May 2, 2026·8 min readGitHub Got Owned by a SemicolonCVE-2026-3854 let any authenticated user pop GitHub's backend with a single git push. The bug class is older than I am. So why does it keep working?#security#vulnerability#github#essay