Skip to content

docs: upgrade 2 CVEs to partial defense after SSRF + yarnrc enhancements#150

Merged
cyyever merged 1 commit intomainfrom
docs/cve-partial-upgrades
Mar 30, 2026
Merged

docs: upgrade 2 CVEs to partial defense after SSRF + yarnrc enhancements#150
cyyever merged 1 commit intomainfrom
docs/cve-partial-upgrades

Conversation

@cyyever
Copy link
Copy Markdown
Collaborator

@cyyever cyyever commented Mar 30, 2026

Summary

  • CVE-2026-26118 (Azure MCP SSRF, 8.8): upgraded Not Defensible β†’ Partial β€” block-ssrf-private-network blocks internal IP targets in tool args
  • CVE-2025-59828 (Yarn plugin autoload, 8.0): upgraded Not Defensible β†’ Partial β€” configscan detects malicious .yarnrc.yml yarnPath overrides

Updated Coverage

Status Count %
Full defense 71 84.5%
Partial defense 3 3.6%
Not defensible 10 11.9%
Total 84

Test plan

  • Doc consistency hook passes
  • Counts verified: 71 + 3 + 10 = 84

- CVE-2026-26118 (Azure MCP SSRF): block-ssrf-private-network now blocks
  internal IP targets in tool args; external attacker endpoint still not
  interceptable
- CVE-2025-59828 (Yarn plugin autoload): configscan now detects malicious
  .yarnrc.yml yarnPath overrides; in-process loading still not interceptable
- Both moved from Not Defensible β†’ Partial in tracker and reference
- Summary: 71 full, 3 partial, 10 not defensible (84 total)
@cyyever cyyever merged commit f4a47e2 into main Mar 30, 2026
16 checks passed
@cyyever cyyever deleted the docs/cve-partial-upgrades branch March 30, 2026 07:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant