Bug 2512206 (CVE-2026-64654) - CVE-2026-64654 github.com/cli/cli: GitHub CLI: Terminal escape sequence injection allows command execution
Summary: CVE-2026-64654 github.com/cli/cli: GitHub CLI: Terminal escape sequence injec...
Keywords:
Status: NEW
Alias: CVE-2026-64654
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-06 22:22 UTC by OSIDB Bzimport
Modified: 2026-08-10 09:32 UTC (History)
10 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-06 22:22:05 UTC
GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed externally controlled gist, API, pull request, release, codespace, skill, or agent-task content without neutralizing terminal escape sequences. An attacker who can influence that content can embed escape sequences that are interpreted by the terminal of a user who runs an affected command, with impact ranging from cosmetic manipulation of the title or on-screen content to, on some terminal emulators, command execution. This extends the same class of issue as CVE-2026-45803—which addressed only gh run view --log—to the other affected command paths. This issue is fixed in version 2.97.0.


Note You need to log in before you can comment on or make changes to this bug.