Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer in github.com/cli/cli
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2024-3269" }