目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

cli 厂商漏洞列表 / CVE 中文分析 13

cli 厂商相关 13 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

CLI 是命令行界面的统称,广泛用于系统管理和开发工具。历史上常见漏洞包括命令注入、路径遍历和权限绕过,攻击者可通过恶意输入执行未授权操作。部分实现存在缓冲区溢出风险,可能导致远程代码执行。安全社区持续关注输入验证和权限分离问题,建议开发者采用参数化输入和最小权限原则。

上位製品 cli: cli go-gh
CVE IDタイトルCVSS深刻度公開日
CVE-2026-64655 GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching — cliCWE-185 2.1 Low2026-08-06
CVE-2026-64654 GitHub CLI: Terminal escape sequence injection in multiple `gh` commands — cliCWE-150 5.3 Medium2026-08-06
CVE-2026-64653 GitHub CLI: Unescaped variable components in request URLs could allow path traversal — cliCWE-22 5.1 Medium2026-08-06
CVE-2026-64652 GitHub CLI: Partial token disclosure in `gh auth status` output — cliCWE-201 3.3 Low2026-08-06
CVE-2026-59831 GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace — cliCWE-829 4.4 Medium2026-07-09
CVE-2026-48501 GitHub CLI tokens leak via `gh attestation` commands — cliCWE-863 7.4 High2026-05-29
CVE-2026-45803 gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection — cliCWE-150 3.5 Low2026-05-15
CVE-2025-48938 Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server — go-ghCWE-501 9.8AICriticalAI2025-05-30
CVE-2025-25204 `gh attestation verify` returns incorrect exit code during verification if no attestations are present — cliCWE-390 6.3 Medium2025-02-14
CVE-2024-54132 GitHub CLI allows downloading malicious GitHub Actions workflow artifact to result in path traversal vulnerability — cliCWE-22 6.5 -2024-12-04
CVE-2024-53858 Recursive repository cloning can leak authentication tokens to non-GitHub submodule hosts in the gh cli — cliCWE-200 6.5 Medium2024-11-27
CVE-2024-53859 go-gh `auth.TokenForHost` violates GitHub host security boundary within a codespace — go-ghCWE-200 6.5 Medium2024-11-27
CVE-2024-52308 Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer — cliCWE-77 8.0 High2024-11-14

本页汇总了 cli 厂商截至目前公开的全部 13 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。