Hi, The following vulnerability was published for gh. CVE-2026-72924[0]: | GitHub CLI (gh) is GitHub's official command line tool. Versions | 2.28.0 through 2.97.0 bind the local listener created by gh | codespace ports forward to all available network interfaces by | default. While port forwarding is active, a service in a Codespace | can therefore become reachable through the user's non-loopback local | IP addresses by other hosts that can route to the user's machine. | This behavior does not change the GitHub-side visibility of the | Codespaces port. Instead, it exposes the forwarded service through a | wildcard-bound listener on the user's local machine, even when the | source Codespaces port remains private. Exploitation requires a | network-adjacent attacker to reach the victim's machine while | forwarding is active. This issue is fixed in version 2.98.0. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-72924 https://www.cve.org/CVERecord?id=CVE-2026-72924 [1] https://github.com/cli/cli/security/advisories/GHSA-vfhh-p7hm-pxfh Please adjust the affected versions in the BTS as needed. Rgards, Salvatore