216.73.217.22

CVE-2025-54594

· Published 06/08/2025 00:15 · Modified 06/08/2025 20:23

Labels: CVE-2025-54594 2025-08-06CVE-2025-54594CWE-94[email protected]

Essential information

Published
06/08/2025 00:15
Modified
06/08/2025 20:23
Author
Creator
CVSS
9.1 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS metrics

Description

react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In versions 0.9.2 and below, the github/workflows/release-canary.yml GitHub Actions repository workflow improperly used the pull_request_target event trigger, which allowed for untrusted code from a forked pull request to be executed in a privileged context. An attacker could create a pull request containing a malicious preinstall script in the package.json file and then trigger the vulnerable workflow by posting a specific comment (!canary). This allowed for arbitrary code execution, leading to the exfiltration of sensitive secrets such as GITHUB_TOKEN and NPM_TOKEN, and could have allowed an attacker to push malicious code to the repository or publish compromised packages to the NPM registry. There is a remediation commit which removes github/workflows/release-canary.yml, but a version with this fix has yet to be released.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
react-native / bottom-tabs cpe:2.3:a:react-native:bottom-tabs:0.9.2:*:*:*:*:*:*:*
react-native / bottom-tabs cpe:2.3:a:react-native:bottom-tabs:*:*:*:*:*:*:*:*

References