Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

cli — Vulnerabilities & Security Advisories 26

All 26 CVE vulnerabilities found in cli, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities associated with command-line interface (CLI) tools, categorized by vendor, product, and specific weakness type. The collection encompasses a broad range of defects, including injection flaws, broken access control, and improper input validation, documenting issues identified over the past five years. Readers can utilize this data to track specific vendor advisories, understand the prevalence of particular weakness classes across different implementations, or examine the complete vulnerability history of a specific product to assess its long-term security posture and remediation patterns. The aggregated records provide a structured view of how command-line interfaces handle sensitive data, execute commands, and manage user inputs, highlighting common failure points that developers and security teams must address. By centralizing this information, the page facilitates comparative analysis across similar tools and helps identify systemic issues within specific software ecosystems or programming languages often used for CLI development. This resource supports both proactive security assessments and reactive incident response by providing a comprehensive historical context for known flaws, enabling stakeholders to prioritize fixes based on frequency and severity trends observed in the collected data.

Vendor: npm

CVE ID Title CVSS Severity Published
CVE-2026-55061 uniget: EDITOR Command Injection in uniget CLI CWE-88 1.0 Low 2026-09-17
CVE-2026-55062 uniget: Path Traversal in Hook Files - Directory Escape Vulnerability CWE-22 8.4 High 2026-09-17
CVE-2026-72924 GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default CWE-1327 2.1 Low 2026-08-25
CVE-2026-64655 GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching CWE-185 2.1 Low 2026-08-06
CVE-2026-64654 GitHub CLI: Terminal escape sequence injection in multiple `gh` commands CWE-150 5.3 Medium 2026-08-06
CVE-2026-64653 GitHub CLI: Unescaped variable components in request URLs could allow path traversal CWE-22 5.1 Medium 2026-08-06
CVE-2026-64652 GitHub CLI: Partial token disclosure in `gh auth status` output CWE-201 3.3 Low 2026-08-06
CVE-2026-47671 Nhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secrets CWE-306 5.4 Medium 2026-07-21
CVE-2026-59831 GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace CWE-829 4.4 Medium 2026-07-09
CVE-2026-56236 Capgo CLI - Arbitrary File Overwrite via Symlink-Following in Local Credential Operations CWE-59 6.1 Medium 2026-06-21
CVE-2026-48501 GitHub CLI tokens leak via `gh attestation` commands CWE-863 7.4 High 2026-05-29
CVE-2026-45152 uniget: Command Injection in tool.Check Leading to Arbitrary Code Execution CWE-78 7.8 High 2026-05-27
CVE-2026-45803 gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection CWE-150 3.5 Low 2026-05-15
CVE-2026-29066 Arbitrary File Read via Disabled Vite Filesystem Restriction in TinaCMS CLI CWE-552 6.2 Medium 2026-03-12
CVE-2026-28793 Path Traversal Leading to Arbitrary File Read, Write and Delete in TinaCMS CWE-22 8.4 High 2026-03-12
CVE-2026-28792 Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS CWE-22 9.7 Critical 2026-03-12
CVE-2026-0775 npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability CWE-732 7.8 - 2026-01-23
CVE-2025-25204 `gh attestation verify` returns incorrect exit code during verification if no attestations are present CWE-390 6.3 Medium 2025-02-14
CVE-2024-54132 GitHub CLI allows downloading malicious GitHub Actions workflow artifact to result in path traversal vulnerability CWE-22 6.5 - 2024-12-04
CVE-2024-53858 Recursive repository cloning can leak authentication tokens to non-GitHub submodule hosts in the gh cli CWE-200 6.5 Medium 2024-11-27
CVE-2024-52308 Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer CWE-77 8.0 High 2024-11-14
CVE-2021-41092 Docker CLI leaks private registry credentials to registry-1.docker.io CWE-200 5.4 Medium 2021-10-04
CVE-2020-15095 Sensitive information exposure through logs in npm cli CWE-532 4.4 Medium 2020-07-07
CVE-2019-16777 Arbitrary File Overwrite in npm CLI CWE-22 7.7 High 2019-12-13
CVE-2019-16776 Unauthorized File Access in npm CLI before before version 6.13.3 CWE-22 7.7 High 2019-12-13
CVE-2019-16775 Unauthorized File Access in npm CLI before before version 6.13.3 CWE-61 7.7 High 2019-12-13

All 26 known CVE vulnerabilities affecting cli with full Chinese analysis, references, and POCs where available.