Boletines de Vulnerabilidades

CVE-2026-10585

   
Software afectado GITHUB
 
A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary JavaScript in another user's browser by injecting a crafted payload into the title of a Discussion in the Q&A category. The AnsweredQuestionStructuredDataComponent did not escape user-controlled Discussion titles before embedding them in a

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-10585