Repository advisory published 5 weeks ago: CVE request accepted but never assigned, not in the Advisory Database #209436
Unanswered
douglasborthwick-crypto
asked this question in
Code Security
Replies: 1 comment
|
Hi! Since it has already been 5 weeks, I would try contacting GitHub’s security advisory team directly at security-advisories@github.com. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
🏷️ Discussion Type
Question
💬 Feature/Topic Area
Supply chain security
Discussion Details
We published repository security advisory GHSA-jg6q-3qfh-r9f8 on 2026-08-28 (insumerapi/mppx-condition-gate) and requested a CVE through the advisory UI on 2026-08-29. The request was accepted, but five weeks later
cve_idis still empty and the advisory has not appeared in the GitHub Advisory Database (github.com/advisories/GHSA-jg6q-3qfh-r9f8 returns 404). As a result npm audit and Dependabot do not flag the affected versions.The repository was transferred from a personal account to the insumerapi organization on 2026-09-25, after the request. Could the transfer have detached the advisory from the review queue?
Affected: @insumermodel/mppx-condition-gate <= 2.0.3 (fixed 3.0.0) and @insumermodel/mppx-token-gate <= 1.0.3 (fixed 1.0.4), npm. Severity high, CWE-290 / CWE-863. Every affected version is already deprecated on npm with a pointer to the advisory.
Support closed our ticket (#4819808) and pointed us here. Is there a way to get the CVE request and Advisory Database review looked at?
All reactions