Request to review GHSA-46qc-4j94-54hf and add patched versions
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 52/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Domain
- security
Research direction
Start with GHSA-46qc-4j94-54hf, the @bananacool467/ui-tools release history, and the repository's security documentation. Compare the documented fixes in 0.1.9-beta, 0.2.0-beta, and 0.2.1-beta with the advisory's affected range, and verify whether 1.0.0 belongs in it. Done means the advisory accurately records the affected and patched version ranges.
Written by the indexing model from the issue text.
Description
I am requesting a review of GHSA-46qc-4j94-54hf for @bananacool467/ui-tools.
The advisory currently lists:
- Affected versions:
0.1.0-betathrough0.1.7-beta - Patched versions: None
The historical issue was an unauthenticated WebSocket terminal endpoint. This functionality was intentional, but authentication and security controls were missing from the early implementation.
The package was subsequently updated to address the issue:
- 0.1.9-beta — authentication was added before the WebSocket upgrade / PTY creation.
- 0.2.0-beta — additional security restrictions and hardening were added, including localhost defaults, origin restrictions, session ownership, connection/message/lifetime limits, environment restrictions, and configurable startup behavior.
- 0.2.1-beta — credential verification and additional execution/sandbox controls were added.
I am therefore requesting that the advisory be reviewed to determine whether these releases should be represented as patched/remediated versions rather than showing “Patched versions: None.”
I am not requesting that the historical security issue or affected versions be removed.
I am requesting that the advisory accurately represent the subsequent security fixes and release history.
There is also a separate version-data issue worth reviewing: the advisory itself lists only the eight 0.1.x-beta versions above, while some third-party security aggregators currently display 1.0.0 as affected. 1.0.0 is not listed in this GHSA.
Relevant evidence includes the package's release history and the corresponding security documentation in the repository.
Please review the advisory and determine the appropriate corrected affected/patched version ranges.
- Dominant language
- No language data
- Stars
- 2.5k
- Forks
- 772
- Avg merge
- 3d 18h
- Merged PRs (30d)
- 48
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from github/advisory-database
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/advisory-database#9255 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#9164 · 1 reaction ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#8994 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/advisory-database#8898 · 4 comments · 1 reaction ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#8841 ·
All issues in github/advisory-database
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
punkpeye/mcp-remote#369 ·
-
Mend: dependency security vulnerability untriaged
Difficulty 1/5 Under an hour Newbie friendliness 86/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 90/100
cisagov/vulnrichment#337 ·
-
bug DUP Reservations
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
bcgov/reserve-rec-public#896 ·