SB2026093096 - Multiple vulnerabilities in GitHub CLI



SB2026093096 - Multiple vulnerabilities in GitHub CLI

Published: September 30, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026093096
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 vulnerabilities.


1) Improper Handling of Case Sensitivity (CVE-ID: N/A)

CWE-ID: CWE-178 - Improper Handling of Case Sensitivity

CVSSv4: 2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause an authorization policy to accept an artifact built from an unintended branch.

The vulnerability exists due to improper handling of case sensitivity in the `gh attestation verify` source-ref policy check when comparing a supplied `--source-ref` value with the source ref in a signing certificate. A remote user can create a branch whose name differs only in case from a protected branch and build an artifact from it to cause an authorization policy to accept an artifact built from an unintended branch.

The signature and certificate remain valid and accurately record the originating ref; the defect occurs in the policy check after signature verification succeeds.


2) Permissive Regular Expression (CVE-ID: N/A)

CWE-ID: CWE-625 - Permissive Regular Expression

CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause integrity impacts in downstream automation.

The vulnerability exists due to a permissive regular expression in the `gh attestation verify` signer-workflow SAN matcher when verifying an attestation with the `--signer-workflow` option. A remote user can add and run a workflow whose path extends the pinned workflow value to cause integrity impacts in downstream automation.

Exploitation requires automation to treat successful attestation verification as authorization.


3) Link following (CVE-ID: N/A)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to write remote content to unintended local files.

The vulnerability exists due to improper link resolution before file access in GitHub CLI download and file-output commands when processing remote content with a destination containing symbolic links. A remote user can provide remote content to write it outside the intended destination.

User interaction is required to invoke an affected command in a vulnerable workspace on a compatible remote resource.


4) Argument injection (CVE-ID: N/A)

CWE-ID: CWE-88 - Argument Injection or Modification

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to write attacker-controlled skill files to an arbitrary directory writable by the user.

The vulnerability exists due to improper neutralization of argument delimiters in the `gh skill search` child installer invocation when handling a flag-like repository-relative path from a search result. A remote attacker can provide a malicious search result whose path is interpreted as an installer option to write attacker-controlled skill files to an arbitrary directory writable by the user.

Exploitation requires the user to select the malicious search result and continue the interactive installation flow. Non-interactive and JSON search modes are not affected.


Remediation

Install update from vendor's website.