Skip to content

Conversation

@decsecre583
Copy link

@decsecre583 decsecre583 commented Feb 6, 2026

Proposed Change

Add cross-reference between CVE-2024-43795 and CVE-2024-46977 to document the incomplete fix relationship.

Evidence

  • Both discovered by GitHub Security Lab (GHSL-2024-128 and GHSL-2024-127) in the same audit
  • CVE-2024-43795 fixes XSS in the login functionality
  • CVE-2024-46977 fixes path traversal in LocalMode's open_local_file — same ScreensController component
  • Both require upgrade to OpenC3 COSMOS 5.19.0
  • Same affected version range: < 5.19.0

@github-actions github-actions bot changed the base branch from main to decsecre583/advisory-improvement-6788 February 6, 2026 04:35
@JonathanLEvans
Copy link

Hi @decsecre583,

Could you explain how CVE-2024-43795 is an incomplete fix of CVE-2024-46977 when they were fixed in the same version and are completely different vulnerability types?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants