CVE-2026-72924: GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default

Published Aug 25, 2026
·
Updated

GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28.0 through 2.97.0 bind the local listener created by gh codespace ports forward to all available network interfaces by default. While port forwarding is active, a service in a Codespace can therefore become reachable through the user's non-loopback local IP addresses by other hosts that can route to the user's machine. This behavior does not change the GitHub-side visibility of the Codespaces port. Instead, it exposes the forwarded service through a wildcard-bound listener on the user's local machine, even when the source Codespaces port remains private. Exploitation requires a network-adjacent attacker to reach the victim's machine while forwarding is active. This issue is fixed in version 2.98.0.

Affected Software

2 affected components
GitHub GitHub CLI (gh)>=2.28.0<=2.97.0
GitHub GitHub CLI (gh)=2.98.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade GitHub CLI (gh) to a version that resolves this vulnerability.

    Fixed in 2.98.0
  2. Compensating control

    While using GitHub CLI versions 2.28.0 through 2.97.0, prevent other hosts from routing to the user's machine non-loopback local IP addresses while `gh codespace ports forward` is active (e.g., block inbound access to the forwarded local wildcard-bound listener at the network/firewall layer).

Event History

Aug 25, 2026
CVE Published
via MITRE·09:03 PM
Data Sourced
via MITRE·09:03 PM
DescriptionWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can reach the forwarded service while the vulnerable command is active?

Other hosts that can route to the user's machine through its non-loopback local IP addresses can reach it. The attacker must be network-adjacent and the port forwarding session must still be active.

2

Does making the Codespaces port private prevent this local exposure?

No. The issue does not change GitHub-side Codespaces port visibility; even a private source port can be exposed by the wildcard-bound listener on the local machine.

3

Which versions are affected, and what version fixes the issue?

GitHub CLI versions 2.28.0 through 2.97.0 are affected. The issue is fixed in version 2.98.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203