-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from GitHub CLI commands (clone/fork/pr checkout) invoking Git with unrestricted credential.helper configurations. The key failure points are: 1) Command implementations that didn't limit credential helper activation to GitHub domains, 2) Credential management logic that leaked enterprise tokens to third-party hosts, and 3) Environment variable handling that inappropriately sourced tokens for non-GitHub operations. The patch in 2.63.0 explicitly restricts credential helper usage to GitHub-controlled domains, confirming these were the vulnerable areas.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/cli/cli/v2 | go | <= 2.62.0 | 2.63.0 |
Ongoing coverage of React2Shell