Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

[GHSA-cj4v-437j-jq4c] [CVE-2026-25921] - Request for CVSS correction or clarification

Abierto
#7,370 1 comentario 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
45/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Tranquilo
Área
security

Línea de trabajo

Revisa el vector CVSS actual del advisory comparándolo con el vector CVSS:3.1 propuesto y la FIRST CVSS v3.1 user guide enlazada. Verifica la justificación de Scope, Complexity, User Interaction y Availability; después, documenta o aplica la puntuación corregida si el análisis la respalda.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Hi GitHub,

Our automated CVSS enrichment pipeline detected some discrepancies between GitHub's provided vector and ours. Since this also passed a GitHub review, I thought it would be helpful to share my insights here, so that the vector or its justification might be corrected. For reference, this was the output from our AI pipeline: https://graph.volerion.com/view?id=CVE-2026-25921.

For the current vector, Scope is Changed (S:C), due to the stated supply-chain attack vector, but I believe this to be secondary impact that an attacker cannot expect to achieve for all or most instances of an attack against this product. Otherwise, including that 'appendage' would increase attack complexity via either AC (an automated system must later pull and utilize the poisoned source) or UI (a user does the same).

Additionally, A:L may have been set due to a common misconception regarding Availability impact. The vulnerable system is still fully available, albeit serving different content than intended, and therefore directly suffers a serious loss of integrity only.

The final vector would then be:
https://volerion.com/cvss/3.1#vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
With a changed base score from 9.3 to 7.5.

Thanks!

Lenguaje dominante
Sin datos de lenguaje
Estrellas
2.5k
Forks
772
Merge medio
3 d 15 h
PR fusionados (30 d)
46

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de github/advisory-database

Todos los issues de github/advisory-database

Issues similares

Más issues de Security

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.