A critical vulnerability (CVE-2026-3854) was discovered in GitHub's internal git infrastructure, allowing remote code execution on GitHub.com and GitHub Enterprise Server. The vulnerability was found by Wiz Research using AI-augmented tooling and was mitigated by GitHub within 6 hours of the report. The vulnerability allowed an attacker to execute arbitrary commands on GitHub's backend servers with a single git push command. GitHub Enterprise Server customers are advised to upgrade to version 3.19.3 or later to patch the vulnerability.