中HT-VULN-001依赖存在已知漏洞
置信度 中L1 · 已知漏洞
package-lock.jsonGitHub
1@opentelemetry/core@2.7.1 GHSA-8988-4f7v-96qf (CVE-2026-54285) fixed in 2.8.0
OSV.dev 收录的公开漏洞存在于锁定的生产依赖树中;是否可被利用取决于插件如何使用该依赖。
修复建议升级到修复版本,或评估并移除该依赖。
通过 Photon 接入 DeepSeek Harness 的双向 iMessage 通道:按发件人白名单路由,支持会话命令、聊天内审批与提问,并提供用于设备授权和托管号码设置的 Settings 页面。
在 58 个文件中有 2 项有效发现(置信度 ≥ 中)。
1@opentelemetry/core@2.7.1 GHSA-8988-4f7v-96qf (CVE-2026-54285) fixed in 2.8.0
1node:child_process
93"prepare": "npm run build"
| 漏洞 | 依赖 | 严重度 | 修复版本 | 摘要 |
|---|---|---|---|---|
| GHSA-8988-4f7v-96qf CVE-2026-54285 | @opentelemetry/core@2.7.1 | 中 | 2.8.0 | OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation |
[](https://dshmod.com/plugins/photon-hq-dsh-imessage)