---
id: CVE-2024-48908
title: >-
  lychee link checking action checks links in Markdown, HTML, and text files
  using lychee
summary: >-
  lychee link checking action checks links in Markdown, HTML, and text files
  using lychee. Prior to version 2.0.2, there is a potential attack of arbitrary
  code injection vulnerability in lychee-setup of the composite action at
  action.yml.…
severity: none
cwe:
  - CWE-94
published: '2025-08-28'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T21:10:00.130'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-48908'
references:
  - url: >-
      https://github.com/lycheeverse/lychee-action/commit/7cd0af4c74a61395d455af97419279d86aafaede
    label: security-advisories@github.com
  - url: >-
      https://github.com/lycheeverse/lychee-action/security/advisories/GHSA-65rg-554r-9j5x
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00385
epssPercentile: 0.29918
ingestedAt: '2026-09-26T21:38:01.483Z'
---

## Overview

lychee link checking action checks links in Markdown, HTML, and text files using lychee. Prior to version 2.0.2, there is a potential attack of arbitrary code injection vulnerability in lychee-setup of the composite action at action.yml. This issue has been patched in version 2.0.2.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
