CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2026-72924 LOW

GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default

CVSS 2.1 EPSS 0.26% Aug 25, 2026
CVE-2026-64655 LOW

GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching

CVSS 2.1 EPSS 0.34% Aug 6, 2026
CVE-2026-64654 MEDIUM

GitHub CLI: Terminal escape sequence injection in multiple `gh` commands

CVSS 5.3 EPSS 0.77% Aug 6, 2026
CVE-2026-64653 MEDIUM

GitHub CLI: Unescaped variable components in request URLs could allow path traversal

CVSS 5.1 EPSS 0.53% Aug 6, 2026
CVE-2026-64652 LOW

GitHub CLI: Partial token disclosure in `gh auth status` output

CVSS 3.3 EPSS 0.15% Aug 6, 2026
CVE-2026-59831 MEDIUM

GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace

CVSS 4.4 EPSS 0.33% Jul 9, 2026
CVE-2026-48501 CRITICAL

GitHub CLI tokens leak via `gh attestation` commands

CVSS 9.1 EPSS 0.45% May 29, 2026
Go
CVE-2026-45803 LOW

gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection

CVSS 3.5 EPSS 0.31% May 15, 2026
Go
CVE-2025-48938 LOW

Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server

CVSS 2.6 EPSS 0.53% May 30, 2025
Go
CVE-2025-25204 MEDIUM

`gh attestation verify` returns incorrect exit code during verification if no attestations are present

CVSS 6.3 EPSS 0.41% Feb 14, 2025
Go
CVE-2024-54132 MEDIUM

GitHub CLI allows downloading malicious GitHub Actions workflow artifact to result in path traversal vulnerability

CVSS 6.3 EPSS 0.63% Dec 4, 2024
Go
CVE-2024-53858 MEDIUM

Recursive repository cloning can leak authentication tokens to non-GitHub submodule hosts in the gh cli

CVSS 6.5 EPSS 0.28% Nov 27, 2024
Go
CVE-2024-53859 HIGH

go-gh `auth.TokenForHost` violates GitHub host security boundary within a codespace

CVSS 7.5 EPSS 0.53% Nov 27, 2024
Go
CVE-2024-52308 CRITICAL

Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer

CVSS 9.6 EPSS 0.85% Nov 14, 2024
Go
CVE-2016-10538 LOW

The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any f…

CVSS 3.5 EPSS 0.99% May 31, 2018
npm

Showing 1 to 15 CVEs · page 1