CVE-2025-8447Disclosure(github / enterprise_server)

LOWCVSS 3.1 · LOW

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from another repository by creating a diff between the repositories. To exploit this vulnerability, an attacker needed to know the name of a private repository along with its branches, tags, or commit SHAs that they could use to trigger compare/diff functionality and retrieve limited code without proper authorization. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.18, and was fixed in versions 3.14.17, 3.15.12, 3.16.8 and 3.17.5. This vulnerability was reported via the GitHub Bug Bounty program.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_server

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
enterprise_server

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-20: 1PoC Mentioned / Linked · 2026-08-20: 1Technical Details · 2026-08-20: 108-20
Signal classification1 categories
Disclosure
1100.0%
Referenced assets3 URLs
Full discourse1 post
  • I'M H4CK3R 42@luckyhacker43
    Disclosure

    $10,000 [CVE-2025-8447] Arbitrary Read of Another Users private repository without Authorization 🤯🔥 🔗 https://hackerone.com/reports/3124517 🔗 https://www.cve.org/cverecord?id=CVE-2025-8447 🔗 Join team 👉https://t.me/luckyhacker42 https://t.co/zVw8HLJocr

    Post summary

    The post reports the discovery of CVE‑2025‑8447, a vulnerability that enables arbitrary reading of private repositories without authorization, and references a HackerOne report and CVE record, but it does not indicate active exploitation, a patch, or a PoC.

    07026132.2K
    4.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgithubenterprise_server---

Explore more