CVE-2024-53859Medium· 6.5▾ Sunlit`auth.TokenForHost` violates GitHub host security boundary when sourcing authentication token within a codespace
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
A security vulnerability has been identified in go-gh that could leak authentication tokens intended for GitHub hosts to non-GitHub hosts when within a codespace.
go-gh sources authentication tokens from different environment variables depending on the host involved:
GITHUB_TOKEN, GH_TOKEN for GitHub.com and ghe.comGITHUB_ENTERPRISE_TOKEN, GH_ENTERPRISE_TOKEN for GitHub Enterprise ServerPrior to 2.11.1, auth.TokenForHost could source a token from the GITHUB_TOKEN environment variable for a host other than GitHub.com or ghe.com when within a codespace.
In 2.11.1, auth.TokenForHost will only source a token from the GITHUB_TOKEN environment variable for GitHub.com or ghe.com hosts.
Successful exploitation could send authentication token to an unintended host.
go-gh to 2.11.1github.com/cli/go-gh/v2 < 2.11.1github.com/cli/go-ghUpgrade to a patched release:
github.com/cli/go-gh/v2 2.11.1Connected by shared product, vendor, weakness, or advisory.
CVE-2024-54132MediumDownloading malicious GitHub Actions workflow artifact results in path traversal vulnerability
CVE-2026-64654Medium· 5.3GitHub CLI (gh) is GitHub's official command line tool
CVE-2025-48938Critical· 9.8go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier