Skip to content

docs(security): monitor unpatched diskcache CVE with 90-day escalation (#3446)#3980

Merged
mrveiss merged 1 commit intoDev_new_guifrom
issue-3446
Apr 8, 2026
Merged

docs(security): monitor unpatched diskcache CVE with 90-day escalation (#3446)#3980
mrveiss merged 1 commit intoDev_new_guifrom
issue-3446

Conversation

@mrveiss
Copy link
Copy Markdown
Owner

@mrveiss mrveiss commented Apr 8, 2026

Issue: diskcache <=5.6.3 has unpatched CVE (deserialization vulnerability, Dependabot alert #278).

Analysis:

  • No explicit dependency in AutoBot (transitive via LlamaIndex)
  • No AutoBot code imports diskcache directly
  • Exposure limited to write-access to cache directory (OS-protected)
  • Dismissed as tolerable_risk on 2026-04-04

Action: Document CVE status with monitoring guidance and 90-day escalation path (2026-07-07).

Closes #3446

@mrveiss mrveiss merged commit cb7165e into Dev_new_gui Apr 8, 2026
1 of 3 checks passed
@mrveiss mrveiss deleted the issue-3446 branch April 8, 2026 09:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant