{"id":"RSEC-2025-0","summary":"Arbitrary Code Execution (ACE) Vulnerability","details":"A bug was identified in releases of the GH R package prior to version 1.5. This flaw could expose sensitive information, such as authentication tokens, through request headers during its operation if responses were cached to disk. \nWe issued a Posit Security Advisory with the 1.5 release and attributed the submitter in the release notes.\n","modified":"2025-08-04T20:30:50.487870Z","published":"2025-07-31T15:00:00Z","upstream":["CVE-2025-54956"],"references":[{"type":"WEB","url":"https://github.com/r-lib/gh/issues/222"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54956"}],"affected":[{"package":{"name":"gh","ecosystem":"CRAN","purl":"pkg:cran/gh"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.1.0"},{"fixed":"1.5.0"}]}],"versions":["1.1.0","1.2.0","1.2.1","1.3.0","1.3.1","1.4.0","1.4.1"],"database_specific":{"source":"https://github.com/RConsortium/r-advisory-database/blob/main/vulns/gh/RSEC-2025-0.yaml"}}],"schema_version":"1.7.3"}