GitHub CLI and extensions can execute arbitrary commands on compromised GitHub Enterprise Server in github.com/cli/go-gh
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2025-3732" }
{ "imports": [ { "path": "github.com/cli/go-gh/v2/pkg/browser", "symbols": [ "Browser.Browse", "Browser.browse" ] } ] }