Skip to content

Conversation

@softworkz
Copy link

Updates

  • Affected products

Comments
Somebody has changed the affected products from the original advisory (GHSA-95fv-5gfj-2r84) to some of our nuget packages which are in no way affected. Now they are shown on Nuget as vulnerable even though that isn't true. The nuget packages are merely containing interfaces for plugins and using a newer or older nuget package doesn't have an effect on security. This is solely a matter of updating the Emby Server software to the latest versions.

Our Nuget packages must not be marked as vulnerable and with all due respect - I do not understand how you can make such a fundamental and impactful change to the information we have given, even without checking back.

Thanks

@github
Copy link
Collaborator

github commented Dec 27, 2025

Hi there @softworkz! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

Copilot AI review requested due to automatic review settings December 27, 2025 21:48
@github-actions github-actions bot changed the base branch from main to softworkz/advisory-improvement-6584 December 27, 2025 21:49
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request corrects a GitHub Security Advisory for an Emby Server vulnerability by removing incorrect NuGet package references and properly identifying the affected product as the Emby Server application itself (not NuGet packages). The advisory originally listed MediaBrowser.Server.Core as the affected package, which caused unaffected NuGet packages to be incorrectly flagged as vulnerable.

  • Changed affected package from MediaBrowser.Server.Core to properly identify Emby Server application (stable and beta versions)
  • Updated fixed version from 4.9.1.81 to 4.9.1.90 for stable release
  • Added separate entry for Emby Server Beta with fixed version 4.9.2.7

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +41 to +44
"package": {
"ecosystem": "NuGet",
"name": "Emby-Server-Beta-(not-any-nuget-package)"
},
Copy link

Copilot AI Dec 27, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The package name "Emby-Server-Beta-(not-any-nuget-package)" is problematic because it's marked as ecosystem "NuGet" but explicitly states it's not a NuGet package. This creates an inconsistency in the advisory metadata. If this is the Emby Server Beta application rather than a NuGet package, consider using a different ecosystem type or advisory format that better represents standalone applications rather than package dependencies.

Copilot uses AI. Check for mistakes.
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There is no matching "ecosystem".

@helixplant
Copy link

Hi @softworkz,
Thank you for bringing this to our attention. We will withdraw the advisory so it will no longer issue alerts for the MediaBrowser.Server.Core package. This will not impact your CVE or GHSA-95fv-5gfj-2r84. We will stop issuing global alerts for the incorrect package, and we are unable to issue alerts for Emby Server as it is not part of a supported ecosystem.

The package was likely included due to an unintentional mapping error, and we will take steps to prevent this from happening in the future.

@softworkz
Copy link
Author

@helixplant

Excellent, thank you very much!

@advisory-database advisory-database bot merged commit 6bd596f into softworkz/advisory-improvement-6584 Dec 29, 2025
10 checks passed
@advisory-database
Copy link
Contributor

Hi @softworkz! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the softworkz-GHSA-95fv-5gfj-2r84 branch December 29, 2025 19:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants