Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-45803

Опубликовано: 15 мая 2026
Источник: redhat
CVSS3: 3.5
EPSS Низкий

Описание

gh is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified in GitHub CLI that could allow terminal escape sequence injection when users view GitHub Actions workflow logs using gh run view --log or gh run view --log-failed. The vulnerability stems from the way GitHub CLI handles raw Actions log output. The gh run view --log and gh run view --log-failed commands stream workflow log lines to stdout or the configured pager without sanitizing terminal control sequences. An attacker who can influence GitHub Actions log content, for example via a PR triggered workflow, can embed escape sequences that are replayed in the user's terminal when they inspect the run. Depending on the victim's terminal emulator, injected sequences could change the window title, manipulate on screen content, or in some terminal emulators (such as screen) potentially execute arbitrary commands. This vulnerability is fixed in 2.92.0.

A flaw was found in GitHub CLI. A remote attacker who can influence GitHub Actions workflow log output could inject terminal escape sequences into workflow logs. When a user views these logs using gh run view --log or gh run view --log-failed, the injected sequences may be replayed by the user's terminal. Depending on the terminal emulator in use, this could result in manipulation of displayed content, changes to the terminal window title, or other unintended terminal behavior.

Отчет

Red Hat Product Security rates this issue as having a Low security impact. This issue results from insufficient sanitization of terminal control sequences in GitHub Actions workflow logs displayed by GitHub CLI. An attacker with the ability to influence workflow log output may inject terminal escape sequences that are replayed when a user views logs using the affected commands. Exploitation requires user interaction and primarily affects the integrity of information presented within the terminal session. The impact is limited to terminal display manipulation and does not directly result in disclosure of sensitive information or denial of service.

This vulnerability affects Github CLI versions greater than v1.6.0. Components included with Red Hat Openshift GitOps and Red Hat OpenStack Platform 18.0 are not affected due to the absence of vulnerable Github CLI code as they use the Github CLI v1.2.1 in their containers or operators which are lower than than the affected one.

Меры по смягчению последствий

As a workaround, log output can be sanitized before display, for example: gh run view --log | cat -v Users should exercise caution when viewing logs generated from untrusted workflow runs.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-rhel8Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-rhel9Not affected
Red Hat OpenStack Platform 18.0rhoso-operators/openstack-operator-bundleNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-150
https://bugzilla.redhat.com/show_bug.cgi?id=2477927github.com/cli/cli: GitHub CLI: Arbitrary command execution via terminal escape sequence injection in workflow logs

EPSS

Процентиль: 11%
0.00206
Низкий

3.5 Low

CVSS3

Связанные уязвимости

CVSS3: 3.5
ubuntu
3 месяца назад

`gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified in GitHub CLI that could allow terminal escape sequence injection when users view GitHub Actions workflow logs using gh run view --log or gh run view --log-failed. The vulnerability stems from the way GitHub CLI handles raw Actions log output. The gh run view --log and gh run view --log-failed commands stream workflow log lines to stdout or the configured pager without sanitizing terminal control sequences. An attacker who can influence GitHub Actions log content, for example via a PR triggered workflow, can embed escape sequences that are replayed in the user's terminal when they inspect the run. Depending on the victim's terminal emulator, injected sequences could change the window title, manipulate on screen content, or in some terminal emulators (such as screen) potentially execute arbitrary commands. This vulnerability is fixed in 2.92.0.

CVSS3: 3.5
nvd
3 месяца назад

`gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified in GitHub CLI that could allow terminal escape sequence injection when users view GitHub Actions workflow logs using gh run view --log or gh run view --log-failed. The vulnerability stems from the way GitHub CLI handles raw Actions log output. The gh run view --log and gh run view --log-failed commands stream workflow log lines to stdout or the configured pager without sanitizing terminal control sequences. An attacker who can influence GitHub Actions log content, for example via a PR triggered workflow, can embed escape sequences that are replayed in the user's terminal when they inspect the run. Depending on the victim's terminal emulator, injected sequences could change the window title, manipulate on screen content, or in some terminal emulators (such as screen) potentially execute arbitrary commands. This vulnerability is fixed in 2.92.0.

CVSS3: 3.5
msrc
3 месяца назад

gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection

CVSS3: 3.5
debian
3 месяца назад

`gh` is GitHub\u2019s official command line tool. From 1.6.0 to before ...

CVSS3: 3.5
github
3 месяца назад

GitHub CLI: GitHub Actions log output in `gh run view` allows terminal escape sequence injection

EPSS

Процентиль: 11%
0.00206
Низкий

3.5 Low

CVSS3