u0e15\u0e32\u0e21\u0e1a\u0e19 internet \u0e22\u0e36\u0e14 GitHub Server \u0e44\u0e14\u0e49 \u0e41\u0e15\u0e48 threat model \u0e17\u0e35\u0e48\u0e16\u0e39\u0e01\u0e15\u0e49\u0e2d\u0e07\u0e04\u0e37\u0e2d attacker \u0e15\u0e49\u0e2d\u0e07\u0e40\u0e1b\u0e47\u0e19 <strong>authenticated user \u0e41\u0e25\u0e30\u0e21\u0e35 push access<\/strong> \u0e01\u0e48\u0e2d\u0e19 \u0e04\u0e27\u0e32\u0e21\u0e23\u0e38\u0e19\u0e41\u0e23\u0e07\u0e21\u0e32\u0e08\u0e32\u0e01\u0e01\u0e32\u0e23\u0e17\u0e35\u0e48\u0e2a\u0e34\u0e17\u0e18\u0e34\u0e4c\u0e23\u0e30\u0e14\u0e31\u0e1a repository \u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e02\u0e49\u0e32\u0e21 trust boundary \u0e44\u0e1b\u0e40\u0e1b\u0e47\u0e19 code execution \u0e1a\u0e19 control plane \u0e02\u0e2d\u0e07\u0e23\u0e30\u0e1a\u0e1a source-code hosting<\/p>\n<p>\u0e1a\u0e17\u0e04\u0e27\u0e32\u0e21\u0e19\u0e35\u0e49\u0e2d\u0e18\u0e34\u0e1a\u0e32\u0e22\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e43\u0e19\u0e21\u0e38\u0e21 DevSecOps, attack surface \u0e02\u0e2d\u0e07 Git protocol, \u0e1c\u0e25\u0e15\u0e48\u0e2d supply chain \u0e41\u0e25\u0e30\u0e02\u0e31\u0e49\u0e19\u0e15\u0e2d\u0e19\u0e17\u0e35\u0e48\u0e1c\u0e39\u0e49\u0e14\u0e39\u0e41\u0e25 GHES \u0e04\u0e27\u0e23\u0e17\u0e33\u0e21\u0e32\u0e01\u0e01\u0e27\u0e48\u0e32\u0e01\u0e32\u0e23\u0e15\u0e34\u0e14\u0e15\u0e31\u0e49\u0e07\u0e41\u0e1e\u0e15\u0e0a\u0e4c<\/p>\n<h2>CVE-2026-3854 \u0e04\u0e37\u0e2d\u0e2d\u0e30\u0e44\u0e23<\/h2>\n<p>\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e2d\u0e22\u0e39\u0e48\u0e43\u0e19 internal push processing pipeline \u0e02\u0e2d\u0e07 GitHub \u0e0b\u0e36\u0e48\u0e07\u0e23\u0e31\u0e1a metadata \u0e08\u0e32\u0e01\u0e01\u0e23\u0e30\u0e1a\u0e27\u0e19\u0e01\u0e32\u0e23 <code>git push<\/code> \u0e41\u0e25\u0e49\u0e27\u0e2a\u0e48\u0e07\u0e15\u0e48\u0e2d\u0e1c\u0e48\u0e32\u0e19 service \u0e2b\u0e25\u0e32\u0e22\u0e0a\u0e31\u0e49\u0e19 \u0e43\u0e19\u0e40\u0e2a\u0e49\u0e19\u0e17\u0e32\u0e07\u0e17\u0e35\u0e48\u0e44\u0e14\u0e49\u0e23\u0e31\u0e1a\u0e1c\u0e25 \u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e17\u0e35\u0e48 attacker \u0e04\u0e27\u0e1a\u0e04\u0e38\u0e21\u0e44\u0e14\u0e49\u0e16\u0e39\u0e01\u0e19\u0e33\u0e44\u0e1b\u0e1b\u0e23\u0e30\u0e01\u0e2d\u0e1a\u0e04\u0e33\u0e2a\u0e31\u0e48\u0e07 shell \u0e42\u0e14\u0e22\u0e44\u0e21\u0e48\u0e21\u0e35\u0e01\u0e32\u0e23\u0e41\u0e22\u0e01 argument\/validate \u0e17\u0e35\u0e48\u0e40\u0e1e\u0e35\u0e22\u0e07\u0e1e\u0e2d \u0e17\u0e33\u0e43\u0e2b\u0e49\u0e40\u0e01\u0e34\u0e14 command injection<\/p>\n<p>\u0e08\u0e38\u0e14\u0e17\u0e35\u0e48\u0e19\u0e31\u0e01\u0e27\u0e34\u0e08\u0e31\u0e22\u0e40\u0e19\u0e49\u0e19\u0e04\u0e37\u0e2d push option \u0e2b\u0e23\u0e37\u0e2d metadata \u0e20\u0e32\u0e22\u0e43\u0e19\u0e17\u0e35\u0e48\u0e40\u0e01\u0e35\u0e48\u0e22\u0e27\u0e01\u0e31\u0e1a <code>X-Stat<\/code> \u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e40\u0e14\u0e34\u0e19\u0e17\u0e32\u0e07\u0e1c\u0e48\u0e32\u0e19 protocol boundary \u0e44\u0e1b\u0e16\u0e36\u0e07 component \u0e0b\u0e36\u0e48\u0e07\u0e43\u0e0a\u0e49 shell invocation \u0e2b\u0e32\u0e01 escaping \u0e44\u0e21\u0e48\u0e2a\u0e2d\u0e14\u0e04\u0e25\u0e49\u0e2d\u0e07\u0e01\u0e31\u0e19 \u0e1c\u0e39\u0e49\u0e43\u0e0a\u0e49\u0e17\u0e35\u0e48\u0e04\u0e27\u0e23\u0e21\u0e35\u0e2a\u0e34\u0e17\u0e18\u0e34\u0e4c\u0e40\u0e1e\u0e35\u0e22\u0e07\u0e2d\u0e31\u0e1b\u0e40\u0e14\u0e15 repository \u0e08\u0e36\u0e07\u0e17\u0e33\u0e43\u0e2b\u0e49 code \u0e17\u0e33\u0e07\u0e32\u0e19\u0e43\u0e19 server context \u0e44\u0e14\u0e49<\/p>\n<p>\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e2a\u0e23\u0e38\u0e1b:<\/p>\n<div style=\"overflow-x:auto;margin:1.5em 0;\">\n<table style=\"width:100%;border-collapse:collapse;\">\n<thead>\n<tr>\n<th style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u9805\u76ee<\/th>\n<th style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">CVE<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">CVE-2026-3854<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e04\u0e30\u0e41\u0e19\u0e19<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">CVSS 8.7 High<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e1b\u0e23\u0e30\u0e40\u0e20\u0e17<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Command Injection \/ Remote Code Execution<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e2a\u0e34\u0e17\u0e18\u0e34\u0e4c\u0e17\u0e35\u0e48\u0e15\u0e49\u0e2d\u0e07\u0e21\u0e35<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Authenticated user \u0e1e\u0e23\u0e49\u0e2d\u0e21 push access<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">User interaction<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e44\u0e21\u0e48\u0e15\u0e49\u0e2d\u0e07\u0e21\u0e35\u0e1c\u0e39\u0e49\u0e43\u0e0a\u0e49\u0e23\u0e32\u0e22\u0e2d\u0e37\u0e48\u0e19\u0e04\u0e25\u0e34\u0e01<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u88fd\u54c1<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">GitHub.com \u0e01\u0e48\u0e2d\u0e19\u0e41\u0e01\u0e49 \u0e41\u0e25\u0e30 GHES \u0e23\u0e38\u0e48\u0e19\u0e17\u0e35\u0e48\u0e44\u0e14\u0e49\u0e23\u0e31\u0e1a\u0e1c\u0e25<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">GitHub.com<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e41\u0e01\u0e49\u0e43\u0e19\u0e27\u0e31\u0e19\u0e23\u0e32\u0e22\u0e07\u0e32\u0e19\u0e15\u0e32\u0e21 GitHub<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">GHES<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e15\u0e49\u0e2d\u0e07\u0e2d\u0e31\u0e1b\u0e40\u0e01\u0e23\u0e14\u0e40\u0e1b\u0e47\u0e19\u0e23\u0e38\u0e48\u0e19 patched<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>\u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e04\u0e27\u0e32\u0e21\u0e1b\u0e25\u0e2d\u0e14\u0e20\u0e31\u0e22 \u0e1a\u0e17\u0e04\u0e27\u0e32\u0e21\u0e19\u0e35\u0e49\u0e44\u0e21\u0e48\u0e40\u0e1c\u0e22\u0e41\u0e1e\u0e23\u0e48 payload \u0e2b\u0e23\u0e37\u0e2d\u0e02\u0e31\u0e49\u0e19\u0e15\u0e2d\u0e19 reproduce \u0e1a\u0e19 production<\/p>\n<h2>Attack Flow \u0e43\u0e19\u0e23\u0e30\u0e14\u0e31\u0e1a\u0e41\u0e19\u0e27\u0e04\u0e34\u0e14<\/h2>\n<ol>\n<li>Attacker \u0e21\u0e35 account\/token\/SSH key \u0e17\u0e35\u0e48 push \u0e44\u0e1b repository \u0e2b\u0e19\u0e36\u0e48\u0e07\u0e44\u0e14\u0e49<\/li>\n<li>\u0e2a\u0e48\u0e07 <code>git push<\/code> \u0e1e\u0e23\u0e49\u0e2d\u0e21 metadata \u0e17\u0e35\u0e48\u0e2a\u0e23\u0e49\u0e32\u0e07\u0e02\u0e36\u0e49\u0e19\u0e40\u0e09\u0e1e\u0e32\u0e30<\/li>\n<li>Git frontend \u0e23\u0e31\u0e1a\u0e41\u0e25\u0e30\u0e2a\u0e48\u0e07\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e44\u0e1b\u0e22\u0e31\u0e07 internal push pipeline<\/li>\n<li>\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e02\u0e49\u0e32\u0e21 service boundary \u0e42\u0e14\u0e22\u0e16\u0e39\u0e01\u0e40\u0e0a\u0e37\u0e48\u0e2d\u0e27\u0e48\u0e32\u0e40\u0e1b\u0e47\u0e19 trusted\/internal metadata<\/li>\n<li>Component \u0e1b\u0e25\u0e32\u0e22\u0e17\u0e32\u0e07\u0e19\u0e33\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e44\u0e1b\u0e1b\u0e23\u0e30\u0e01\u0e2d\u0e1a shell command<\/li>\n<li>\u0e40\u0e01\u0e34\u0e14 command injection \u0e43\u0e19 context \u0e02\u0e2d\u0e07 server-side service<\/li>\n<\/ol>\n<p>\u0e1a\u0e17\u0e40\u0e23\u0e35\u0e22\u0e19\u0e04\u0e37\u0e2d <strong>\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e17\u0e35\u0e48\u0e1c\u0e48\u0e32\u0e19\u0e23\u0e30\u0e1a\u0e1a\u0e20\u0e32\u0e22\u0e43\u0e19\u0e44\u0e21\u0e48\u0e44\u0e14\u0e49\u0e01\u0e25\u0e32\u0e22\u0e40\u0e1b\u0e47\u0e19\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e17\u0e35\u0e48\u0e40\u0e0a\u0e37\u0e48\u0e2d\u0e16\u0e37\u0e2d\u0e44\u0e14\u0e49\u0e42\u0e14\u0e22\u0e2d\u0e31\u0e15\u0e42\u0e19\u0e21\u0e31\u0e15\u0e34<\/strong> \u0e17\u0e38\u0e01 boundary \u0e15\u0e49\u0e2d\u0e07\u0e23\u0e31\u0e01\u0e29\u0e32 type, encoding \u0e41\u0e25\u0e30 validation \u0e02\u0e2d\u0e07\u0e15\u0e19\u0e40\u0e2d\u0e07<\/p>\n<h2>\u0e17\u0e33\u0e44\u0e21\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e19\u0e35\u0e49\u0e21\u0e35\u0e1c\u0e25\u0e2a\u0e39\u0e07\u0e41\u0e21\u0e49\u0e15\u0e49\u0e2d\u0e07\u0e21\u0e35 Push Access<\/h2>\n<p>Push access \u0e40\u0e1b\u0e47\u0e19\u0e2a\u0e34\u0e17\u0e18\u0e34\u0e4c\u0e17\u0e35\u0e48\u0e1e\u0e1a\u0e44\u0e14\u0e49\u0e17\u0e31\u0e48\u0e27\u0e44\u0e1b\u0e43\u0e19\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23:<\/p>\n<ul>\n<li>developer \u0e41\u0e25\u0e30 contractor<\/li>\n<li>CI bot \u0e2b\u0e23\u0e37\u0e2d deploy key<\/li>\n<li>integration \u0e08\u0e32\u0e01\u0e23\u0e30\u0e1a\u0e1a build\/release<\/li>\n<li>service account \u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a mirror repository<\/li>\n<li>automation \u0e17\u0e35\u0e48\u0e43\u0e0a\u0e49 personal access token<\/li>\n<\/ul>\n<p>\u0e2b\u0e32\u0e01 credential \u0e01\u0e25\u0e38\u0e48\u0e21\u0e19\u0e35\u0e49\u0e16\u0e39\u0e01\u0e02\u0e42\u0e21\u0e22 \u0e1c\u0e39\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e1b\u0e01\u0e15\u0e34\u0e04\u0e27\u0e23\u0e41\u0e01\u0e49\u0e44\u0e14\u0e49\u0e40\u0e09\u0e1e\u0e32\u0e30 repository \u0e17\u0e35\u0e48\u0e44\u0e14\u0e49\u0e23\u0e31\u0e1a\u0e2a\u0e34\u0e17\u0e18\u0e34\u0e4c \u0e41\u0e15\u0e48 CVE-2026-3854 \u0e40\u0e1b\u0e34\u0e14\u0e42\u0e2d\u0e01\u0e32\u0e2a\u0e43\u0e2b\u0e49\u0e02\u0e49\u0e32\u0e21\u0e08\u0e32\u0e01 data plane \u0e44\u0e1b\u0e22\u0e31\u0e07 server execution \u0e1c\u0e25\u0e01\u0e23\u0e30\u0e17\u0e1a\u0e17\u0e35\u0e48\u0e40\u0e1b\u0e47\u0e19\u0e44\u0e1b\u0e44\u0e14\u0e49\u0e02\u0e36\u0e49\u0e19\u0e01\u0e31\u0e1a sandbox, service identity \u0e41\u0e25\u0e30 architecture \u0e40\u0e0a\u0e48\u0e19\u0e40\u0e02\u0e49\u0e32\u0e16\u0e36\u0e07 repository \u0e2d\u0e37\u0e48\u0e19, secret, internal service \u0e2b\u0e23\u0e37\u0e2d\u0e2a\u0e23\u0e49\u0e32\u0e07 persistence<\/p>\n<p>\u0e44\u0e21\u0e48\u0e04\u0e27\u0e23\u0e01\u0e25\u0e48\u0e32\u0e27\u0e27\u0e48\u0e32\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e19\u0e35\u0e49\u0e22\u0e37\u0e19\u0e22\u0e31\u0e19\u0e01\u0e32\u0e23\u0e22\u0e36\u0e14\u0e17\u0e38\u0e01 repository \u0e2b\u0e23\u0e37\u0e2d supply-chain compromise \u0e43\u0e19\u0e17\u0e38\u0e01\u0e01\u0e23\u0e13\u0e35 \u0e1c\u0e25\u0e08\u0e23\u0e34\u0e07\u0e02\u0e36\u0e49\u0e19\u0e01\u0e31\u0e1a\u0e2a\u0e34\u0e17\u0e18\u0e34\u0e4c\u0e02\u0e2d\u0e07 process \u0e41\u0e25\u0e30 control \u0e23\u0e2d\u0e1a infrastructure \u0e41\u0e15\u0e48 trust-boundary violation \u0e40\u0e1e\u0e35\u0e22\u0e07\u0e2d\u0e22\u0e48\u0e32\u0e07\u0e40\u0e14\u0e35\u0e22\u0e27\u0e01\u0e47\u0e23\u0e49\u0e32\u0e22\u0e41\u0e23\u0e07\u0e1e\u0e2d\u0e43\u0e2b\u0e49\u0e40\u0e23\u0e48\u0e07\u0e41\u0e1e\u0e15\u0e0a\u0e4c<\/p>\n<h2>GitHub.com \u0e01\u0e31\u0e1a GitHub Enterprise Server \u0e15\u0e48\u0e32\u0e07\u0e01\u0e31\u0e19\u0e2d\u0e22\u0e48\u0e32\u0e07\u0e44\u0e23<\/h2>\n<h3>GitHub.com<\/h3>\n<p>GitHub \u0e23\u0e30\u0e1a\u0e38\u0e27\u0e48\u0e32\u0e44\u0e14\u0e49\u0e23\u0e31\u0e1a\u0e23\u0e32\u0e22\u0e07\u0e32\u0e19\u0e27\u0e31\u0e19\u0e17\u0e35\u0e48 4 \u0e21\u0e35\u0e19\u0e32\u0e04\u0e21 2026 \u0e41\u0e25\u0e30\u0e41\u0e01\u0e49\u0e23\u0e30\u0e1a\u0e1a hosted service \u0e43\u0e19\u0e27\u0e31\u0e19\u0e40\u0e14\u0e35\u0e22\u0e27\u0e01\u0e31\u0e19 \u0e25\u0e39\u0e01\u0e04\u0e49\u0e32 GitHub.com \u0e44\u0e21\u0e48\u0e15\u0e49\u0e2d\u0e07\u0e15\u0e34\u0e14\u0e15\u0e31\u0e49\u0e07 server patch \u0e40\u0e2d\u0e07 \u0e41\u0e15\u0e48\u0e22\u0e31\u0e07\u0e04\u0e27\u0e23:<\/p>\n<ul>\n<li>\u0e15\u0e23\u0e27\u0e08 security log \u0e41\u0e25\u0e30 token hygiene<\/li>\n<li>revoke credential \u0e17\u0e35\u0e48\u0e2a\u0e07\u0e2a\u0e31\u0e22\u0e27\u0e48\u0e32\u0e16\u0e39\u0e01\u0e02\u0e42\u0e21\u0e22<\/li>\n<li>\u0e15\u0e23\u0e27\u0e08 repository\/integration anomaly \u0e15\u0e32\u0e21\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e08\u0e32\u0e01 GitHub<\/li>\n<li>\u0e15\u0e34\u0e14\u0e15\u0e32\u0e21 vendor communication<\/li>\n<\/ul>\n<h3>GitHub Enterprise Server<\/h3>\n<p>\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e17\u0e35\u0e48\u0e23\u0e31\u0e19 GHES \u0e43\u0e19 data center \u0e2b\u0e23\u0e37\u0e2d private cloud \u0e15\u0e49\u0e2d\u0e07\u0e2d\u0e31\u0e1b\u0e40\u0e01\u0e23\u0e14\u0e40\u0e2d\u0e07 \u0e23\u0e38\u0e48\u0e19\u0e41\u0e01\u0e49\u0e44\u0e02\u0e17\u0e35\u0e48\u0e40\u0e1c\u0e22\u0e41\u0e1e\u0e23\u0e48 \u0e44\u0e14\u0e49\u0e41\u0e01\u0e48:<\/p>\n<ul>\n<li>3.14.24<\/li>\n<li>3.15.19<\/li>\n<li>3.16.15<\/li>\n<li>3.17.12<\/li>\n<li>3.18.6<\/li>\n<li>3.19.3<\/li>\n<\/ul>\n<p>\u0e2b\u0e32\u0e01\u0e2d\u0e22\u0e39\u0e48\u0e1a\u0e19\u0e2a\u0e32\u0e22\u0e40\u0e01\u0e48\u0e32\u0e01\u0e27\u0e48\u0e32\u0e2b\u0e23\u0e37\u0e2d\u0e2b\u0e21\u0e14 support \u0e04\u0e27\u0e23\u0e27\u0e32\u0e07\u0e41\u0e1c\u0e19\u0e2d\u0e31\u0e1b\u0e40\u0e01\u0e23\u0e14\u0e44\u0e1b supported release \u0e25\u0e48\u0e32\u0e2a\u0e38\u0e14 \u0e44\u0e21\u0e48\u0e43\u0e0a\u0e48\u0e2b\u0e22\u0e38\u0e14\u0e17\u0e35\u0e48\u0e40\u0e25\u0e02 patch \u0e02\u0e31\u0e49\u0e19\u0e15\u0e48\u0e33\u0e08\u0e32\u0e01 advisory \u0e40\u0e14\u0e37\u0e2d\u0e19\u0e21\u0e35\u0e19\u0e32\u0e04\u0e21\/\u0e40\u0e21\u0e29\u0e32\u0e22\u0e19<\/p>\n<h2>Timeline \u0e02\u0e2d\u0e07\u0e01\u0e32\u0e23\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22<\/h2>\n<div style=\"overflow-x:auto;margin:1.5em 0;\">\n<table style=\"width:100%;border-collapse:collapse;\">\n<thead>\n<tr>\n<th style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e27\u0e31\u0e19\u0e17\u0e35\u0e48<\/th>\n<th style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e40\u0e2b\u0e15\u0e38\u0e01\u0e32\u0e23\u0e13\u0e4c<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">4 \u0e21\u0e35.\u0e04. 2026<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Wiz \u0e23\u0e32\u0e22\u0e07\u0e32\u0e19\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e1c\u0e48\u0e32\u0e19 GitHub Bug Bounty; GitHub \u0e41\u0e01\u0e49 GitHub.com \u0e43\u0e19\u0e27\u0e31\u0e19\u0e40\u0e14\u0e35\u0e22\u0e27\u0e01\u0e31\u0e19<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">10 \u0e21\u0e35.\u0e04. 2026<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">GitHub \u0e2d\u0e2d\u0e01 GHES security patches \u0e15\u0e32\u0e21\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e01\u0e32\u0e23\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">28 \u0e40\u0e21.\u0e22. 2026<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e21\u0e35\u0e01\u0e32\u0e23\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22\u0e23\u0e32\u0e22\u0e25\u0e30\u0e40\u0e2d\u0e35\u0e22\u0e14\u0e2a\u0e32\u0e18\u0e32\u0e23\u0e13\u0e30\u0e41\u0e25\u0e30 CVE-2026-3854<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e2b\u0e25\u0e31\u0e07\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e04\u0e27\u0e23\u0e22\u0e37\u0e19\u0e22\u0e31\u0e19\u0e40\u0e27\u0e2d\u0e23\u0e4c\u0e0a\u0e31\u0e19 GHES \u0e41\u0e25\u0e30\u0e15\u0e23\u0e27\u0e08\u0e22\u0e49\u0e2d\u0e19\u0e2b\u0e25\u0e31\u0e07\u0e15\u0e32\u0e21 log retention<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>\u0e04\u0e27\u0e32\u0e21\u0e40\u0e23\u0e47\u0e27\u0e02\u0e2d\u0e07 GitHub.com \u0e41\u0e2a\u0e14\u0e07\u0e04\u0e38\u0e13\u0e04\u0e48\u0e32\u0e02\u0e2d\u0e07 SaaS patching \u0e41\u0e15\u0e48\u0e25\u0e39\u0e01\u0e04\u0e49\u0e32 GHES \u0e15\u0e49\u0e2d\u0e07\u0e1a\u0e23\u0e34\u0e2b\u0e32\u0e23 maintenance window \u0e41\u0e25\u0e30 upgrade dependency \u0e40\u0e2d\u0e07<\/p>\n<h2>AI \u0e21\u0e35\u0e1a\u0e17\u0e1a\u0e32\u0e17\u0e2d\u0e22\u0e48\u0e32\u0e07\u0e44\u0e23\u0e43\u0e19\u0e01\u0e32\u0e23\u0e04\u0e49\u0e19\u0e1e\u0e1a\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48<\/h2>\n<p>Wiz \u0e2d\u0e18\u0e34\u0e1a\u0e32\u0e22\u0e27\u0e48\u0e32\u0e01\u0e32\u0e23\u0e27\u0e34\u0e08\u0e31\u0e22\u0e43\u0e0a\u0e49 AI \u0e0a\u0e48\u0e27\u0e22 reverse engineer \u0e41\u0e25\u0e30\u0e40\u0e0a\u0e37\u0e48\u0e2d\u0e21\u0e42\u0e22\u0e07 code path \u0e43\u0e19\u0e23\u0e30\u0e1a\u0e1a\u0e17\u0e35\u0e48\u0e0b\u0e31\u0e1a\u0e0b\u0e49\u0e2d\u0e19 \u0e19\u0e35\u0e48\u0e44\u0e21\u0e48\u0e43\u0e0a\u0e48\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19\u0e27\u0e48\u0e32 AI agent \u0e42\u0e08\u0e21\u0e15\u0e35 GitHub \u0e42\u0e14\u0e22\u0e2d\u0e31\u0e15\u0e42\u0e19\u0e21\u0e31\u0e15\u0e34\u0e17\u0e31\u0e49\u0e07\u0e2b\u0e21\u0e14 \u0e41\u0e15\u0e48\u0e41\u0e2a\u0e14\u0e07\u0e27\u0e48\u0e32 AI \u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e25\u0e14\u0e40\u0e27\u0e25\u0e32\u0e17\u0e35\u0e48\u0e19\u0e31\u0e01\u0e27\u0e34\u0e08\u0e31\u0e22\u0e43\u0e0a\u0e49\u0e17\u0e33\u0e07\u0e32\u0e19\u0e0b\u0e49\u0e33 \u0e40\u0e0a\u0e48\u0e19:<\/p>\n<ul>\n<li>\u0e2a\u0e23\u0e38\u0e1b behavior \u0e02\u0e2d\u0e07 binary\/component<\/li>\n<li>\u0e15\u0e31\u0e49\u0e07 hypothesis \u0e40\u0e01\u0e35\u0e48\u0e22\u0e27\u0e01\u0e31\u0e1a data flow<\/li>\n<li>\u0e40\u0e1b\u0e23\u0e35\u0e22\u0e1a\u0e40\u0e17\u0e35\u0e22\u0e1a validation \u0e23\u0e30\u0e2b\u0e27\u0e48\u0e32\u0e07 service<\/li>\n<li>\u0e0a\u0e48\u0e27\u0e22\u0e2a\u0e23\u0e49\u0e32\u0e07 test case \u0e43\u0e19 lab<\/li>\n<li>\u0e0a\u0e35\u0e49\u0e08\u0e38\u0e14\u0e17\u0e35\u0e48\u0e04\u0e27\u0e23\u0e15\u0e23\u0e27\u0e08\u0e14\u0e49\u0e27\u0e22\u0e21\u0e19\u0e38\u0e29\u0e22\u0e4c<\/li>\n<\/ul>\n<p>\u0e04\u0e27\u0e32\u0e21\u0e23\u0e31\u0e1a\u0e1c\u0e34\u0e14\u0e0a\u0e2d\u0e1a\u0e22\u0e31\u0e07\u0e2d\u0e22\u0e39\u0e48\u0e17\u0e35\u0e48 researcher \u0e43\u0e19\u0e01\u0e32\u0e23\u0e22\u0e37\u0e19\u0e22\u0e31\u0e19\u0e1c\u0e25 \u0e04\u0e27\u0e1a\u0e04\u0e38\u0e21 scope \u0e41\u0e25\u0e30\u0e23\u0e32\u0e22\u0e07\u0e32\u0e19\u0e1c\u0e48\u0e32\u0e19 coordinated disclosure<\/p>\n<h2>\u0e1c\u0e25\u0e01\u0e23\u0e30\u0e17\u0e1a\u0e15\u0e48\u0e2d DevOps \u0e41\u0e25\u0e30 Software Supply Chain<\/h2>\n<p>Source-code platform \u0e40\u0e1b\u0e47\u0e19\u0e08\u0e38\u0e14\u0e23\u0e27\u0e21:<\/p>\n<ul>\n<li>source code \u0e41\u0e25\u0e30\u0e1b\u0e23\u0e30\u0e27\u0e31\u0e15\u0e34\u0e01\u0e32\u0e23\u0e40\u0e1b\u0e25\u0e35\u0e48\u0e22\u0e19\u0e41\u0e1b\u0e25\u0e07<\/li>\n<li>CI\/CD workflow<\/li>\n<li>deploy key, app token \u0e41\u0e25\u0e30 webhook secret<\/li>\n<li>package publishing permission<\/li>\n<li>infrastructure-as-code<\/li>\n<li>approval \u0e41\u0e25\u0e30 branch protection<\/li>\n<\/ul>\n<p>\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48 RCE \u0e1a\u0e19 platform \u0e19\u0e35\u0e49\u0e08\u0e36\u0e07\u0e44\u0e21\u0e48\u0e43\u0e0a\u0e48\u0e41\u0e04\u0e48\u0e1b\u0e31\u0e0d\u0e2b\u0e32 server \u0e2b\u0e19\u0e36\u0e48\u0e07\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07 \u0e2b\u0e32\u0e01 control \u0e2d\u0e37\u0e48\u0e19\u0e2d\u0e48\u0e2d\u0e19 attacker \u0e2d\u0e32\u0e08\u0e41\u0e01\u0e49 pipeline, \u0e2a\u0e2d\u0e14\u0e41\u0e17\u0e23\u0e01 artifact, \u0e02\u0e42\u0e21\u0e22 secret \u0e2b\u0e23\u0e37\u0e2d\u0e1b\u0e25\u0e2d\u0e21 release \u0e44\u0e14\u0e49<\/p>\n<p>\u0e41\u0e15\u0e48\u0e01\u0e32\u0e23\u0e1b\u0e23\u0e30\u0e40\u0e21\u0e34\u0e19\u0e15\u0e49\u0e2d\u0e07\u0e21\u0e35\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19 \u0e44\u0e21\u0e48\u0e04\u0e27\u0e23\u0e1b\u0e23\u0e30\u0e01\u0e32\u0e28 supply-chain breach \u0e40\u0e1e\u0e35\u0e22\u0e07\u0e40\u0e1e\u0e23\u0e32\u0e30\u0e43\u0e0a\u0e49 GHES \u0e23\u0e38\u0e48\u0e19 vulnerable \u0e43\u0e2b\u0e49\u0e41\u0e22\u0e01\u0e2a\u0e32\u0e21\u0e2a\u0e16\u0e32\u0e19\u0e30: vulnerable, attempted exploitation \u0e41\u0e25\u0e30 confirmed compromise<\/p>\n<h2>Playbook \u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a\u0e1c\u0e39\u0e49\u0e14\u0e39\u0e41\u0e25 GHES<\/h2>\n<h3>1. \u0e22\u0e37\u0e19\u0e22\u0e31\u0e19 Version \u0e41\u0e25\u0e30 Exposure<\/h3>\n<ul>\n<li>\u0e23\u0e30\u0e1a\u0e38 GHES instance \u0e17\u0e38\u0e01 environment \u0e23\u0e27\u0e21 DR\/staging<\/li>\n<li>\u0e15\u0e23\u0e27\u0e08 version\/build \u0e42\u0e14\u0e22\u0e15\u0e23\u0e07<\/li>\n<li>\u0e23\u0e30\u0e1a\u0e38 instance \u0e17\u0e35\u0e48\u0e40\u0e1b\u0e34\u0e14 internet \u0e2b\u0e23\u0e37\u0e2d\u0e40\u0e02\u0e49\u0e32\u0e16\u0e36\u0e07\u0e08\u0e32\u0e01 partner<\/li>\n<li>map \u0e1c\u0e39\u0e49\u0e43\u0e0a\u0e49\/automation \u0e17\u0e35\u0e48\u0e21\u0e35 push access<\/li>\n<li>\u0e15\u0e23\u0e27\u0e08\u0e27\u0e48\u0e32\u0e21\u0e35 instance \u0e40\u0e01\u0e48\u0e32\u0e2b\u0e23\u0e37\u0e2d snapshot \u0e17\u0e35\u0e48\u0e01\u0e25\u0e31\u0e1a\u0e21\u0e32 online \u0e44\u0e14\u0e49\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/li>\n<\/ul>\n<h3>2. \u0e2d\u0e31\u0e1b\u0e40\u0e01\u0e23\u0e14<\/h3>\n<p>\u0e15\u0e34\u0e14\u0e15\u0e31\u0e49\u0e07 hotpatch\/upgrade \u0e15\u0e32\u0e21 GitHub advisory \u0e41\u0e25\u0e30 supported upgrade path \u0e2a\u0e33\u0e23\u0e2d\u0e07 configuration\/data \u0e15\u0e32\u0e21\u0e04\u0e39\u0e48\u0e21\u0e37\u0e2d \u0e41\u0e25\u0e30\u0e17\u0e14\u0e2a\u0e2d\u0e1a authentication, Git over SSH\/HTTPS, Actions, webhook \u0e41\u0e25\u0e30 integration \u0e2b\u0e25\u0e31\u0e07\u0e2d\u0e31\u0e1b\u0e40\u0e01\u0e23\u0e14<\/p>\n<h3>3. \u0e25\u0e14 Credential Risk<\/h3>\n<ul>\n<li>revoke token\/SSH key \u0e17\u0e35\u0e48\u0e44\u0e21\u0e48\u0e43\u0e0a\u0e49<\/li>\n<li>\u0e25\u0e14 scope \u0e02\u0e2d\u0e07 personal access token<\/li>\n<li>\u0e43\u0e0a\u0e49 service account \u0e41\u0e22\u0e01\u0e15\u0e32\u0e21 integration<\/li>\n<li>\u0e2b\u0e21\u0e38\u0e19 deploy key \u0e41\u0e25\u0e30 secret \u0e17\u0e35\u0e48\u0e21\u0e35\u0e40\u0e2b\u0e15\u0e38\u0e2a\u0e07\u0e2a\u0e31\u0e22<\/li>\n<li>\u0e1a\u0e31\u0e07\u0e04\u0e31\u0e1a MFA \u0e41\u0e25\u0e30 SSO \u0e15\u0e32\u0e21\u0e04\u0e27\u0e32\u0e21\u0e40\u0e2b\u0e21\u0e32\u0e30\u0e2a\u0e21<\/li>\n<li>\u0e15\u0e23\u0e27\u0e08 orphaned account \u0e02\u0e2d\u0e07\u0e1e\u0e19\u0e31\u0e01\u0e07\u0e32\u0e19\/contractor<\/li>\n<\/ul>\n<h3>4. \u0e15\u0e23\u0e27\u0e08\u0e22\u0e49\u0e2d\u0e19\u0e2b\u0e25\u0e31\u0e07<\/h3>\n<p>\u0e23\u0e48\u0e27\u0e21\u0e01\u0e31\u0e1a GitHub Support\/advisory \u0e15\u0e23\u0e27\u0e08:<\/p>\n<ul>\n<li>push event \u0e41\u0e25\u0e30 push option \u0e1c\u0e34\u0e14\u0e1b\u0e01\u0e15\u0e34<\/li>\n<li>repository activity \u0e08\u0e32\u0e01 account \u0e17\u0e35\u0e48\u0e44\u0e21\u0e48\u0e04\u0e38\u0e49\u0e19\u0e40\u0e04\u0e22<\/li>\n<li>command\/process anomaly \u0e1a\u0e19 GHES appliance \u0e15\u0e32\u0e21 telemetry \u0e17\u0e35\u0e48\u0e23\u0e2d\u0e07\u0e23\u0e31\u0e1a<\/li>\n<li>outbound connection \u0e08\u0e32\u0e01 appliance<\/li>\n<li>token usage \u0e08\u0e32\u0e01\u0e41\u0e2b\u0e25\u0e48\u0e07\u0e43\u0e2b\u0e21\u0e48<\/li>\n<li>\u0e01\u0e32\u0e23\u0e40\u0e1b\u0e25\u0e35\u0e48\u0e22\u0e19 webhook, Actions runner \u0e41\u0e25\u0e30 organization setting<\/li>\n<\/ul>\n<p>\u0e2d\u0e22\u0e48\u0e32\u0e14\u0e31\u0e14\u0e41\u0e1b\u0e25\u0e07 appliance \u0e42\u0e14\u0e22\u0e15\u0e34\u0e14\u0e15\u0e31\u0e49\u0e07 forensic agent \u0e17\u0e35\u0e48\u0e44\u0e21\u0e48\u0e23\u0e2d\u0e07\u0e23\u0e31\u0e1a\u0e42\u0e14\u0e22\u0e44\u0e21\u0e48\u0e21\u0e35\u0e04\u0e33\u0e41\u0e19\u0e30\u0e19\u0e33 vendor \u0e40\u0e1e\u0e23\u0e32\u0e30\u0e2d\u0e32\u0e08\u0e01\u0e23\u0e30\u0e17\u0e1a supportability \u0e41\u0e25\u0e30\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19<\/p>\n<h3>5. \u0e1b\u0e23\u0e30\u0e40\u0e21\u0e34\u0e19 Blast Radius<\/h3>\n<p>\u0e2b\u0e32\u0e01\u0e1e\u0e1a\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19 code execution \u0e43\u0e2b\u0e49\u0e16\u0e37\u0e2d\u0e40\u0e1b\u0e47\u0e19 incident \u0e23\u0e30\u0e14\u0e31\u0e1a platform:<\/p>\n<ul>\n<li>isolate \u0e15\u0e32\u0e21\u0e41\u0e1c\u0e19\u0e17\u0e35\u0e48\u0e44\u0e21\u0e48\u0e17\u0e33\u0e25\u0e32\u0e22\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19<\/li>\n<li>\u0e15\u0e34\u0e14\u0e15\u0e48\u0e2d GitHub Support\/Incident Response<\/li>\n<li>\u0e2b\u0e21\u0e38\u0e19 secret \u0e17\u0e35\u0e48 GHES \u0e40\u0e02\u0e49\u0e32\u0e16\u0e36\u0e07\u0e44\u0e14\u0e49<\/li>\n<li>\u0e15\u0e23\u0e27\u0e08 CI runner \u0e41\u0e25\u0e30 artifact registry<\/li>\n<li>validate branch\/release\/tag \u0e2a\u0e33\u0e04\u0e31\u0e0d<\/li>\n<li>\u0e15\u0e23\u0e27\u0e08 downstream deployment<\/li>\n<\/ul>\n<h2>Hardening \u0e2b\u0e25\u0e31\u0e07\u0e40\u0e2b\u0e15\u0e38\u0e01\u0e32\u0e23\u0e13\u0e4c<\/h2>\n<h3>Network Segmentation<\/h3>\n<p>GHES \u0e44\u0e21\u0e48\u0e04\u0e27\u0e23\u0e40\u0e02\u0e49\u0e32\u0e16\u0e36\u0e07\u0e17\u0e38\u0e01 subnet \u0e42\u0e14\u0e22\u0e1b\u0e23\u0e34\u0e22\u0e32\u0e22 \u0e08\u0e33\u0e01\u0e31\u0e14 outbound \u0e41\u0e25\u0e30 management path \u0e43\u0e2b\u0e49\u0e40\u0e17\u0e48\u0e32\u0e17\u0e35\u0e48\u0e08\u0e33\u0e40\u0e1b\u0e47\u0e19 \u0e1e\u0e23\u0e49\u0e2d\u0e21 monitor connection \u0e17\u0e35\u0e48\u0e1c\u0e34\u0e14 baseline<\/p>\n<h3>Push Permission Hygiene<\/h3>\n<p>\u0e43\u0e0a\u0e49\u0e17\u0e35\u0e21\u0e41\u0e25\u0e30 role \u0e41\u0e17\u0e19\u0e01\u0e32\u0e23\u0e43\u0e2b\u0e49\u0e2a\u0e34\u0e17\u0e18\u0e34\u0e4c\u0e23\u0e32\u0e22\u0e1a\u0e38\u0e04\u0e04\u0e25\u0e42\u0e14\u0e22\u0e44\u0e21\u0e48\u0e21\u0e35\u0e27\u0e31\u0e19\u0e2b\u0e21\u0e14\u0e2d\u0e32\u0e22\u0e38 \u0e17\u0e1a\u0e17\u0e27\u0e19 external collaborator \u0e41\u0e25\u0e30 bot account \u0e2a\u0e21\u0e48\u0e33\u0e40\u0e2a\u0e21\u0e2d<\/p>\n<h3>Secret Separation<\/h3>\n<p>\u0e2d\u0e22\u0e48\u0e32\u0e43\u0e2b\u0e49 source platform \u0e16\u0e37\u0e2d production credential \u0e17\u0e35\u0e48\u0e01\u0e27\u0e49\u0e32\u0e07\u0e40\u0e01\u0e34\u0e19\u0e08\u0e33\u0e40\u0e1b\u0e47\u0e19 \u0e43\u0e0a\u0e49 short-lived identity \u0e41\u0e25\u0e30 workload federation \u0e40\u0e21\u0e37\u0e48\u0e2d\u0e23\u0e2d\u0e07\u0e23\u0e31\u0e1a<\/p>\n<h3>Runner Isolation<\/h3>\n<p>Self-hosted runner \u0e04\u0e27\u0e23\u0e41\u0e22\u0e01 trust zone, \u0e43\u0e0a\u0e49 ephemeral instance \u0e41\u0e25\u0e30\u0e44\u0e21\u0e48\u0e41\u0e0a\u0e23\u0e4c credential \u0e23\u0e30\u0e2b\u0e27\u0e48\u0e32\u0e07 repository \u0e17\u0e35\u0e48\u0e21\u0e35\u0e23\u0e30\u0e14\u0e31\u0e1a\u0e04\u0e27\u0e32\u0e21\u0e40\u0e0a\u0e37\u0e48\u0e2d\u0e16\u0e37\u0e2d\u0e15\u0e48\u0e32\u0e07\u0e01\u0e31\u0e19<\/p>\n<h3>Upgrade SLA<\/h3>\n<p>\u0e01\u0e33\u0e2b\u0e19\u0e14 SLA \u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a GHES critical patch \u0e1e\u0e23\u0e49\u0e2d\u0e21\u0e40\u0e08\u0e49\u0e32\u0e02\u0e2d\u0e07 maintenance window \u0e41\u0e25\u0e30 DR instance \u0e43\u0e2b\u0e49\u0e0a\u0e31\u0e14\u0e40\u0e08\u0e19<\/p>\n<h2>\u0e1a\u0e17\u0e40\u0e23\u0e35\u0e22\u0e19\u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a Secure Coding<\/h2>\n<p>CVE-2026-3854 \u0e40\u0e1b\u0e47\u0e19\u0e01\u0e23\u0e13\u0e35\u0e28\u0e36\u0e01\u0e29\u0e32\u0e02\u0e2d\u0e07\u0e23\u0e30\u0e1a\u0e1a\u0e2b\u0e25\u0e32\u0e22 service:<\/p>\n<ul>\n<li>\u0e2b\u0e25\u0e35\u0e01\u0e40\u0e25\u0e35\u0e48\u0e22\u0e07 shell command construction \u0e40\u0e21\u0e37\u0e48\u0e2d\u0e43\u0e0a\u0e49 structured API \u0e44\u0e14\u0e49<\/li>\n<li>\u0e41\u0e22\u0e01 executable \u0e01\u0e31\u0e1a argument \u0e41\u0e17\u0e19\u0e15\u0e48\u0e2d string<\/li>\n<li>validate \u0e17\u0e35\u0e48 trust boundary \u0e17\u0e38\u0e01\u0e08\u0e38\u0e14<\/li>\n<li>\u0e2d\u0e22\u0e48\u0e32\u0e43\u0e0a\u0e49 header\/internal metadata \u0e40\u0e1b\u0e47\u0e19 trusted input \u0e42\u0e14\u0e22\u0e2d\u0e31\u0e15\u0e42\u0e19\u0e21\u0e31\u0e15\u0e34<\/li>\n<li>\u0e17\u0e33 negative test \u0e01\u0e31\u0e1a delimiter, encoding \u0e41\u0e25\u0e30 option injection<\/li>\n<li>threat model protocol extension \u0e41\u0e25\u0e30 backward compatibility<\/li>\n<li>fuzz \u0e17\u0e31\u0e49\u0e07 entry point \u0e41\u0e25\u0e30 inter-service serialization<\/li>\n<\/ul>\n<p>Code review \u0e15\u0e49\u0e2d\u0e07\u0e15\u0e34\u0e14\u0e15\u0e32\u0e21 data flow \u0e15\u0e31\u0e49\u0e07\u0e41\u0e15\u0e48 untrusted input \u0e16\u0e36\u0e07 dangerous sink \u0e44\u0e21\u0e48\u0e43\u0e0a\u0e48\u0e15\u0e23\u0e27\u0e08\u0e40\u0e09\u0e1e\u0e32\u0e30\u0e44\u0e1f\u0e25\u0e4c\u0e17\u0e35\u0e48\u0e21\u0e35 shell call<\/p>\n<h2>\u0e21\u0e38\u0e21 Penetration Testing \u0e17\u0e35\u0e48\u0e1b\u0e25\u0e2d\u0e14\u0e20\u0e31\u0e22<\/h2>\n<p>\u0e1c\u0e39\u0e49\u0e17\u0e14\u0e2a\u0e2d\u0e1a\u0e17\u0e35\u0e48\u0e44\u0e14\u0e49\u0e23\u0e31\u0e1a\u0e2d\u0e19\u0e38\u0e0d\u0e32\u0e15\u0e04\u0e27\u0e23\u0e2b\u0e25\u0e35\u0e01\u0e40\u0e25\u0e35\u0e48\u0e22\u0e07\u0e01\u0e32\u0e23\u0e22\u0e34\u0e07 public exploit \u0e43\u0e2a\u0e48 production GHES \u0e40\u0e1e\u0e23\u0e32\u0e30\u0e2d\u0e32\u0e08\u0e17\u0e33\u0e43\u0e2b\u0e49 source platform \u0e2b\u0e22\u0e38\u0e14\u0e2b\u0e23\u0e37\u0e2d\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e40\u0e2a\u0e35\u0e22\u0e2b\u0e32\u0e22 \u0e27\u0e34\u0e18\u0e35\u0e1b\u0e23\u0e30\u0e40\u0e21\u0e34\u0e19\u0e17\u0e35\u0e48\u0e1b\u0e25\u0e2d\u0e14\u0e20\u0e31\u0e22\u0e01\u0e27\u0e48\u0e32:<\/p>\n<ul>\n<li>\u0e15\u0e23\u0e27\u0e08 version \u0e41\u0e25\u0e30 patch evidence<\/li>\n<li>review push-access inventory<\/li>\n<li>\u0e17\u0e14\u0e2a\u0e2d\u0e1a token scope \u0e41\u0e25\u0e30 branch protection<\/li>\n<li>\u0e15\u0e23\u0e27\u0e08 segmentation\/outbound policy<\/li>\n<li>\u0e08\u0e33\u0e25\u0e2d\u0e07 credential compromise \u0e43\u0e19 isolated repository<\/li>\n<li>tabletop supply-chain incident<\/li>\n<li>validate logging \u0e41\u0e25\u0e30 response workflow<\/li>\n<\/ul>\n<p>\u0e2b\u0e32\u0e01\u0e08\u0e33\u0e40\u0e1b\u0e47\u0e19\u0e15\u0e49\u0e2d\u0e07 reproduce CVE \u0e43\u0e2b\u0e49\u0e43\u0e0a\u0e49 lab instance \u0e23\u0e38\u0e48\u0e19\u0e40\u0e14\u0e35\u0e22\u0e27\u0e01\u0e31\u0e19\u0e17\u0e35\u0e48\u0e44\u0e21\u0e48\u0e21\u0e35\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e08\u0e23\u0e34\u0e07 \u0e1e\u0e23\u0e49\u0e2d\u0e21 snapshot \u0e41\u0e25\u0e30 stop condition<\/p>\n<h2>Checklist<\/h2>\n<ul>\n<li>\u0e23\u0e30\u0e1a\u0e38 GHES \u0e17\u0e38\u0e01 instance \u0e23\u0e27\u0e21 DR \u0e41\u0e25\u0e30 staging<\/li>\n<li>\u0e2d\u0e31\u0e1b\u0e40\u0e01\u0e23\u0e14\u0e40\u0e1b\u0e47\u0e19 fixed\/supported release \u0e25\u0e48\u0e32\u0e2a\u0e38\u0e14<\/li>\n<li>\u0e15\u0e23\u0e27\u0e08\u0e27\u0e48\u0e32 GitHub.com \u0e44\u0e21\u0e48\u0e15\u0e49\u0e2d\u0e07\u0e15\u0e34\u0e14\u0e15\u0e31\u0e49\u0e07 patch \u0e1d\u0e31\u0e48\u0e07\u0e25\u0e39\u0e01\u0e04\u0e49\u0e32<\/li>\n<li>\u0e17\u0e1a\u0e17\u0e27\u0e19 account, SSH key, token \u0e41\u0e25\u0e30 push permission<\/li>\n<li>\u0e15\u0e23\u0e27\u0e08 log \u0e22\u0e49\u0e2d\u0e19\u0e2b\u0e25\u0e31\u0e07\u0e15\u0e32\u0e21 timeline\/advisory<\/li>\n<li>\u0e2b\u0e21\u0e38\u0e19 secret \u0e2b\u0e32\u0e01\u0e1e\u0e1a\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19 compromise<\/li>\n<li>\u0e15\u0e23\u0e27\u0e08 Actions runner, webhook \u0e41\u0e25\u0e30 artifact pipeline<\/li>\n<li>\u0e08\u0e33\u0e01\u0e31\u0e14 network path \u0e02\u0e2d\u0e07 GHES<\/li>\n<li>\u0e1b\u0e23\u0e31\u0e1a upgrade SLA \u0e41\u0e25\u0e30 owner<\/li>\n<li>tabletop \u0e01\u0e23\u0e13\u0e35 source-control platform \u0e16\u0e39\u0e01\u0e22\u0e36\u0e14<\/li>\n<\/ul>\n<h2>\u3088\u304f\u3042\u308b\u8cea\u554f<\/h2>\n<h3>\u0e43\u0e04\u0e23\u0e01\u0e47\u0e44\u0e14\u0e49\u0e43\u0e0a\u0e49 git push \u0e41\u0e25\u0e49\u0e27\u0e22\u0e36\u0e14 GitHub Server \u0e44\u0e14\u0e49\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/h3>\n<p>\u0e44\u0e21\u0e48\u0e43\u0e0a\u0e48 \u0e1c\u0e39\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e15\u0e49\u0e2d\u0e07 authenticated \u0e41\u0e25\u0e30\u0e21\u0e35 push access \u0e44\u0e1b\u0e22\u0e31\u0e07 repository \u0e01\u0e48\u0e2d\u0e19 \u0e41\u0e15\u0e48 push access \u0e1e\u0e1a\u0e44\u0e14\u0e49\u0e01\u0e27\u0e49\u0e32\u0e07\u0e43\u0e19\u0e17\u0e35\u0e21\u0e1e\u0e31\u0e12\u0e19\u0e32 \u0e08\u0e36\u0e07\u0e22\u0e31\u0e07\u0e40\u0e1b\u0e47\u0e19\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e23\u0e49\u0e32\u0e22\u0e41\u0e23\u0e07<\/p>\n<h3>\u0e1c\u0e39\u0e49\u0e43\u0e0a\u0e49 GitHub.com \u0e15\u0e49\u0e2d\u0e07\u0e17\u0e33\u0e2d\u0e30\u0e44\u0e23<\/h3>\n<p>GitHub \u0e23\u0e30\u0e1a\u0e38\u0e27\u0e48\u0e32\u0e41\u0e01\u0e49 hosted service \u0e43\u0e19\u0e27\u0e31\u0e19\u0e23\u0e32\u0e22\u0e07\u0e32\u0e19 \u0e25\u0e39\u0e01\u0e04\u0e49\u0e32\u0e44\u0e21\u0e48\u0e15\u0e49\u0e2d\u0e07\u0e41\u0e1e\u0e15\u0e0a\u0e4c server \u0e40\u0e2d\u0e07 \u0e41\u0e15\u0e48\u0e04\u0e27\u0e23\u0e14\u0e39 vendor notice \u0e41\u0e25\u0e30\u0e15\u0e23\u0e27\u0e08 credential\/repository anomaly \u0e2b\u0e32\u0e01\u0e21\u0e35\u0e40\u0e2b\u0e15\u0e38\u0e2a\u0e07\u0e2a\u0e31\u0e22<\/p>\n<h3>GHES \u0e15\u0e49\u0e2d\u0e07\u0e2d\u0e31\u0e1b\u0e40\u0e01\u0e23\u0e14\u0e40\u0e1b\u0e47\u0e19\u0e23\u0e38\u0e48\u0e19\u0e43\u0e14<\/h3>\n<p>fixed versions \u0e17\u0e35\u0e48\u0e40\u0e1c\u0e22\u0e41\u0e1e\u0e23\u0e48\u0e40\u0e23\u0e34\u0e48\u0e21\u0e17\u0e35\u0e48 3.14.24, 3.15.19, 3.16.15, 3.17.12, 3.18.6 \u0e41\u0e25\u0e30 3.19.3 \u0e2d\u0e22\u0e48\u0e32\u0e07\u0e44\u0e23\u0e01\u0e47\u0e15\u0e32\u0e21 \u0e13 \u0e40\u0e27\u0e25\u0e32\u0e1b\u0e0f\u0e34\u0e1a\u0e31\u0e15\u0e34\u0e07\u0e32\u0e19\u0e04\u0e27\u0e23\u0e43\u0e0a\u0e49 supported release \u0e25\u0e48\u0e32\u0e2a\u0e38\u0e14\u0e15\u0e32\u0e21 GitHub advisory<\/p>\n<h3>\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e19\u0e35\u0e49\u0e22\u0e37\u0e19\u0e22\u0e31\u0e19\u0e27\u0e48\u0e32\u0e21\u0e35 supply-chain breach \u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/h3>\n<p>\u0e44\u0e21\u0e48 \u0e01\u0e32\u0e23\u0e21\u0e35 vulnerable version \u0e41\u0e1b\u0e25\u0e27\u0e48\u0e32\u0e21\u0e35 exposure \u0e44\u0e21\u0e48\u0e43\u0e0a\u0e48\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19\u0e27\u0e48\u0e32\u0e16\u0e39\u0e01 exploit \u0e15\u0e49\u0e2d\u0e07\u0e15\u0e23\u0e27\u0e08 log, process, credential \u0e41\u0e25\u0e30 downstream artifact \u0e01\u0e48\u0e2d\u0e19\u0e2a\u0e23\u0e38\u0e1b<\/p>\n<h3>AI \u0e40\u0e1b\u0e47\u0e19\u0e1c\u0e39\u0e49\u0e04\u0e49\u0e19\u0e1e\u0e1a\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e40\u0e2d\u0e07\u0e17\u0e31\u0e49\u0e07\u0e2b\u0e21\u0e14\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/h3>\n<p>AI \u0e0a\u0e48\u0e27\u0e22\u0e40\u0e23\u0e48\u0e07 reverse engineering \u0e41\u0e25\u0e30\u0e01\u0e32\u0e23\u0e15\u0e31\u0e49\u0e07 hypothesis \u0e15\u0e32\u0e21\u0e23\u0e32\u0e22\u0e07\u0e32\u0e19\u0e02\u0e2d\u0e07\u0e19\u0e31\u0e01\u0e27\u0e34\u0e08\u0e31\u0e22 \u0e41\u0e15\u0e48\u0e01\u0e32\u0e23\u0e22\u0e37\u0e19\u0e22\u0e31\u0e19 \u0e04\u0e27\u0e1a\u0e04\u0e38\u0e21\u0e01\u0e32\u0e23\u0e17\u0e14\u0e2a\u0e2d\u0e1a \u0e41\u0e25\u0e30 coordinated disclosure \u0e22\u0e31\u0e07\u0e14\u0e33\u0e40\u0e19\u0e34\u0e19\u0e01\u0e32\u0e23\u0e42\u0e14\u0e22\u0e21\u0e19\u0e38\u0e29\u0e22\u0e4c<\/p>\n<h2>\u307e\u3068\u3081<\/h2>\n<p>CVE-2026-3854 \u0e41\u0e2a\u0e14\u0e07\u0e43\u0e2b\u0e49\u0e40\u0e2b\u0e47\u0e19\u0e27\u0e48\u0e32 operation \u0e18\u0e23\u0e23\u0e21\u0e14\u0e32\u0e2d\u0e22\u0e48\u0e32\u0e07 <code>git push<\/code> \u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e01\u0e25\u0e32\u0e22\u0e40\u0e1b\u0e47\u0e19 server-side RCE \u0e40\u0e21\u0e37\u0e48\u0e2d untrusted metadata \u0e02\u0e49\u0e32\u0e21 service boundary \u0e41\u0e25\u0e30\u0e16\u0e39\u0e01\u0e19\u0e33\u0e44\u0e1b\u0e1b\u0e23\u0e30\u0e01\u0e2d\u0e1a shell command \u0e42\u0e14\u0e22\u0e44\u0e21\u0e48\u0e1b\u0e25\u0e2d\u0e14\u0e20\u0e31\u0e22<\/p>\n<p>\u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e17\u0e35\u0e48\u0e43\u0e0a\u0e49 GHES \u0e01\u0e32\u0e23\u0e2d\u0e31\u0e1b\u0e40\u0e01\u0e23\u0e14\u0e40\u0e1b\u0e47\u0e19\u0e40\u0e1e\u0e35\u0e22\u0e07\u0e08\u0e38\u0e14\u0e40\u0e23\u0e34\u0e48\u0e21\u0e15\u0e49\u0e19 \u0e15\u0e49\u0e2d\u0e07\u0e15\u0e23\u0e27\u0e08 push credential, log, runner, secret \u0e41\u0e25\u0e30 downstream pipeline \u0e14\u0e49\u0e27\u0e22 \u0e2a\u0e48\u0e27\u0e19\u0e17\u0e35\u0e21\u0e1e\u0e31\u0e12\u0e19\u0e32\u0e04\u0e27\u0e23\u0e19\u0e33\u0e1a\u0e17\u0e40\u0e23\u0e35\u0e22\u0e19\u0e40\u0e23\u0e37\u0e48\u0e2d\u0e07 structured execution \u0e41\u0e25\u0e30 trust-boundary validation \u0e44\u0e1b\u0e43\u0e0a\u0e49\u0e01\u0e31\u0e1a\u0e23\u0e30\u0e1a\u0e1a automation \u0e17\u0e38\u0e01\u0e0a\u0e19\u0e34\u0e14 \u0e44\u0e21\u0e48\u0e40\u0e09\u0e1e\u0e32\u0e30 Git hosting<\/p>\n<h2>\u0e41\u0e2b\u0e25\u0e48\u0e07\u0e2d\u0e49\u0e32\u0e07\u0e2d\u0e34\u0e07<\/h2>\n<ol>\n<li><a href=\"https:\/\/github.blog\/security\/securing-the-git-push-pipeline-responding-to-a-critical-remote-code-execution-vulnerability\/\" target=\"_blank\" rel=\"noopener\">GitHub \u2014 Securing the git push pipeline: Responding to a critical RCE vulnerability<\/a><\/li>\n<li><a href=\"https:\/\/www.wiz.io\/blog\/github-rce-vulnerability-cve-2026-3854\" target=\"_blank\" rel=\"noopener\">Wiz Research \u2014 GitHub RCE vulnerability CVE-2026-3854<\/a><\/li>\n<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@latest\/admin\/release-notes\" target=\"_blank\" rel=\"noopener\">GitHub Enterprise Server Release Notes<\/a><\/li>\n<li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-3854\" target=\"_blank\" rel=\"noopener\">NVD \u2014 CVE-2026-3854<\/a><\/li>\n<\/ol>","protected":false},"excerpt":{"rendered":"<p>\u0e27\u0e34\u0e40\u0e04\u0e23\u0e32\u0e30\u0e2b\u0e4c CVE-2026-3854 \u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48 command injection \u0e43\u0e19 GitHub push pipeline \u0e04\u0e30\u0e41\u0e19\u0e19 CVSS 8.7 \u0e1c\u0e25\u0e15\u0e48\u0e2d GitHub.com \u0e41\u0e25\u0e30 GHES \u0e1e\u0e23\u0e49\u0e2d\u0e21\u0e27\u0e34\u0e18\u0e35\u0e15\u0e23\u0e27\u0e08\u0e40\u0e27\u0e2d\u0e23\u0e4c\u0e0a\u0e31\u0e19\u0e41\u0e25\u0e30\u0e23\u0e31\u0e1a\u0e21\u0e37\u0e2d<\/p>","protected":false},"author":0,"featured_media":18428,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[264,265],"tags":[317,315,319,318,316,314,298,320],"class_list":["post-18396","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-zero-day-vulnerability","tag-command-injection","tag-cve-2026-3854","tag-devsecops","tag-ghes","tag-git-push","tag-github","tag-rce","tag-supply-chain"],"acf":[],"rttpg_featured_image_url":{"full":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/09.jpg",1200,630,false],"landscape":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/09.jpg",1200,630,false],"portraits":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/09.jpg",1200,630,false],"thumbnail":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/09-150x150.jpg",150,150,true],"medium":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/09-300x158.jpg",300,158,true],"large":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/09-1024x538.jpg",1024,538,true],"1536x1536":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/09.jpg",1200,630,false],"2048x2048":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/09.jpg",1200,630,false],"trp-custom-language-flag":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/09-18x9.jpg",18,9,true],"woocommerce_thumbnail":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/09-300x300.jpg",300,300,true],"woocommerce_single":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/09-600x315.jpg",600,315,true],"woocommerce_gallery_thumbnail":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/09-100x100.jpg",100,100,true]},"rttpg_author":{"display_name":"","author_link":"https:\/\/droneth.or.th\/ja\/author\/"},"rttpg_comment":0,"rttpg_category":"<a href=\"https:\/\/droneth.or.th\/ja\/category\/cybersecurity\/\" rel=\"category tag\">Cybersecurity<\/a> <a href=\"https:\/\/droneth.or.th\/ja\/category\/cybersecurity\/zero-day-vulnerability\/\" rel=\"category tag\">Zero-Day \u0e41\u0e25\u0e30\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48<\/a>","rttpg_excerpt":"\u0e27\u0e34\u0e40\u0e04\u0e23\u0e32\u0e30\u0e2b\u0e4c CVE-2026-3854 \u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48 command injection \u0e43\u0e19 GitHub push pipeline \u0e04\u0e30\u0e41\u0e19\u0e19 CVSS 8.7 \u0e1c\u0e25\u0e15\u0e48\u0e2d GitHub.com \u0e41\u0e25\u0e30 GHES \u0e1e\u0e23\u0e49\u0e2d\u0e21\u0e27\u0e34\u0e18\u0e35\u0e15\u0e23\u0e27\u0e08\u0e40\u0e27\u0e2d\u0e23\u0e4c\u0e0a\u0e31\u0e19\u0e41\u0e25\u0e30\u0e23\u0e31\u0e1a\u0e21\u0e37\u0e2d","_links":{"self":[{"href":"https:\/\/droneth.or.th\/ja\/wp-json\/wp\/v2\/posts\/18396","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/droneth.or.th\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/droneth.or.th\/ja\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/droneth.or.th\/ja\/wp-json\/wp\/v2\/comments?post=18396"}],"version-history":[{"count":1,"href":"https:\/\/droneth.or.th\/ja\/wp-json\/wp\/v2\/posts\/18396\/revisions"}],"predecessor-version":[{"id":18411,"href":"https:\/\/droneth.or.th\/ja\/wp-json\/wp\/v2\/posts\/18396\/revisions\/18411"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/droneth.or.th\/ja\/wp-json\/wp\/v2\/media\/18428"}],"wp:attachment":[{"href":"https:\/\/droneth.or.th\/ja\/wp-json\/wp\/v2\/media?parent=18396"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/droneth.or.th\/ja\/wp-json\/wp\/v2\/categories?post=18396"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/droneth.or.th\/ja\/wp-json\/wp\/v2\/tags?post=18396"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}