USN-7130-1: GitHub CLI vulnerability
26 November 2024
GitHub CLI could be made to run programs as your login if it connected to a malicious server.
Releases
Packages
- gh - GitHub CLI, GitHub’s official command line tool
Details
It was discovered that GitHub CLI incorrectly handled username
validation. An attacker could possibly use this issue to perform
remote code execution if the user connected to a malicious server.
(CVE-2024-52308)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.10
Ubuntu 24.04
-
gh
-
2.45.0-1ubuntu0.2+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.