PT-2026-57006 · Github · Github Cli
CVE-2026-59831
·
Published
2026-07-09
·
Updated
2026-07-10
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GitHub CLI (gh) versions 2.10.0 through 2.95.0
Description
Connecting to a malicious Codespace using the
gh codespace jupyter command can lead to command execution. This occurs because the tool opens a JupyterLab URL provided by a process within the Codespace without verifying that it is a loopback HTTP or HTTPS address. Consequently, a specially crafted vscode:// or vscode-insiders:// URL can be passed to VS Code.Recommendations
Update to version 2.96.0.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github Cli