Skip to content

[GHSA-rh9f-gr6q-mpc4] moonshine Stored Cross-Site Scripting Vulnerability in Create Admin - #9613

Open
nikpivkin wants to merge 1 commit into
nikpivkin/advisory-improvement-9613from
nikpivkin-GHSA-rh9f-gr6q-mpc4
Open

nikpivkin wants to merge 1 commit into
nikpivkin/advisory-improvement-9613from
nikpivkin-GHSA-rh9f-gr6q-mpc4

Conversation

@nikpivkin

Copy link
Copy Markdown

Updates

  • Affected products

Comments
The first patched version should be 3.12.4, not 3.12.14. The vulnerable range < 3.12.4 is correct and does not need a change.

The fix commit linked in the advisory is moonshine-software/moonshine@f108f4e. Tag 3.12.4 contains it and tag 3.12.3 does not. The 3.12.4 release notes also list "Security fixes (escape values)": https://github.com/moonshine-software/moonshine/releases/tag/3.12.4

The OSV export takes the fixed version from the first patched version, so versions 3.12.4 to 3.12.13 are reported as vulnerable even though they have the fix.

Copilot AI balanced review requested due to automatic review settings September 19, 2026 10:55
@github-actions
github-actions Bot changed the base branch from main to nikpivkin/advisory-improvement-9613 September 19, 2026 10:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The OSV events now accurately represent versions before 3.12.4 as vulnerable.

Review effort: Balanced
Findings: None

What changed in this PR

Corrects Moonshine’s advisory so OSV exports recognize 3.12.4 as the first patched release.

Changes:

  • Updates the fixed version from 3.12.14 to 3.12.4.
  • Removes redundant affected-range metadata.
  • Updates the modification timestamp.
File Description
advisories/​github-reviewed/​2025/​08/​GHSA-rh9f-gr6q-mpc4/​GHSA-rh9f-gr6q-mpc4.json Corrects Moonshine’s patched version and associated metadata.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants