VYPR
Medium severity4.3NVD Advisory· Published Jul 15, 2025· Updated Jun 17, 2026

CVE-2025-6981

CVE-2025-6981

Description

An incorrect authorization vulnerability allowed unauthorized read access to the contents of internal repositories for contractor accounts when the Contractors API feature was enabled. The Contractors API is a rarely-enabled feature in private preview. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.18 and was fixed in versions 3.14.15, 3.15.10, 3.16.6 and 3.17.3

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*range: <3.14.5
    • (no CPE)range: pre-3.18, fixed in 3.14.15, 3.15.10, 3.16.6, 3.17.3
    • (no CPE)range: 3.14.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.