{"id":"GHSA-fqfh-778m-2v32","aliases":["GO-2022-0395"],"url":"https://o3.security/vulnerability/GHSA-fqfh-778m-2v32","summary":"GitHub CLI can execute a git binary from the current directory","details":"### Impact\nGitHub CLI depends on a `git.exe` executable being found in system `%PATH%` on Windows. However, if a malicious `.\\git.exe` or `.\\git.bat` is found in the current working directory at the time of running `gh`, the malicious command will be invoked instead of the system one.\n\nWindows users who run `gh` inside untrusted directories are affected.\n\n### Patches\nUsers should upgrade to GitHub CLI v1.2.1.\n\n### Workarounds\nOther than avoiding untrusted repositories, there is no workaround.\n\n### References\nhttps://github.com/golang/go/issues/38736","published":"2022-02-11T23:41:11Z","modified":"2024-08-21T14:57:06.656640Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/cli/cli","fixedVersion":"1.2.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/cli/cli/security/advisories/GHSA-fqfh-778m-2v32"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-08-21T14:57:06.656640Z"}}