-
Notifications
You must be signed in to change notification settings - Fork 29
Issues
is:issue state:open
is:issue state:open
Issue creation is restricted in this repository
Search results
Dependency regression detected by npm audit (weekly)
GrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial CampaignAudit finding under the Official CampaignAudit finding under the Official CampaignStatus: Open.#40 In OrbitChainLabs/OrbitChain-API;[CRITICAL] —
PATCH /campaigns/:idis an IDOR: any authenticated wallet holder can overwrite *any* campaign's title, description, story, and imagebugSomething isn't workingSomething isn't workingGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial CampaignAudit finding under the Official CampaignAudit finding under the Official CampaignsecuritySecurity vulnerability or hardeningSecurity vulnerability or hardeningStatus: Open.#19 In OrbitChainLabs/OrbitChain-API;[LOW] — Widespread
@Request() req: any,@Req() req: Request & { user: any }, andas anypatterns defeat type safety across ~30 call sitesgood first issueGood for newcomersGood for newcomersGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSShelp wantedExtra attention is neededExtra attention is neededMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial CampaignAudit finding under the Official CampaignAudit finding under the Official CampaignrefactoringCode restructuring without behavioural changeCode restructuring without behavioural changeStatus: Open.#17 In OrbitChainLabs/OrbitChain-API;[MEDIUM] — Three independent Redis client connections across
CacheModule,ThrottlerRedisStorage, andRedisHealthIndicator; no shared connection poolGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSShelp wantedExtra attention is neededExtra attention is neededMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial CampaignAudit finding under the Official CampaignAudit finding under the Official CampaignrefactoringCode restructuring without behavioural changeCode restructuring without behavioural changeStatus: Open.#14 In OrbitChainLabs/OrbitChain-API;[MEDIUM] — Stellar event listener persists cursor in cache with global 60s TTL, silently losing the cursor on restart and causing duplicate event processing
bugSomething isn't workingSomething isn't workingGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial CampaignAudit finding under the Official CampaignAudit finding under the Official CampaignrefactoringCode restructuring without behavioural changeCode restructuring without behavioural changeStatus: Open.#13 In OrbitChainLabs/OrbitChain-API;[MEDIUM] — Horizon HTTP fetches in
StellarTransactionsServicelackAbortController/ request timeout, can block indefinitely on Horizon hangsbugSomething isn't workingSomething isn't workingGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial CampaignAudit finding under the Official CampaignAudit finding under the Official CampaignrefactoringCode restructuring without behavioural changeCode restructuring without behavioural changeStatus: Open.#11 In OrbitChainLabs/OrbitChain-API;[MEDIUM] —
AdminGuardissues a freshprisma.user.findUniqueon every protected request instead of caching role lookupsGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSShelp wantedExtra attention is neededExtra attention is neededMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial CampaignAudit finding under the Official CampaignAudit finding under the Official CampaignrefactoringCode restructuring without behavioural changeCode restructuring without behavioural changeStatus: Open.#10 In OrbitChainLabs/OrbitChain-API;[MEDIUM] —
parseAcceptedAssetssilently drops malformed entries instead of rejecting the create/update requestbugSomething isn't workingSomething isn't workinggood first issueGood for newcomersGood for newcomersGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial CampaignAudit finding under the Official CampaignAudit finding under the Official CampaignStatus: Open.#9 In OrbitChainLabs/OrbitChain-API;[HIGH] — WebSocket gateway declares
cors.origin: '*'alongsidecredentials: true, an invalid combination exploitable depending on proxy configurationGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial CampaignAudit finding under the Official CampaignAudit finding under the Official CampaignrefactoringCode restructuring without behavioural changeCode restructuring without behavioural changesecuritySecurity vulnerability or hardeningSecurity vulnerability or hardeningStatus: Open.#7 In OrbitChainLabs/OrbitChain-API;[HIGH] —
GET /campaignscache key omitspage,limitandsortBy, serving identical payloads for vastly different requestsbugSomething isn't workingSomething isn't workingGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial CampaignAudit finding under the Official CampaignAudit finding under the Official CampaignStatus: Open.#5 In OrbitChainLabs/OrbitChain-API;[HIGH] —
EmailService.sendlogs the full rendered HTML body to console in development; may leak PII into log streamsgood first issueGood for newcomersGood for newcomersGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial CampaignAudit finding under the Official CampaignAudit finding under the Official CampaignsecuritySecurity vulnerability or hardeningSecurity vulnerability or hardeningStatus: Open.#4 In OrbitChainLabs/OrbitChain-API;[HIGH] — JWT strategy and WebSocket gateway fall back to insecure hardcoded strings when
JWT_SECRETis unset, allowing weak-secret boots in any environmentGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial CampaignAudit finding under the Official CampaignAudit finding under the Official CampaignrefactoringCode restructuring without behavioural changeCode restructuring without behavioural changesecuritySecurity vulnerability or hardeningSecurity vulnerability or hardeningStatus: Open.#3 In OrbitChainLabs/OrbitChain-API;