Skip to content

Conversation

@Cycloctane
Copy link

Updates

  • Affected products
  • CWEs
  • Description
  • Source code location
  • Summary

Comments
Add affected/patched package version and source code location. Update description and CWE.

Copilot AI review requested due to automatic review settings December 12, 2025 14:04
@github-actions github-actions bot changed the base branch from main to Cycloctane/advisory-improvement-6549 December 12, 2025 14:05
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request updates the security advisory GHSA-fxmw-jcgr-w44v for a critical vulnerability in pgAdmin4. The changes refine the vulnerability classification, add affected package information, and improve the description accuracy.

Key changes:

  • Updated CWE classification from CWE-94 (Code Injection) to CWE-77 (Command Injection) to more accurately reflect the vulnerability type
  • Added affected package information specifying pgadmin4 on PyPI with versions up to 9.10 affected and 9.11 as the fixed version
  • Enhanced the vulnerability description to specify it as a command injection that bypasses meta-command filters

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@advisory-database advisory-database bot merged commit 450d9b3 into Cycloctane/advisory-improvement-6549 Dec 12, 2025
10 checks passed
@advisory-database
Copy link
Contributor

Hi @Cycloctane! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the Cycloctane-GHSA-fxmw-jcgr-w44v branch December 12, 2025 16:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants