mirror of
https://github.com/DeusData/codebase-memory-mcp.git
synced 2026-10-02 04:54:47 +08:00
GHSA-82fw-gwwq-j7x9: path traversal / arbitrary file read via the @vitest/mocker redirect mock, CVSS 5.9, affecting >= 2.1.0 < 4.1.11. graph-ui resolved 4.1.8. Development scope, and graph-ui appears nowhere in scripts/package-release.sh, so no released artifact was ever exposed. It is fixed rather than reasoned around because it is the repository's only open code-scanning alert, and the gate that is supposed to act on it cannot do its job while it stands. The manifest floor moves ^4.1.0 -> ^4.1.11 as well as the lockfile, so a fresh npm install cannot resolve back into the vulnerable range. graph-ui: npm ci clean, 47 tests across 12 files pass on 4.1.11. Split from the code-scanning gate fix deliberately. That change makes the gate able to see open alerts and fail closed; merging it while this alert is still open would block it on the very condition it exists to detect. Landing the bump first lets Scorecard rescan main (it runs on push) and clear the alert, after which the gate fix merges against a clean slate. Signed-off-by: Martin Vogel <martin.vogel.tech@gmail.com>