GitHub CLI and extensions can execute arbitrary commands on compromised GitHub Enterprise Server in github.com/cli/go-gh
{ "url": "https://pkg.go.dev/vuln/GO-2025-3732", "review_status": "REVIEWED" }
{ "imports": [ { "symbols": [ "Browser.Browse", "Browser.browse" ], "path": "github.com/cli/go-gh/v2/pkg/browser" } ] }