Argument injection in GitHub CLI - #VU152997
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to write attacker-controlled skill files to an arbitrary directory writable by the user.
The vulnerability exists due to improper neutralization of argument delimiters in the `gh skill search` child installer invocation when handling a flag-like repository-relative path from a search result. A remote attacker can provide a malicious search result whose path is interpreted as an installer option to write attacker-controlled skill files to an arbitrary directory writable by the user.
Exploitation requires the user to select the malicious search result and continue the interactive installation flow. Non-interactive and JSON search modes are not affected.