PatchSiren

cli CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW cli CVE published 2026-08-06

CVE-2026-64652

CVE-2026-64652 debrief: GitHub CLI token exposure through gh auth status command. The vulnerability allowed part of certain fine-grained personal access tokens and GitHub App tokens to appear in terminal or CI output when running the gh auth status command. This issue affected fine-grained personal access tokens (github_pat_*) and GitHub App installation and user access tokens (ghs_*, ghu_*). The vulnerab [truncated]

MEDIUM cli CVE published 2026-07-09

CVE-2026-59831

CVE-2026-59831 is a medium-severity vulnerability in GitHub CLI (gh) versions 2.10.0 through 2.95.0. The issue allows command execution when connecting to a malicious Codespace with 'gh codespace jupyter' due to improper validation of JupyterLab URLs supplied by a process inside the Codespace. This could potentially allow a crafted vscode:// or vscode-insiders:// URL to be handed to VS Code. The vulnerabi [truncated]

HIGH cli CVE published 2026-05-29

CVE-2026-48501

GitHub CLI (gh) versions prior to 2.93.0 incorrectly transmit authorization tokens to external hosts during attestation and release verification operations. The vulnerability stems from flawed host normalization logic in the CLI's shared HTTP client authentication layer, which collapses any *.github.com subdomain to github.com. This causes requests to tuf-repo.github.com—a GitHub Pages site hosting TUF me [truncated]

LOW cli CVE published 2026-05-15

CVE-2026-45803

CVE-2026-45803 is a low-severity GitHub CLI issue in which workflow log content can be rendered to a terminal without sanitizing control sequences. If an attacker can influence Actions log output, viewing a run with gh run view --log or gh run view --log-failed can cause terminal escape sequence injection in the user’s session. The issue is fixed in GitHub CLI 2.92.0.