{"id":"AZL-95462","summary":"CVE-2026-64654 affecting package gh 2.62.0-20","details":"GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed externally controlled gist, API, pull request, release, codespace, skill, or agent-task content without neutralizing terminal escape sequences. An attacker who can influence that content can embed escape sequences that are interpreted by the terminal of a user who runs an affected command, with impact ranging from cosmetic manipulation of the title or on-screen content to, on some terminal emulators, command execution. This extends the same class of issue as CVE-2026-45803—which addressed only gh run view --log—to the other affected command paths. This issue is fixed in version 2.97.0.","modified":"2026-08-30T05:26:50Z","published":"2026-08-06T22:18:13Z","upstream":["CVE-2026-64654"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64654"}],"affected":[{"package":{"name":"gh","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/gh"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.62.0-20"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95462.json"}}],"schema_version":"1.9.0"}