
@sampullara @Swizec Being able to control this in the past would have been full RCE. https://hack.do/posts/cve-2025-48938/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user's machine by replacing HTTP URLs provided by GitHub with local file paths for browsing. In `2.12.1`, `Browser.Browse()` has been enhanced to allow and disallow a variety of scenarios to avoid opening or executing files on the filesystem without unduly impacting HTTP URLs. No known workarounds are available other than upgrading.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.

@sampullara @Swizec Being able to control this in the past would have been full RCE. https://hack.do/posts/cve-2025-48938/
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | cli | go-gh | - | go | - |