cobo-cli

Install command:
brew install cobo-cli

Build, test, and manage your integration with Cobo Wallet-as-a-Service

https://github.com/CoboGlobal/cobo-cli

License: MIT

Development: Pull requests

Formula JSON API: /api/formula/cobo-cli.json

Formula code: cobo-cli.rb on GitHub

Bottle (binary package) installation support provided for:

macOS on
Apple Silicon
golden gate ✅
tahoe ✅
sequoia ✅
sonoma ✅
macOS on
Intel
sonoma ✅
Linux ARM64 ✅
x86_64 ✅

Current versions:

stable ✅ 0.1.10
head ⚡️ HEAD

Depends on:

certifi 2026.7.22 Mozilla CA bundle for Python
cffi 2.1.1 C Foreign Function Interface for Python
libsodium 1.0.22 NaCl networking and cryptography library
libyaml 0.2.5 YAML Parser
pydantic 2.13.5 Data validation using Python type hints
python@3.14 3.14.8 Interpreted, interactive, object-oriented programming language

Uses from macOS: libffi

Binaries: cobo

Known vulnerabilities in the current version:

GHSA-59cr-6r3x-644w GitPython submodule update path traversal can write outside the repository
GHSA-rwj8-pgh3-r573 (high) GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
GHSA-956x-8gvw-wg5v (high) GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, an...
GHSA-v396-v7q4-x2qj GitPython unsafe clone option gate bypass through joined short options
GHSA-2f96-g7mh-g2hx (high) GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blo...
GHSA-3rp5-jjmw-4wv2 (high) GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand...
GHSA-539m-9xh6-q6rr (medium) GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, ...
GHSA-3f7w-8rr8-f37f (high) GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enab...
GHSA-p538-c434-8v24 (medium) GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Co...
GHSA-94p4-4cq8-9g67 (high) GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incompl...
GHSA-6p8h-3wgx-97gf (high) GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary comma...
GHSA-fjr4-x663-mwxc (high) GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (ke...
GHSA-r9mr-m37c-5fr3 (high) GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enable...
GHSA-hh9p-6wh2-4mfc (medium) GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
GHSA-9rj7-rf2p-w77r (high) GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via -...
GHSA-4gmw-gg2m-w46p (high) GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enab...
GHSA-wvpp-8hx9-p66j (high) GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token ...
GHSA-jm78-9fvv-mhgr (high) GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling ...
GHSA-hmq2-w58f-27jc (high) GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules...
GHSA-7833-fr7j-v32q (high) GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodul...
GHSA-284h-m62q-gf8w (critical) GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g....
GHSA-8mcc-hrx5-hvxc (high) GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling a...
GHSA-5xxx-qhh7-9287 (medium) GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrar...
GHSA-3wxw-xv34-2frg (medium) GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling a...
PYSEC-2026-3982 (high) GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution
PYSEC-2026-3984 (high) GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — co...
GHSA-8988-9cw3-xx77 urllib3: HTTPS proxy TLS configuration may be ignored or overridden
GHSA-gh4c-6fx4-qh6g urllib3: Chunked Deflate streaming can enter an infinite loop
GHSA-vxq7-64xx-v4gw urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory

Data from Homebrew/advisory-database. Run brew vulns cobo-cli for a live check.

Analytics:

30 days90 days365 days
Installs579420
Installs (--HEAD)113
Installs on Request579420
Installs on Request (--HEAD)113
Build Errors0