CVE-2026-48501 Details
Description
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh release verify-asset commands. The CLI uses a shared HTTP client with an authentication layer that automatically attaches tokens to outgoing requests. This layer lacks accurate host detection and can incorrectly attribute the target host, providing it with a token it should never receive. Specifically, the host normalization logic collapses any *.github.com subdomain to github.com, so a request to tuf-repo.github.com (a GitHub Pages site, not a GitHub API endpoint) is treated as a request to github.com and receives the user's github.com token. For hosts that don't match github.com or a known GHES instance at all, the resolver falls back to GH_ENTERPRISE_TOKEN if set. The gh attestation, gh release verify and gh release verify-asset commands fetch data from several external hosts as part of their normal operation (TUF metadata from tuf-repo.github.com and tuf-repo-cdn.sigstore.dev, artifact bundles from Azure Blob Storage). Because these requests go through the same authenticated HTTP client, the token is sent to all of them. This vulnerability is fixed in 2.93.0.
A vulnerability exists in GitHub CLI (gh) versions prior to 2.93.0, where the tool incorrectly includes authorization headers in API requests to TUF repository mirrors. This issue arises in commands such as 'gh attestation', 'gh release verify', and 'gh release verify-asset'. The vulnerability is rooted in a shared HTTP client that automatically attaches authentication tokens to outgoing requests. However, the client lacks proper host detection, leading to incorrect token attribution. Specifically, requests to 'tuf-repo.github.com' are misidentified as requests to 'github.com', resulting in the unintentional inclusion of the user's GitHub token. Similarly, for hosts that do not correspond to GitHub.com or a known GitHub Enterprise Server instance, the client may revert to using the 'GH_ENTERPRISE_TOKEN' if it is set. This flaw allows for the unauthorized transmission of authentication tokens to external hosts during normal CLI operations.
Users are advised to revoke any authentication tokens used with GitHub CLI, upgrade to version 2.93.0, and review their personal security log and any relevant audit logs for actions associated with their account or enterprise.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cli/cli/security/advisories/GHSA-8xvp-7hj6-mcj9 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| github cli | < 2.93.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | Initial Analysis | [email protected] |
| May 29, 2026 | New CVE Received | [email protected] |