Tech

GitHub patches critical remote code execution flaw in under six hours following AI discovery

Wiz Research identifies vulnerability in internal git infrastructure using artificial intelligence; Alexis Wales confirms rapid response amidst backdrop of recent platform outages.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: The Verge · original
GitHub rushed to fix a critical vulnerability in less than six hours
Security team validates report within 40 minutes and deploys fix to both GitHub.com and Enterprise Server before forensic checks confirm no exploitation occurred.

GitHub has resolved a critical remote code execution vulnerability affecting its internal git infrastructure in less than six hours after the flaw was identified by Wiz Research. The security incident, which was detected using artificial intelligence models, targeted a system that could have allowed attackers to access millions of public and private code repositories. Despite the severity of the issue, GitHub's engineering team managed to contain the threat and deploy a comprehensive fix with remarkable speed.

The discovery process marked a notable shift in how critical flaws in closed-source binaries are identified, as the vulnerability was found using an AI model. Sagi Tzadik, a security researcher at Wiz, described the incident as one of the first instances of a critical vulnerability in such systems being uncovered this way. The specific AI model used to identify the flaw has not been publicly disclosed, though the method highlights an emerging trend in security research where automated tools are increasingly used to probe complex software architectures.

Upon receiving the report from Wiz Research, GitHub's security team moved with urgency. Alexis Wales, the company's chief information security officer, confirmed that the team validated the bug bounty report within 40 minutes. By reproducing the vulnerability internally, the security team confirmed the severity of the issue, which Wales described as requiring immediate action. This rapid validation allowed the engineering team to develop a solution and deploy it to both GitHub.com and GitHub Enterprise Server just over an hour after the root cause was identified.

Forensic investigations conducted immediately following the deployment concluded that there was no evidence the vulnerability was exploited prior to the patch. Wales noted that the entire lifecycle of the incident, from validation to the commencement of forensic checks, was completed in less than two hours. The swift response ensured that the window of opportunity for potential attackers was effectively closed before any damage could be done to the millions of repositories hosted on the platform.

The severity of the flaw was such that Wiz Research deemed it "remarkably easy to exploit" despite the complexity of GitHub's underlying system. Consequently, the discovery earned one of the highest rewards available in Wiz's Bug Bounty program. This high reward reflects the rarity of the finding and underscores the value of skilled researchers who can utilise advanced tools to ask the right questions regarding software integrity.

This security incident occurs against a backdrop of recent reliability challenges for the platform. Reports indicate that GitHub has experienced a trend of outages, including a significant event where previously merged commits were randomly reverted for some users. Employee concerns regarding leadership stability and the company's reputation have also been raised in recent weeks, adding context to the heightened scrutiny surrounding the company's technical operations.

Continue reading

More from Tech

Read next: The Walrus warns of collapsing digital memory as AI erodes search reliability
Read next: Open-source tool claims 97 per cent token savings for AI agents
Read next: Valvoline Unveils August 2026 Promotional Offers for Service and Retail Buyers