CVE-2026-64655 | GitHub CLI up to 2.96.x Attestation Verify signer-repo/signer-workflow incorrect regex

SecurityVulns

A vulnerability classified as problematic has been found in GitHub CLI up to 2.96.x. Impacted is an unknown function of the component Attestation Verify. This manipulation of the argument signer-repo/signer-workflow causes incorrect regular expression.

This vulnerability is registered as CVE-2026-64655. Remote exploitation of the attack is possible. No exploit is available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More