mirror of
https://github.com/NicolasBohn/NexQuant.git
synced 2026-07-27 23:47:46 +00:00
chore: Document transformers CVE-2025-3777 is already fixed
- Add comment explaining transformers >=4.53.0 is already safe (CVE fixed in >=4.52.1) - Dependabot alert #37 is false positive due to missing lockfile - No version change needed - current specification is already secure Security Status: - CVE-2025-3777: Fixed in transformers >=4.52.1, current spec >=4.53.0 ✓ - Affects: image_utils.py URL validation via startswith() bypass - Impact: URL username injection allowing malicious domain redirection Note: Without a lockfile (pip-tools/uv/poetry), Dependabot cannot determine the installed version and raises alerts based on the requirement spec alone.
This commit is contained in:
@@ -24,9 +24,10 @@ pydantic>=2.4.0 # Security fix: CVE-2024-3772 (ReDoS via crafted email)
|
||||
# Models
|
||||
# Security: transformers >=4.51.0 fixes CVE-2025-3263 (ReDoS in get_configuration_file)
|
||||
# Security: transformers >=4.50.0 fixes CVE-2025-1194 (ReDoS in GPT-NeoX-Japanese tokenizer)
|
||||
# Security: transformers >=4.52.1 fixes CVE-2025-3777 (URL validation bypass via username injection)
|
||||
# Current spec (>=4.53.0) is already safe. Dependabot alerts are false positives due to missing lockfile.
|
||||
torch>=2.8.0 # Security fix: CVE-2025-32434 (torch.load RCE), CVE-2025-3730 (DoS in ctc_loss)
|
||||
transformers>=4.53.0 # Security fix: CVE-2024-11393 (RCE), CVE-2025-3264/3933/2099/6051/1194 (ReDoS)
|
||||
transformers>=4.53.0 # Security fix: CVE-2024-11393 (RCE), CVE-2025-3264/3933/2099/6051/1194 (ReDoS), CVE-2025-3777 (URL validation)
|
||||
huggingface_hub>=0.20.0
|
||||
|
||||
# Web services
|
||||
|
||||
Reference in New Issue
Block a user