{
  "@context": "https://openvex.dev/ns/v0.2.0",
  "@id": "https://growsurf.com/security/openvex.json",
  "author": "https://growsurf.com",
  "role": "Document Creator",
  "timestamp": "2026-09-16T13:44:34.649271+00:00",
  "version": 2,
  "statements": [
    {
      "vulnerability": {
        "@id": "https://github.com/advisories/GHSA-qwqh-hm9m-p5hr",
        "name": "CVE-2023-26118"
      },
      "products": [
        {
          "@id": "urn:sha256:ea96b8d853e5cf905e31b406296b1aae7b9e8ff272d5a203c99db28c258f715f",
          "subcomponents": [
            {
              "@id": "https://app.growsurf.com/913.feb1e4be986168c9db18.bundle.js",
              "hashes": {
                "sha-256": "c5f0c0b25b0c5f33058e1eee036eac1e4eb2c711a4da2e77d665ef5577d3a938"
              }
            },
            {
              "@id": "https://app.growsurf.com/main.4cb6f983797329bf9b8f.bundle.js",
              "hashes": {
                "sha-256": "b44d3d2944cb04f64b2821e989036aa12ae2ecc8d71abbe78e7df96d094a657d"
              }
            },
            {
              "@id": "pkg:npm/angular"
            }
          ]
        }
      ],
      "status": "not_affected",
      "status_notes": "Scope is the two captured dashboard bundles only; no other build, server, or product is covered.",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "GrowSurf replaces AngularJS URL inputs with bounded native URL validation. Deployed runtime checks accept HTTPS, reject FTP, and reject values beyond the 500-character limit. Parsed strings in both captured bundles contain no URL-type input templates; source and dynamic-template review found no reachable AngularJS URL-input path."
    },
    {
      "vulnerability": {
        "@id": "https://github.com/advisories/GHSA-4p4w-6hg8-63wx",
        "name": "CVE-2025-2336"
      },
      "products": [
        {
          "@id": "urn:sha256:ea96b8d853e5cf905e31b406296b1aae7b9e8ff272d5a203c99db28c258f715f",
          "subcomponents": [
            {
              "@id": "https://app.growsurf.com/913.feb1e4be986168c9db18.bundle.js",
              "hashes": {
                "sha-256": "c5f0c0b25b0c5f33058e1eee036eac1e4eb2c711a4da2e77d665ef5577d3a938"
              }
            },
            {
              "@id": "https://app.growsurf.com/main.4cb6f983797329bf9b8f.bundle.js",
              "hashes": {
                "sha-256": "b44d3d2944cb04f64b2821e989036aa12ae2ecc8d71abbe78e7df96d094a657d"
              }
            },
            {
              "@id": "pkg:npm/angular-sanitize"
            }
          ]
        }
      ],
      "status": "not_affected",
      "status_notes": "Scope is the two captured dashboard bundles only; no other build, server, or product is covered.",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "GrowSurf disables SVG support in the AngularJS sanitizer. The captured bundle contains the setting, and the deployed sanitizer removes SVG and image elements from the representative SVG input."
    },
    {
      "vulnerability": {
        "@id": "https://github.com/advisories/GHSA-4w4v-5hc9-xrr2",
        "name": "CVE-2024-21490"
      },
      "products": [
        {
          "@id": "urn:sha256:ea96b8d853e5cf905e31b406296b1aae7b9e8ff272d5a203c99db28c258f715f",
          "subcomponents": [
            {
              "@id": "https://app.growsurf.com/913.feb1e4be986168c9db18.bundle.js",
              "hashes": {
                "sha-256": "c5f0c0b25b0c5f33058e1eee036eac1e4eb2c711a4da2e77d665ef5577d3a938"
              }
            },
            {
              "@id": "https://app.growsurf.com/main.4cb6f983797329bf9b8f.bundle.js",
              "hashes": {
                "sha-256": "b44d3d2944cb04f64b2821e989036aa12ae2ecc8d71abbe78e7df96d094a657d"
              }
            },
            {
              "@id": "pkg:npm/angular"
            }
          ]
        }
      ],
      "status": "not_affected",
      "status_notes": "Scope is the two captured dashboard bundles only; no other build, server, or product is covered.",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "The captured application bundle contains no srcset references. Parsed template strings in both bundles contain no image or source srcset bindings. Source, dependency-template, and dynamic-compilation review found no reachable affected binding. The deployed sanitizer removes srcset attributes."
    },
    {
      "vulnerability": {
        "@id": "https://github.com/advisories/GHSA-7x27-g8rg-x87w",
        "name": "CVE-2026-11998"
      },
      "products": [
        {
          "@id": "urn:sha256:ea96b8d853e5cf905e31b406296b1aae7b9e8ff272d5a203c99db28c258f715f",
          "subcomponents": [
            {
              "@id": "https://app.growsurf.com/913.feb1e4be986168c9db18.bundle.js",
              "hashes": {
                "sha-256": "c5f0c0b25b0c5f33058e1eee036eac1e4eb2c711a4da2e77d665ef5577d3a938"
              }
            },
            {
              "@id": "https://app.growsurf.com/main.4cb6f983797329bf9b8f.bundle.js",
              "hashes": {
                "sha-256": "b44d3d2944cb04f64b2821e989036aa12ae2ecc8d71abbe78e7df96d094a657d"
              }
            },
            {
              "@id": "pkg:npm/angular"
            }
          ]
        }
      ],
      "status": "not_affected",
      "status_notes": "Scope is the two captured dashboard bundles only; no other build, server, or product is covered.",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "GrowSurf keeps SCE enabled with a self-only trusted resource URL policy. The captured bundle contains that policy. Deployed runtime checks allow a same-origin resource and reject external origins, a lookalike host, and an origin embedded in a query string. Reviewed explicit trust calls use developer-controlled resource URLs."
    },
    {
      "vulnerability": {
        "@id": "https://github.com/advisories/GHSA-w93q-cq9w-58p7",
        "name": "GHSA-w93q-cq9w-58p7"
      },
      "products": [
        {
          "@id": "urn:sha256:ea96b8d853e5cf905e31b406296b1aae7b9e8ff272d5a203c99db28c258f715f",
          "subcomponents": [
            {
              "@id": "https://app.growsurf.com/913.feb1e4be986168c9db18.bundle.js",
              "hashes": {
                "sha-256": "c5f0c0b25b0c5f33058e1eee036eac1e4eb2c711a4da2e77d665ef5577d3a938"
              }
            },
            {
              "@id": "https://app.growsurf.com/main.4cb6f983797329bf9b8f.bundle.js",
              "hashes": {
                "sha-256": "b44d3d2944cb04f64b2821e989036aa12ae2ecc8d71abbe78e7df96d094a657d"
              }
            },
            {
              "@id": "pkg:npm/suneditor"
            }
          ]
        }
      ],
      "status": "not_affected",
      "status_notes": "Scope is the two captured dashboard bundles only; no other build, server, or product is covered.",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The shipped SunEditor module does not contain the reported 3.x embed plugin. Inspection of the captured vendor module confirms the video setup_url path uses an iframe and contains no script-element creation. The source dependency is pinned to SunEditor 2.47.12; this conclusion is based on the captured code path, not a version string in the bundle."
    }
  ],
  "last_updated": "2026-09-16T14:11:24.206185+00:00"
}
