Hi maintainers,
Following up on issue #310 / PR #313, which fixed a Critical-severity path traversal and command injection vulnerability in src/orchestration/local-worker.ts.
Vladimir Pirvu (@vladimirwashere), who wrote the fix, attempted to publish a security advisory and request a CVE, but GitHub declined because his advisory was on a fork (GHSA-m483-77g2-48r9). GitHub only issues CVEs from advisories on the official upstream repository.
Could a maintainer here publish a security advisory on this repo for the vulnerability? It takes a few clicks via Security tab → Advisories → New draft security advisory, and GitHub auto-assigns the CVE. The technical content can be mirrored from Vladimir’s existing GHSA.
Suggested credits:
• Finder: @jayantkamble10000 (reported in #310)
• Remediation developer: @vladimirwashere (PR #313)
This would let downstream users (Snyk, Dependabot, npm audit, NVD) properly track the vulnerability. Happy to provide any details needed.
Thanks.
cc @unifiedh
Hi maintainers,
Following up on issue #310 / PR #313, which fixed a Critical-severity path traversal and command injection vulnerability in src/orchestration/local-worker.ts.
Vladimir Pirvu (@vladimirwashere), who wrote the fix, attempted to publish a security advisory and request a CVE, but GitHub declined because his advisory was on a fork (GHSA-m483-77g2-48r9). GitHub only issues CVEs from advisories on the official upstream repository.
Could a maintainer here publish a security advisory on this repo for the vulnerability? It takes a few clicks via Security tab → Advisories → New draft security advisory, and GitHub auto-assigns the CVE. The technical content can be mirrored from Vladimir’s existing GHSA.
Suggested credits:
• Finder: @jayantkamble10000 (reported in #310)
• Remediation developer: @vladimirwashere (PR #313)
This would let downstream users (Snyk, Dependabot, npm audit, NVD) properly track the vulnerability. Happy to provide any details needed.
Thanks.
cc @unifiedh