Skip to content

Request: publish security advisory for fixed vulnerability in #310/#313 (CVE eligibility) #323

Description

@jayantkamble10000

Hi maintainers,
Following up on issue #310 / PR #313, which fixed a Critical-severity path traversal and command injection vulnerability in src/orchestration/local-worker.ts.
Vladimir Pirvu (@vladimirwashere), who wrote the fix, attempted to publish a security advisory and request a CVE, but GitHub declined because his advisory was on a fork (GHSA-m483-77g2-48r9). GitHub only issues CVEs from advisories on the official upstream repository.
Could a maintainer here publish a security advisory on this repo for the vulnerability? It takes a few clicks via Security tab → Advisories → New draft security advisory, and GitHub auto-assigns the CVE. The technical content can be mirrored from Vladimir’s existing GHSA.
Suggested credits:
• Finder: @jayantkamble10000 (reported in #310)
• Remediation developer: @vladimirwashere (PR #313)
This would let downstream users (Snyk, Dependabot, npm audit, NVD) properly track the vulnerability. Happy to provide any details needed.
Thanks.

cc @unifiedh

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions