CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default
GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching
GitHub CLI: Terminal escape sequence injection in multiple `gh` commands
GitHub CLI: Unescaped variable components in request URLs could allow path traversal
GitHub CLI: Partial token disclosure in `gh auth status` output
GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace
GitHub CLI tokens leak via `gh attestation` commands
gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection
Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server
`gh attestation verify` returns incorrect exit code during verification if no attestations are present
GitHub CLI allows downloading malicious GitHub Actions workflow artifact to result in path traversal vulnerability
Recursive repository cloning can leak authentication tokens to non-GitHub submodule hosts in the gh cli
go-gh `auth.TokenForHost` violates GitHub host security boundary within a codespace
Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer
The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any f…
Showing 1 to 15 CVEs · page 1