Security Dashboard #236

Open
opened 2026-08-09 20:58:10 -04:00 by renovate-bot · 0 comments
Collaborator

Automated weekly security sweep — last rewritten 2026-08-31 07:30 UTC (runs).

This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them with a written reason (this repo's .gitleaks.toml for secrets, an inline # nosemgrep: <rule-id> -- <reason> for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.

Secrets (gitleaks)

  • backend/app/services/pixiv_client.py:71 — rule generic-api-key, commit 86ae3969 2026-07-03T13:36:54Z
  • backend/app/services/pixiv_client.py:72 — rule generic-api-key, commit 86ae3969 2026-07-03T13:36:54Z
  • extension/background/background.js:14 — rule generic-api-key, commit df82abe7 2026-05-24T03:34:11Z
  • extension/background/background.js:15 — rule generic-api-key, commit df82abe7 2026-05-24T03:34:11Z

Code findings (semgrep, curated family ruleset)

ERROR — believed-real on this family's code (3):

  • alembic/env.py:62 opt.security-rules.fabled-sql-string-interpolation — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.
  • alembic/versions/0069_default_siglip2.py:31 opt.security-rules.fabled-sql-string-interpolation — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.
  • alembic/versions/0088_reconcile_models_with_schema.py:99 opt.security-rules.fabled-sql-string-interpolation — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.
    WARNING — useful, precision not yet proven (2):
  • frontend/src/components/modal/ProvenancePanel.vue:62 opt.security-rules.fabled-vue-v-html — v-html renders raw HTML into the DOM. Legitimate only when the value is server-escaped (FabledForge's Reader is). Confirm the source is escaped server-side; if it is user-supplied and unescaped this i
  • frontend/src/components/posts/PostCard.vue:87 opt.security-rules.fabled-vue-v-html — v-html renders raw HTML into the DOM. Legitimate only when the value is server-escaped (FabledForge's Reader is). Confirm the source is escaped server-side; if it is user-supplied and unescaped this i

Dependency CVEs (osv-scanner)

Published image (trivy)

  • HIGH CVE-2026-58049 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-64830 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-64831 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-64832 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-64834 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-64835 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-66036 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-66039 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-66040 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-66041 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-70628 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-70632 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-41992 — gzip 1.13-1 (no fix released)
  • HIGH CVE-2026-54369 — libacl1 2.3.2-2+b1 (no fix released)
  • HIGH CVE-2026-58049 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-64830 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-64831 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-64832 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-64834 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-64835 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-66036 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-66039 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-66040 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-66041 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-70628 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-70632 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-58049 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-64830 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-64831 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-64832 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-64834 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-64835 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-66036 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-66039 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-66040 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-66041 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-70628 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-70632 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-58049 — libavfilter10 7:7.1.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-64830 — libavfilter10 7:7.1.5-0+deb13u1 (no fix released)
    …and 146 more line(s) truncated — run the scanner locally or trigger the sweep with only= for the full list.

Coverage & limits

  • All four scanners ran with nothing skipped.
<!-- fabledsentry-security-dashboard --> _Automated weekly security sweep — last rewritten 2026-08-31 07:30 UTC ([runs](https://git.fabledsword.com/bvandeusen/CI-runner/actions))._ This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them **with a written reason** (this repo's `.gitleaks.toml` for secrets, an inline `# nosemgrep: <rule-id> -- <reason>` for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface. ## Secrets (gitleaks) - `backend/app/services/pixiv_client.py:71` — rule `generic-api-key`, commit `86ae3969` 2026-07-03T13:36:54Z - `backend/app/services/pixiv_client.py:72` — rule `generic-api-key`, commit `86ae3969` 2026-07-03T13:36:54Z - `extension/background/background.js:14` — rule `generic-api-key`, commit `df82abe7` 2026-05-24T03:34:11Z - `extension/background/background.js:15` — rule `generic-api-key`, commit `df82abe7` 2026-05-24T03:34:11Z ## Code findings (semgrep, curated family ruleset) **ERROR — believed-real on this family's code (3):** - `alembic/env.py:62` `opt.security-rules.fabled-sql-string-interpolation` — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation. - `alembic/versions/0069_default_siglip2.py:31` `opt.security-rules.fabled-sql-string-interpolation` — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation. - `alembic/versions/0088_reconcile_models_with_schema.py:99` `opt.security-rules.fabled-sql-string-interpolation` — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation. **WARNING — useful, precision not yet proven (2):** - `frontend/src/components/modal/ProvenancePanel.vue:62` `opt.security-rules.fabled-vue-v-html` — v-html renders raw HTML into the DOM. Legitimate only when the value is server-escaped (FabledForge's Reader is). Confirm the source is escaped server-side; if it is user-supplied and unescaped this i - `frontend/src/components/posts/PostCard.vue:87` `opt.security-rules.fabled-vue-v-html` — v-html renders raw HTML into the DOM. Legitimate only when the value is server-escaped (FabledForge's Reader is). Confirm the source is escaped server-side; if it is user-supplied and unescaped this i ## Dependency CVEs (osv-scanner) - `idna 3.9.0` (PyPI, `agent/requirements.txt`): [GHSA-65pc-fj4g-8rjx](https://osv.dev/vulnerability/GHSA-65pc-fj4g-8rjx), [PYSEC-2026-215](https://osv.dev/vulnerability/PYSEC-2026-215) - `pillow 9.5.0` (PyPI, `agent/requirements.txt`): [GHSA-3f63-hfp8-52jq](https://osv.dev/vulnerability/GHSA-3f63-hfp8-52jq), [GHSA-44wm-f244-xhp3](https://osv.dev/vulnerability/GHSA-44wm-f244-xhp3), [GHSA-45hq-cxwh-f6vc](https://osv.dev/vulnerability/GHSA-45hq-cxwh-f6vc), [GHSA-4x4j-2g7c-83w6](https://osv.dev/vulnerability/GHSA-4x4j-2g7c-83w6), [GHSA-5x94-69rx-g8h2](https://osv.dev/vulnerability/GHSA-5x94-69rx-g8h2), [GHSA-62p4-gmf7-7g93](https://osv.dev/vulnerability/GHSA-62p4-gmf7-7g93), [GHSA-6r8x-57c9-28j4](https://osv.dev/vulnerability/GHSA-6r8x-57c9-28j4), [GHSA-8ghj-p4vj-mr35](https://osv.dev/vulnerability/GHSA-8ghj-p4vj-mr35), [GHSA-8v84-f9pq-wr9x](https://osv.dev/vulnerability/GHSA-8v84-f9pq-wr9x), [GHSA-9hw9-ch79-4vh6](https://osv.dev/vulnerability/GHSA-9hw9-ch79-4vh6), [GHSA-fj7v-r99m-22gq](https://osv.dev/vulnerability/GHSA-fj7v-r99m-22gq), [GHSA-j7hp-h8jx-5ppr](https://osv.dev/vulnerability/GHSA-j7hp-h8jx-5ppr), [GHSA-jjj6-mw9f-p565](https://osv.dev/vulnerability/GHSA-jjj6-mw9f-p565), [GHSA-phj9-mv4w-65pm](https://osv.dev/vulnerability/GHSA-phj9-mv4w-65pm), [GHSA-r73j-pqj5-w3x7](https://osv.dev/vulnerability/GHSA-r73j-pqj5-w3x7), [GHSA-vjc4-5qp5-m44j](https://osv.dev/vulnerability/GHSA-vjc4-5qp5-m44j), [GHSA-wjx4-4jcj-g98j](https://osv.dev/vulnerability/GHSA-wjx4-4jcj-g98j), [GHSA-xj96-63gp-2gmr](https://osv.dev/vulnerability/GHSA-xj96-63gp-2gmr), [PYSEC-2023-175](https://osv.dev/vulnerability/PYSEC-2023-175), [PYSEC-2023-227](https://osv.dev/vulnerability/PYSEC-2023-227), [PYSEC-2026-165](https://osv.dev/vulnerability/PYSEC-2026-165), [PYSEC-2026-1793](https://osv.dev/vulnerability/PYSEC-2026-1793), [PYSEC-2026-1794](https://osv.dev/vulnerability/PYSEC-2026-1794), [PYSEC-2026-2253](https://osv.dev/vulnerability/PYSEC-2026-2253), [PYSEC-2026-2254](https://osv.dev/vulnerability/PYSEC-2026-2254), [PYSEC-2026-2255](https://osv.dev/vulnerability/PYSEC-2026-2255), [PYSEC-2026-2256](https://osv.dev/vulnerability/PYSEC-2026-2256), [PYSEC-2026-2257](https://osv.dev/vulnerability/PYSEC-2026-2257), [PYSEC-2026-2874](https://osv.dev/vulnerability/PYSEC-2026-2874), [PYSEC-2026-3451](https://osv.dev/vulnerability/PYSEC-2026-3451), [PYSEC-2026-3453](https://osv.dev/vulnerability/PYSEC-2026-3453), [PYSEC-2026-3454](https://osv.dev/vulnerability/PYSEC-2026-3454), [PYSEC-2026-3493](https://osv.dev/vulnerability/PYSEC-2026-3493), [PYSEC-2026-3494](https://osv.dev/vulnerability/PYSEC-2026-3494), [PYSEC-2026-3495](https://osv.dev/vulnerability/PYSEC-2026-3495), [PYSEC-2026-3496](https://osv.dev/vulnerability/PYSEC-2026-3496), [PYSEC-2026-457](https://osv.dev/vulnerability/PYSEC-2026-457) - `torch 1.8.1` (PyPI, `agent/requirements.txt`): [GHSA-3749-ghw9-m3mg](https://osv.dev/vulnerability/GHSA-3749-ghw9-m3mg), [GHSA-47fc-vmwq-366v](https://osv.dev/vulnerability/GHSA-47fc-vmwq-366v), [GHSA-53q9-r3pm-6pq6](https://osv.dev/vulnerability/GHSA-53q9-r3pm-6pq6), [GHSA-5pcm-hx3q-hm94](https://osv.dev/vulnerability/GHSA-5pcm-hx3q-hm94), [GHSA-887c-mr87-cxwp](https://osv.dev/vulnerability/GHSA-887c-mr87-cxwp), [GHSA-c678-jfcj-6jmf](https://osv.dev/vulnerability/GHSA-c678-jfcj-6jmf), [GHSA-f4hp-rmr7-r7v8](https://osv.dev/vulnerability/GHSA-f4hp-rmr7-r7v8), [GHSA-pg7h-5qx3-wjr3](https://osv.dev/vulnerability/GHSA-pg7h-5qx3-wjr3), [GHSA-qfhq-4f3w-5fph](https://osv.dev/vulnerability/GHSA-qfhq-4f3w-5fph), [GHSA-rrmf-rvhw-rf47](https://osv.dev/vulnerability/GHSA-rrmf-rvhw-rf47), [GHSA-vgrw-7cvw-pwgx](https://osv.dev/vulnerability/GHSA-vgrw-7cvw-pwgx), [GHSA-x3gm-94wq-g975](https://osv.dev/vulnerability/GHSA-x3gm-94wq-g975), [PYSEC-2022-43015](https://osv.dev/vulnerability/PYSEC-2022-43015), [PYSEC-2024-250](https://osv.dev/vulnerability/PYSEC-2024-250), [PYSEC-2024-251](https://osv.dev/vulnerability/PYSEC-2024-251), [PYSEC-2024-252](https://osv.dev/vulnerability/PYSEC-2024-252), [PYSEC-2024-259](https://osv.dev/vulnerability/PYSEC-2024-259), [PYSEC-2025-191](https://osv.dev/vulnerability/PYSEC-2025-191), [PYSEC-2025-198](https://osv.dev/vulnerability/PYSEC-2025-198), [PYSEC-2025-203](https://osv.dev/vulnerability/PYSEC-2025-203), [PYSEC-2025-204](https://osv.dev/vulnerability/PYSEC-2025-204), [PYSEC-2025-205](https://osv.dev/vulnerability/PYSEC-2025-205), [PYSEC-2025-206](https://osv.dev/vulnerability/PYSEC-2025-206), [PYSEC-2025-207](https://osv.dev/vulnerability/PYSEC-2025-207), [PYSEC-2025-208](https://osv.dev/vulnerability/PYSEC-2025-208), [PYSEC-2025-209](https://osv.dev/vulnerability/PYSEC-2025-209), [PYSEC-2025-41](https://osv.dev/vulnerability/PYSEC-2025-41), [PYSEC-2026-139](https://osv.dev/vulnerability/PYSEC-2026-139), [PYSEC-2026-1970](https://osv.dev/vulnerability/PYSEC-2026-1970), [PYSEC-2026-2286](https://osv.dev/vulnerability/PYSEC-2026-2286) ## Published image (trivy) - **HIGH** CVE-2026-58049 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-64830 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-64831 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-64832 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-64834 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-64835 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-66036 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-66039 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-66040 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-66041 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-70628 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-70632 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-41992 — `gzip 1.13-1` (no fix released) - **HIGH** CVE-2026-54369 — `libacl1 2.3.2-2+b1` (no fix released) - **HIGH** CVE-2026-58049 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-64830 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-64831 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-64832 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-64834 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-64835 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-66036 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-66039 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-66040 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-66041 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-70628 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-70632 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-58049 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-64830 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-64831 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-64832 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-64834 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-64835 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-66036 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-66039 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-66040 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-66041 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-70628 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-70632 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-58049 — `libavfilter10 7:7.1.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-64830 — `libavfilter10 7:7.1.5-0+deb13u1` (no fix released) _…and 146 more line(s) truncated — run the scanner locally or trigger the sweep with `only=` for the full list._ ## Coverage & limits - All four scanners ran with nothing skipped.
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: bvandeusen/FabledCurator#236