Skip to content

Application security review — validated findings#4

Draft
cursor[bot] wants to merge 1 commit into
mainfrom
cursor/application-security-review-dff3
Draft

Application security review — validated findings#4
cursor[bot] wants to merge 1 commit into
mainfrom
cursor/application-security-review-dff3

Conversation

@cursor

@cursor cursor Bot commented Jun 2, 2026

Copy link
Copy Markdown

Summary

Scheduled application security review documenting validated medium, high, and critical vulnerabilities with end-to-end attack paths.

New findings this scan:

  • Medium — Permission model read checks do not follow symlink targets allowing sandbox bypass (src/node_file.cc)
  • Medium — Bundled npm pacote remote fetch lacks SSRF protections on resolved tarball URLs (deps/npm/node_modules/pacote/lib/remote.js)

See .security-review/flagged-vulnerabilities.md for full details including all 3 findings (includes prior NODE_OPTIONS child_process bypass).

Open in Web View Automation 

Scheduled security scan documenting validated medium+ vulnerabilities
with end-to-end attack paths at current commit.

Co-authored-by: quan.m.le <quan.m.le@opswat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant