VDB

CVE-2026-64654

CVE-2026-64654 PUBLISHED CVSS 5.3 MEDIUM

Reported by GitHub_M · Published August 6, 2026

GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed externally controlled gist, API, pull request, release, codespace, skill, or agent-task content without neutralizing terminal escape sequences. An attacker who can influence that content can embed escape sequences that are interpreted by the terminal of a user who runs an affected command, with impact ranging from cosmetic manipulation of the title or on-screen content to, on some terminal emulators, command execution. This extends the same class of issue as CVE-2026-45803—which addressed only gh run view --log—to the other affected command paths. This issue is fixed in version 2.97.0.

Risk Scores

CVSS 4.0
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Affected Products

VendorProductVersions
clicli< 2.97.0
clicli< 2.97.0, < 2.97.0

Timeline

  • Aug 6, 2026 CVE Published
  • Aug 7, 2026 EPSS Score
  • Aug 7, 2026 Coalition ESS Score
  • Aug 7, 2026 CVE Updated
  • Aug 9, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 28, 2026 EPSS Score
  • Aug 29, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 5, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›