Skip to content

[GHSA-f29h-pxvx-f335] eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, napi-postinstall have embedded malicious code #5842

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Conversation

ocsurfnut
Copy link

Updates

  • CVSS v3
  • Severity

Comments
I'd recommend Critical severity, since this represents a attack vector on Windows PCs, and Critical would be more likely to block pipelines and automated updates.

@github-actions github-actions bot changed the base branch from main to ocsurfnut/advisory-improvement-5842 July 22, 2025 19:11
@helixplant
Copy link

Hi @ocsurfnut,
I understand that the targeting of Windows machines with malware makes this vulnerability concerning for a large population of users. However, vulnerability severity concerns the severity of a vulnerability when exploitation occurs, not the likelihood of exploitation occurring in the first place. The GitHub Advisory Database supports the Exploit Prediction Scoring System (EPSS), which does assess the likelihood of future exploitation.

My colleagues and I believe that the CVSS 3.1 value provided by MITRE, the CNA that issued the CVE, is accurate and provides a reasonable assessment of the severity of the vulnerability. If you have a different assessment of severity based on CVSS 3.1 or CVSS 4.0, you can request a change to the CVE record and contact MITRE, the assigning CNA, at https://cveform.mitre.org/ with your concerns about the CVSS. Thank you for taking the time to make the open source community safer!

@helixplant helixplant closed this Jul 23, 2025
@github-actions github-actions bot deleted the ocsurfnut-GHSA-f29h-pxvx-f335 branch July 23, 2025 14:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants
pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy