top of page
perceptive_background_267k.jpg

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository …

Published:

28 mei 2026 om 22:00:00

Alert date:

29 mei 2026 om 17:11:07

Source:

nvd.nist.gov

Click to open the original link from this advisory

Security Tools, Supply Chain & Dependencies

GitHub CLI prior to version 2.93.0 incorrectly includes authorization headers in API requests to TUF repository mirrors. The vulnerability affects gh attestation, gh release verify, and gh release verify-asset commands. The CLI uses a shared HTTP client with faulty host detection logic that collapses *.github.com subdomains to github.com, causing tokens to be sent to unauthorized hosts. This results in GitHub tokens being leaked to external services including tuf-repo.github.com, tuf-repo-cdn.sigstore.dev, and Azure Blob Storage. The issue stems from inadequate host normalization logic in the authentication layer. The vulnerability is fixed in GitHub CLI version 2.93.0.

Technical details

Mitigation steps:

Affected products:

GitHub CLI

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page