Repository navigation
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Version 1.0.2 is incorrectly marked affected, the narrative contains related historical inaccuracies, and valid CVSS v3 metadata is removed.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Updates the advisory with package metadata, affected versions, expanded technical details, and references.
Changes:
- Adds Packagist package and version-range metadata.
- Expands vulnerability details and source references.
- Normalizes CVSS v4 metadata and removes CVSS v3.
| File | Description |
|---|---|
advisories/unreviewed/2026/10/GHSA-mpgp-p4pg-fp7c/GHSA-mpgp-p4pg-fp7c.json |
Updates advisory metadata, severity, affected range, description, and references. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| ], | ||
| "details": "The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.", | ||
| "summary": "alexpechkarev/google-maps disables TLS certificate verification by default", | ||
| "details": "The `alexpechkarev/google-maps` Laravel package disables TLS certificate and hostname verification by default starting in version 1.0.2.\n\nThe bundled configuration sets `ssl_verify_peer` to `FALSE`. This value is loaded by `WebService` and passed directly to `CURLOPT_SSL_VERIFYPEER`. When disabled, the package also sets `CURLOPT_SSL_VERIFYHOST` to `0`.\n\nAs a result, HTTPS connections made by the package do not authenticate the remote TLS endpoint by default. An on-path attacker may therefore be able to intercept or modify Google Maps web-service requests and responses, including potentially exposing API keys transmitted in request URLs.\n\nThe insecure default was introduced in commit `7f9dcce` and is present in release 1.0.2. Version 1.0.1 does not contain the `ssl_verify_peer` configuration option. The insecure default remains present in the latest release, 12.16, and on the current default branch. No patched release has been identified.", |
There was a problem hiding this comment.
Confirmed after checking the upstream Git history and affected release tags.
Although ssl_verify_peer => FALSE was added to the bundled configuration in version 1.0.2, that version does not contain the WebService runtime logic that consumes this setting.
The relevant cURL behavior was introduced by commit d1867b2. The first release containing that commit is 1.0.3.
Direct tag verification shows:
1.0.1: no relevantWebServiceSSL verification code1.0.2: no relevantWebServiceSSL verification code1.0.3: readsgooglemaps.ssl_verify_peerinto$verifySSLand passes it toCURLOPT_SSL_VERIFYPEER
Therefore, I agree that the affected range should begin at 1.0.3, not 1.0.2.
Versions through v12.16 remain affected because the bundled configuration continues to set ssl_verify_peer => FALSE. No patched release has been identified.
| { | ||
| "type": "CVSS_V4", | ||
| "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" | ||
| "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N" |
There was a problem hiding this comment.
Confirmed against the pre-PR advisory metadata from the current upstream main branch.
The existing advisory contains the following CVSS v3.1 vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The improvement was intended only to normalize the CVSS v4 vector by removing the unsupported optional X metrics. It should not remove the existing CVSS v3.1 severity metadata.
Therefore, the advisory should retain both:
- CVSS v3.1:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N - CVSS v4:
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
I agree that the existing CVSS v3.1 entry should be restored.

Updates
Comments
This improvement adds missing Composer package metadata and corrects the affected version range based on the upstream repository history.
The affected package is
alexpechkarev/google-maps.Upstream Git history shows that
ssl_verify_peer => FALSEwas introduced in commit7f9dcce, which is tagged as version1.0.2. Version1.0.1does not contain this setting, while version1.0.2does. Therefore, the affected range begins at1.0.2, rather than1.0.3.The configuration value is security-relevant:
WebService.phploadsgooglemaps.ssl_verify_peerinto$this->verifySSL, which is subsequently passed toCURLOPT_SSL_VERIFYPEER. When false,CURLOPT_SSL_VERIFYHOSTis also set to0.The insecure default remains present in the latest release,
v12.16, and on the current default branch. No patched release has been identified, so the affected range is represented as>= 1.0.2.This improvement also normalizes the existing CVSS v4 vector by retaining its base metrics while removing unsupported optional
Xmetrics rejected by the GitHub advisory form.