
🔏 GitHub CLI attestation verification bypass CVE-2026-64655 affects GitHub CLI before 2.97.0. gh attestation verify can interpret characters in repository or workflow names as regex syntax rather than literal text. An attacker could potentially use a carefully chosen lookalike repository/workflow name to bypass intended Sigstore signer verification. 🔎 Source: GitHub / Tenable. #GitHub #SupplyChain #Sigstore #DevSecOps #CyberSecurity
Post summary
This post announces CVE-2026-64655, highlighting a regex-based verification bypass in GitHub CLI before 2.97.0 that could let attackers use lookalike repository or workflow names to evade Sigstore signer checks. No PoC, exploit, patch, or active exploitation details are provided.
