Skip to content

fix: suppress smolagents GHSA-54fq-v6x8-244g and GHSA-jxgv-6j54-wwc7 (CVSS 6.3, no stable fix yet) #35

@JacobPEvans-personal

Description

@JacobPEvans-personal

Context

smolagents has two CVSS 6.3 advisories with no stable fix version as of 2026-05-07:

The CVSS 10.0 vulnerability (GHSA-q9r5-6hrr-9ph7) was resolved by upgrading to 1.24.0.

These two are suppressed in osv-scanner.toml until 2026-08-07.

Action Required

When smolagents 1.25.0 stable is released, close this issue and remove both suppression entries from osv-scanner.toml.

Verification command:

osv-scanner scan --config osv-scanner.toml uv.lock

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions