#VU109635 Exposed dangerous method or function in GitHub Enterprise Server - CVE-2025-3509
Published: May 22, 2025
GitHub Enterprise Server
GitHub
Description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists within the pre-receive hook functionality, which becomes available during a hot patch upgrade. A remote user with site administrator permissions or a user with privileges to modify repositories containing pre-receive hooks can execute arbitrary code on the system.
Remediation
External links
- https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.13.14
- https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.11
- https://docs.github.com/en/enterprise-server@3.15/admin/release-notes#3.15.6
- https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.2