VYPR

CWE-1116

Inaccurate Source Code Comments

BaseIncomplete

Description

The source code contains comments that do not accurately describe or explain aspects of the portion of the code with which the comment is associated.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2025-47271Med0.340.00May 12, 2025The OZI action is a GitHub Action that publishes releases to PyPI and mirror releases, signature bundles, and provenance in a tagged release. In versions 1.13.2 through 1.13.5, potentially untrusted data flows into PR creation logic. A malicious actor could construct a branch name that injects arbitrary code. This is patched in 1.13.6. As a workaround, one may downgrade to a version prior to 1.13.2.