Skip to content

[Aikido] Fix security issue in zerovec-derive via minor version upgrade from 0.11.3 to 0.11.5 in src-tauri - #53

Merged
cst8t merged 1 commit into
v0.12.1-developfrom
fix/aikido-security-update-packages-133372454-7rjt
Oct 4, 2026
Merged

cst8t merged 1 commit into
v0.12.1-developfrom
fix/aikido-security-update-packages-133372454-7rjt

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Upgrade zerovec-derive to fix validation bypass in #[derive(ULE)] macro that allowed malformed bytes to pass validation, enabling undefined behavior through unsafe reinterpretation.

✅ 1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2026-573777
HIGH
[zerovec-derive] The #[derive(ULE)] macro's validation function only checks the first element of multi-element buffers, allowing malformed bit patterns in later elements to bypass validation and cause undefined behavior through unsafe zero-copy reinterpretation.

@cst8t
cst8t merged commit 0ee3a2e into v0.12.1-develop Oct 4, 2026
2 checks passed
@cst8t
cst8t deleted the fix/aikido-security-update-packages-133372454-7rjt branch October 4, 2026 17:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant