vciy

78 records in one advisory

78 records announced together, published 2022-07-11, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://github.com/github/securitylab/issues/669#issuecomment-1117265726. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

Every record names something of its own, listed against it below.

What this page does not cover

This batch is 78 of the 87 records that cite the same advisory. The other 9 are different findings announced alongside it.

None of those 9 is grouped with any other. Each one has its own record page and nothing else.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

One researcher ran a CodeQL query across GitHub and filed about 92 reports

A researcher using the handle porcupineyhairs opened a placeholder issue with GitHub Security Lab on 28 April 2022 saying "I plan on sending bulk PR's to approx 100 projects", as an entry to the lab's Bug Slayer bounty programme. On 4 May 2022 the same researcher posted a table of close to 92 reports, each one a Python project using Flask's send_file function in a way that let a request read files outside the intended directory, and later confirmed "the findings are from my CodeQL query". Most of the affected projects were small public repositories, and the researcher asked MITRE for identifiers directly when maintainers did not respond, which is why our index holds 78 of these records all published on 11 July 2022. Then the thread turned. Readers showed the proof-of-concept examples used relative rather than absolute traversal, and the researcher replied "I used an automation script to generate those PoC's. Hence, the PoC's could be incorrect". Java teams arrived reporting broken builds, because the product identifiers attached to some of these records matched unrelated libraries such as jakarta-annotation-api and JUnit 5. GitHub Security Lab acknowledged on 19 July 2022 that "there was an error assigning the CPEs for some of the CVEs associated with this Bug Slayer submission" and said it had raised the problem with NIST.

This record is one entry in a table filed by one person from one automated query, so the others are the same pattern in different unrelated projects rather than related work by any project's maintainers. The affected project is usually a small repository, and the researcher wrote the fix as well as the report. One identifier from that table, CVE-2022-31569, was withdrawn after the dispute.

2022-04-28porcupineyhairs opens the issue as a placeholder for bulk reports to about 100 projects
2022-05-04The researcher posts the table of close to 92 reports with a project, a pull request and an identifier for each
2022-07-15A reader reports that the product identifier on one of these records is matching unrelated Java libraries…
2022-07-18A reader reports ten Java projects in his department failing builds because of that matching
2022-07-19GitHub Security Lab says the product identifiers were assigned in error and that it has told NIST; the researcher reports that CVE-2022-31569 has…
2022-07-28GitHub Security Lab closes the issue, labelled both Bug Slayer and invalid

The gap here is not a missing technical detail; it is that parts of this batch were disputed and some of it was withdrawn, and a record does not carry that argument. The reporter's account has since been deleted, so the thread shows a ghost and the researcher's real identity appears nowhere we could read. The published example for a given record may not match what was actually tested, by the researcher's own statement. And a record does not tell you whether the small project it names is still maintained, or whether its own identifier survived.

Written from github.com, github.com, github.com, github.com, github.com, securitylab.github.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2022-31502operatorequals/wormnest
CVE-2022-31505cheo0/mercadoenlineaback
CVE-2022-31506cmusatyalab/opendiamond
CVE-2022-31509iedadata/usap-dc-website
CVE-2022-31511afdudley/equanimity
CVE-2022-31512atom02/flask-mvc
CVE-2022-31513bolunhan/krypton
CVE-2022-31514caoyongqi912/fan_platform
CVE-2022-31515delor4/carceresbe
CVE-2022-31516harveyzyh/python
CVE-2022-31517holgergraef/msm
CVE-2022-31518justanothersoftwaredeveloper/python-recipe-database
CVE-2022-31519lukasavicus/windmill
CVE-2022-31520luxas98/logstash-management-api
CVE-2022-31521niyaz-mohamed/mosaic
CVE-2022-31522notvinay/karaokey
CVE-2022-31523paddlepaddle/anakin
CVE-2022-31524purestorage-openconnect/swagger
CVE-2022-31525summalabs/dls
CVE-2022-31526thunderatz/thunderdocs
CVE-2022-31527wildog/flask-file-server
CVE-2022-31528bonn-activity-maps/bam_annotation_tool
CVE-2022-31529cinemaproject/monorepo
CVE-2022-31530csm-aut/csm
CVE-2022-31531dainst/cilantro
CVE-2022-31532dankolbman/travel_blahg
CVE-2022-31533decentraminds/umbral
CVE-2022-31534echoleegroup/pythonweb
CVE-2022-31535freefood89/fishtank
CVE-2022-31536jaygarza1982/ytdl-sync
CVE-2022-31537jmcginty15/solar-system-simulator
CVE-2022-31538joaopedro-fg/mp-m08-interface
CVE-2022-31539kotekan/kotekan
CVE-2022-31540kumardeepak/hin-eng-preprocessing
CVE-2022-31541lyubolp/barry-voice-assistant
CVE-2022-31542mandoku/mdweb
CVE-2022-31543maxtortime/setupbox
CVE-2022-31544meerstein/rbtm
CVE-2022-31545ml-inory/modelconverter
CVE-2022-31546nlpweb/glance
CVE-2022-31547noamezekiel/sphere
CVE-2022-31548nrlakin/homepage
CVE-2022-31550olmax99/pyathenastack
CVE-2022-31551pleomax00/flask-mongo-skel
CVE-2022-31552project-anuvaad/anuvaad-corpus
CVE-2022-31553rainsoupah/sleep-learner
CVE-2022-31554rohitnayak/movie-review-sentiment-analysis
CVE-2022-31555romain20100/nursequest
CVE-2022-31556rusyasoft/trainenergyserver
CVE-2022-31557seveas/golem
CVE-2022-31558tooxie/shiva-server
CVE-2022-31559tsileo/flask-yeoman
CVE-2022-31560uncleyiba/photo_tag
CVE-2022-31561varijkapil13/sphere_imagebackend
CVE-2022-31562waveyan/internshipsystem
CVE-2022-31563whmacmac/vprj
CVE-2022-31565yogson/syrabond
CVE-2022-31566dsab-local/dsab
CVE-2022-31567dsabenchmark/dsab
CVE-2022-31568rexians/rex-web
CVE-2022-31570adriankoczuruek/ceneo-web-scrapper
CVE-2022-31571akashtalole/python-flask-restful-api
CVE-2022-31572ceee-vip/cockybook
CVE-2022-31573chainer/chainerrl-visualizer
CVE-2022-31574deepaliupadhyay/realestate
CVE-2022-31575duducosmos/livro_python
CVE-2022-31576heidi-luong1109/shackerpanel
CVE-2022-31577longmaoteamtf/audio_aligner_app
CVE-2022-31578piaoyunsoft/bt_lnmp
CVE-2022-31579ralphjzhang/iasset
CVE-2022-31580sanojtharindu/caretakerr-api
CVE-2022-31582shaolo1/videoserver
CVE-2022-31583sravaniboinepelli/automatedquizeval
CVE-2022-31584stonethree/s3label
CVE-2022-31585umeshpatil-dev/home__internet
CVE-2022-31586unizar-30226-2019-06/changepop-back
CVE-2022-31587yuriyouzhou/kg-fashion-chatbot
CVE-2022-31588zippies/testplatform

78 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.