OA010: Vulnerable Floor
Severity: variable (tracks worst admitted advisory) · Auto-fix: yes · Requires: --check-network
An override floor is a range (such as >=5.7.0 <6 or ^5.7.0), admitting every published version above the floor within the permitted ceiling. Even when the installed version is already fixed, a range floor can admit later published versions that carry known vulnerabilities.
A standard CVE scan asks: what fixes the version I have installed? A floor asks a different question: is everything this range permits clean? Even if your lockfile currently resolves a clean version, an override floor that admits vulnerable releases permits future resolutions inside that range to select a vulnerable version.
Like OA007, OA010 requires --check-network. OA010 is a pure consumer of data that the audit gathers only when --check-network is enabled; OA010 itself makes no network calls and silently no-ops otherwise.
Example
{
"pnpm": {
"overrides": {
"fast-xml-parser": ">=5.7.0 <6"
}
}
}
This represents the motivating real-world case:
fast-xml-parser@5.5.8was installed.5.7.0fixed GHSA-gh4j-gqv2-49f6.- The override
>=5.7.0 <6was added to patch the vulnerability, but the range also admits later releases such as5.9.3and5.10.0. - Those versions carry GHSA-8r6m-32jq-jx6q.
- That advisory is high severity and is first patched in
5.10.1. - OA010 flags the range and raises the floor to
>=5.10.1 <6.
This issue was observed in CopilotKit/CopilotKit#7167, where an external maintainer found the same problem by querying the advisory API manually after refreshing stale override floors.
Terminal output
HIGH (1)
| Rule | Package | Message |
|---|---|---|
| OA010 | fast-xml-parser | Override floor admits a known-vulnerable version package.json > /pnpm/overrides/fast-xml-parser |
cve-lite . overrides --fix --rule OA010 --check-network
Scope
OA010 evaluates override ranges that specify a floor:
| Pattern | Handled by |
|---|---|
">=5.7.0 <6" (range floor and ceiling) | OA010 |
"^5.7.0" (caret range) | OA010 |
">=5.7.0" (unbounded floor) | OA010 |
"5.7.0" (exact pin) | OA008 / OA004 |
"latest" (floating tag) | OA007 / OA002 |
Exact pins such as "5.7.0" are not in scope: an exact pin admits exactly one version, which is evaluated by OA008 (checking whether a vulnerable copy materialized on disk) or OA004 (checking whether the pin is surpassed).
Fix
cve-lite . overrides --fix --rule OA010 --check-network
--fix raises the floor using an RFC 6902 replace patch:
- Clears the highest vulnerable version: The replacement floor is the lowest admitted clean version that clears the highest vulnerable version admitted by the range, not merely the lowest vulnerable version.
- Preserves existing ceilings: Existing upper bounds are preserved, so
>=5.7.0 <6becomes>=5.10.1 <6. - Rewrites caret ranges: A bare caret cannot express a raised floor, so
^5.7.0becomes>=5.10.1 <6.0.0. - No clean version available: If every admitted version in the range is vulnerable, OA010 reports the finding without an auto-fix patch. Raising the floor cannot help without widening the ceiling, which is an architectural decision that requires developer review.
Severity
Inherited from the worst advisory found in the admitted range. It is not fixed; unlike the other rules, severity varies per finding (e.g. low, medium, high, or critical depending on the advisories affecting the admitted versions).
Network requirement
OA010 requires --check-network. It is a pure consumer of data that the audit gathers only when --check-network is enabled. OA010 itself makes no network calls and silently no-ops when network checks are disabled or when registry and advisory data are unavailable. This is the same contract as OA007.
Complementary rules
| Rule | Question |
|---|---|
| OA008 | Is a vulnerable copy of this package on disk right now? |
| OA009 | Is this floor redundant, already met by every parent? |
| OA010 | Is the range this floor admits safe? |
| OA007 | Has a floating tag frozen behind the npm registry? (also requires --check-network) |