Improper Neutralization of Escape, Meta, or Control Sequences in GitHub CLI - CVE-2026-64654
Published: July 31, 2026
GitHub CLI
Detailed vulnerability description
The vulnerability allows a remote user to inject terminal escape sequences and potentially execute commands.
The vulnerability exists due to improper neutralization of terminal escape sequences in multiple gh commands when printing externally controlled content to the terminal or configured pager. A remote user can provide crafted content to inject terminal escape sequences and potentially execute commands.
User interaction is required to run an affected command and view the attacker-influenced content. The impact depends on the terminal emulator and may range from screen or title manipulation to command execution on some emulators.