Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Crash when missing severity rating on vulnerability

Open Beginner friendly
#26 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
82/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
python
Domain
data, security

Research direction

Start at the parse_vulnerability_data entry point named in the browser traceback, then follow its call from parse_json_data using the supplied CycloneDX JSON as the reproduction case. Done means an SBOM rating without severity no longer crashes and the vulnerability is rendered with an unknown severity; verify the result in the web interface.

Written by the indexing model from the issue text.

Description

The tool shows no information (not even an Error in the HTML), when the SBOM has a "vulnerabilities" section, but missing a "severity" in the "rating", by just setting the "severity" to "unknown", it works.

I've created the flowing SBOM with osv-scanner, and it seems not to include a "severity":

JSON File
{
  "$schema": "http://cyclonedx.org/schema/bom-1.7.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.7",
  "version": 1,
  "components": [
    {
      "bom-ref": "pkg:npm/[email protected]",
      "type": "library",
      "name": "vite",
      "version": "5.4.21",
      "licenses": [],
      "purl": "pkg:npm/[email protected]"
    }
  ],
  "vulnerabilities": [
    {
      "id": "GHSA-4w7w-66w2-5vf9",
      "references": [
        {
          "id": "CVE-2026-39365",
          "source": {}
        }
      ],
      "ratings": [
        {
          "method": "CVSSv4",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        }
      ],
      "description": "Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
      "detail": "### Summary\n\nAny files ending with `.map` even out side the project can be returned to the browser.\n\n### Impact\n\nOnly apps that match the following conditions are affected:\n\n- explicitly exposes the Vite dev server to the network (using `--host` or [`server.host` config option](https://vitejs.dev/config/server-options.html#server-host))\n- have a sensitive content in files ending with `.map` and the path is predictable\n\n### Details\n\nIn Vite v7.3.1, the dev server’s handling of `.map` requests for optimized dependencies resolves file paths and calls `readFile` without restricting `../` segments in the URL. As a result, it is possible to bypass the [`server.fs.strict`](https://vite.dev/config/server-options#server-fs-strict) allow list and retrieve `.map` files located outside the project root, provided they can be parsed as valid source map JSON.\n\n### PoC\n1. Create a minimal PoC sourcemap outside the project root\n    ```bash\n    cat \u003e /tmp/poc.map \u003c\u003c'EOF'\n    {\"version\":3,\"file\":\"x.js\",\"sources\":[],\"names\":[],\"mappings\":\"\"}\n    EOF\n    ```\n2. Start the Vite dev server (example)\n    ```bash\n    pnpm -C playground/fs-serve dev --host 127.0.0.1 --port 18080\n    ```\n3. Confirm that direct `/@fs` access is blocked by `strict` (returns 403)\n    \u003cimg width=\"4004\" height=\"1038\" alt=\"image\" src=\"https://github.com/user-attachments/assets/15a859a8-1dc6-4105-8d58-80527c0dd9ab\" /\u003e\n4. Inject `../` segments under the optimized deps `.map` URL prefix to reach `/tmp/poc.map`\n    \u003cimg width=\"2790\" height=\"846\" alt=\"image\" src=\"https://github.com/user-attachments/assets/5d02957d-2e6a-4c45-9819-3f024e0e81f2\" /\u003e",
      "advisories": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39365"
        }
      ],
      "published": "2026-04-06T18:03:46Z",
      "updated": "2026-09-10T03:50:42Z",
      "credits": {
        "organizations": []
      },
      "affects": [
        {
          "ref": "pkg:npm/vite"
        }
      ]
    }
  ]
}

The flowing Error is shown in the Browser console:

Uncaught (in promise) PythonError: Traceback (most recent call last):
  File "<exec>", line 2277, in main_web
  File "<exec>", line 1430, in parse_string
  File "<exec>", line 1388, in parse_json_data
  File "<exec>", line 853, in parse_vulnerability_data
UnboundLocalError: cannot access local variable 'current_vuln_severity' where it is not associated with a value

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
  File "/lib/python312.zip/pyodide/webloop.py", line 340, in run_handle
    h._run()
  File "/lib/python312.zip/asyncio/events.py", line 88, in _run
    self._context.run(self._callback, *self._args)
  File "/lib/python312.zip/_pyodide/_base.py", line 597, in eval_code_async
    await CodeRunner(
  File "/lib/python312.zip/_pyodide/_base.py", line 411, in run_async
    coroutine = eval(self.code, globals, locals)
                ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "<exec>", line 2432, in <module>
  File "<exec>", line 2280, in main_web
  File "<frozen _sitebuiltins>", line 26, in __call__
SystemExit: None
Dominant language
HTML
Stars
125
Forks
16
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from CycloneDX/Sunshine

All issues in CycloneDX/Sunshine

Similar issues

More Data Engineering issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.