It was possible to trigger repository updates for many repositories via a crafted webhook payload.
Disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability.
Thanks to Hector Ruiz Ruiz & NaxusAI for responsibly disclosing this vulnerability to us.
{
"nvd_published_at": null,
"github_reviewed_at": "2025-12-15T22:01:04Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-1286"
],
"github_reviewed": true
}