Skip to content

fix: Add exclusion for critical vulnerability in protobufjs affecting versions < 7.5.5#8545

Merged
mohd-kashif merged 1 commit into
masterfrom
CGD-782
Apr 17, 2026
Merged

fix: Add exclusion for critical vulnerability in protobufjs affecting versions < 7.5.5#8545
mohd-kashif merged 1 commit into
masterfrom
CGD-782

Conversation

@mohd-kashif
Copy link
Copy Markdown
Contributor

Ticket: CGD: 782

@linear
Copy link
Copy Markdown

linear Bot commented Apr 17, 2026

@mohd-kashif mohd-kashif marked this pull request as ready for review April 17, 2026 04:13
@mohd-kashif mohd-kashif requested review from a team as code owners April 17, 2026 04:13
Copy link
Copy Markdown

@diksha190 diksha190 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

Verified the exclusion rationale, all protobuf definitions are static bundled files from trusted dependencies, not user-controlled. The vulnerability requires attacker-supplied .proto files which is not possible in this architecture. Safe to exclude.

Copy link
Copy Markdown
Contributor

@Venkat-Annavazzala Venkat-Annavazzala left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link
Copy Markdown

@Vignesh-285 Vignesh-285 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was reviewed by @BitGo/app-sec and assessed as safe to exclude.

Comment thread .iyarc
@mohd-kashif mohd-kashif merged commit 62ccb25 into master Apr 17, 2026
23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants