Skip to content

fix(security): adm-zip >=0.6.0 + exact host matching in mitm DNS test - #7732

Merged
diegosouzapw merged 1 commit into
release/v3.8.49from
fix/sec-alerts-adm-zip-codeql-release
Jul 19, 2026
Merged

diegosouzapw merged 1 commit into
release/v3.8.49from
fix/sec-alerts-adm-zip-codeql-release

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Addresses Dependabot #106 and CodeQL code-scanning alerts on release/v3.8.49.

adm-zip (Dependabot #106, high, dev-scope)

Crafted-ZIP 4GB-allocation advisory. adm-zip is a dev-only transitive dependency (promptfoo → onnxruntime-node, pinned ^0.5.16). Added an npm overrides entry forcing ^0.6.0; regenerated the lockfile (npm install --package-lock-only → found 0 vulnerabilities). onnxruntime-node still resolves and only uses adm-zip to extract its own trusted prebuilt binary — never attacker-controlled input.

CodeQL js/incomplete-url-substring-sanitization (#743, #744, #745)

Test doubles in tests/unit/mitm-dns-graceful-degrade-6127.test.ts used substring .includes() on host strings. Switched to exact (h === "custom.example.com") and suffix (h.endsWith(".googleapis.com")) matching. Edits are line-neutral; test stays green (8/8).

Note on CodeQL #742 (liveZone js/insufficient-password-hash)

Separate false positive — dismissed via the code-scanning API with justification (all synthetic no-auth credential fields are null; the sha256 is a content-addressable cache key, not password-at-rest hashing). That file does not exist on main.

Regression: node --import tsx/esm --test tests/unit/mitm-dns-graceful-degrade-6127.test.ts → 8/8 pass.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@diegosouzapw
diegosouzapw force-pushed the fix/sec-alerts-adm-zip-codeql-release branch from 0f297e0 to 86a9e4f Compare July 19, 2026 13:10
@diegosouzapw

Copy link
Copy Markdown
Owner Author

Merging — adm-zip 0.5.18→0.6.0 override clears the crafted-ZIP advisory and the mitm DNS test now asserts exact/suffix host matching (CodeQL js/incomplete-url-substring-sanitization). Validated in local merge-train @ 65768d6e9 (FAST gates green). Stale per-PR CI reds were the shared stryker base-red on the tip, now cleared (07b2cf9).

@diegosouzapw
diegosouzapw merged commit 3c30607 into release/v3.8.49 Jul 19, 2026
9 of 10 checks passed
@diegosouzapw
diegosouzapw deleted the fix/sec-alerts-adm-zip-codeql-release branch July 19, 2026 21:01
HouMinXi pushed a commit to HouMinXi/OmniRoute that referenced this pull request Aug 2, 2026
diegosouzapw added a commit that referenced this pull request Sep 15, 2026
Dependabot #214 (GHSA-vwc7-r8mq-g2x9 / CVE-2026-76845, moderate): adm-zip
0.5.9–0.6.0 follows a symlink that already exists inside the extraction root
and writes through it, outside the root. The advisory still reports
`first_patched_version: null`, but 0.6.1 (published after the advisory) is the
fix — `util/utils.js` gains `assertPathSafe`, which walks every path component
below the root with `lstat` and throws on a symlink; `extractAllTo` calls it
before every write. Verified by diffing the two tarballs.

Reach in this repo: adm-zip is pulled only by `onnxruntime-node` (an
optionalDependency, itself pinned by override) and used only in its install
script to unpack the vendor's own runtime binary. No request path touches it.

The override already existed at ^0.6.0 (PR #7732, the previous adm-zip CVE);
this just raises the floor. Lockfile moves 0.6.0 → 0.6.1, nothing else.
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
Dependabot diegosouzapw#214 (GHSA-vwc7-r8mq-g2x9 / CVE-2026-76845, moderate): adm-zip
0.5.9–0.6.0 follows a symlink that already exists inside the extraction root
and writes through it, outside the root. The advisory still reports
`first_patched_version: null`, but 0.6.1 (published after the advisory) is the
fix — `util/utils.js` gains `assertPathSafe`, which walks every path component
below the root with `lstat` and throws on a symlink; `extractAllTo` calls it
before every write. Verified by diffing the two tarballs.

Reach in this repo: adm-zip is pulled only by `onnxruntime-node` (an
optionalDependency, itself pinned by override) and used only in its install
script to unpack the vendor's own runtime binary. No request path touches it.

The override already existed at ^0.6.0 (PR diegosouzapw#7732, the previous adm-zip CVE);
this just raises the floor. Lockfile moves 0.6.0 → 0.6.1, nothing else.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant