THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-48938 (CRITICAL 9.8) — go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user's machine by r

[NVD] CVE-2025-48938 (CRITICAL 9.8) — go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user's machine by r

lownvdPublished 2025-05-30

CVE-2025-48938 CVSS: 9.8 CRITICAL Published: 2025-05-30T19:15:29.980

go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user's machine by replacing HTTP URLs provided by GitHub with local f

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-48938