Skip to content

false vulnerability on redis-commander NSWG-ECO-362 #1540

Description

@ktzsolt

Hi Team!

There is this alleged vulnerability: https://github.com/nodejs/security-wg/blob/main/vuln/npm/362.json

The json contains the following for redis-commander

"vulnerable_versions": "<=0.13.12",
"patched_versions": null,

There is no 0.13.12 version for redis-commander, the newest version is 0.9.1:
https://github.com/joeferner/redis-commander/tags
https://github.com/joeferner/redis-commander/pkgs/container/redis-commander
and 0.9.0 on npm
https://www.npmjs.com/package/redis-commander?activeTab=versions

The issue was discussed and closed with resolution in this hackerone thread: https://hackerone.com/reports/296377
And gh issue is opened in the projet repo: joeferner/redis-commander#227
The gh issue is closed, this comment shows it is fixed: joeferner/redis-commander#227 (comment)
The clipboard.swf file is indeed removed since v0.5.0 version (git tag) with this commit: joeferner/redis-commander@1a483eb

Please update the file https://github.com/nodejs/security-wg/blob/main/vuln/npm/362.json based on this information because Trivy is picking up this vulnerability as unknown severity thus reporting it as a false positive: aquasecurity/trivy#10024 (comment)

Thank you!

Activity

  1. RafaelGSS commented on Jan 12, 2026

    @RafaelGSS
    Member

    Hi,

    The npm database is not updated for quite a while, I guess we could simply remove it.

    cc: @nodejs/security-wg

  2. added a commit that references this issue on Jan 24, 2026
  3. ktzsolt commented on Mar 2, 2026

    @ktzsolt
    Author

    Hi @RafaelGSS !

    I see that in PR #1546 you are trying to retire the vuln/npm thing that might break some other stuff based on @marco-ippolito comments.

    In the meantime you figure out this retirement, could we just update this line so Trivy would not pick this up as a false positive?
    from

    "vulnerable_versions": "<=0.13.12",

    to

    "vulnerable_versions": "<=0.5.0",
    

    Thanks!

  4. github-actions commented on Jun 1, 2026

    @github-actions
    Contributor

    This issue has been inactive for 90 days. It will be closed in 14 days unless there is further activity or the stale label is taken off.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions