Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

cli — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting cli. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CLI serves as a fundamental interface for interacting with operating systems and applications through text commands, enabling efficient system administration and automation. Historically, common vulnerabilities include remote code execution through command injection, cross-site scripting in web-based CLIs, and privilege escalation via misconfigured permissions or insecure default settings. Notable security characteristics often involve reliance on secure input validation and proper privilege management. While no major public incidents are widely documented, the presence of six CVEs highlights ongoing security concerns, particularly around command handling and access control in various implementations.

Found 12 results / 14 Clear Filters
Top products by cli: cli go-gh
CVE ID Title CVSS Severity Published
CVE-2026-72924 GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default — cli CWE-1327 2.1 Low 2026-08-25
CVE-2026-64655 GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching — cli CWE-185 2.1 Low 2026-08-06
CVE-2026-64654 GitHub CLI: Terminal escape sequence injection in multiple `gh` commands — cli CWE-150 5.3 Medium 2026-08-06
CVE-2026-64653 GitHub CLI: Unescaped variable components in request URLs could allow path traversal — cli CWE-22 5.1 Medium 2026-08-06
CVE-2026-64652 GitHub CLI: Partial token disclosure in `gh auth status` output — cli CWE-201 3.3 Low 2026-08-06
CVE-2026-59831 GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace — cli CWE-829 4.4 Medium 2026-07-09
CVE-2026-48501 GitHub CLI tokens leak via `gh attestation` commands — cli CWE-863 7.4 High 2026-05-29
CVE-2026-45803 gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection — cli CWE-150 3.5 Low 2026-05-15
CVE-2025-25204 `gh attestation verify` returns incorrect exit code during verification if no attestations are present — cli CWE-390 6.3 Medium 2025-02-14
CVE-2024-54132 GitHub CLI allows downloading malicious GitHub Actions workflow artifact to result in path traversal vulnerability — cli CWE-22 6.5 - 2024-12-04
CVE-2024-53858 Recursive repository cloning can leak authentication tokens to non-GitHub submodule hosts in the gh cli — cli CWE-200 6.5 Medium 2024-11-27
CVE-2024-52308 Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer — cli CWE-77 8.0 High 2024-11-14

This page lists every published CVE security advisory associated with cli. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.