Skip to content

incidents: add INC-138..INC-147 — ten GenAI tooling CVEs (LMDeploy, vLLM, SQLBot, Contentful MCP) - #183

Merged
emmanuelgjr merged 3 commits into
mainfrom
triage/cve-records-2026-09
Oct 1, 2026
Merged

emmanuelgjr merged 3 commits into
mainfrom
triage/cve-records-2026-09

Conversation

@emmanuelgjr

@emmanuelgjr emmanuelgjr commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Maintainer changes (2026-09-30, after this description was written).

  • CVE-2026-53555 (SQLBot stored XSS) dropped. It qualifies as a CVE in GenAI tooling, but nothing about it is AI-specific and its only mapping rested on the product type. Issue [new-cve] CVE-2026-53555 — SQLBot is an intelligent Text-to-SQL system based on large language models and R #149 is closed as noted, not by this PR.
  • Renumbered so ids stay contiguous: INC-146 → INC-145, INC-147 → INC-146, INC-148 → INC-147. In the tables below, read the old ids accordingly; the INC-145 row there is the dropped record.
  • INC-143 severity confirmed as Medium (CVSS 3.1) by the maintainer: it is the score in the vendor advisory and the CNA agrees.
  • Now 10 records, INC-138..INC-147. Branch merged with main (INC-137) and regenerated. Local: validate 0 errors / 93 warnings, stats:check current, 89/89 tests.

Eleven watcher-surfaced CVEs in GenAI tooling, triaged under the CVEs section of docs/TRIAGE_RULES.md.
Every one names an affected version and has a citable maintainer advisory (GHSA) and a fix release. None was dropped.

Closes #145
Closes #152
Closes #153
Closes #146
Closes #147
Closes #177
Closes #148
Closes #150
Closes #151
Closes #154

All records: incident_class: "tooling-cve", mapping_status: "draft", category: "research-demonstrated"
(INC-132..135 precedent). INC-137 is left free for the parallel PR.

The records

id CVE product affected → fixed severity (source) CNA NVD status control_failures
INC-138 CVE-2025-59953 LMDeploy, AsyncRPCServer pickle RCE 0.9.1 → 0.10.2 Critical 9.8 (CNA, CVSS 3.1) GitHub Deferred yes — ASVS V1.5
INC-139 CVE-2025-66455 LMDeploy, DistServe recv_pyobj pickle RCE 0.9.2 → 0.16.0 Critical 9.8 (CNA, CVSS 3.1) GitHub Awaiting Analysis yes — ASVS V1.5
INC-140 CVE-2026-33625 LMDeploy, eval() of model quant_dtype 0.12.1–0.12.2 → 0.12.3 High 8.8 (CNA, CVSS 3.1) GitHub Deferred yes — ASVS V1.3.2
INC-141 CVE-2026-57173 vLLM, chat audio decode OOM < 0.24.0 → 0.24.0 Medium 6.5 (CNA, CVSS 3.1) GitHub Undergoing Analysis no
INC-142 CVE-2026-69147 vLLM, request-selected GPU video decoder < 0.28.0 → 0.28.0 Medium 6.5 (CNA, CVSS 3.1) GitHub Awaiting Analysis no
INC-143 CVE-2026-100653 vLLM, revision pin not propagated 0.22.1 → 0.28.0 (see caveats) Medium 6.5 (CNA, CVSS 3.1) VulnCheck Awaiting Analysis no
INC-144 CVE-2026-53554 SQLBot, upload path → Alembic module exec < 1.9.0 → 1.9.0 High 7.3 (CNA, CVSS 4.0) GitHub Deferred no
INC-145 CVE-2026-53555 SQLBot, stored XSS via SVG < 1.9.0 → 1.9.0 Medium 5.1 (CNA, CVSS 4.0) GitHub Deferred yes — ASVS V1.3.5
INC-146 CVE-2026-53556 SQLBot, previewData SQLi → pg_read_file < 1.9.0 → 1.9.0 Medium 6.0 (CNA, CVSS 4.0) GitHub Deferred yes — ASVS V1.2.4
INC-147 CVE-2026-53557 SQLBot, second-order SQLi → COPY TO PROGRAM < 1.9.0 → 1.9.0 High 7.7 (CNA, CVSS 4.0) GitHub Deferred yes — ASVS V1.2.4
INC-148 CVE-2026-53957 Contentful MCP server, LLM-controlled host leaks token mcp-server < 1.7.19, mcp-tools < 0.4.5 High 7.7 (CNA, CVSS 3.1) GitHub Deferred yes — ASVS V1.3.6

Entry mapping is DRAFT

owasp_entries is a proposal pending SME review (C4), kept narrow:

ids proposed reasoning
INC-138, INC-139 LLM04 Vulnerable component in the model-serving stack
INC-140 LLM04, DSGAI04 Malicious model artifact, as INC-009
INC-141, INC-142 LLM06 Resource exhaustion of the inference service
INC-143 LLM04 Model artifact provenance / pinning
INC-144, INC-145, INC-147 DSGAI12 Text-to-SQL gateway and its datasources
INC-146 DSGAI12, DSGAI01 As above, plus disclosure of server files and credentials
INC-148 LLM01, ASI02, DSGAI02 Prompt-injection path stated in the advisory; tool misuse; agent credential exposure

The weakest fit is INC-145 (stored XSS in the SQLBot UI): DSGAI12 is there because of the product class, not the
mechanism. A reviewer may prefer another entry, or to reject the record as not AI-relevant.

Control failures: eight drafted, three omitted

Each drafted failure quotes the vendor advisory verbatim (source_url = the GHSA), has confirmed_by: [], and
the record carries draft-evidence. Two quotes (INC-146) had markdown bold in the source; the emphasis markers were
dropped, the words were not changed. The control choices are OWASP ASVS ids that exist in the registry:
V1.5 Safe Deserialization, V1.3.2 avoid eval(), V1.3.5 sanitise scriptable content, V1.2.4 parameterised queries,
V1.3.6 SSRF allow-listing. Choosing the control is a judgment and waits for confirmation like any draft.

Omitted, and why:

  • INC-141, INC-142 — the advisories do state a failed control (a duration guard not wired into one path; a GPU
    memory reservation computed from static config only), but these are product-internal resource budgets and no
    registry control matches them without stretching.
  • INC-143 — the failed control is revision pinning; the nearest registry controls (AISVS 3.1.2 signing,
    6.1.3 integrity verification) are not what the advisory says failed.
  • INC-144 — the advisory says the upload handler trusts the client filename and writes before validation, but
    the registry has no file-path or storage-location control (only file size and section-level V5 ids).

npm run validate now emits five new orphan-evidence warnings (89 → 94 on current main): the ASVS controls above are not mapped
from the drafted entries. That is expected and is the human call the warning asks for — I did not add mappings.

Provenance, stated plainly

  • No NVD score anywhere. Every severity is the CNA's own CVSS base severity, which NVD carries as a secondary
    metric; NVD has Deferred, Awaiting or Undergoing Analysis on all eleven. Each record says so.
  • INC-143 — CNA is VulnCheck, not the vendor. VulnCheck publishes CVSS 3.1 6.5 (Medium) and CVSS 4.0 8.3 (High).
    The record transcribes Medium because CVSS 3.1 is the only score the vendor advisory (GHSA-hhv2-872h-628q)
    carries and the two agree on it. Maintainer judgment: if the rule should be "use the newest CVSS version the CNA
    publishes", this becomes High. The GitHub advisory database auto-imported the CVE as an unreviewed advisory
    (GHSA-r3cf-2wgr-7xh9) rated high; not cited.
  • INC-143 — range is inconsistent at source. The CVE says "from 0.22.1 through 0.28.0" and also that 0.28.0 is
    the fix; the GHSA lists >= 0.22.1, <= 0.28.0 affected with 0.28.0 patched, and says the lower bound may be 0.21.0.
    I checked the v0.28.0 tag: the FunAudioChat loads pass revision= there, so 0.28.0 is fixed. NVD's commit
    reference (d26a28ab) is the earlier CVE-2026-47155 fix, as the advisory itself says; it is not cited.
  • SQLBot (INC-144..147) — CVSS 4.0 only. The CNA published CVSS 4.0 scores (7.3 / 5.1 / 6.0 / 7.7); the repository
    advisories carry a bare "High" label with no vector. The records transcribe the CVSS base severity, so INC-145 and
    INC-146 are Medium
    although the repository advisory says High. The advisories are not in the reviewed GitHub
    advisory database (no package ecosystem).
  • INC-141 — the vector scores privileges required as Low, although the advisory describes the endpoint as
    unauthenticated by default. Stated in the record.
  • INC-140 — the advisory classifies the weakness as CWE-95; the NVD record shows CWE-400. Stated in the record.
  • INC-148 — the CVE and the reviewed GitHub advisory database agree on fixed versions 1.7.19 / 0.4.5 (released
    2026-06-01); the repository advisory itself only lists the tested versions (<= 1.7.15 / <= 0.4.1) with no patched
    version. Stated in the record.
  • INC-138 — the fix release 0.10.2 shipped 2025-10-28, almost a year before the advisory was published
    (2026-09-16). Stated in the record.
  • Several SQLBot and LMDeploy advisory bodies are the reporter's write-up, published by the maintainers in their own
    repository advisory — the same standing as INC-133 / INC-134. INC-138's control-failure basis uses the
    maintainer assessment section rather than the reporter's first-person text.

Relation to INC-085 (ShadowMQ) — not cross-referenced

INC-138 and INC-139 are the same class as INC-085 (pickle over ZeroMQ in inference servers), but neither advisory
mentions ShadowMQ or CVE-2024-50050, so the records do not link it. Flagging for the maintainer in case a
cross-reference is wanted.

Verification

  • Each CVE re-read live from the NVD 2.0 API (score, vector, CNA, status, CWE, references); each GHSA read through
    the GitHub API (repository advisory and global advisory database); every fix release tag confirmed to exist.
  • Every quotation in a description and every basis checked programmatically against the advisory text.
  • node scripts/generate.js + npm run stats (no hand edits to generated files).
  • npm run validate: 0 errors, 94 warnings (89 on main; +5 orphan-evidence warnings described above), 328 passed.
  • npm run stats:check: current. npm test: 89/89.
  • npm run audit:incidents: 148 incidents, 0 advisory-style, 25 with control failures.

Merge-order note

Resolved: main (with #182, INC-137) is merged into this branch and the generated files were regenerated on
top (head 2ce30f4). The corpus reads INC-137 followed by INC-138..INC-148; the checks above were re-run on that head.

🤖 Generated with Claude Code

emmanuelgjr and others added 3 commits September 30, 2026 23:03
Eleven published CVEs in GenAI tooling, each with a named affected
version, a maintainer advisory and a fix release: three in LMDeploy
(two pickle deserialisation RCEs, one eval() of a model config value),
three in vLLM (two multimodal resource-exhaustion DoS, one revision pin
not propagated), four in SQLBot (file write to code execution, stored
XSS, two SQL injections), and one in the Contentful MCP server
(LLM-controlled host argument leaking the management token).

All are incident_class tooling-cve with mapping_status draft. Severity
is transcribed from the CNA's published CVSS base severity, and each
record states that NVD carries it as a secondary metric and has not
analysed it. INC-143 states that its CNA is VulnCheck, not the vendor,
and that its sources disagree on the affected range.

Eight records carry a drafted control failure against an OWASP ASVS
control, each with a verbatim basis from the vendor advisory and an
empty confirmed_by. INC-137 is left free for a parallel PR.

Regenerated with generate.js and npm run stats.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
data/incidents.json: main's records through INC-137, then this branch's
INC-138..148 appended unchanged. Generated files (entries, docs/*.js,
stats, README stats) taken from main and regenerated with generate.js +
npm run stats rather than hand-resolved.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Maintainer decision: the stored XSS via an SVG logo upload qualifies as a
CVE in GenAI tooling, but nothing about it is AI-specific and its only
mapping (DSGAI12) rested on the product type, not the mechanism. It is
removed, and the three records after it are renumbered so ids stay
contiguous: INC-146 -> INC-145, INC-147 -> INC-146, INC-148 -> INC-147.
No record referenced the old ids. Regenerated with generate.js +
npm run stats.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@emmanuelgjr emmanuelgjr changed the title incidents: add INC-138..INC-148 — eleven GenAI tooling CVEs (LMDeploy, vLLM, SQLBot, Contentful MCP) incidents: add INC-138..INC-147 — ten GenAI tooling CVEs (LMDeploy, vLLM, SQLBot, Contentful MCP) Oct 1, 2026
@emmanuelgjr
emmanuelgjr merged commit 7e1669d into main Oct 1, 2026
6 checks passed
@emmanuelgjr
emmanuelgjr deleted the triage/cve-records-2026-09 branch October 1, 2026 03:17
emmanuelgjr added a commit that referenced this pull request Oct 3, 2026
…e current version (#185)

#123 translated all three ASVS mapping files to 5.0.0 identifiers, but
the framework kept the name "OWASP ASVS 4.0.3" in titles, README tables,
the registry, the generator/grammar/report keys, and so in every export
and the webapp. 5.0.0 is the latest versioned release; ASVS's `latest`
tag is its Bleeding Edge build.

- 26 counted replacements across 17 hand-written files (script asserts
  each count): ASVS file titles, intro links and references; "14
  chapters" -> 17 (V1–V17 in 5.0.0); README + de/es/ja; RATIONALE;
  llms.txt; ai-standards-crosswalk page; LLM_AITG reference; keys in
  generate.js, control-ids.js, compliance-report.js; owasp-asvs.json and
  framework-sources.json names.
- incidents.json: six control_failures from #183 (INC-138/139/140/
  145/146/147) cite 5.0.0 ids under the old name (V1.2.4 SQLi, V1.3.2
  eval, V1.3.6 SSRF, V1.5 deserialization, checked against
  0x10-V1-Encoding-and-Sanitization.md at v5.0.0_release); label fixed.
- Regenerated entries, backlinks and webapp bundles: line-for-line label
  swaps, stats.json unchanged.
- Kept at 4.0.3 on purpose: CHANGELOG history, the translation report,
  the 24 retained-row markers, and docs/classifier-predictions.js (an
  April classifier snapshot whose ids are 4.0.3 chapters).
- CHANGELOG: "Changed" entry, since export consumers filtering by
  framework name must update the string.

Co-authored-by: sim <sim@local>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment