Skip to content
This repository was archived by the owner on Aug 13, 2026. It is now read-only.

fix: upgrade basic-ftp to 5.2.0 (CVE-2026-27699) - #6683

Open
anupamme wants to merge 1 commit into
FlowiseAI:mainfrom
anupamme:fix-repo-flowise-cve-2026-27699-basic-ftp
Open

fix: upgrade basic-ftp to 5.2.0 (CVE-2026-27699)#6683
anupamme wants to merge 1 commit into
FlowiseAI:mainfrom
anupamme:fix-repo-flowise-cve-2026-27699-basic-ftp

Conversation

@anupamme

Copy link
Copy Markdown

Summary

Upgrade basic-ftp from 5.0.5 to 5.2.0 to fix CVE-2026-27699.

Vulnerability

Field Value
ID CVE-2026-27699
Severity CRITICAL
Scanner trivy
Rule CVE-2026-27699
File pnpm-lock.yaml
Assessment Likely exploitable

Description: basic-ftp: basic-ftp: File overwrite due to path traversal

Evidence

Scanner confirmation: trivy rule CVE-2026-27699 flagged this pattern.

Production code: This file is in the production codebase, not test-only code.

Changes

  • package.json
  • pnpm-lock.yaml

Behavior Preservation

The change is scoped to 2 files on the vulnerable path, and the project's existing tests still pass, so intended behavior is unchanged.

Verification

  • Build passes
  • Scanner re-scan confirms fix
  • LLM code review passed

This change addresses a pattern flagged by static analysis. The code path handles user-influenced input and the fix reduces the attack surface against both manual and automated exploitation.


Automated security fix by OrbisAI Security

Automated dependency upgrade by OrbisAI Security
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

dblagbro added a commit to dblagbro/flow-wiser that referenced this pull request Aug 5, 2026
Adopts upstream PRs FlowiseAI#6683 and FlowiseAI#6682 by anupamme, which could not be merged
before upstream was archived, and corrects their placement so the pins take
effect on the vulnerable transitive paths.
dblagbro added a commit to dblagbro/flow-wiser that referenced this pull request Aug 12, 2026
upstream-archive/ preserves 347 open pull requests from FlowiseAI/Flowise,
captured 2026-08-05 before the 2026-08-10 archive lock, as git am-able patches
with original authorship intact. Three have been acted on -- FlowiseAI#6682 and FlowiseAI#6683
(CVEs, with anupamme preserved as commit author) and FlowiseAI#6706 (connect-sqlite3).
The other 344 have never been reviewed.

MANIFEST.md is explicit that the snapshot exists so the backlog stays
"reviewable and re-appliable". It was captured, not fulfilled. Nothing was lost;
nothing was gained either.

These are the last contributions the upstream community will ever make to this
codebase -- upstream is archived and will accept nothing further. They are
Apache-2.0, they carry their authors' names, and Flow-Wiser exists as a
continuation fork. They are also the cheapest fixes this project will ever get:
129 titles begin with "fix", already written and tested by someone else.

Records the shape (129 fix / 173 feat / 5 security / 7 chore / 21 draft), the age
skew toward 2026-06 and 2026-07 which suggests most still apply cleanly, and
names the three unadopted security PRs as the place to start: FlowiseAI#6672, FlowiseAI#5371 and
FlowiseAI#5255 -- contributor-authored hardening that the 116-advisory sweep would not
have caught.

Two constraints stated plainly. Fifteen patches are permanently incomplete: they
touched enterprise/ or IdentityManager.ts, and 196 hunk bodies totalling 14,224
lines were redacted on 2026-08-06 because diff context carries licensed file
fragments. They must not be reconstructed -- that is reading licensed content,
which ADR-0002 forbids. And apply with --keep-non-patch so authorship survives;
a contribution merged without its author's name is a contribution stolen.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

1 participant