Skip to content

fix(security): resolve CodeQL CWE-209, libfreetype6 DoS, and openclaw vulnerabilities - #1081

Merged
sbharatjoshi merged 1 commit into
mainfrom
fix/security-alerts-remediation
Oct 9, 2026
Merged

sbharatjoshi merged 1 commit into
mainfrom
fix/security-alerts-remediation

Conversation

@jarvispectrayan

Copy link
Copy Markdown
Collaborator

Summary

Remediates the open GitHub Code Scanning alerts and Dependabot alerts across spectrayan/spector.

Targeted Security Alerts Remediated

GitHub Code Scanning Alerts

  • Code Scanning Alert 485 — CodeQL java/error-message-exposure (CWE-209)
    • Fix: Sanitized NamespaceResolutionFilter HTTP 403 response payload. Replaced raw e.getMessage() serialization with constant safe client-facing error strings ("Cross-tenant access forbidden" / "Namespace access denied"), keeping diagnostic exception details strictly within server-side logs.
  • Code Scanning Alert 486 — Trivy libfreetype6 (CVE-2026-95512)
    • Fix: Added libfreetype6 to apt-get --only-upgrade install -y in both Gateway and Runtime stages of deploy/docker/Dockerfile to pull patched version 2.14.2+dfsg-1ubuntu0.2.

GitHub Dependabot Alerts

  • Dependabot Alert 149 — proxy-addr (CVE-2026-90711, Critical)
    • Fix: Added proxy-addr: "^2.0.8" to npm overrides in plugins/openclaw/package.json and updated package-lock.json.
  • Dependabot Alert 150 — source-map-js (CVE-2026-93749, High)
    • Fix: Added source-map-js: "^1.2.2" to npm overrides in plugins/openclaw/package.json and updated package-lock.json.
  • Dependabot Alert 151 — @modelcontextprotocol/sdk (CVE-2026-104850, High)
    • Fix: Added @modelcontextprotocol/sdk: "^1.31.0" to npm overrides in plugins/openclaw/package.json and updated package-lock.json.

(Note: Dependabot Alert 152 and Code Scanning Alert 487 for org.jsoup:jsoup were resolved in PR #1080).


Verification Performed

  • mvn test -pl synapse/spector-synapse -Dtest=NamespaceResolutionFilterTest — Passed (6/6 tests).
  • mvn license:check — Passed across all 29 reactor modules.
  • cd plugins/openclaw && npm audit — 0 vulnerabilities found (down from 4).
  • cd plugins/openclaw && npm test — 3/3 tests passed.

Signed-off-by: Forge forge@spectrayan.com
Co-authored-by: Bharat Joshi bharatjoshi@spectrayan.com

…patch openclaw npm dependencies

- Sanitize NamespaceResolutionFilter HTTP 403 response payload to prevent CWE-209 information exposure (remediates Code Scanning Alert 485)
- Add libfreetype6 to apt-get --only-upgrade in Dockerfile to remediate CVE-2026-95512 (remediates Code Scanning Alert 486)
- Add @modelcontextprotocol/sdk, proxy-addr, and source-map-js overrides in OpenClaw plugin (remediates Dependabot Alerts 149, 150, 151)

Co-authored-by: Bharat Joshi <bharatjoshi@spectrayan.com>
Signed-off-by: Forge <forge@spectrayan.com>
@jarvispectrayan
jarvispectrayan requested review from a team and sbharatjoshi as code owners October 9, 2026 01:00
@sbharatjoshi
sbharatjoshi merged commit 934202f into main Oct 9, 2026
24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants