Skip to content

guard-livereload security vulnerability #289

Activity

  1. phillmv commented on Apr 10, 2017

    @phillmv
    Member

    We're definitely missing this issue - but what part is invalid?

  2. skorth commented on Apr 11, 2017

    @skorth
    ContributorAuthor

    @phillmv I just didn't find any CVE assignment on mitre.

  3. attritionorg commented on Apr 11, 2017

    @attritionorg

    That is part of DWF, which is a newly minted CNA. MITRE has not fully setup the process to automatically pull in and process DWF-assigned IDs. That is the official DWF GitHub though, so any assignment information there is legitimate.

  4. jasnow commented on Jan 12, 2026

    @jasnow
    Member

    NOTE: Found that this gem has not been released after fixing this vulnerability in release 2.5.2.
    See reference for gem rack-livereload in the last commit done.

  5. kallal79 commented on Mar 31, 2026

    @kallal79

    Hi @postmodern @jasnow ,
    I’ve already started investigating this guard-livereload vulnerability and reviewing the CVE/DWF references. Could you please assign this issue to me so I can continue working on it and prepare a PR with the necessary updates? Thanks!

  6. jasnow commented on May 31, 2026

    @jasnow
    Member

    @kallal79 provided update on PR #1026 today.

  7. jasnow commented on Jun 9, 2026

    @jasnow
    Member

    PR #1110 has been merged so closing this issue.

  8. jasnow commented on Jun 14, 2026

    @jasnow
    Member
  9. jasnow commented on Jun 20, 2026

    @jasnow
    Member
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions