Yeah, but this still gives any employee RCE on the GHES server right?

I suppose so. The company invested pretty heavily in security tooling, though I think it wouldn't have been hard to do something to bypass the security for internal servers.