Логотип exploitDog
bind:CVE-2025-48938
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-48938

Количество 4

Количество 4

ubuntu логотип

CVE-2025-48938

20 дней назад

go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user's machine by replacing HTTP URLs provided by GitHub with local file paths for browsing. In `2.12.1`, `Browser.Browse()` has been enhanced to allow and disallow a variety of scenarios to avoid opening or executing files on the filesystem without unduly impacting HTTP URLs. No known workarounds are available other than upgrading.

EPSS: Низкий
nvd логотип

CVE-2025-48938

20 дней назад

go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user's machine by replacing HTTP URLs provided by GitHub with local file paths for browsing. In `2.12.1`, `Browser.Browse()` has been enhanced to allow and disallow a variety of scenarios to avoid opening or executing files on the filesystem without unduly impacting HTTP URLs. No known workarounds are available other than upgrading.

EPSS: Низкий
debian логотип

CVE-2025-48938

20 дней назад

go-gh is a collection of Go modules to make authoring GitHub CLI exten ...

EPSS: Низкий
github логотип

GHSA-g9f5-x53j-h563

20 дней назад

Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-48938

go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user's machine by replacing HTTP URLs provided by GitHub with local file paths for browsing. In `2.12.1`, `Browser.Browse()` has been enhanced to allow and disallow a variety of scenarios to avoid opening or executing files on the filesystem without unduly impacting HTTP URLs. No known workarounds are available other than upgrading.

0%
Низкий
20 дней назад
nvd логотип
CVE-2025-48938

go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user's machine by replacing HTTP URLs provided by GitHub with local file paths for browsing. In `2.12.1`, `Browser.Browse()` has been enhanced to allow and disallow a variety of scenarios to avoid opening or executing files on the filesystem without unduly impacting HTTP URLs. No known workarounds are available other than upgrading.

0%
Низкий
20 дней назад
debian логотип
CVE-2025-48938

go-gh is a collection of Go modules to make authoring GitHub CLI exten ...

0%
Низкий
20 дней назад
github логотип
GHSA-g9f5-x53j-h563

Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server

0%
Низкий
20 дней назад

Уязвимостей на страницу