Command Line Tool Vulnerability in GitHub CLI Prior to Version 2.97.0
CVE-2026-64654
5.3MEDIUM
What is CVE-2026-64654?
The GitHub CLI, an official command line tool from GitHub, contains a vulnerability that allows for the injection of terminal escape sequences in commands prior to version 2.97.0. This flaw can lead to various impacts, such as altering the visual presentation of content in the terminal or, in certain terminal emulators, facilitating the execution of arbitrary commands. Attackers with the capability to control the content provided to specific GitHub CLI commands can exploit this issue, making it essential for users to update to the latest version to mitigate potential security risks. This vulnerability shares a similarity with a previous issue documented in CVE-2026-45803, which was limited to a single command flag.
Affected Version(s)
cli < 2.97.0
