Skip to content

[GHSA-v6h2-p8h4-qcjw] brace-expansion Regular Expression Denial of Service vulnerability #5742

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed

Conversation

V1j2t3
Copy link

@V1j2t3 V1j2t3 commented Jun 21, 2025

Updates

  • Affected products
  • CVSS v3
  • CVSS v4

Comments
Yes

@Copilot Copilot AI review requested due to automatic review settings June 21, 2025 04:29
Copy link

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the advisory for the "[GHSA-v6h2-p8h4-qcjw] brace-expansion Regular Expression Denial of Service vulnerability" by revising metadata and severity scores. Key changes include updating the modified timestamp, replacing existing CVSS entries with a revised CVSS_V3 score, and changing the ecosystem designation from "npm" to "SwiftURL" for the affected package.

Comments suppressed due to low confidence (3)

advisories/github-reviewed/2025/06/GHSA-v6h2-p8h4-qcjw/GHSA-v6h2-p8h4-qcjw.json:20

  • Confirm that updating the 'ecosystem' field from 'npm' to 'SwiftURL' correctly reflects the affected product and that all related references are consistent.
        "ecosystem": "SwiftURL",

advisories/github-reviewed/2025/06/GHSA-v6h2-p8h4-qcjw/GHSA-v6h2-p8h4-qcjw.json:42

  • Confirm that updating the 'ecosystem' field from 'npm' to 'SwiftURL' for this advisory entry is intentional and accurately represents the affected product.
        "ecosystem": "SwiftURL",

advisories/github-reviewed/2025/06/GHSA-v6h2-p8h4-qcjw/GHSA-v6h2-p8h4-qcjw.json:14

  • The CVSS_V4 entry has been removed and the CVSS_V3 score updated; please confirm that this change accurately reflects the vulnerability severity as intended.
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N"

@github-actions github-actions bot changed the base branch from main to V1j2t3/advisory-improvement-5742 June 21, 2025 04:30
@helixplant
Copy link

Hi @V1j2t3, I am closing this PR due to the proposed changes in the CVSS scoring. Removing the system impact metrics does not properly reflect the scope of this vulnerability. Thank you for your interest in helping improve GHSA-v6h2-p8h4-qcjw and have a great day!

@helixplant helixplant closed this Jun 27, 2025
@github-actions github-actions bot deleted the V1j2t3-GHSA-v6h2-p8h4-qcjw branch June 27, 2025 15:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants