PT-2026-81860 · Github · Github Cli
CVSS v4.0
2.1
Low
| Vector | AV:A/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
GitHub CLI (gh) versions 2.28.0 through 2.97.0
Description
The local listener created by the
gh codespace ports forward command binds to all available network interfaces by default. This allows services within a Codespace to be accessible via the user's non-loopback local IP addresses to other hosts capable of routing to the user's machine, regardless of whether the source Codespaces port is set to private. Exploitation requires a network-adjacent attacker to access the victim's machine while port forwarding is active.Recommendations
Update to version 2.98.0.
Exploit
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Github Cli