Only the latest release receives fixes. Check yours with sudo ./setupkali.sh --version.
Please do not open a public issue for security problems.
Use GitHub's private reporting: Security tab > Report a vulnerability on UCYBERS/setupkali.
Include the version, what you did, what you expected and what happened. You will get a reply as soon as a maintainer can look at it.
setupkali runs as root and installs software, so these matter most:
- Downloads that are not verified (SHA-256 for release assets, pinned commits for git sources)
- Anything that lets a local user gain root through the tool (temporary files, file ownership)
- Weakened defaults (passwords, SSH, screen lock) outside a training VM
- The script, its pinned hashes and
fixed-http-shellshock.nselive in the same repository. Review a release before running it, and prefer a tagged release overmaster. - The default root password
ucybersis public. It is offered only on desktop virtual machines (VMware, VirtualBox, Hyper-V, Parallels) and is meant for isolated NAT / Host-Only lab networks.