Cli maintains a focused product portfolio centered on command-line tooling and GitHub integration libraries, with its limited disclosure history clustering around information-exposure and trust-boundary issues characteristic of tools that handle authentication credentials and user data. The recurring weakness classes—exposure of sensitive information, trust-boundary violations, and insufficient data validation—reflect the security demands of CLI utilities that mediate access to external services. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cli over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-48938CRITICAL go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-contr | May 30, 2025 | 9.8 | 26 | NO | NO |
CVE-2024-53859HIGH go-gh is a Go module for interacting with the `gh` utility and the GitHub API from the command line. A security vulnerability has been identified in `go-gh` that could leak authent | Nov 27, 2024 | 7.5 | 21 | NO | NO |
The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access | May 31, 2018 | 3.5 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cli.
Media articles that mention a CVE ID that affects a product developed by Cli — matched by CVE ID, not by vendor name.