diff --git a/security/reports/README.md b/security/reports/README.md new file mode 100644 index 0000000..27e18b4 --- /dev/null +++ b/security/reports/README.md @@ -0,0 +1,10 @@ +# Security scan reports + +Generated 2026-08-08 18:58 UTC on branch `cursor/cve-report-and-remediation-6925`. + +| Report | Description | +|--------|-------------| +| [cve-report.html](cve-report.html) | Multi-scanner CVE summary (Trivy, Grype, Syft, Snyk, Scout, Dockle, Dive, osv-scanner) | +| [human-review.html](human-review.html) | Findings needing code/process changes with FIX or IGNORE recommendations | + +Machine-readable scanner outputs remain local/gitignored under `security-reports/` (see makefile `security-scan` targets). Accepted Python finding: `diskcache` CVE-2025-69872 via [`../vex/fastworkflow.openvex.json`](../vex/fastworkflow.openvex.json). diff --git a/security/reports/cve-report.html b/security/reports/cve-report.html new file mode 100644 index 0000000..0fe7f47 --- /dev/null +++ b/security/reports/cve-report.html @@ -0,0 +1,75 @@ + + + + +fastWorkflow CVE Report — 2026-08-08 18:58 UTC + + + +
+

fastWorkflow multi-scanner CVE report

+

Generated 2026-08-08 18:58 UTC against branch cursor/cve-report-and-remediation-6925 (post PR #57 / v2.30.0). Tools: Trivy, Grype, Syft, Snyk, Docker Scout, Dockle, Dive, osv-scanner (+ pip-audit corroboration).

+
+
+
+

Executive summary

+
+
1Python advisory (diskcache)
+
0Fixable via pyproject.toml
+
0Open Python vulns after OpenVEX
+
24Proxy-image High/Critical (not product)
+
+

Easy third-party package bumps: none. Full OSV sweep of 142 locked PyPI packages found only diskcache==5.6.3, and PyPI still has no patched release. Existing floors in pyproject.toml already cover prior CVE sets (litellm, multipart, starlette, cryptography, etc.).

+
+
+

Scanner run status

+ + + +
ToolStatusNotes
SyftOKSBOM generated from poetry.lock (CycloneDX/SPDX/JSON)
TrivyOKFS/lockfile scan: 1 MEDIUM (diskcache), suppressed via OpenVEX → 0 open
GrypeOKSBOM scan: 1 MEDIUM (diskcache); with OpenVEX → No vulnerabilities found
osv-scannerOKpoetry.lock: 1 MEDIUM (diskcache / CVE-2025-69872); no fixed version
pip-auditOKvenv audit: 1 known vulnerability (diskcache); requirements.txt install-audit blocked by platform markers
SnykSKIPPEDSNYK_TOKEN not configured
Docker ScoutSKIPPEDDocker Hub login required for scout CLI
DockleOK (proxy image)Scanned python:3.12-slim-bookworm (no first-party Dockerfile); CIS warnings only
DiveFAILED (env)Layer fetch failed in nested containerd; not a project defect
+
+
+

Python / poetry.lock findings (pre-VEX)

+ + + +
CVE / IDPackageVersionSeverityFixed inSummaryDetected by
CVE-2025-69872diskcache5.6.3MEDIUMNone (no release)DiskCache has unsafe pickle deserializationosv-scanner, trivy, grype, pip-audit
+

With security/vex/fastworkflow.openvex.json, Trivy and Grype report a clean poetry.lock. See human-review report for Fix/Ignore decision.

+
+
+

Proxy image High/Critical (python:3.12-slim-bookworm)

+

Included because Dockle/Dive/Scout/image scanners require an image and this repo has no Dockerfile. These are distro CVEs in a stand-in base image.

+

Severity totals — Critical: 6, High: 18, Medium: 70, Low: 97

+ + + +
SevIDPackageInstalledFixedTitle
CRITICALCVE-2023-45853zlib1g1:1.2.13.dfsg-1zlib: integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_6
CRITICALCVE-2025-7458libsqlite3-03.40.1-2+deb12u2sqlite: SQLite integer overflow
CRITICALCVE-2026-13221perl-base5.36.0-7+deb12u3Perl versions through 5.43.9 produce silently incorrect regular expres ...
CRITICALCVE-2026-42496perl-base5.36.0-7+deb12u3perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access
CRITICALCVE-2026-57433perl-base5.36.0-7+deb12u3Storable versions before 3.41 for Perl have a signed integer overflow ...
CRITICALCVE-2026-8376perl-base5.36.0-7+deb12u3perl: Perl: Heap buffer overflow when compiling regular expressions on 32-bit builds
HIGHCVE-2025-69720libncursesw66.4-4ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.
HIGHCVE-2025-69720libtinfo66.4-4ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.
HIGHCVE-2025-69720ncurses-base6.4-4ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.
HIGHCVE-2025-69720ncurses-bin6.4-4ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.
HIGHCVE-2026-41992gzip1.12-1GNU gzip contains a global buffer overflow vulnerability in the LZH de ...
HIGHCVE-2026-42497perl-base5.36.0-7+deb12u3perl-Archive-Tar: perl-Archive-Tar: Arbitrary file modification via crafted hardlinks during archive extraction
HIGHCVE-2026-48962perl-base5.36.0-7+deb12u3perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob
HIGHCVE-2026-53615bsdutils1:2.38.1-5+deb12u3[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c]
HIGHCVE-2026-53615libblkid12.38.1-5+deb12u3[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c]
HIGHCVE-2026-53615libmount12.38.1-5+deb12u3[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c]
HIGHCVE-2026-53615libsmartcols12.38.1-5+deb12u3[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c]
HIGHCVE-2026-53615libuuid12.38.1-5+deb12u3[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c]
HIGHCVE-2026-53615mount2.38.1-5+deb12u3[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c]
HIGHCVE-2026-53615util-linux2.38.1-5+deb12u3[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c]
HIGHCVE-2026-53615util-linux-extra2.38.1-5+deb12u3[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c]
HIGHCVE-2026-54369libacl12.3.1-3acl: Symlink traversal privilege escalation via libacl functions
HIGHCVE-2026-57432perl-base5.36.0-7+deb12u3perl: Perl: Information disclosure via integer overflow in pack/unpack operations
HIGHCVE-2026-9538perl-base5.36.0-7+deb12u3perl-Archive-Tar: perl-Archive-Tar: Denial of Service via crafted tar header with large entry size
+
+
+

Artifacts

+

Machine-readable outputs were written under gitignored security-reports/ (Syft SBOM, Trivy/Grype/OSV JSON, Dockle JSON, status notes for Snyk/Scout/Dive). Tracked HTML lives in security/reports/.

+
+
+ + diff --git a/security/reports/human-review.html b/security/reports/human-review.html new file mode 100644 index 0000000..8a7b890 --- /dev/null +++ b/security/reports/human-review.html @@ -0,0 +1,70 @@ + + + + +fastWorkflow vulnerability human review — 2026-08-08 18:58 UTC + + + +
+

Vulnerabilities requiring human review

+

Findings that cannot be closed by an easy pyproject.toml version bump. Each item has a recommendation of FIX or IGNORE with documented rationale. Generated 2026-08-08 18:58 UTC.

+
+ IGNORE = accept / already VEX’d / out of product scope + FIX = code or process change required +
+
+
+ +
+
IGNORE
+

Unsafe pickle deserialization in DiskCache

+

ID: CVE-2025-69872 / GHSA-w8v5-vhqr-4h9v / PYSEC-2026-2447
+ Component: diskcache 5.6.3 (transitive via dspy)

+

Why a code / process change (not pyproject alone)

+

No patched PyPI release exists (latest still 5.6.3). A pyproject.toml bump cannot remediate. Mitigation would require application changes (disable DSPy disk cache, relocate/harden cache dir permissions, or wait for upstream non-pickle default).

+

Rationale

+

Already documented in security/vex/fastworkflow.openvex.json as not_affected with justification vulnerable_code_cannot_be_controlled_by_adversary. Exploitation requires write access to the process-local DSPy cache directory; remote API/MCP clients cannot write that path. An adversary who can write as the service user already has equivalent privilege to pickle RCE. Re-evaluate if cache directory is shared across trust boundaries or world-writable. When upstream ships a fix, add a floor constraint in pyproject.toml.

+
+
+
IGNORE
+

6 Critical / 18 High findings on proxy scan image

+

ID: Proxy base image OS CVEs (Trivy/Grype on python:3.12-slim-bookworm)
+ Component: Debian bookworm packages in python:3.12-slim-bookworm (not shipped by this repo)

+

Why a code / process change (not pyproject alone)

+

This repository has no Dockerfile. Image CVEs are in distro packages (perl, libc, sqlite, etc.) and cannot be fixed via pyproject.toml. Remediation would mean publishing and maintaining a hardened runtime image, then refreshing base tags / applying distro patches.

+

Rationale

+

fastWorkflow is distributed as a PyPI package, not a container image. Proxy image scan was performed only to exercise Dockle/Dive/Trivy-image/Grype-image as required by the automation. Do not treat these OS CVEs as product vulnerabilities until a first-party image is published. If/when a Dockerfile is added, pin a maintained base and rebuild on distro security updates.

+
+
+
IGNORE
+

Container runs as root; no HEALTHCHECK; content trust unset

+

ID: Dockle CIS-DI-0001 (and related INFO findings)
+ Component: python:3.12-slim-bookworm proxy image

+

Why a code / process change (not pyproject alone)

+

Requires Dockerfile USER/HEALTHCHECK instructions and deployment content-trust policy — not addressable in pyproject.toml.

+

Rationale

+

Findings apply to the proxy base image used for scanner coverage, not a shipped fastWorkflow image. Track as image-hardening requirements when a first-party Dockerfile is introduced.

+
+
+

pyproject.toml easy-fix outcome

+

No third-party package vulnerability in the locked graph had a fixed version available on PyPI. Therefore this PR does not change dependency pins for CVE remediation. Prior release work (v2.25–v2.30) already raised floors for litellm, python-multipart, starlette, cryptography, aiohttp, urllib3, requests, setuptools, and related packages.

+

Optional follow-ups (not done here): add SNYK_TOKEN / Docker Hub auth for Scout; publish a first-party runtime Dockerfile if container CVEs should become product backlog.

+
+
+ +