-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stemmed from two key flaws: 1) The IsPlugin check didn't consider environment variables, allowing plugins to be configured with dangerous env vars. 2) The linter allowed environment variables in plugin steps through insufficient validation. The patches added environment checks to IsPlugin and replaced lintCommands with lintSettings that enforces mutual exclusivity between settings and environment/commands/entrypoint.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| go.woodpecker-ci.org/woodpecker/v2 | go | < 2.7.0 | 2.7.0 |
| go.woodpecker-ci.org/woodpecker | go | < 2.7.0 | 2.7.0 |
Ongoing coverage of React2Shell