Skip to content

Require on-device confirmation for host XPUB requests - #381

Open
schnuartz-ai wants to merge 14 commits into
cryptoadvance:masterfrom
Schnuartz:claude/xpub-host-command-confirm-p8x5r9
Open

schnuartz-ai wants to merge 14 commits into
cryptoadvance:masterfrom
Schnuartz:claude/xpub-host-command-confirm-p8x5r9

xpubs: validate a plain xpub request before deriving anything

9bfeb11
Select commit
Loading
Failed to load commit list.
Debricked / Vulnerability analysis completed Sep 4, 2026 in 15s

An automation triggered a pipeline warning

Found 12 vulnerabilities. An additional 0 vulnerabilities have been marked as unaffected.

Output from Automations

4 rules were checked:


If a new dependency is added where the license risk is at least medium

then notify all users in the group admins by email

✔️ The rule did not trigger. Manage rule



If a dependency contains a vulnerability which has not been marked as unaffected and which has not triggered this rule for this dependency before

then notify all users in the group admins by email

✔️ The rule did not trigger. Manage rule



If there is a dependency where the license risk is at least high

then send a pipeline warning

✔️ The rule did not trigger. Manage rule



If a dependency contains a vulnerability which has not been marked as unaffected

then send a pipeline warning

⚠️ The rule triggered for the following vulnerabilities, causing a pipeline warning. Manage rule

Vulnerability CVSS2 CVSS3 CVSS4 Dependency Dependency Licenses
CVE-2025-66471 N/A 7.5 8.9 urllib3 (pypi) MIT
CVE-2025-66418 N/A 7.5 8.9 urllib3 (pypi) MIT
CVE-2026-21441 N/A 7.5 8.9 urllib3 (pypi) MIT
CVE-2026-44431 N/A 5.3 8.2 urllib3 (pypi) MIT
CVE-2025-69534 N/A 7.5 N/A markdown (pypi) BSD-3-Clause
CVE-2026-7246 N/A 7.2 N/A click (pypi) BSD-3-Clause
CVE-2026-45409 N/A 5.3 6.9 idna (pypi) BSD-3-Clause
CVE-2025-50182 N/A 6.1 N/A urllib3 (pypi) MIT
CVE-2025-50181 N/A 6.1 N/A urllib3 (pypi) MIT
CVE-2026-25645 N/A 5.5 N/A requests (pypi) Apache-2.0
CVE-2025-27516 N/A 8.8 5.4 Jinja2 (pypi) BSD-3-Clause
CVE-2024-47081 N/A 5.3 N/A requests (pypi) Apache-2.0