Network Exposure in GitHub's Command Line Tool Version 2.28.0 to 2.97.0
CVE-2026-72924

2.1LOW

Key Information:

Vendor

Cli

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-72924?

The GitHub Command Line Interface (CLI), versions 2.28.0 through 2.97.0, is susceptible to a network exposure vulnerability that permits local services to become reachable through non-loopback IP addresses on the user's machine while port forwarding is enabled. This occurs because the local listener created by the GitHub CLI binds to all available network interfaces by default, allowing a network-adjacent attacker to access these services. This critical exposure does not alter the visibility of the Codespaces port on GitHub's side but allows unintended access to the user's local environment if exploited. The issue has been addressed in version 2.98.0.

Affected Version(s)

cli >= 2.28.0, < 2.98.0

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.