{"affected":[{"database_specific":{"source":"https://github.com/RConsortium/r-advisory-database/blob/main/vulns/gh/RSEC-2025-0.yaml"},"package":{"ecosystem":"CRAN","name":"gh","purl":"pkg:cran/gh"},"ranges":[{"events":[{"introduced":"1.1.0"},{"fixed":"1.5.0"}],"type":"ECOSYSTEM"}],"versions":["1.1.0","1.2.0","1.2.1","1.3.0","1.3.1","1.4.0","1.4.1"]}],"details":"A bug was identified in releases of the GH R package prior to version 1.5. This flaw could expose sensitive information, such as authentication tokens, through request headers during its operation if responses were cached to disk. \nWe issued a Posit Security Advisory with the 1.5 release and attributed the submitter in the release notes.\n","id":"RSEC-2025-0","modified":"2025-08-04T20:30:50.487870Z","published":"2025-07-31T15:00:00Z","references":[{"type":"WEB","url":"https://github.com/r-lib/gh/issues/222"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54956"}],"schema_version":"1.7.3","summary":"Arbitrary Code Execution (ACE) Vulnerability","upstream":["CVE-2025-54956"]}