Improper Handling of Case Sensitivity in GitHub CLI - #VU152994

 

Improper Handling of Case Sensitivity in GitHub CLI - #VU152994

Published: September 30, 2026


Vulnerability identifier: #VU152994
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-178
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause an authorization policy to accept an artifact built from an unintended branch.

The vulnerability exists due to improper handling of case sensitivity in the `gh attestation verify` source-ref policy check when comparing a supplied `--source-ref` value with the source ref in a signing certificate. A remote user can create a branch whose name differs only in case from a protected branch and build an artifact from it to cause an authorization policy to accept an artifact built from an unintended branch.

The signature and certificate remain valid and accurately record the originating ref; the defect occurs in the policy check after signature verification succeeds.


Affected software

GitHub CLI

Remediation

Install security update from vendor's website.

GitHub CLI - update to 2.102.0

External References

Related Security Bulletins