Skip to main content

OA010: Vulnerable Floor

Severity: variable (tracks worst admitted advisory)  ·  Auto-fix: yes  ·  Requires: --check-network

An override floor is a range (such as >=5.7.0 <6 or ^5.7.0), admitting every published version above the floor within the permitted ceiling. Even when the installed version is already fixed, a range floor can admit later published versions that carry known vulnerabilities.

A standard CVE scan asks: what fixes the version I have installed? A floor asks a different question: is everything this range permits clean? Even if your lockfile currently resolves a clean version, an override floor that admits vulnerable releases permits future resolutions inside that range to select a vulnerable version.

Like OA007, OA010 requires --check-network. OA010 is a pure consumer of data that the audit gathers only when --check-network is enabled; OA010 itself makes no network calls and silently no-ops otherwise.


Example​

{
"pnpm": {
"overrides": {
"fast-xml-parser": ">=5.7.0 <6"
}
}
}

This represents the motivating real-world case:

  • fast-xml-parser@5.5.8 was installed.
  • 5.7.0 fixed GHSA-gh4j-gqv2-49f6.
  • The override >=5.7.0 <6 was added to patch the vulnerability, but the range also admits later releases such as 5.9.3 and 5.10.0.
  • Those versions carry GHSA-8r6m-32jq-jx6q.
  • That advisory is high severity and is first patched in 5.10.1.
  • OA010 flags the range and raises the floor to >=5.10.1 <6.

This issue was observed in CopilotKit/CopilotKit#7167, where an external maintainer found the same problem by querying the advisory API manually after refreshing stale override floors.


Terminal output​

HIGH (1)

RulePackageMessage
OA010fast-xml-parserOverride floor admits a known-vulnerable version
package.json > /pnpm/overrides/fast-xml-parser
cve-lite . overrides --fix --rule OA010 --check-network

Scope​

OA010 evaluates override ranges that specify a floor:

PatternHandled by
">=5.7.0 <6" (range floor and ceiling)OA010
"^5.7.0" (caret range)OA010
">=5.7.0" (unbounded floor)OA010
"5.7.0" (exact pin)OA008 / OA004
"latest" (floating tag)OA007 / OA002

Exact pins such as "5.7.0" are not in scope: an exact pin admits exactly one version, which is evaluated by OA008 (checking whether a vulnerable copy materialized on disk) or OA004 (checking whether the pin is surpassed).


Fix​

cve-lite . overrides --fix --rule OA010 --check-network

--fix raises the floor using an RFC 6902 replace patch:

  • Clears the highest vulnerable version: The replacement floor is the lowest admitted clean version that clears the highest vulnerable version admitted by the range, not merely the lowest vulnerable version.
  • Preserves existing ceilings: Existing upper bounds are preserved, so >=5.7.0 <6 becomes >=5.10.1 <6.
  • Rewrites caret ranges: A bare caret cannot express a raised floor, so ^5.7.0 becomes >=5.10.1 <6.0.0.
  • No clean version available: If every admitted version in the range is vulnerable, OA010 reports the finding without an auto-fix patch. Raising the floor cannot help without widening the ceiling, which is an architectural decision that requires developer review.

Severity​

Inherited from the worst advisory found in the admitted range. It is not fixed; unlike the other rules, severity varies per finding (e.g. low, medium, high, or critical depending on the advisories affecting the admitted versions).


Network requirement​

OA010 requires --check-network. It is a pure consumer of data that the audit gathers only when --check-network is enabled. OA010 itself makes no network calls and silently no-ops when network checks are disabled or when registry and advisory data are unavailable. This is the same contract as OA007.


Complementary rules​

RuleQuestion
OA008Is a vulnerable copy of this package on disk right now?
OA009Is this floor redundant, already met by every parent?
OA010Is the range this floor admits safe?
OA007Has a floating tag frozen behind the npm registry? (also requires --check-network)