PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-64655 GitHub CVE debrief

GitHub CLI (gh) versions prior to 2.97.0 are vulnerable to a supply chain verification bypass due to improper handling of regex metacharacters in the --signer-repo and --signer-workflow flag values. An attacker can register a lookalike repository and produce valid attestations to bypass Sigstore attestation verification. This issue affects organizations using GitHub CLI (gh) in CI/CD pipelines or policy gates that pin trust to a specific signing workflow. The vulnerability has a CVSS score of 2.1 and is considered low severity. To mitigate this vulnerability, organizations should update to version 2.97.0 or later. The CVE record and official advisory provide additional context and guidance for defenders.

Vendor
GitHub
Product
GitHub CLI
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-08
Advisory published
2026-08-06
Advisory updated
2026-08-08

Who should care

Organizations using GitHub CLI (gh) versions prior to 2.97.0, especially those relying on Sigstore attestation verification in CI/CD pipelines or policy gates, should be aware of this vulnerability. Operators, platform administrators, vulnerability management teams, and security teams may be impacted by this issue and should review their deployments for potential exposure. Affected product context includes GitHub CLI (gh) usage in automated workflows and manual deployments. Defensive impact involves potential supply chain verification bypasses, which could undermine trust in CI/CD pipelines or policy gates. Source-grounded technical framing emphasizes the importance of updating to version 2.97.0 or later to prevent exploitation. Security teams should prioritize verification of affected deployments and review compensating controls for exposed systems while remediation is scheduled and verified. Monitoring and detection capabilities should be reviewed to ensure they can identify potential exploitation attempts. Asset inventory and change management processes should also be assessed to ensure they can track and manage affected systems effectively. Rollback and change window planning should be considered to minimize potential downtime during remediation. Source tracking and verification of attestations should be implemented to prevent unauthorized access to sensitive data or systems. By taking these steps, organizations can reduce their risk exposure and prevent potential supply chain verification bypasses. To further improve defensive posture, organizations should consider implementing additional security controls, such as multi-factor authentication and access controls, to prevent unauthorized access to sensitive data or systems. Regular security audits and penetration testing can also help identify potential vulnerabilities and weaknesses in the supply chain. By prioritizing security and taking proactive steps to address this vulnerability, organizations can help protect their supply chain and prevent potential security breaches. The CVE record and official advisory provide additional context and guidance for defenders. Evidence limits suggest that affected depl

Technical summary

GitHub CLI (gh) versions prior to 2.97.0 are vulnerable to a supply chain verification bypass due to improper handling of regex metacharacters in the --signer-repo and --signer-workflow flag values. An attacker can register a lookalike repository and produce valid attestations to bypass Sigstore attestation verification. This issue affects organizations using GitHub CLI (gh) in CI/CD pipelines or policy gates that pin trust to a specific signing workflow.

Defensive priority

Organizations using GitHub CLI (gh) versions prior to 2.97.0 should update to the latest version to prevent potential supply chain verification bypasses in CI/CD pipelines or policy gates.

Recommended defensive actions

  • Update GitHub CLI (gh) to version 2.97.0 or later
  • Review and update CI/CD pipelines or policy gates that rely on Sigstore attestation verification
  • Monitor for potential lookalike repository creations and valid attestations
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record indicates that GitHub CLI (gh) versions prior to 2.97.0 are vulnerable to a supply chain verification bypass due to improper handling of regex metacharacters in the --signer-repo and --signer-workflow flag values. The issue is fixed in version 2.97.0. To verify, defenders should review the official advisory and assess their exposure. Evidence limits suggest that affected deployments may exist, but further verification is needed.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:18:13.527Z and has not been modified since then.