CVE-2026-59831Disclosure

LOWCVSS 4.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution because the command opens a JupyterLab URL supplied by a process inside the Codespace without validating that it is a loopback HTTP or HTTPS address, allowing a crafted vscode:// or vscode-insiders:// URL to be handed to VS Code. This issue is fixed in version 2.96.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-829

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-07-10); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-07-10: 2Mentions · 2026-07-16: 2Patch / Workaround · 2026-07-16: 1Technical Details · 2026-07-10: 2Technical Details · 2026-07-16: 107-1007-16
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-102
Disclosure2
2026-07-162
General1Patch1
Full discourse4 posts
  • connect24h@connect24h
    Patch

    地味に攻撃面になってる。正直、開発端末側まで刺さるのは嫌だ。 GitHub CLI v2.10.0〜v2.95.0で、悪性Codespaceに `gh codespace jupyter` で接続すると、ローカルで任意コード実行の可能性がある。CVE-2026-59831、CVSS 4.4。細工した `vscode://` URLをVS Codeへ渡す、CVE-2024-52308の亜種だ。確認操作が1回必要でも、開発者なら通しかねない。 CSIRT初動は `gh --version`、shell historyの同コマンド、接続先Codespaceとdevcontainerの入手元、VS CodeのTrust承認有無を棚卸し。該当者はv2.96.0以降へ更新してほしい。#セキュリティ

    Post summary

    GitHub CLI versions 2.10.0–2.95.0 are vulnerable (CVE-2026-59831 and related CVE-2024-52308) to arbitrary local code execution via malicious Codespaces and crafted `vscode://` URLs; upgrade to v2.96.0 or later to remediate.

    10021816
    6.8K followersView on X
  • connect24h@connect24h
    General

    ソース: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59831

    Post summary

    The text simply cites a Microsoft Security Response Center link for CVE-2026-59831, with no additional information on exploitation, patches, or technical details.

    00000145
    4.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-59831 GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command ex… https://www.cve.org/CVERecord?id=CVE-2026-59831 ----- Traducción: CVE-2026-59831 Git… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-59831, indicating a remote code execution vulnerability in GitHub CLI when interacting with malicious Codespaces, without providing a PoC, exploit, patch, or evidence of active exploitation.

    0000051
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-59831 GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command ex… https://www.cve.org/CVERecord?id=CVE-2026-59831

    Post summary

    CVE-2026-59831 is a remote code execution vulnerability in GitHub CLI (versions 2.10.0 through 2.95.0) that allows execution of arbitrary commands when connecting to a malicious Codespace via the gh codespace jupyter command.

    00000794
    57.8K followersView on X

Explore more