incidents: add INC-138..INC-147 — ten GenAI tooling CVEs (LMDeploy, vLLM, SQLBot, Contentful MCP) - #183
Merged
Conversation
Eleven published CVEs in GenAI tooling, each with a named affected version, a maintainer advisory and a fix release: three in LMDeploy (two pickle deserialisation RCEs, one eval() of a model config value), three in vLLM (two multimodal resource-exhaustion DoS, one revision pin not propagated), four in SQLBot (file write to code execution, stored XSS, two SQL injections), and one in the Contentful MCP server (LLM-controlled host argument leaking the management token). All are incident_class tooling-cve with mapping_status draft. Severity is transcribed from the CNA's published CVSS base severity, and each record states that NVD carries it as a secondary metric and has not analysed it. INC-143 states that its CNA is VulnCheck, not the vendor, and that its sources disagree on the affected range. Eight records carry a drafted control failure against an OWASP ASVS control, each with a verbatim basis from the vendor advisory and an empty confirmed_by. INC-137 is left free for a parallel PR. Regenerated with generate.js and npm run stats. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
data/incidents.json: main's records through INC-137, then this branch's INC-138..148 appended unchanged. Generated files (entries, docs/*.js, stats, README stats) taken from main and regenerated with generate.js + npm run stats rather than hand-resolved. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Maintainer decision: the stored XSS via an SVG logo upload qualifies as a CVE in GenAI tooling, but nothing about it is AI-specific and its only mapping (DSGAI12) rested on the product type, not the mechanism. It is removed, and the three records after it are renumbered so ids stay contiguous: INC-146 -> INC-145, INC-147 -> INC-146, INC-148 -> INC-147. No record referenced the old ids. Regenerated with generate.js + npm run stats. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
emmanuelgjr
added a commit
that referenced
this pull request
Oct 3, 2026
…e current version (#185) #123 translated all three ASVS mapping files to 5.0.0 identifiers, but the framework kept the name "OWASP ASVS 4.0.3" in titles, README tables, the registry, the generator/grammar/report keys, and so in every export and the webapp. 5.0.0 is the latest versioned release; ASVS's `latest` tag is its Bleeding Edge build. - 26 counted replacements across 17 hand-written files (script asserts each count): ASVS file titles, intro links and references; "14 chapters" -> 17 (V1–V17 in 5.0.0); README + de/es/ja; RATIONALE; llms.txt; ai-standards-crosswalk page; LLM_AITG reference; keys in generate.js, control-ids.js, compliance-report.js; owasp-asvs.json and framework-sources.json names. - incidents.json: six control_failures from #183 (INC-138/139/140/ 145/146/147) cite 5.0.0 ids under the old name (V1.2.4 SQLi, V1.3.2 eval, V1.3.6 SSRF, V1.5 deserialization, checked against 0x10-V1-Encoding-and-Sanitization.md at v5.0.0_release); label fixed. - Regenerated entries, backlinks and webapp bundles: line-for-line label swaps, stats.json unchanged. - Kept at 4.0.3 on purpose: CHANGELOG history, the translation report, the 24 retained-row markers, and docs/classifier-predictions.js (an April classifier snapshot whose ids are 4.0.3 chapters). - CHANGELOG: "Changed" entry, since export consumers filtering by framework name must update the string. Co-authored-by: sim <sim@local> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Eleven watcher-surfaced CVEs in GenAI tooling, triaged under the CVEs section of
docs/TRIAGE_RULES.md.Every one names an affected version and has a citable maintainer advisory (GHSA) and a fix release. None was dropped.
Closes #145
Closes #152
Closes #153
Closes #146
Closes #147
Closes #177
Closes #148
Closes #150
Closes #151
Closes #154
All records:
incident_class: "tooling-cve",mapping_status: "draft",category: "research-demonstrated"(INC-132..135 precedent). INC-137 is left free for the parallel PR.
The records
recv_pyobjpickle RCEeval()of modelquant_dtypepg_read_fileCOPY TO PROGRAMEntry mapping is DRAFT
owasp_entriesis a proposal pending SME review (C4), kept narrow:The weakest fit is INC-145 (stored XSS in the SQLBot UI): DSGAI12 is there because of the product class, not the
mechanism. A reviewer may prefer another entry, or to reject the record as not AI-relevant.
Control failures: eight drafted, three omitted
Each drafted failure quotes the vendor advisory verbatim (
source_url= the GHSA), hasconfirmed_by: [], andthe record carries
draft-evidence. Two quotes (INC-146) had markdown bold in the source; the emphasis markers weredropped, the words were not changed. The control choices are OWASP ASVS ids that exist in the registry:
V1.5 Safe Deserialization, V1.3.2 avoid
eval(), V1.3.5 sanitise scriptable content, V1.2.4 parameterised queries,V1.3.6 SSRF allow-listing. Choosing the control is a judgment and waits for confirmation like any draft.
Omitted, and why:
memory reservation computed from static config only), but these are product-internal resource budgets and no
registry control matches them without stretching.
6.1.3 integrity verification) are not what the advisory says failed.
the registry has no file-path or storage-location control (only file size and section-level V5 ids).
npm run validatenow emits five new orphan-evidence warnings (89 → 94 on current main): the ASVS controls above are not mappedfrom the drafted entries. That is expected and is the human call the warning asks for — I did not add mappings.
Provenance, stated plainly
metric; NVD has Deferred, Awaiting or Undergoing Analysis on all eleven. Each record says so.
The record transcribes Medium because CVSS 3.1 is the only score the vendor advisory (GHSA-hhv2-872h-628q)
carries and the two agree on it. Maintainer judgment: if the rule should be "use the newest CVSS version the CNA
publishes", this becomes High. The GitHub advisory database auto-imported the CVE as an unreviewed advisory
(GHSA-r3cf-2wgr-7xh9) rated high; not cited.
the fix; the GHSA lists
>= 0.22.1, <= 0.28.0affected with 0.28.0 patched, and says the lower bound may be 0.21.0.I checked the v0.28.0 tag: the FunAudioChat loads pass
revision=there, so 0.28.0 is fixed. NVD's commitreference (
d26a28ab) is the earlier CVE-2026-47155 fix, as the advisory itself says; it is not cited.advisories carry a bare "High" label with no vector. The records transcribe the CVSS base severity, so INC-145 and
INC-146 are Medium although the repository advisory says High. The advisories are not in the reviewed GitHub
advisory database (no package ecosystem).
unauthenticated by default. Stated in the record.
2026-06-01); the repository advisory itself only lists the tested versions (
<= 1.7.15/<= 0.4.1) with no patchedversion. Stated in the record.
(2026-09-16). Stated in the record.
repository advisory — the same standing as INC-133 / INC-134. INC-138's control-failure basis uses the
maintainer assessment section rather than the reporter's first-person text.
Relation to INC-085 (ShadowMQ) — not cross-referenced
INC-138 and INC-139 are the same class as INC-085 (pickle over ZeroMQ in inference servers), but neither advisory
mentions ShadowMQ or CVE-2024-50050, so the records do not link it. Flagging for the maintainer in case a
cross-reference is wanted.
Verification
the GitHub API (repository advisory and global advisory database); every fix release tag confirmed to exist.
basischecked programmatically against the advisory text.node scripts/generate.js+npm run stats(no hand edits to generated files).npm run validate: 0 errors, 94 warnings (89 on main; +5 orphan-evidence warnings described above), 328 passed.npm run stats:check: current.npm test: 89/89.npm run audit:incidents: 148 incidents, 0 advisory-style, 25 with control failures.Merge-order note
Resolved: main (with #182, INC-137) is merged into this branch and the generated files were regenerated on
top (head 2ce30f4). The corpus reads INC-137 followed by INC-138..INC-148; the checks above were re-run on that head.
🤖 Generated with Claude Code