Listen to this Post
An unconfirmed or mishandled pre-release check in cve-lite-cli historically caused compareVersions to rank a pre-release above its associated release, violating semver rules. Specifically, an installed pre-release sitting below the fix version was reported as non-vulnerable, meaning a next canary build could silently clear CVE-2025-29927—a critical middleware authentication bypass—without performing a valid security check. Build metadata was incorrectly factored into the version comparison logic, allowing unpatched packages to bypass vulnerability thresholds during routine scans. This flaw meant that developers relying on automated CI/CD gating using cve-lite-cli would receive false-negative results on pre-release branches, leaving critical authentication layers exposed to unauthorized access. Remediation required updating compareVersions to strictly ignore build metadata per semver specification and ensuring pre-release installs are properly evaluated against their affected ranges.
DailyCVE Form:
Platform: OWASP CLI
Version: v1.34.0
Vulnerability : Auth Bypass
Severity: Critical
date: 2025-04-01
Prediction: 2025-04-01
What Undercode Say
`npx cve-lite-cli –sbom spdx2.3 –incomplete-policy error`
`compareVersions –ignore-build-metadata`
Exploit: (Educational Purposes!)
npm install [email protected] npx cve-lite-cli . --sbom spdx2.3
Protection:
Upgrade to version v1.34.0 or later where pre-release comparison bugs are fixed.
Impact:
Complete authentication bypass on protected endpoints.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

