Crash when missing severity rating on vulnerability
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 82/100
Research direction
Start at the parse_vulnerability_data entry point named in the browser traceback, then follow its call from parse_json_data using the supplied CycloneDX JSON as the reproduction case. Done means an SBOM rating without severity no longer crashes and the vulnerability is rendered with an unknown severity; verify the result in the web interface.
Written by the indexing model from the issue text.
Description
The tool shows no information (not even an Error in the HTML), when the SBOM has a "vulnerabilities" section, but missing a "severity" in the "rating", by just setting the "severity" to "unknown", it works.
I've created the flowing SBOM with osv-scanner, and it seems not to include a "severity":
JSON File
{
"$schema": "http://cyclonedx.org/schema/bom-1.7.schema.json",
"bomFormat": "CycloneDX",
"specVersion": "1.7",
"version": 1,
"components": [
{
"bom-ref": "pkg:npm/[email protected]",
"type": "library",
"name": "vite",
"version": "5.4.21",
"licenses": [],
"purl": "pkg:npm/[email protected]"
}
],
"vulnerabilities": [
{
"id": "GHSA-4w7w-66w2-5vf9",
"references": [
{
"id": "CVE-2026-39365",
"source": {}
}
],
"ratings": [
{
"method": "CVSSv4",
"vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
}
],
"description": "Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
"detail": "### Summary\n\nAny files ending with `.map` even out side the project can be returned to the browser.\n\n### Impact\n\nOnly apps that match the following conditions are affected:\n\n- explicitly exposes the Vite dev server to the network (using `--host` or [`server.host` config option](https://vitejs.dev/config/server-options.html#server-host))\n- have a sensitive content in files ending with `.map` and the path is predictable\n\n### Details\n\nIn Vite v7.3.1, the dev server’s handling of `.map` requests for optimized dependencies resolves file paths and calls `readFile` without restricting `../` segments in the URL. As a result, it is possible to bypass the [`server.fs.strict`](https://vite.dev/config/server-options#server-fs-strict) allow list and retrieve `.map` files located outside the project root, provided they can be parsed as valid source map JSON.\n\n### PoC\n1. Create a minimal PoC sourcemap outside the project root\n ```bash\n cat \u003e /tmp/poc.map \u003c\u003c'EOF'\n {\"version\":3,\"file\":\"x.js\",\"sources\":[],\"names\":[],\"mappings\":\"\"}\n EOF\n ```\n2. Start the Vite dev server (example)\n ```bash\n pnpm -C playground/fs-serve dev --host 127.0.0.1 --port 18080\n ```\n3. Confirm that direct `/@fs` access is blocked by `strict` (returns 403)\n \u003cimg width=\"4004\" height=\"1038\" alt=\"image\" src=\"https://github.com/user-attachments/assets/15a859a8-1dc6-4105-8d58-80527c0dd9ab\" /\u003e\n4. Inject `../` segments under the optimized deps `.map` URL prefix to reach `/tmp/poc.map`\n \u003cimg width=\"2790\" height=\"846\" alt=\"image\" src=\"https://github.com/user-attachments/assets/5d02957d-2e6a-4c45-9819-3f024e0e81f2\" /\u003e",
"advisories": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39365"
}
],
"published": "2026-04-06T18:03:46Z",
"updated": "2026-09-10T03:50:42Z",
"credits": {
"organizations": []
},
"affects": [
{
"ref": "pkg:npm/vite"
}
]
}
]
}
The flowing Error is shown in the Browser console:
Uncaught (in promise) PythonError: Traceback (most recent call last):
File "<exec>", line 2277, in main_web
File "<exec>", line 1430, in parse_string
File "<exec>", line 1388, in parse_json_data
File "<exec>", line 853, in parse_vulnerability_data
UnboundLocalError: cannot access local variable 'current_vuln_severity' where it is not associated with a value
During handling of the above exception, another exception occurred:
Traceback (most recent call last):
File "/lib/python312.zip/pyodide/webloop.py", line 340, in run_handle
h._run()
File "/lib/python312.zip/asyncio/events.py", line 88, in _run
self._context.run(self._callback, *self._args)
File "/lib/python312.zip/_pyodide/_base.py", line 597, in eval_code_async
await CodeRunner(
File "/lib/python312.zip/_pyodide/_base.py", line 411, in run_async
coroutine = eval(self.code, globals, locals)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "<exec>", line 2432, in <module>
File "<exec>", line 2280, in main_web
File "<frozen _sitebuiltins>", line 26, in __call__
SystemExit: None
- Dominant language
- HTML
- Stars
- 125
- Forks
- 16
- PR merge metrics
- No merged PRs in 30d
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from CycloneDX/Sunshine
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 72/100
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 68/100
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 38/100
-
enhancement
Difficulty 5/5 Over a week Newbie friendliness 25/100
All issues in CycloneDX/Sunshine
Similar issues
-
Bug
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
resources
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
railmapgen/rmg-palette#2447 ·
-
import-issue
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
public-transport/transitous#2519 ·
Maintainers usually reply within 1 day