


Perceptive Security
SOC/SIEM Consultancy

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository …
Published:
28 mei 2026 om 22:00:00
Alert date:
29 mei 2026 om 17:11:07
Source:
nvd.nist.gov
Security Tools, Supply Chain & Dependencies
GitHub CLI prior to version 2.93.0 incorrectly includes authorization headers in API requests to TUF repository mirrors. The vulnerability affects gh attestation, gh release verify, and gh release verify-asset commands. The CLI uses a shared HTTP client with faulty host detection logic that collapses *.github.com subdomains to github.com, causing tokens to be sent to unauthorized hosts. This results in GitHub tokens being leaked to external services including tuf-repo.github.com, tuf-repo-cdn.sigstore.dev, and Azure Blob Storage. The issue stems from inadequate host normalization logic in the authentication layer. The vulnerability is fixed in GitHub CLI version 2.93.0.
Technical details
Mitigation steps:
Affected products:
GitHub CLI
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-48501
https://github.com/cli/cli/security/advisories/GHSA-8xvp-7hj6-mcj9
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
