Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[GHSA-rp9m-7r4c-75qg] [CVE-2026-35039] - Request for CVSS correction or clarification

Open
#7,372 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Quiet
Domain
security

Research direction

Review GHSA-rp9m-7r4c-75qg and CVE-2026-35039 alongside the linked CVSS 3.1 guidance and the reporter's proposed vector. Verify whether possession of a valid JWT changes PR and whether the stated impact is justified; done means documenting the decision and updating the advisory metadata if warranted.

Written by the indexing model from the issue text.

Description

Hi GitHub,

Our automated CVSS enrichment pipeline detected some discrepancies between GitHub's provided vector and ours. Since this also passed a GitHub review, I thought it would be helpful to share my insights here, so that the vector or its justification might be corrected. For reference, this was the output from our AI pipeline: https://graph.volerion.com/view?id=CVE-2026-35039.

For the current vector, PR:N was set, but exploitation requires an attacker to possess a valid JWT, which is an authentication artifact, and therefore constitutes at least a low privilege requirement.

Additionally, impact could have been downgraded to C:L/I:L due to the fact it may not be reasonable to believe that an attacker could obtain administrator-like control in most implementations involving this library. However, since that is also arguably the most subjective part of the CVSS specification, I won't press that point if you feel otherwise.

My suggestion would be to change PR:N to PR:L which comes down to a final vector of:
https://volerion.com/cvss/3.1#vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Thanks!

Dominant language
No language data
Stars
2.5k
Forks
772
Avg merge
3d 15h
Merged PRs (30d)
46

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/advisory-database

All issues in github/advisory-database

Similar issues

More Security issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.