GHSA-73p9-6hrp-8qhr: AIIR verification and policy gates could report success without enforcing the control (fail-open)
Several of AIIR’s verification and policy paths could return a success/“verified” result without actually enforcing the control they represent — they could fail open rather than fail closed. For a tool whose purpose is trustworthy verification, a consumer relying on these gates may have treated unverified or non-conforming input as verified.
Found during an internal adversarial hardening review of AIIR (not a third-party audit). All paths are fixed in 1.7.0.
References
Code Behaviors & Features
Detect and mitigate GHSA-73p9-6hrp-8qhr with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →