Skip to content

Add CVSS 3.1 severity for GHSA-r67w-f99w-mgxj#6877

Open
sunnypatell wants to merge 1 commit intogithub:sunnypatell/advisory-improvement-6877from
sunnypatell:cvss-GHSA-r67w-f99w-mgxj
Open

Add CVSS 3.1 severity for GHSA-r67w-f99w-mgxj#6877
sunnypatell wants to merge 1 commit intogithub:sunnypatell/advisory-improvement-6877from
sunnypatell:cvss-GHSA-r67w-f99w-mgxj

Conversation

@sunnypatell
Copy link

Changes

Added CVSS 3.1 scoring to GHSA-r67w-f99w-mgxj (Embedchain ReDoS in JSON loader).

  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (7.5 High)

CVSS justification

  • AV:N - an attacker can supply malicious input strings remotely via any data ingestion path
  • AC:L/PR:N/UI:N - no authentication or special conditions needed; the vulnerable regex is triggered during normal JSON loading
  • A:H - a crafted long string causes catastrophic backtracking in the regex, blocking the event loop and making the service unresponsive

References

Copilot AI review requested due to automatic review settings February 13, 2026 20:57
@github-actions github-actions bot changed the base branch from main to sunnypatell/advisory-improvement-6877 February 13, 2026 20:58
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request adds CVSS 3.1 severity scoring to the GitHub Security Advisory GHSA-r67w-f99w-mgxj, which documents a Regular Expression Denial of Service (ReDoS) vulnerability in the Embedchain JSON loader (CVE-2024-23732). The CVSS vector string indicates a base score of 7.5 (HIGH severity) for this availability-impacting vulnerability.

Changes:

  • Added CVSS 3.1 severity scoring with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H to the advisory JSON file

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +11 to +16
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
Copy link

Copilot AI Feb 13, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The CVSS 3.1 vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H calculates to a base score of 7.5, which is classified as HIGH severity (7.0-8.9 range), not MODERATE. However, the database_specific.severity field at line 60 still shows "MODERATE". This field should be updated to "HIGH" to match the CVSS score. All other advisories in the repository with this same CVSS vector have "HIGH" severity in their database_specific section.

Copilot uses AI. Check for mistakes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant