Skip to content
COOEY

FAIL › dossier

CLI

PRODUCT

· dossier confidence 60%

CLI is a developer tooling product with a severely compromised security posture, evidenced by multiple critical and high-severity vulnerabilities including unauthenticated remote code execution and command injection flaws. The company's track record of failing to patch critical vulnerabilities in its CLI tools poses significant risks to organizations relying on these tools for development workflows.

PROFILE
CategoryDeveloper ToolingWhat they doCLI is a command-line interface product used for software development and automation tasks.
SECURITY POSTURE

The security posture is compromised by a history of critical and high-severity vulnerabilities, including unauthenticated remote code execution and command injection flaws, indicating systemic issues in vulnerability management and patching processes.

Notable failures
  • CVE-2025-11953: Unauthenticated RCE via React Native CLI
  • CVE-2026-48501: GitHub CLI vulnerability
  • CVE-2025-48938: go-gh critical vulnerability
Patterns: repeated unpatched command injection and RCE vulnerabilities in CLI tools
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2026-02-05 CVE-2025-11953 high React Native CLI exposed to OS command injection, allowing unauthenticated remote code execution.
2026-05-29 CVE-2026-48501 high CVE-2026-48501: GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub
2025-05-30 CVE-2025-48938 critical CVE-2025-48938: go-gh is a collection of Go modules to make authoring GitHub CLI extensions easi
Open questions: What is the exact founding date and headquarters location of CLI? · What is the current ownership structure of CLI? · What is the official website for CLI?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-24 03:48:25.451215+00:00