Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-9132: GitHub Enterprise Server Copilot diff endpoint exposed private repo code

A missing authorization flaw in the GitHub Copilot pull request description diff summary endpoint in GitHub Enterprise Server let any authenticated user render cross-repository comparison diffs and read source code from private repositories they had no access to. It affected all versions prior to 3.21 and was fixed in 3.17.17, 3.18.11, 3.19.8 and 3.20.4.

Disclosed 30 June 2026 · Record updated 13 September 2026

Impact

Authenticated users on an affected instance with read access to at least one repository could read source code from private repositories they were not authorized to view.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-9132