n improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied HTML to inject DOM elements with IDs that collided with server-initialized data islands. These collisions could overwrite or shadow critical application state objects used by certain Project views, leading to unintended server-side POST requests or other unauthorized backend interactions. Successful exploitation requires an attacker to have access to the target GitHub Enterprise Server instance and to entice a privileged user to view crafted malicious content that includes conflicting HTML elements. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.18.3, 3.17.9, 3.16.12, 3.15.16, and 3.14.21.
Configuration 1 (hide)
|
19 Dec 2025, 19:47
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| First Time |
Github enterprise Server
Github |
|
| CPE | cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* | |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.14.21 - Release Notes | |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.15.16 - Release Notes | |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.16.12 - Release Notes | |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.17.9 - Release Notes | |
| References | () https://docs.github.com/en/[email protected]/admin/release-notes#3.18.3 - Release Notes |
12 Dec 2025, 15:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-12-11 18:16
Updated : 2025-12-19 19:47
NVD link : CVE-2025-14046
Mitre link : CVE-2025-14046
CVE.ORG link : CVE-2025-14046
JSON object : View
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')