Command Line Tool Vulnerability in GitHub CLI Prior to Version 2.97.0
CVE-2026-64654

5.3MEDIUM

Key Information:

Vendor

Cli

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-64654?

The GitHub CLI, an official command line tool from GitHub, contains a vulnerability that allows for the injection of terminal escape sequences in commands prior to version 2.97.0. This flaw can lead to various impacts, such as altering the visual presentation of content in the terminal or, in certain terminal emulators, facilitating the execution of arbitrary commands. Attackers with the capability to control the content provided to specific GitHub CLI commands can exploit this issue, making it essential for users to update to the latest version to mitigate potential security risks. This vulnerability shares a similarity with a previous issue documented in CVE-2026-45803, which was limited to a single command flag.

Affected Version(s)

cli < 2.97.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.