CVE-2025-6981 MEDIUM

CVE-2025-6981: Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized read-only access

Vendor Github
Product Enterprise Server
Weakness CWE-863 · Incorrect authorization
Published July 15, 2025
Last update July 16, 2025

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N

What the vulnerability does

01Description

An incorrect authorization vulnerability allowed unauthorized read access to the contents of internal repositories for contractor accounts when the Contractors API feature was enabled. The Contractors API is a rarely-enabled feature in private preview. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.18 and was fixed in versions 3.14.15, 3.15.10, 3.16.6 and 3.17.3

Key dates

02Disclosure timeline

July 15, 2025 CVE published
July 16, 2025 Record updated