CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64654

unknowncovered by 2 sourcesfirst seen 2026-08-06
GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed externally controlled gist, API, pull request, release, codespace, skill, or agent-task content without neutralizing terminal escape sequences. An attacker who can influence that content can embed escape sequences that are interpreted by the terminal of a user who runs an affected command, with impact ranging from cosmetic manipulation of the title or on-screen content to, on some terminal emulators, command execution. This extends the same class of issue as CVE-2026-45803—which addressed only gh run view --log—to the other affected command paths. This issue is fixed in version 2.97.0.

CSIRTS triage

What
Terminal escape sequence injection in multiple gh commands allows arbitrary terminal control.
Who is affected
Users of affected GitHub CLI versions executing gh commands with untrusted input.
Urgency
Severity unknown but escape sequence injection can enable code execution or credential theft via terminal manipulation.
Action
Update GitHub CLI to patched version that sanitizes output or properly escapes terminal sequences.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-64654

Get an email if CVE-2026-64654 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-64654

CVE.org record

Embed the live status

CVE-2026-64654 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64654 status](https://www.csirts.com/badge/CVE-2026-64654)](https://www.csirts.com/cve/CVE-2026-64654)