Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16493 | Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server |
Github GHSA |
GHSA-g9f5-x53j-h563 | Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server |
Wed, 15 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cli
Cli go-gh |
|
| CPEs | cpe:2.3:a:cli:go-gh:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cli
Cli go-gh |
|
| Metrics |
cvssV3_1
|
Fri, 30 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 May 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user's machine by replacing HTTP URLs provided by GitHub with local file paths for browsing. In `2.12.1`, `Browser.Browse()` has been enhanced to allow and disallow a variety of scenarios to avoid opening or executing files on the filesystem without unduly impacting HTTP URLs. No known workarounds are available other than upgrading. | |
| Title | Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server | |
| Weaknesses | CWE-501 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-30T20:38:51.984Z
Reserved: 2025-05-28T18:49:07.579Z
Link: CVE-2025-48938
Updated: 2025-05-30T20:38:47.794Z
Status : Analyzed
Published: 2025-05-30T19:15:29.980
Modified: 2025-10-15T18:10:11.280
Link: CVE-2025-48938
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA