-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability documentation explicitly identifies downloadAction and updateAction as entry points. Technical analysis shows downloadAction fetches untrusted content, while updateAction triggers code inclusion via SelfUpdater. The chain allows attackers to inject malicious PHP code through crafted zip packages, meeting CWE-94 criteria for code injection. The functions' direct involvement in handling untrusted input and code execution pathways justifies high confidence.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| pagekit/pagekit | composer | <= 1.0.18 |
Ongoing coverage of React2Shell