<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:37:34 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-242245</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-242245</link>
      <description>EUVD-2026-242245</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-242245</guid>
    </item>
    <item>
      <title>fkie_cve-2025-48938</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-48938</link>
      <description>&lt;p&gt;go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user&amp;#39;s machine by replacing HTTP URLs provided by GitHub with local file paths for browsing. In `2.12.1`, `Browser.Browse()` has been enhanced to allow and disallow a variety of scenarios to avoid opening or executing files on the filesystem without unduly impacting HTTP URLs. No known workarounds are available other than upgrading.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user&amp;#39;s machine by replacing HTTP URLs provided by GitHub with local file paths for browsing. In `2.12.1`, `Browser.Browse()` has been enhanced to allow and disallow a variety of scenarios to avoid opening or executing files on the filesystem without unduly impacting HTTP URLs. No known workarounds are available other than upgrading.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-48938</guid>
    </item>
    <item>
      <title>GHSA-g9f5-x53j-h563 — Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g9f5-x53j-h563</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/cli/go-gh/v2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A security vulnerability has been identified in `go-gh` where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user&amp;#39;s machine by replacing HTTP URLs provided by GitHub with local file paths for browsing.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The GitHub CLI and CLI extensions allow users to transition from their terminal for a variety of use cases through the [`Browser` capability in `github.com/cli/go-gh/v2/pkg/browser`](https://github.com/cli/go-gh/blob/61bf393cf4aeea6d00a6251390f5f67f5b67e727/pkg/browser/browser.go):&lt;/p&gt;
&lt;p&gt;- Using the `-w, --web` flag, GitHub CLI users can view GitHub repositories, issues, pull requests, and more using their web browser
- Using the `gh codespace` command set, GitHub CLI users can transition to Visual Studio Code to work with GitHub Codespaces&lt;/p&gt;
&lt;p&gt;This is done by using URLs provided through API responses from authenticated GitHub hosts when users execute `gh` commands.&lt;/p&gt;
&lt;p&gt;Prior to `2.12.1`, `Browser.Browse()` would attempt to open the provided URL using a variety of OS-specific approaches regardless of the scheme.  An attacker-controlled GitHub Enterprise Server could modify API responses to use a specially tailored local executable path instead of HTTP URLs to resources.  This could allow the attacker to execute arbitrary executables on the user&amp;#39;s machine.&lt;/p&gt;
&lt;p&gt;In `2.12.1`, `Browser.Browse()` has been enhanced to allow and disallow a variety of scenarios to avoid opening or executing files on the filesystem withou…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/cli/go-gh/v2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A security vulnerability has been identified in `go-gh` where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user&amp;#39;s machine by replacing HTTP URLs provided by GitHub with local file paths for browsing.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The GitHub CLI and CLI extensions allow users to transition from their terminal for a variety of use cases through the [`Browser` capability in `github.com/cli/go-gh/v2/pkg/browser`](https://github.com/cli/go-gh/blob/61bf393cf4aeea6d00a6251390f5f67f5b67e727/pkg/browser/browser.go):&lt;/p&gt;
&lt;p&gt;- Using the `-w, --web` flag, GitHub CLI users can view GitHub repositories, issues, pull requests, and more using their web browser
- Using the `gh codespace` command set, GitHub CLI users can transition to Visual Studio Code to work with GitHub Codespaces&lt;/p&gt;
&lt;p&gt;This is done by using URLs provided through API responses from authenticated GitHub hosts when users execute `gh` commands.&lt;/p&gt;
&lt;p&gt;Prior to `2.12.1`, `Browser.Browse()` would attempt to open the provided URL using a variety of OS-specific approaches regardless of the scheme.  An attacker-controlled GitHub Enterprise Server could modify API responses to use a specially tailored local executable path instead of HTTP URLs to resources.  This could allow the attacker to execute arbitrary executables on the user&amp;#39;s machine.&lt;/p&gt;
&lt;p&gt;In `2.12.1`, `Browser.Browse()` has been enhanced to allow and disallow a variety of scenarios to avoid opening or executing files on the filesystem withou…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g9f5-x53j-h563</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-48938 — Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-48938</link>
      <description>msrc_CVE-2025-48938</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-48938</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15225-1 — govulncheck-vulndb-0.0.20250612T141001-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15225-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250612T141001-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250612T141001-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15225-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-48938</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-48938</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: golang-github-cli-go-gh, Ubuntu:Pro:24.04:LTS: golang-github-cli-go-gh-v2, Ubuntu:25.10: golang-github-cli-go-gh, Ubuntu:25.10: golang-github-cli-go-gh-v2, Ubuntu:26.04:LTS: golang-github-cli-go-gh, Ubuntu:26.04:LTS: golang-github-cli-go-gh-v2&lt;/p&gt;
&lt;p&gt;go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user&amp;#39;s machine by replacing HTTP URLs provided by GitHub with local file paths for browsing. In `2.12.1`, `Browser.Browse()` has been enhanced to allow and disallow a variety of scenarios to avoid opening or executing files on the filesystem without unduly impacting HTTP URLs. No known workarounds are available other than upgrading.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: golang-github-cli-go-gh, Ubuntu:Pro:24.04:LTS: golang-github-cli-go-gh-v2, Ubuntu:25.10: golang-github-cli-go-gh, Ubuntu:25.10: golang-github-cli-go-gh-v2, Ubuntu:26.04:LTS: golang-github-cli-go-gh, Ubuntu:26.04:LTS: golang-github-cli-go-gh-v2&lt;/p&gt;
&lt;p&gt;go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user&amp;#39;s machine by replacing HTTP URLs provided by GitHub with local file paths for browsing. In `2.12.1`, `Browser.Browse()` has been enhanced to allow and disallow a variety of scenarios to avoid opening or executing files on the filesystem without unduly impacting HTTP URLs. No known workarounds are available other than upgrading.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-48938</guid>
    </item>
  </channel>
</rss>
