Vulnerabilidades en cli
13 resultadosAnálisis Vexday
A CLI apresenta 9 vulnerabilidades catalogadas, com 3 divulgadas nos últimos 90 dias, indicando atividade recente de descobertas. Nenhuma está sob exploração ativa conhecida (KEV) e não há críticas CVSS, reduzindo a urgência imediata. A fragilidade predominante é exposição de informações (CWE-200), sugerindo risco de vazamento de dados em vez de comprometimento direto do sistema.
CVE-2024-52308HIGHConnecting to a malicious Codespaces via GH CLI could allow command execution on the user's computerEPSS 0.9%CVE-2026-64654MEDIUMGitHub CLI: Terminal escape sequence injection in multiple `gh` commandsEPSS 0.7%CVE-2024-54132MEDIUMGitHub CLI allows downloading malicious GitHub Actions workflow artifact to result in path traversal vulnerabilityEPSS 0.6%CVE-2024-53859MEDIUMgo-gh `auth.TokenForHost` violates GitHub host security boundary within a codespaceEPSS 0.5%CVE-2026-64653MEDIUMGitHub CLI: Unescaped variable components in request URLs could allow path traversalEPSS 0.5%CVE-2025-48938LOWPrevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise ServerEPSS 0.5%CVE-2025-25204MEDIUM`gh attestation verify` returns incorrect exit code during verification if no attestations are presentEPSS 0.4%CVE-2026-64655LOWGitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN MatchingEPSS 0.3%CVE-2026-48501HIGHGitHub CLI tokens leak via `gh attestation` commandsEPSS 0.3%CVE-2024-53858MEDIUMRecursive repository cloning can leak authentication tokens to non-GitHub submodule hosts in the gh cliEPSS 0.3%CVE-2026-59831MEDIUMGitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious CodespaceEPSS 0.3%CVE-2026-45803LOWgh: GitHub Actions log output in `gh run view` allows terminal escape sequence injectionEPSS 0.2%CVE-2026-64652LOWGitHub CLI: Partial token disclosure in `gh auth status` outputEPSS 0.1%