mirror of
https://github.com/exo-explore/exo.git
synced 2026-07-30 07:07:07 -04:00
## Summary Upgrade devalue from 5.5.0 to 5.6.2 to fix CVE-2026-22774. ## Vulnerability | Field | Value | |-------|-------| | **ID** | CVE-2026-22774 | | **Severity** | HIGH | | **Scanner** | trivy | | **Rule** | `CVE-2026-22774` | | **File** | `dashboard/package-lock.json` | | **Assessment** | Likely exploitable | **Description**: devalue: devalue: Denial of Service due to excessive resource consumption from untrusted input ## Evidence **Scanner confirmation**: trivy rule `CVE-2026-22774` flagged this pattern. **Production code**: This file is in the production codebase, not test-only code. ## Threat Model Context This is a web service - vulnerabilities in request handlers are directly exploitable by remote attackers. ## Changes - `dashboard/package.json` - `dashboard/package-lock.json` ## Verification - [x] Build passes - [x] Scanner re-scan confirms fix - [x] LLM code review passed --- *This change addresses a pattern flagged by static analysis. The code path handles user-influenced input and the fix reduces the attack surface against both manual and automated exploitation.* --- *Automated security fix by [OrbisAI Security](https://orbisappsec.com)*