Repository advisory published 5 weeks ago: CVE request accepted but never assigned, not in the Advisory Database #209435
Replies: 1 comment
|
Thank you for your interest in contributing to our community! We currently only accept discussions created through the GitHub UI using our provided discussion templates. Please re-submit your discussion by navigating to the appropriate category and using the template provided. This discussion has been closed because it was not submitted through the expected format. If you believe this was a mistake, please reach out to the maintainers. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
We published repository security advisory GHSA-jg6q-3qfh-r9f8 on 2026-08-28 (insumerapi/mppx-condition-gate) and requested a CVE through the advisory UI on 2026-08-29. The request was accepted, but five weeks later
cve_idis still empty and the advisory has not appeared in the GitHub Advisory Database (github.com/advisories/GHSA-jg6q-3qfh-r9f8 returns 404). As a result npm audit and Dependabot do not flag the affected versions.The repository was transferred from a personal account to the insumerapi organization on 2026-09-25, after the request. Could the transfer have detached the advisory from the review queue?
Affected: @insumermodel/mppx-condition-gate <= 2.0.3 (fixed 3.0.0) and @insumermodel/mppx-token-gate <= 1.0.3 (fixed 1.0.4), npm. Severity high, CWE-290 / CWE-863. Every affected version is already deprecated on npm with a pointer to the advisory.
Support closed our ticket (#4819808) and pointed us here. Is there a way to get the CVE request and Advisory Database review looked at?
All reactions