检测 GitHub Enterprise Server (GHES) 实例是否受 CVE-2026-3854 和 CVE-2026-4821 影响。
Git Push 远程代码执行 — babeld 组件未对 git push 选项中的分号进行清理,导致可远程执行代码。
受影响版本:
| 主版本 | 受影响范围 | 最低安全版本 |
|---|---|---|
| 3.14.x | <= 3.14.24 | 3.14.25 |
| 3.15.x | <= 3.15.19 | 3.15.20 |
| 3.16.x | <= 3.16.15 | 3.16.16 |
| 3.17.x | <= 3.17.12 | 3.17.13 |
| 3.18.x | <= 3.18.6 | 3.18.7 |
| 3.19.x | <= 3.19.3 | 3.19.4 |
| 3.20.x+ | 不受影响 | — |
管理控制台代理注入 — 代理配置字段未对 shell 元字符进行清理。
受影响版本:
修复版本:3.20.1、3.15.21
pip install ghes-cve-scanner
git clone https://github.com/isagoakira/ghes-cve-scanner.git
cd ghes-cve-scanner
pip install -e .
python scanner.py scan https://ghes.company.com
python scanner.py scan-batch instances.csv -o report.html
url,ip,port
https://ghes1.company.com,10.0.1.1,443
https://ghes2.company.com,10.0.1.2,443
| 选项 | 说明 | 默认值 |
|---|---|---|
--timeout N | HTTP 超时时间(秒) | 5 |
--retries N | 重试次数 | 2 |
--verbose, -v | 启用详细输出 | false |
| 选项 | 说明 |
|---|---|
url | GHES 实例 URL |
--cve-only CVE_ID | 仅扫描指定的 CVE |
--format, -f | 输出格式(console/json/csv/html) |
--output, -o | 输出文件路径 |
--exit-code | 启用退出码 |
| 选项 | 说明 |
|---|---|
file | CSV 文件路径 |
--url-column N | URL 列索引 |
--ip-column N | IP 列索引 |
--port-column N | 端口列索引 |
--format, -f | 输出格式 |
--output, -o | 输出文件路径 |
--workers N | 最大并行线程数 |
--exit-code | 启用退出码 |
| 代码 | 含义 |
|---|---|
| 0 | 所有实例均安全 |
| 1 | 至少一个实例存在漏洞 |
| 2 | 至少一个实例无法扫描 |
| GHES 版本 | CVE-2026-3854 | CVE-2026-4821 |
|---|---|---|
| 3.14.0 - 3.14.24 | 存在漏洞 | 存在漏洞 |
| 3.14.25+ | 安全 | 存在漏洞 |
| 3.15.0 - 3.15.20 | 存在漏洞 | 存在漏洞 |
| 3.15.21+ | 安全 | 安全 |
| 3.16.0 - 3.16.15 | 存在漏洞 | 存在漏洞 |
| 3.16.16+ | 安全 | 存在漏洞 |
| 3.17.0 - 3.17.12 | 存在漏洞 | 存在漏洞 |
| 3.17.13+ | 安全 | 存在漏洞 |
| 3.18.0 - 3.18.6 | 存在漏洞 | 存在漏洞 |
| 3.18.7+ | 安全 | 存在漏洞 |
| 3.19.0 - 3.19.3 | 存在漏洞 | 存在漏洞 |
| 3.19.4+ | 安全 | 存在漏洞 |
| 3.20.0 | 安全 | 存在漏洞 |
| 3.20.1+ | 安全 | 安全 |
# 单实例扫描
./examples/single_instance.sh https://ghes.company.com
# 批量扫描
./examples/batch_scan.sh instances.csv report.html
# CI 集成
# 参见 examples/ci_integration.sh
MIT 许可证