CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64653

unknowncovered by 2 sourcesfirst seen 2026-08-06
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable path components without percent encoding, allowing URL path metacharacters in attacker-controlled repository or resource values to make gh address a different API endpoint or resource than the user intended. This issue is fixed in version 2.97.0.

CSIRTS triage

What
Unescaped variable components in request URLs allow path traversal attacks.
Who is affected
Users of GitHub CLI versions containing this vulnerability when issuing API requests.
Urgency
Severity unknown; path traversal could lead to unauthorized resource access depending on context and endpoint.
Action
Update GitHub CLI to a patched version when released.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-64653

Get an email if CVE-2026-64653 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-64653

CVE.org record

Embed the live status

CVE-2026-64653 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64653 status](https://www.csirts.com/badge/CVE-2026-64653)](https://www.csirts.com/cve/CVE-2026-64653)