cli has 4 CVEs on record between 2024 and 2026. 1 was published in the last 90 days. The median CVSS is 6.5 (medium), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
Products
- cli 1
- github.com/cli/cli/v2 1
- github.com/cli/go-gh/v2 1
- go-gh 1
Worst active — by depth score
CVE-2025-48938Critical· 9.8go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier54CVE-2024-53859Medium· 6.5`auth.TokenForHost` violates GitHub host security boundary when sourcing authentication token within a codespace36CVE-2026-64654Medium· 5.3GitHub CLI (gh) is GitHub's official command line tool29CVE-2024-54132MediumDownloading malicious GitHub Actions workflow artifact results in path traversal vulnerability28
cli vulnerabilities
CVEs affecting cli, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-64654Medium· 5.3GitHub CLI (gh) is GitHub's official command line tool
GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed externally controlled gist, API, pull request, release, codespace, skill, or agent-task content without neutralizing te…
CVE-2025-48938Critical· 9.8go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier
go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing …
CVE-2024-54132MediumDownloading malicious GitHub Actions workflow artifact results in path traversal vulnerability
Downloading malicious GitHub Actions workflow artifact results in path traversal vulnerability
CVE-2024-53859Medium· 6.5`auth.TokenForHost` violates GitHub host security boundary when sourcing authentication token within a codespace
`auth.TokenForHost` violates GitHub host security boundary when sourcing authentication token within a codespace