Cli Project maintains a narrowly scoped command-line tool whose vulnerability footprint centers on concurrency and filesystem-access issues, specifically race conditions in shared resources and path-traversal weaknesses in pathname handling. Current exploitation activity, severity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cli Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-48938CRITICAL go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-contr | May 30, 2025 | 9.8 | 26 | NO | NO |
CVE-2024-53859HIGH go-gh is a Go module for interacting with the `gh` utility and the GitHub API from the command line. A security vulnerability has been identified in `go-gh` that could leak authent | Nov 27, 2024 | 7.5 | 21 | NO | NO |
The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access | May 31, 2018 | 3.5 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cli Project.
Media articles that mention a CVE ID that affects a product developed by Cli Project — matched by CVE ID, not by vendor name.