[GHSA-cr45-98w9-gwqx] Viewing wget extractor output while logged in as an admin allows archived JS to execute in the admins context - #9269
Conversation
|
Hi there @pirate! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
|
This is a known issue thoroughly documented in our wiki, repo README, and existing issues since 2019. SECURITY.md is a brand new file I only made recently because the GitHub UI recommended it, it's not at all an accurate representation of the project's security history on the multi-year timescale. The reporter is throwing a hissy fit over CVE credits for something they did not discover. In fact I completely turned off security advisories on the repo because all the reports were duplicates of this same issue that's been thoroughly documented for years, all trying to grab CVEs with no context on this project or why this issue is hard. There's a reason it's been open a long time, it's essentially an open research problem on how to solve it, there is no trivial fix that doesn't wreck UX. I don’t really care how you want to handle this, publish it however you want, but im not sinking any more energy into dealing with this guy.
My original response to them:
|
The maintainer's response above does not address the central issue of this dispute — the retroactive modification of CVE-2023-45815. The NVD Change History at https://nvd.nist.gov/vuln/detail/CVE-2023-45815 documents the following: The original CPE configuration scoped this CVE to versions up to and including 0.6.2. On July 7, 2026 — 23 days after the maintainer accepted my finding on June 14 — GitHub, Inc. as CNA pushed a modification expanding affected versions to "< 0.9.0", rewriting the description, and adding a Wikipedia reference to Cross-site Request Forgery. None of these elements existed in the original October 2023 publication. I am attaching a screenshot of the full Change History for reference. Regarding the maintainer's specific claims: He states this is a known issue "since 2019." On June 14, 2026, he accepted my report, patched it on dev within minutes, and wrote "thanks for reporting and testing." These are his own words, preserved in the GHSA record. He states the SECURITY.md is a new file he created because the GitHub UI recommended it. This confirms the file did not exist before my disclosure — and the commit history shows it was created the day after he accepted my report. He states he shut down security advisories because all reports were duplicates. This confirms retaliatory action in response to vulnerability reports. I respectfully ask the curation team to evaluate the NVD Change History timeline against the maintainer's claims. |


Updates
Comments
On June 14, 2026, I disclosed a Stored XSS vulnerability to the ArchiveBox maintainer via GHSA-32m2-xhwx-92mh. The maintainer accepted the finding, patched it on the development branch, and acknowledged it in writing with "thanks for reporting and testing."
On July 7, 2026 — 23 days later — CVE-2023-45815 was modified through GitHub's CNA pipeline with three simultaneous changes:
Affected versions expanded from "≤ 0.6.2" to "< 0.9.0"
A Wikipedia reference to Cross-site Request Forgery was added
The description was rewritten
None of these elements existed in the original October 2023 publication. The NVD Change History is publicly verifiable at https://nvd.nist.gov/vuln/detail/CVE-2023-45815 under "Change History."
The effect of this modification was to retroactively subsume my independently disclosed finding into a pre-existing record, manufacturing the appearance of a duplicate. MITRE subsequently rejected my CAN-2026-2035774 citing this record as "prior art" — a record that did not cover my finding's versions, CWE classification, or attack chain until 23 days after I disclosed it.
This violates CNA Operational Rules v4.2.0, specifically:
Rule 4.2.6: Distinct vulnerabilities require distinct CVE IDs. My finding targets v0.7.3/v0.7.4 (stable releases), exploits a different attack chain (same-origin XSS → CSRF bypass → authenticated admin action), and requires different remediation than the original CVE-2023-45815 scope.
Rule 4.1: Vulnerability determination must reflect technical reality, not post-hoc administrative bundling.
The maintainer's pattern of retroactive modifications is documented in the repository's own commit history — five successive SECURITY.md modifications between June 15 and July 28, 2026, each introduced after receiving vulnerability reports, each designed to exclude those same reports from CVE eligibility.
This matter is currently under active review by CERT/CC (CISA Vulnerability Response and Coordination).
I am requesting that the GitHub Security Lab curation team review the modification history of CVE-2023-45815, evaluate whether the July 7 expansion was a legitimate update or a retroactive suppression of an independent finding, and if warranted, revert the record to its pre-July 7 scope and assign a separate CVE for the independently disclosed vulnerability.
Ing. Zampier Zago
PS 1978 Limited — github.com/FUNFACTOR1