Vulnerability Description
The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the Authorization header from the corresponding HTTP request.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/r-lib/gh/commit/b575d488c71318449cc6c8c989c617db29275848
- https://github.com/r-lib/gh/compare/v1.4.1...v1.5.0
- https://github.com/r-lib/gh/issues/222
- https://lists.debian.org/debian-lts-announce/2025/11/msg00021.html
FAQ
What is CVE-2025-54956?
CVE-2025-54956 is a vulnerability with a CVSS score of 3.2 (LOW). The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the Authorization header from the corresponding HTTP request.
How severe is CVE-2025-54956?
CVE-2025-54956 has been rated LOW with a CVSS base score of 3.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-54956?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.