Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-72924— GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default

Quick assessment

Affected
cli cli
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GitHub CLI(gh)是 GitHub 的官方命令行工具。在版本 2.28.0 至 2.97.0 中,gh codespace 端口转发功能默认将本地监听器绑定到所有可用的网络接口。当端口转发处于活动状态时,CodeSpaces 中的服务可通过用户非环回(non-loopback)的本地 IP 地址,被能够路由到用户机器的其他主机访问。 该行为并不会改变 GitHub 端对 CodeSpaces 端口的可见性控制。相反,即使用户源 CodeSpaces 端口保持私有状态,本地机器上的通配符绑定(wildcar

CVSS 2.1 · Low EPSS 0.18% · P7
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-72924

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default
Source: CVE Program / CVE List V5
Vulnerability Description
GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28.0 through 2.97.0 bind the local listener created by gh codespace ports forward to all available network interfaces by default. While port forwarding is active, a service in a Codespace can therefore become reachable through the user's non-loopback local IP addresses by other hosts that can route to the user's machine. This behavior does not change the GitHub-side visibility of the Codespaces port. Instead, it exposes the forwarded service through a wildcard-bound listener on the user's local machine, even when the source Codespaces port remains private. Exploitation requires a network-adjacent attacker to reach the victim's machine while forwarding is active. This issue is fixed in version 2.98.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1327
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
cli cli >= 2.28.0, < 2.98.0 -

II. Public POCs for CVE-2026-72924

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-72924

登录查看更多情报信息。

Vendor Advisories for CVE-2026-72924 (1)

Vendor Pages for CVE-2026-72924 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-72924

No comments yet


Leave a comment