GHSA-w7pm-9g55-mxfmHighDisclosed before NVD

stigmem-node's unsigned plugin override could be enabled without a second explicit acknowledgment

Published
May 29, 2026
Last Modified
May 29, 2026

📋 Description

Impact

A single configuration flag could disable plugin signature enforcement. If an operator unintentionally carried that setting into an environment where plugin paths are writable by less-trusted users, unsigned plugin code could be loaded.

Patches

Patched in 0.9.0a2. Disabling plugin signature enforcement now requires a second explicit acknowledgment value.

Workarounds

Before upgrading, keep plugin signing required in all shared or production environments and ensure plugin directories are not writable by untrusted users.

Upgrade

Upgrade to the patched release:

pip install --upgrade --pre stigmem-node

If developers install through the Stigmem meta-package instead, they should use the matching extra for deployments, for example:

pip install --upgrade --pre 'stigmem[node]'

Resources

  • Release: https://github.com/eidetic-labs/stigmem/releases/tag/v0.9.0a2
  • Changelog: https://github.com/eidetic-labs/stigmem/blob/v0.9.0a2/CHANGELOG.md#L14-L35
  • Security policy and posture: https://github.com/eidetic-labs/stigmem/blob/v0.9.0a2/SECURITY.md

🎯 Affected products1

  • pip/stigmem-node:< 0.9.0a2

🔗 References (5)