CVE-2025-48938(cli / go-gh)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user's machine by replacing HTTP URLs provided by GitHub with local file paths for browsing. In `2.12.1`, `Browser.Browse()` has been enhanced to allow and disallow a variety of scenarios to avoid opening or executing files on the filesystem without unduly impacting HTTP URLs. No known workarounds are available other than upgrading.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-501

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go-gh

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
go-gh

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-25: 109-25
Referenced assets1 URL
By indicator
Full discourse1 post
  • Matt Austin@mattaustin

    @sampullara @Swizec Being able to control this in the past would have been full RCE. https://hack.do/posts/cve-2025-48938/

    10010114
    1.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcligo-gh-go-

Explore more