Skip to content

🚨 Security: Critical issues in graphlit-mcp-server container #351

@github-actions

Description

@github-actions

🚨 Security Scan Alert

A periodic security scan found critical issues in the container image:

  • Image: ghcr.io/stacklok/dockyard/npx/graphlit-mcp-server:1.0.20260112001
  • Critical vulnerabilities: 2
  • High vulnerabilities: 13
  • Secrets detected: 0

Details

See the Security tab for full details.

Critical Vulnerabilities

  • CVE-2025-15467 in libcrypto3: openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing
  • CVE-2025-15467 in libssl3: openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing

Automated security scan from periodic-security-scan workflow

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions