Executive brief
GitHub CLI is the official command-line tool for interacting with GitHub. The `gh attestation verify` command failed to properly escape regex metacharacters when validating Sigstore attestations against trusted signing workflows, allowing an attacker to register a lookalike repository (e.g., `github/artifact.attestations-workflows` instead of `github/artifact-attestations-workflows`) that would pass verification. This could let an attacker inject malicious code into CI/CD pipelines or bypass supply chain security policies that rely on attestation verification.
Technical details
The vulnerability is a regex injection flaw in the `gh attestation verify` command. When the `--signer-repo` and `--signer-workflow` flags are used to specify a trusted signer, the tool constructs a certificate Subject Alternative Name matcher without escaping regex metacharacters. Characters like `.` that are valid in GitHub organization, repository, and workflow names are regex wildcards, allowing an attacker to craft a repository name that matches a different intended signer. Exploitation requires creating a plausible lookalike repository and generating valid Sigstore attestations from it. The attack vector is network-based, requiring no authentication or special user interaction beyond the user running the verify command. The fix was applied in version 2.97.0 by properly escaping the metacharacters.
Affected products
- GitHub CLI before 2.97.0
Timeline
- 2026-08-06: disclosed
- 2026-07-31: patched: Fixed in version 2.97.0