CVE-2026-64652

NameCVE-2026-64652
DescriptionGitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in certain fine-grained personal access tokens and GitHub App tokens. As a result, part of an affected token could appear in terminal or CI output that is captured or shared. Authenticated users are affected if they ran gh auth status (without the --show-token flag) with a token type whose format contains an underscore after the prefix. This includes fine-grained personal access tokens (github_pat_*) and GitHub App installation and user access tokens (ghs_*, ghu_*; for example, ghs_<APPID>_<JWT>), as well as the Actions GITHUB_TOKEN. Classic tokens such as gho_* and ghp_* have an underscore-free body and are not affected. This issue is fixed in version 2.97.0.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1144403

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gh (PTS)bookworm2.23.0+dfsg1-1vulnerable
trixie2.46.0-3vulnerable
sid2.46.0-4vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ghsource(unstable)(unfixed)1144403

Notes

[trixie] - gh <no-dsa> (Minor issue)
https://github.com/cli/cli/security/advisories/GHSA-cg6r-mpgc-h9mm
https://github.com/cli/cli/commit/3f6a16a9f8c7fe9676aa8d8f47b399310dd231c3 (v2.97.0)

Search for package or bug name: Reporting problems