Link following in GitHub CLI - #VU152996
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to write remote content to unintended local files.
The vulnerability exists due to improper link resolution before file access in GitHub CLI download and file-output commands when processing remote content with a destination containing symbolic links. A remote user can provide remote content to write it outside the intended destination.
User interaction is required to invoke an affected command in a vulnerable workspace on a compatible remote resource.