Executive brief
GitHub CLI (gh) is GitHub's official command-line tool for managing repositories and workflows. Prior to version 2.97.0, several gh commands (gist view, api, pr diff, release download, codespace logs, skills preview, and agent-task view) could print externally controlled content containing terminal escape sequences without sanitization. An attacker who can influence that content could embed sequences that manipulate the terminal display or, on vulnerable terminal emulators, execute arbitrary commands.
Technical details
This is a terminal escape sequence injection vulnerability affecting multiple GitHub CLI commands that display externally controlled content (API responses, pull request data, gist contents, etc.). The root cause is that these commands printed untrusted data directly to the terminal without neutralizing ANSI escape sequences. An attacker who can influence the content displayed by these commands (e.g., by controlling gist content, PR titles, release notes, or codespace output) can inject escape sequences that modify terminal behavior or, in some terminal emulators, lead to command execution. The fix introduces terminal-safety mechanisms including an Untrusted content type wrapper, ContentOut sink with sanitization, and a shared asciisanitizer, along with an optional --allow-escape-sequences flag for commands that require raw output. Version 2.97.0 and later include these protections.
Affected products
- GitHub CLI prior to 2.97.0
Timeline
- 2026-08-06: disclosed
- 2026-07-31: patched: Fixed in GitHub CLI version 2.97.0