Executive brief
Recursive repository cloning can leak authentication tokens to non-GitHub submodule hosts in github.com/cli/cli
Affected products
- Go github.com/cli/cli
- Go github.com/cli/cli/v2
Junglewise Threat Intelligence
CVE-2024-53858 · Severity: low · CVSS 3.1 · Published 2024-12-02
Technologies: github.com/cli/cli (Go), github.com/cli/cli/v2 (Go). Vendors: Go.
Recursive repository cloning can leak authentication tokens to non-GitHub submodule hosts in github.com/cli/cli