VYPR
Low severity3.2OSV Advisory· Published Aug 3, 2025· Updated Jun 17, 2026

CVE-2025-54956

CVE-2025-54956

Description

The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the Authorization header from the corresponding HTTP request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • R Lib/GhOSV2 versions
    1.1.0, v1.2.0, v1.2.1, …+ 1 more
    • (no CPE)range: 1.1.0, v1.2.0, v1.2.1, …
    • (no CPE)range: <1.5.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.