Skip to content

Commit fb34fed

Browse files
authored
Merge pull request #1245 from jasnow/ghsa-syncbot-2026-09-23-11_10_43
GHSA/SYNC: 3 modified (2 of 3 were renamed) advisories @simi - Thanks for reviewing and approving this PR.
2 parents 1272ae6 + e57d143 commit fb34fed

3 files changed

Lines changed: 27 additions & 13 deletions

File tree

‎gems/mpxj/CVE-2026-61570.yml‎

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
gem: mpxj
33
cve: 2026-61570
44
ghsa: 5vvx-3h34-f3gj
5-
url: https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-61570
5+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-61570
66
title: XXE Vulnerability in MerlinReader
77
date: 2026-06-22
88
description: |
@@ -30,11 +30,13 @@ patched_versions:
3030
- ">= 16.4.1"
3131
related:
3232
url:
33-
- https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-61570
33+
- https://nvd.nist.gov/vuln/detail/CVE-2026-61570
3434
- https://rubygems.org/gems/mpxj/versions/16.4.1
3535
- https://github.com/joniles/mpxj/releases/tag/v16.4.1
36+
- https://github.com/joniles/mpxj/blob/master/CHANGELOG.md#1641-2026-06-22
37+
- https://osv.dev/vulnerability/GHSA-5vvx-3h34-f3gj
3638
- https://github.com/joniles/mpxj/security/advisories/GHSA-5vvx-3h34-f3gj
39+
- https://github.com/advisories/GHSA-5vvx-3h34-f3gj
3740
notes: |
38-
- CVE is reserved, but not published.
39-
- cvss_v3 value from GHSA.
40-
- data from gem release date.
41+
- cvss_v3 from GHSA and nvd.nist.gov URLs.
42+
- date from gem release date.
Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,8 @@
11
---
22
gem: mpxj
3+
cve: 2026-65829
34
ghsa: 7952-gx68-cjqr
4-
url: https://github.com/joniles/mpxj/security/advisories/GHSA-7952-gx68-cjqr
5+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-65829
56
title: Potential Path Traversal Vulnerability in Primavera P3 PRX and
67
SureTrak STX readers
78
date: 2026-07-03
@@ -21,9 +22,13 @@ patched_versions:
2122
- ">= 16.5.0"
2223
related:
2324
url:
25+
- https://nvd.nist.gov/vuln/detail/CVE-2026-65829
2426
- https://rubygems.org/gems/mpxj/versions/16.5.0
2527
- https://github.com/joniles/mpxj/releases/tag/v16.5.0
28+
- https://github.com/joniles/mpxj/blob/master/CHANGELOG.md#1650-2026-07-03
29+
- https://github.com/joniles/mpxj/commit/4347315afab1ef5a2907978a754fbc5b0ff58e6f
2630
- https://github.com/joniles/mpxj/security/advisories/GHSA-7952-gx68-cjqr
31+
- https://github.com/advisories/GHSA-7952-gx68-cjqr
2732
notes: |
28-
- No CVE.
29-
- cvss_v3 value from GHSA
33+
- cvss_v3 from GHSA and nvd.nist.gov URLs.
34+
- date from rubygems.org URL.
Lines changed: 12 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,8 @@
11
---
22
gem: spree_api
3+
cve: 2026-94462
34
ghsa: 4825-p4xm-pcf2
4-
url: https://github.com/spree/spree/security/advisories/GHSA-4825-p4xm-pcf2
5+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-94462
56
title: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)
67
date: 2026-07-20
78
description: |
@@ -53,13 +54,19 @@ patched_versions:
5354
- ">= 5.5.4"
5455
related:
5556
url:
57+
- https://nvd.nist.gov/vuln/detail/CVE-2026-94462
5658
- https://rubygems.org/gems/spree_api/versions/5.5.4
57-
- https://github.com/spree/spree/releases/tag/v5.5.4
59+
- https://github.com/spree/spree/releases/tag/v5.5.4
60+
- https://github.com/spree/spree/commit/af0d1a2d582a60d179de65b7d3ea024cb26426a8
5861
- https://rubygems.org/gems/spree_api/versions/5.4.4
59-
- https://github.com/spree/spree/releases/tag/v5.4.4
62+
- https://github.com/spree/spree/releases/tag/v5.4.4
63+
- https://github.com/spree/spree/commit/8834230a1f47bb5988f23f45dbd162776cf592bd
64+
- https://github.com/spree/spree/pull/14314
65+
- https://advisories.gitlab.com/gem/spree_api/CVE-2026-94462
66+
- https://osv.dev/vulnerability/GHSA-4825-p4xm-pcf2
6067
- https://github.com/spree/spree/security/advisories/GHSA-4825-p4xm-pcf2
68+
- https://github.com/advisories/GHSA-4825-p4xm-pcf2
6169
notes: |
6270
- NOTE: Gem name is "spree_api" but repo name is "spree".
63-
- cvss_v3 from project GHSA
64-
- No CVE in project GHSA
71+
- cvss_v3 from GHSA and nvd.nist.gov URLs.
6572
- date field is rubygems.org release date.

0 commit comments

Comments
 (0)