It was possible to trigger repository updates for many repositories via a crafted webhook payload.
Disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability.
Thanks to Hector Ruiz Ruiz & NaxusAI for responsibly disclosing this vulnerability to us.
{
"github_reviewed": true,
"nvd_published_at": "2025-12-16T01:15:51Z",
"cwe_ids": [
"CWE-1286"
],
"github_reviewed_at": "2025-12-15T22:01:04Z",
"severity": "MODERATE"
}