Repository advisory GHSA-7v25-vcp6-4hcr not in global Advisory Database
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 30/100
調査の方向性
This is a request for the GitHub Advisory Database curation team to review a published repository advisory for inclusion. The issue is about process and database synchronization, not code changes. A newcomer would need to understand the advisory database ingestion pipeline, the criteria for inclusion, and how to escalate a stuck advisory. Check the repository's contribution guidelines and existing similar issues to see how curation requests are handled. 'Done' means the advisory appears in the global database.
索引モデルが issue の本文から書いたものです。
説明
Summary
I maintain tumf/mcp-shell-server. Repository advisory GHSA-7v25-vcp6-4hcr was published on 2026-09-19 and remains absent from the global GitHub Advisory Database more than 72 hours later.
Advisory
- Repository advisory: https://github.com/tumf/mcp-shell-server/security/advisories/GHSA-7v25-vcp6-4hcr
- Package:
mcp-shell-server(pip) - Affected versions:
<= 1.1.11 - Patched version:
1.1.12 - CWE: CWE-88
- Severity: High
- Reporter credit: accepted
The advisory describes Git global options with separated values causing the validator to misidentify the subcommand, allowing persistent git config writes and later command execution when git is allowlisted. Version 1.1.12 fixes the affected parser state.
Current state
- Repository advisory state:
published cve_id:nullsubmission.accepted:falseGET /advisories/GHSA-7v25-vcp6-4hcr:404 Not Found- Advisory
updated_at:2026-09-19T01:21:39Z
Request
Could the curation team review this published repository advisory for inclusion in the global GitHub Advisory Database?
I have not requested a CVE because database inclusion and CVE assignment are separate. If a CVE or additional information is required for curation, please advise.
- 主要言語
- 言語のデータがありません
- スター
- 2.5k
- フォーク
- 772
- 平均マージ
- 3日 15時間
- マージ済み PR(30日)
- 46
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
github/advisory-database のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
github/advisory-database#9255 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
github/advisory-database#9164 · リアクション 1 件 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
github/advisory-database#8994 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
github/advisory-database#8898 · コメント 4 件 · リアクション 1 件 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
github/advisory-database#8841 ·
github/advisory-database の issue をすべて見る
似ている issue
-
needs-triage
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
-
Nmap
難易度 1/5 1時間未満 初心者へのやさしさ 85/100
-
Mend: dependency security vulnerability untriaged
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
-
blocklist removal
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
MetaMask/eth-phishing-detect#296544 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
Azure/azure-functions-docker#1257 ·