Repository navigation
Request CVE for GHSA-r7qm-wg9p-pjfc && GHSA-8qrv-mmch-fr9c #1546
ExPatch-LLC
started this conversation in
General
Replies: 2 comments
|
Requested 👍 |
0 replies
|
Thanks! |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Hi Oleksii — I'm the reporter of advisory GHSA-r7qm-wg9p-pjfc (HTML attribute injection in the HTML export, fixed in 2.47.2) && GHSA-8qrv-mmch-fr9c, credited as ExPatch LLC.
Would you be willing to request a CVE for it? GitHub can still assign one even though the advisory is already published:
Repo → Security → Advisories → open the advisory → Edit → CVE identifier section at the bottom → Request CVE. As the CNA, GitHub usually reviews within ~72h and, since the advisory is already public, the CVE record gets published automatically.
If it's easier on your side, you could instead add me as a collaborator on the advisory and I'll handle the request and any GitHub correspondence.
One note for the request: although it's currently mitigated by Discord's server-side emoji-name validation, the code itself lacks the output encoding used elsewhere, and the issue is reachable when export data comes from non-Discord sources or if Discord relaxes that validation — worth stating so GitHub treats it as eligible.
Thanks!
All reactions