{"id":"CVE-2024-48908","aliases":["GHSA-65rg-554r-9j5x"],"url":"https://o3.security/vulnerability/CVE-2024-48908","summary":"lychee-action vulnerable to arbitrary code injection in composite action","details":"lychee link checking action checks links in Markdown, HTML, and text files using lychee. Prior to version 2.0.2, there is a potential attack of arbitrary code injection vulnerability in lychee-setup of the composite action at action.yml. This issue has been patched in version 2.0.2.","published":"2025-08-28T14:56:43.967Z","modified":"2026-07-15T01:49:03.190955159Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"GitHub Actions","name":"lycheeverse/lychee-action","fixedVersion":"2.0.2"}],"fix":{"url":"https://github.com/lycheeverse/lychee-action/commit/7cd0af4c74a61395d455af97419279d86aafaede","label":"lycheeverse/lychee-action@7cd0af4"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/48xxx/CVE-2024-48908.json"},{"type":"ADVISORY","url":"https://github.com/lycheeverse/lychee-action/security/advisories/GHSA-65rg-554r-9j5x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-48908"},{"type":"FIX","url":"https://github.com/lycheeverse/lychee-action/commit/7cd0af4c74a61395d455af97419279d86aafaede"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:03.190955159Z"}}