CVE-2024-48908 - Lychee Link Checking Action Arbitrary Code Injection Vulnerability
CVE ID : CVE-2024-48908
Published : Aug. 28, 2025, 3:15 p.m. | 2 hours, 23 minutes ago
Description : lychee link checking action checks links in Markdown, HTML, and text files using lychee. Prior to version 2.0.2, there is a potential attack of arbitrary code injection vulnerability in lychee-setup of the composite action at action.yml. This issue has been patched in version 2.0.2.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 28, 2025, 3:15 p.m. | 2 hours, 23 minutes ago
Description : lychee link checking action checks links in Markdown, HTML, and text files using lychee. Prior to version 2.0.2, there is a potential attack of arbitrary code injection vulnerability in lychee-setup of the composite action at action.yml. This issue has been patched in version 2.0.2.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...