CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-59831

mediumCVSS 4.4covered by 2 sourcesfirst seen 2026-07-09
GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution because the command opens a JupyterLab URL supplied by a process inside the Codespace without validating that it is a loopback HTTP or HTTPS address, allowing a crafted vscode:// or vscode-insiders:// URL to be handed to VS Code. This issue is fixed in version 2.96.0.

CSIRTS triage

What
A vulnerability in GitHub CLI could allow remote code execution when connecting to a malicious Codespace.
Who is affected
Users of GitHub CLI are affected by this vulnerability.
Urgency
Remediation is medium urgency due to the medium severity of the vulnerability.
Action
Update GitHub CLI to the latest version to mitigate the risk.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-59831

Get an email if CVE-2026-59831 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-59831

CVE.org record

Embed the live status

CVE-2026-59831 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-59831 status](https://www.csirts.com/badge/CVE-2026-59831)](https://www.csirts.com/cve/CVE-2026-59831)