CVE-2024-48908
Executive Summary
CVE-2024-48908 exposes an arbitrary code injection flaw in the lychee-setup step of the lychee link‑checking GitHub Action (prior to v2.0.2). Attackers could inject malicious code during the action’s setup, potentially executing arbitrary commands in the CI environment. The issue is fixed in v2.0.2; users should upgrade immediately to mitigate the risk.
Authoritative CVE Metadata - CVSS Base Score: Unknown (Unknown) - Published: 2025-08-28T15:15:42.390 - Last Modified: 2026-09-26T21:10:00.130
Original Description: lychee link checking action checks links in Markdown, HTML, and text files using lychee. Prior to version 2.0.2, there is a potential attack of arbitrary code injection vulnerability in lychee-setup of the composite action at action.yml. This issue has been patched in version 2.0.2.
"Sooner or later, those who win are those who think they can."
— Richard Bach