Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Request to review GHSA-46qc-4j94-54hf and add patched versions

Open
#9,478 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
52/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Domain
security

Research direction

Start with GHSA-46qc-4j94-54hf, the @bananacool467/ui-tools release history, and the repository's security documentation. Compare the documented fixes in 0.1.9-beta, 0.2.0-beta, and 0.2.1-beta with the advisory's affected range, and verify whether 1.0.0 belongs in it. Done means the advisory accurately records the affected and patched version ranges.

Written by the indexing model from the issue text.

Description

I am requesting a review of GHSA-46qc-4j94-54hf for @bananacool467/ui-tools.

The advisory currently lists:

  • Affected versions: 0.1.0-beta through 0.1.7-beta
  • Patched versions: None

The historical issue was an unauthenticated WebSocket terminal endpoint. This functionality was intentional, but authentication and security controls were missing from the early implementation.

The package was subsequently updated to address the issue:

  • 0.1.9-beta — authentication was added before the WebSocket upgrade / PTY creation.
  • 0.2.0-beta — additional security restrictions and hardening were added, including localhost defaults, origin restrictions, session ownership, connection/message/lifetime limits, environment restrictions, and configurable startup behavior.
  • 0.2.1-beta — credential verification and additional execution/sandbox controls were added.

I am therefore requesting that the advisory be reviewed to determine whether these releases should be represented as patched/remediated versions rather than showing “Patched versions: None.”

I am not requesting that the historical security issue or affected versions be removed.

I am requesting that the advisory accurately represent the subsequent security fixes and release history.

There is also a separate version-data issue worth reviewing: the advisory itself lists only the eight 0.1.x-beta versions above, while some third-party security aggregators currently display 1.0.0 as affected. 1.0.0 is not listed in this GHSA.

Relevant evidence includes the package's release history and the corresponding security documentation in the repository.

Please review the advisory and determine the appropriate corrected affected/patched version ranges.

Dominant language
No language data
Stars
2.5k
Forks
772
Avg merge
3d 18h
Merged PRs (30d)
48

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/advisory-database

All issues in github/advisory-database

Similar issues

More Security issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.