CVE-2024-54132

unknown
Published 2024-12-04 · Modified 2026-02-04
CVSS v3
CVSS v2
VIR risk

Description

The GitHub CLI is GitHub’s official command line tool. A security vulnerability has been identified in GitHub CLI that could create or overwrite files in unintended directories when users download a malicious GitHub Actions workflow artifact through gh run download. This vulnerability stems from a GitHub Actions workflow artifact named .. when downloaded using gh run download. The artifact name and --dir flag are used to determine the artifact’s download path. When the artifact is named .., the resulting files within the artifact are extracted exactly 1 directory higher than the specified --dir flag value. This vulnerability is fixed in 2.63.1.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2024-54132.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2024-54132

OS impact

OSVersionStatusFixed in
debian debianbookwormaffected
debian debiansidfixed2.46.0-3
debian debiantrixiefixed2.46.0-3
suse slesaffected

Package impact

EcosystemPackageVulnerableFixed
golang Gogithub.com/cli/cli/v2<2.63.12.63.1
golang Gogithub.com/cli/cli<=1.14.0
golang Gogithub.com/cli/cli

References

Verify integrity in audit chain (admin only). AS-IS.