CVE-2025-25204

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Feb 14, 2025
CWE ID 390

Summary

CVE-2025-25204 is a vulnerability affecting the `gh` command-line tool used by GitHub. In versions 2.49.0 to 2.66.9, there is a bug in the Artifact Attestation cli tool `gh attestation verify`. Under certain conditions, this tool incorrectly returns a zero exit status when no attestations are present. This behavior is problematic because a non-zero exit status code should be returned when no attestations are verified. An attacker could exploit this flaw by deploying malicious artifacts on systems that rely on `gh attestation verify`'s exit codes to control deployments. Users are urged to upgrade to the patched version 2.67.0 as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share