Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-54594

Опубликовано: 06 авг. 2025
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In versions 0.9.2 and below, the github/workflows/release-canary.yml GitHub Actions repository workflow improperly used the pull_request_target event trigger, which allowed for untrusted code from a forked pull request to be executed in a privileged context. An attacker could create a pull request containing a malicious preinstall script in the package.json file and then trigger the vulnerable workflow by posting a specific comment (!canary). This allowed for arbitrary code execution, leading to the exfiltration of sensitive secrets such as GITHUB_TOKEN and NPM_TOKEN, and could have allowed an attacker to push malicious code to the repository or publish compromised packages to the NPM registry. There is a remediation commit which removes github/workflows/release-canary.yml, but a version with this fix has yet to be released.

EPSS

Процентиль: 15%
0.00049
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.1
fstec
6 месяцев назад

Уязвимость библиотеки нативных нижних вкладок для React Native react-native-bottom-tabs, связанная с небезопасным управлением привилегиями, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 15%
0.00049
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-94