PT-2025-31791 · Gh+1 · Gh+1

Foysal1197

·

Published

2025-07-31

·

Updated

2025-11-26

·

CVE-2025-54956

CVSS v3.1

3.2

Low

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions gh package versions prior to 1.5.0
Description The gh package for R delivers an HTTP response that includes the Authorization header from the corresponding HTTP request.
Recommendations Update the gh package to version 1.5.0 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-54956
DLA-4378-1
RSEC-2025-0

Affected Products

Debian
Gh