Network Exposure in GitHub's Command Line Tool Version 2.28.0 to 2.97.0
CVE-2026-72924
2.1LOW
What is CVE-2026-72924?
The GitHub Command Line Interface (CLI), versions 2.28.0 through 2.97.0, is susceptible to a network exposure vulnerability that permits local services to become reachable through non-loopback IP addresses on the user's machine while port forwarding is enabled. This occurs because the local listener created by the GitHub CLI binds to all available network interfaces by default, allowing a network-adjacent attacker to access these services. This critical exposure does not alter the visibility of the Codespaces port on GitHub's side but allows unintended access to the user's local environment if exploited. The issue has been addressed in version 2.98.0.
Affected Version(s)
cli >= 2.28.0, < 2.98.0
