CVE-2026-64653

medium

Description

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable path components without percent encoding, allowing URL path metacharacters in attacker-controlled repository or resource values to make gh address a different API endpoint or resource than the user intended. This issue is fixed in version 2.97.0.

References

https://github.com/cli/cli/security/advisories/GHSA-4fjg-2h4q-fwg3

https://github.com/cli/cli/releases/tag/v2.97.0

https://github.com/cli/cli/commit/0c2eea6338a2323cfff000160b9b5a56a38d2a06

Details

Source: Mitre, NVD

Published: 2026-08-06

Updated: 2026-08-07

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 8.2

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

Severity: High

CVSS v4

Base Score: 5.1

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Severity: Medium

EPSS

EPSS: 0.00504