Permissive Regular Expression in GitHub CLI - #VU152995

 

Permissive Regular Expression in GitHub CLI - #VU152995

Published: September 30, 2026


Vulnerability identifier: #VU152995
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-625
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause integrity impacts in downstream automation.

The vulnerability exists due to a permissive regular expression in the `gh attestation verify` signer-workflow SAN matcher when verifying an attestation with the `--signer-workflow` option. A remote user can add and run a workflow whose path extends the pinned workflow value to cause integrity impacts in downstream automation.

Exploitation requires automation to treat successful attestation verification as authorization.


Affected software

GitHub CLI

Remediation

Install security update from vendor's website.

GitHub CLI - update to 2.102.0

External References

Related Security Bulletins