CVE-2025-48938

go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user's machine by replacing HTTP URLs provided by GitHub with local file paths for browsing. In `2.12.1`, `Browser.Browse()` has been enhanced to allow and disallow a variety of scenarios to avoid opening or executing files on the filesystem without unduly impacting HTTP URLs. No known workarounds are available other than upgrading.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cli:go-gh:*:*:*:*:*:*:*:*

History

15 Oct 2025, 18:10

Type Values Removed Values Added
References () https://github.com/cli/go-gh/blob/61bf393cf4aeea6d00a6251390f5f67f5b67e727/pkg/browser/browser.go - () https://github.com/cli/go-gh/blob/61bf393cf4aeea6d00a6251390f5f67f5b67e727/pkg/browser/browser.go - Product
References () https://github.com/cli/go-gh/commit/a08820a13f257d6c5b4cb86d37db559ec6d14577 - () https://github.com/cli/go-gh/commit/a08820a13f257d6c5b4cb86d37db559ec6d14577 - Patch
References () https://github.com/cli/go-gh/security/advisories/GHSA-g9f5-x53j-h563 - () https://github.com/cli/go-gh/security/advisories/GHSA-g9f5-x53j-h563 - Mitigation, Vendor Advisory
First Time Cli go-gh
Cli
CPE cpe:2.3:a:cli:go-gh:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) go-gh es una colección de módulos de Go que facilita la creación de extensiones de la CLI de GitHub. Se identificó una vulnerabilidad de seguridad en versiones anteriores a la 2.12.1, donde un servidor de GitHub Enterprise controlado por un atacante podía ejecutar comandos arbitrarios en el equipo de un usuario al reemplazar las URL HTTP proporcionadas por GitHub con rutas de archivos locales para la navegación. En la versión 2.12.1, se mejoró `Browser.Browse()` para permitir y deshabilitar diversos escenarios y evitar la apertura o ejecución de archivos en el sistema de archivos sin afectar negativamente a las URL HTTP. No se conocen workarounds aparte de la actualización.

30 May 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-30 19:15

Updated : 2025-10-15 18:10


NVD link : CVE-2025-48938

Mitre link : CVE-2025-48938

CVE.ORG link : CVE-2025-48938


JSON object : View

Products Affected

cli

  • go-gh
CWE
CWE-501

Trust Boundary Violation