Cli / Cli
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-72924 | GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default | LOW | 2.1 | Aug 25, 2026 |
| CVE-2026-64655 | GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching | LOW | 2.1 | Aug 6, 2026 |
| CVE-2026-64654 | GitHub CLI: Terminal escape sequence injection in multiple `gh` commands | MEDIUM | 5.3 | Aug 6, 2026 |
| CVE-2026-64653 | GitHub CLI: Unescaped variable components in request URLs could allow path traversal | MEDIUM | 5.1 | Aug 6, 2026 |
| CVE-2026-64652 | GitHub CLI: Partial token disclosure in `gh auth status` output | LOW | 3.3 | Aug 6, 2026 |
| CVE-2026-59831 | GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace | MEDIUM | 4.4 | Jul 9, 2026 |
| CVE-2026-48501 | GitHub CLI tokens leak via `gh attestation` commands | CRITICAL | 9.1 | May 29, 2026 |
| CVE-2026-45803 | gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection | LOW | 3.5 | May 15, 2026 |
| CVE-2025-25204 | `gh attestation verify` returns incorrect exit code during verification if no attestations are present | MEDIUM | 6.3 | Feb 14, 2025 |
| CVE-2024-54132 | GitHub CLI allows downloading malicious GitHub Actions workflow artifact to result in path traversal vulnerability | MEDIUM | 6.3 | Dec 4, 2024 |
| CVE-2024-53858 | Recursive repository cloning can leak authentication tokens to non-GitHub submodule hosts in the gh cli | MEDIUM | 6.5 | Nov 27, 2024 |
| CVE-2024-52308 | Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer | CRITICAL | 9.6 | Nov 14, 2024 |
| CVE-2016-10538 | The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any f… | LOW | 3.5 | May 31, 2018 |
Showing 1 to 13 of 13 CVEs