-
Notifications
You must be signed in to change notification settings - Fork 62
Open
@mend-bolt-for-github
Description
CVE-2025-9287 - High Severity Vulnerability
Vulnerable Library - cipher-base-1.0.4.tgz
abstract base class for crypto-streams
Library home page: https://registry.npmjs.org/cipher-base/-/cipher-base-1.0.4.tgz
Path to dependency file: /ui/package.json
Path to vulnerable library: /ui/package.json
Dependency Hierarchy:
- @postgres.ai/shared-4.0.0.tgz (Root Library)
- crypto-browserify-3.12.0.tgz
- create-hmac-1.1.7.tgz
- ❌ cipher-base-1.0.4.tgz (Vulnerable Library)
- create-hmac-1.1.7.tgz
- crypto-browserify-3.12.0.tgz
Found in base branch: master
Vulnerability Details
Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4.
Publish Date: 2025年08月20日
URL: CVE-2025-9287
CVSS 3 Score Details (8.7)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Origin: GHSA-cpq7-6gpm-g9rc
Release Date: 2025年08月20日
Fix Resolution: cipher-base - 1.0.4
Step up your Open Source Security Game with Mend here