Skip to content

Add v1.0.6 release review - #145

Draft
erayd wants to merge 3 commits into
parcel-pm:masterfrom
erayd:v1.0.6-review
Draft

Add v1.0.6 release review#145
erayd wants to merge 3 commits into
parcel-pm:masterfrom
erayd:v1.0.6-review

Conversation

@erayd

@erayd erayd commented Aug 19, 2026

Copy link
Copy Markdown
Member

v1.0.6 Security Review — New Findings

Two-model review using kimi-k3 and glm-5.2, merged August 19, 2026 against Parcel v1.0.6 (commit 03fec5a).

ID Severity Title
F52C CRITICAL VALIDSIG signer extraction was forgeable via an unanchored grep (fixed in #144)
F53M MEDIUM Concurrent host processes multiply the persisted rate-limiter budget
F54L LOW Unvalidated otpauth:// digits/period → large-allocation DoS in browser-side TOTP
F55L LOW clientDataJSON.crossOrigin hardcoded false for cross-origin-iframe ceremonies
F56L LOW No adversarial regression test for the #144 VALIDSIG-injection fix
F57L LOW Schema unknown-property rejection is prototype-subvertible
F58L LOW MetaSchema nested self-recursion never fires

Totals: 1 CRITICAL (fixed in release, not exploitable in the shipped tree), 1 MEDIUM, 5 LOW. No CRITICAL/HIGH exploitable in v1.0.6; make test passes 440/440. Three findings disputed between models (F52C reachability, F57L & F58L finding-vs-residual); canonical severities recorded with both positions in the merged report.

F52C was fixed in #144 before release; the v1.0.6 committed tree is not vulnerable.

Task tracking

@erayd erayd self-assigned this Aug 19, 2026
@erayd erayd added the security This relates to the security of the extension label Aug 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security This relates to the security of the extension

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant