-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems directly from the fs.chmodSync call with 777 permissions in the downloadKubectl function. The commit diff shows this was changed to 775 in the patch, and all vulnerability descriptions explicitly reference this insecure permission assignment as the root cause. The function's role in setting executable permissions makes it the clear vulnerable component.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| Azure/setup-kubectl | actions | < 3 | 3 |
Ongoing coverage of React2Shell