From e57d143391dae9eb13cfc82f9fe30fe4dd867f4b Mon Sep 17 00:00:00 2001 From: Al Snow <43523+jasnow@users.noreply.github.com> Date: Wed, 23 Sep 2026 14:01:50 -0400 Subject: [PATCH] GHSA/SYNC: 3 modified and 2 renamed advisories --- gems/mpxj/CVE-2026-61570.yml | 12 +++++++----- ...SA-7952-gx68-cjqr.yml => CVE-2026-65829.yml} | 11 ++++++++--- ...SA-4825-p4xm-pcf2.yml => CVE-2026-94462.yml} | 17 ++++++++++++----- 3 files changed, 27 insertions(+), 13 deletions(-) rename gems/mpxj/{GHSA-7952-gx68-cjqr.yml => CVE-2026-65829.yml} (61%) rename gems/spree_api/{GHSA-4825-p4xm-pcf2.yml => CVE-2026-94462.yml} (78%) diff --git a/gems/mpxj/CVE-2026-61570.yml b/gems/mpxj/CVE-2026-61570.yml index 44006058ce..8618ecdf0f 100644 --- a/gems/mpxj/CVE-2026-61570.yml +++ b/gems/mpxj/CVE-2026-61570.yml @@ -2,7 +2,7 @@ gem: mpxj cve: 2026-61570 ghsa: 5vvx-3h34-f3gj -url: https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-61570 +url: https://nvd.nist.gov/vuln/detail/CVE-2026-61570 title: XXE Vulnerability in MerlinReader date: 2026-06-22 description: | @@ -30,11 +30,13 @@ patched_versions: - ">= 16.4.1" related: url: - - https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-61570 + - https://nvd.nist.gov/vuln/detail/CVE-2026-61570 - https://rubygems.org/gems/mpxj/versions/16.4.1 - https://github.com/joniles/mpxj/releases/tag/v16.4.1 + - https://github.com/joniles/mpxj/blob/master/CHANGELOG.md#1641-2026-06-22 + - https://osv.dev/vulnerability/GHSA-5vvx-3h34-f3gj - https://github.com/joniles/mpxj/security/advisories/GHSA-5vvx-3h34-f3gj + - https://github.com/advisories/GHSA-5vvx-3h34-f3gj notes: | - - CVE is reserved, but not published. - - cvss_v3 value from GHSA. - - data from gem release date. + - cvss_v3 from GHSA and nvd.nist.gov URLs. + - date from gem release date. diff --git a/gems/mpxj/GHSA-7952-gx68-cjqr.yml b/gems/mpxj/CVE-2026-65829.yml similarity index 61% rename from gems/mpxj/GHSA-7952-gx68-cjqr.yml rename to gems/mpxj/CVE-2026-65829.yml index 5f4095e81b..58b323479d 100644 --- a/gems/mpxj/GHSA-7952-gx68-cjqr.yml +++ b/gems/mpxj/CVE-2026-65829.yml @@ -1,7 +1,8 @@ --- gem: mpxj +cve: 2026-65829 ghsa: 7952-gx68-cjqr -url: https://github.com/joniles/mpxj/security/advisories/GHSA-7952-gx68-cjqr +url: https://nvd.nist.gov/vuln/detail/CVE-2026-65829 title: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers date: 2026-07-03 @@ -21,9 +22,13 @@ patched_versions: - ">= 16.5.0" related: url: + - https://nvd.nist.gov/vuln/detail/CVE-2026-65829 - https://rubygems.org/gems/mpxj/versions/16.5.0 - https://github.com/joniles/mpxj/releases/tag/v16.5.0 + - https://github.com/joniles/mpxj/blob/master/CHANGELOG.md#1650-2026-07-03 + - https://github.com/joniles/mpxj/commit/4347315afab1ef5a2907978a754fbc5b0ff58e6f - https://github.com/joniles/mpxj/security/advisories/GHSA-7952-gx68-cjqr + - https://github.com/advisories/GHSA-7952-gx68-cjqr notes: | - - No CVE. - - cvss_v3 value from GHSA + - cvss_v3 from GHSA and nvd.nist.gov URLs. + - date from rubygems.org URL. diff --git a/gems/spree_api/GHSA-4825-p4xm-pcf2.yml b/gems/spree_api/CVE-2026-94462.yml similarity index 78% rename from gems/spree_api/GHSA-4825-p4xm-pcf2.yml rename to gems/spree_api/CVE-2026-94462.yml index 596bd558c2..55894375fa 100644 --- a/gems/spree_api/GHSA-4825-p4xm-pcf2.yml +++ b/gems/spree_api/CVE-2026-94462.yml @@ -1,7 +1,8 @@ --- gem: spree_api +cve: 2026-94462 ghsa: 4825-p4xm-pcf2 -url: https://github.com/spree/spree/security/advisories/GHSA-4825-p4xm-pcf2 +url: https://nvd.nist.gov/vuln/detail/CVE-2026-94462 title: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR) date: 2026-07-20 description: | @@ -53,13 +54,19 @@ patched_versions: - ">= 5.5.4" related: url: + - https://nvd.nist.gov/vuln/detail/CVE-2026-94462 - https://rubygems.org/gems/spree_api/versions/5.5.4 - - https://github.com/spree/spree/releases/tag/v5.5.4 + - https://github.com/spree/spree/releases/tag/v5.5.4 + - https://github.com/spree/spree/commit/af0d1a2d582a60d179de65b7d3ea024cb26426a8 - https://rubygems.org/gems/spree_api/versions/5.4.4 - - https://github.com/spree/spree/releases/tag/v5.4.4 + - https://github.com/spree/spree/releases/tag/v5.4.4 + - https://github.com/spree/spree/commit/8834230a1f47bb5988f23f45dbd162776cf592bd + - https://github.com/spree/spree/pull/14314 + - https://advisories.gitlab.com/gem/spree_api/CVE-2026-94462 + - https://osv.dev/vulnerability/GHSA-4825-p4xm-pcf2 - https://github.com/spree/spree/security/advisories/GHSA-4825-p4xm-pcf2 + - https://github.com/advisories/GHSA-4825-p4xm-pcf2 notes: | - NOTE: Gem name is "spree_api" but repo name is "spree". - - cvss_v3 from project GHSA - - No CVE in project GHSA + - cvss_v3 from GHSA and nvd.nist.gov URLs. - date field is rubygems.org release date.