CVE-2026-3854: How a Trusted Internal Header Turned `git push` into RCE on GitHub
Wiz Research disclosed a command injection in GitHub’s internal git pipeline that let any authenticated user reach RCE with a single git push. The root cause is the same one that has burned multi-service architectures for thirty years: trust boundaries that don’t actually exist.