Home

Description

The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the Authorization header from the corresponding HTTP request.

PUBLISHED Reserved 2025-08-03 | Published 2025-08-03 | Updated 2025-11-25 | Assigner mitre




LOW: 3.2CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N

Problem types

CWE-669 Incorrect Resource Transfer Between Spheres

Product status

Default status
unaffected

Any version before 1.5.0
affected

References

lists.debian.org/debian-lts-announce/2025/11/msg00021.html

github.com/r-lib/gh/issues/222

github.com/...ommit/b575d488c71318449cc6c8c989c617db29275848

github.com/r-lib/gh/compare/v1.4.1...v1.5.0

cve.org (CVE-2025-54956)

nvd.nist.gov (CVE-2025-54956)

Download JSON