Overview
Image: ghcr.io/github/serena-mcp-server:sha-891c160 — pinned reference:
ghcr.io/github/serena-mcp-server:sha-891c160@sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5
This is the largest and worst-scoring scanned image (2314 packages). Grype found 31 unique Critical CVEs and 205 unique High CVEs (plus Medium/Low/Negligible/Unknown findings). Grant found 514 license policy violations. This image needs the most urgent remediation attention.
Key metrics (unique CVE/advisory IDs)
| Severity |
Unique findings |
| Critical |
31 |
| High |
205 |
| Medium |
~172+ (423 raw rows) |
| Low |
95 (raw rows) |
| Negligible |
115 (raw rows) |
| Unknown |
39 (raw rows) |
Critical vulnerabilities
All 31 unique Critical CVEs
| CVE/Advisory |
Package(s) |
Fixed |
| CVE-2025-55130 |
libnode-dev, libnode115, nodejs |
+deb13u1 |
| CVE-2025-68121 |
golang-1.24-go/src |
(no fix listed) |
| CVE-2026-10536 |
libcurl3t64-gnutls |
(no fix listed) |
| CVE-2026-11856 |
libcurl3t64-gnutls |
(no fix listed) |
| CVE-2026-8924 |
libcurl3t64-gnutls |
(no fix listed) |
| CVE-2026-8926 |
libcurl3t64-gnutls |
(no fix listed) |
| CVE-2026-8927 |
libcurl3t64-gnutls |
(no fix listed) |
| CVE-2026-9079 |
libcurl3t64-gnutls |
(no fix listed) |
| CVE-2026-12087 |
perl (family) |
(no fix listed) |
| CVE-2026-13221 |
perl (family) |
(no fix listed) |
| CVE-2026-42496 |
perl (family) |
(no fix listed) |
| CVE-2026-57433 |
perl (family) |
(no fix listed) |
| CVE-2026-8376 |
perl (family) |
(no fix listed) |
| CVE-2026-13697 |
node-undici |
(no fix listed) |
| CVE-2026-1525 |
node-undici |
(no fix listed) |
| CVE-2026-25547 |
node-brace-expansion |
(no fix listed) |
| CVE-2026-27143 |
golang-1.24 |
(no fix listed) |
| CVE-2026-27699 |
node-agent-base, data-uri-to-buffer, http-proxy-agent, https-proxy-agent |
+deb13u1 |
| CVE-2026-31789 |
libssl-dev, libssl3t64, openssl, openssl-provider-legacy |
3.5.5 |
| CVE-2026-34182 |
libssl-dev, libssl3t64, openssl, openssl-provider-legacy |
3.5.6-1~deb13u2 |
| CVE-2026-33228 |
node-flatted |
+deb13u1 |
| CVE-2026-33845 |
libgnutls30t64 |
+deb13u4 |
| CVE-2026-42010 |
libgnutls30t64 |
+deb13u4 |
| CVE-2026-33937 |
handlebars |
(no fix via CVE; see GHSA-2w6w-674q-4c4q) |
| GHSA-2w6w-674q-4c4q |
handlebars |
4.7.9 |
| CVE-2026-45623 |
node-postcss |
(no fix listed) |
| CVE-2026-4800 |
node-lodash, node-lodash-packages |
(no fix listed) |
| CVE-2026-48930 |
libnode-dev, libnode115, nodejs |
(no fix listed) |
| CVE-2026-5450 |
libc-bin, libc6 |
(no fix listed) |
| CVE-2026-7598 |
libssh2-1t64 |
+deb13u1 |
| GO-2026-4337 |
stdlib (Go) |
go1.24.13 / 1.25.7 / 1.26.0-rc.3 |
High vulnerabilities
All 205 unique High CVEs (by affected component)
Grouped by component to keep this readable; every CVE/GHSA/GO ID below is a distinct finding:
- golang-1.24-go/src@1.24.4-1 — ~15+ CVEs, no fixed version listed by Grype (Debian stdlib package; requires distro patch).
- python@3.11.14 family — multiple CVEs, fixes range from 3.13.x to 3.15.x depending on advisory.
- libssl3t64 / openssl / openssl-provider-legacy / libssl-dev@3.5.4-1~deb13u2 — many CVEs, fixed in 3.5.5 or 3.5.6.
- perl family@5.40.1-6 — many CVEs, no fix listed (Debian perl package).
- libnode-dev / libnode115 / nodejs@20.19.2+dfsg-1 — many CVEs; some fixed in +deb13u1/+deb13u2, others unfixed.
- libcurl3t64-gnutls@8.14.1-2+deb13u2 — many CVEs; some fixed in +deb13u4.
- node-undici / node-ajv / node-brace-expansion / node-postcss / node-tar / handlebars (npm-level GHSA advisories) — each has a clear upstream fix version.
- stdlib (Go) via multiple
GO-xxxx IDs — fixes available at various Go point releases.
- Third-party Python packages:
cryptography, starlette, pyjwt, mcp, urllib3, ujson, black, wheel, python-multipart, soupsieve, jaraco-context — each with a GHSA ID and clear fix version.
- serena-agent@0.1.4 — GHSA-37h2-6p4f-mp3q, fixed in 1.5.2.
- github.com/modelcontextprotocol/go-sdk@v0.8.0 — multiple GHSA IDs, fixed in range 1.3.1–1.4.1.
Full per-CVE, per-package detail (371 raw rows / 205 unique IDs) is available in the raw scan log at /tmp/gh-aw/agent/image-scan/compile-output.txt (grep serena-mcp-server:sha-891c160 and \[High\]).
Medium / Low / Negligible / Unknown vulnerabilities
423 Medium, 95 Low, 115 Negligible, 39 Unknown raw findings
Given the volume, these are not individually enumerated here; they follow the same component distribution as the Critical/High findings above (Debian base OS packages: golang-1.24, python3.11, openssl, perl, libcurl, libnode/nodejs, plus transitive npm and Python application dependencies). Full detail available by grepping the raw scan log at /tmp/gh-aw/agent/image-scan/compile-output.txt for serena-mcp-server:sha-891c160 combined with [Medium], [Low], [Negligible], or [Unknown].
License policy violations
514 rejected/unknown licenses across 507 distinct packages (128 unique license strings)
Dominant patterns:
- 264 packages flagged
(Expat) — MIT-style license not on the allow-list.
- 28 packages —
(no licenses found).
- 18 packages —
(Expat, GPL-3.0-only, GPL-3.0-or-later) multi-license combos.
- Numerous smaller groups covering
GPL-2.0-only/GPL-2.0-or-later, GPL-3.0-only/GPL-3.0-or-later, LGPL family, BSD variants (2/3/4-clause), Artistic/Artistic-2.0, CC0-1.0, MPL-2.0, Zlib, HPND, public-domain, and several vendor-specific compound license strings (e.g. curl's own compound license listing, Python's compound license listing).
This image's large Debian + Python + Node.js + Go toolchain stack accounts for the bulk of all 725 license violations found across all 10 scanned images in this run. Full per-package detail available by grepping /tmp/gh-aw/agent/image-scan/compile-output.txt for serena-mcp-server:sha-891c160:1:1: error: license policy violation.
Remediation
- This image mixes Debian (bookworm/trixie-era) OS packages, Python 3.11, Node.js 20.19, and a Go 1.24 toolchain — the largest attack surface of any scanned image. Prioritize:
- Rebuild against a current Debian base to pick up
openssl>=3.5.5/3.5.6, libgnutls30t64>=+deb13u4, libssh2-1t64>=+deb13u1, and Node.js/libnode>=+deb13u1/+deb13u2 fixes — this resolves the majority of the 31 Critical findings with fixed versions.
- Bump the vendored Go toolchain to >=1.24.13/1.25.7/1.26.0-rc.3 (GO-2026-4337) and >=1.25.12/1.26.5 range for High Go stdlib advisories.
- Update npm-level dependencies:
handlebars>=4.7.9, node-flatted, node-agent-base/data-uri-to-buffer/http-proxy-agent/https-proxy-agent, node-undici, node-brace-expansion, node-postcss, node-tar.
- Upgrade
serena-agent itself to >=1.5.2 (GHSA-37h2-6p4f-mp3q) and github.com/modelcontextprotocol/go-sdk to >=1.3.1 (multiple GHSA advisories).
- Several Critical/High CVEs (
libcurl3t64-gnutls, perl family, golang-1.24-go/src, node-lodash) currently have no fixed version upstream — track for distro patches and document explicit risk acceptance per the 7-day Critical SLA if unresolved.
- License violations are largely inherent to the broad Debian/Python/Node/Go base; review the Grant policy allow-list for common permissive licenses (
Expat/MIT, BSD, Artistic-2.0, CC0-1.0) if they are intentionally acceptable, to reduce noise on future scans, and evaluate switching to a smaller/pinned base image to shrink the package surface.
- This workflow runs
gh aw compile --force-refresh-container-pins daily; a pin refresh PR to a newer serena-mcp-server build is the default remediation step once upstream publishes a patched image.
Generated by 🛡️ Daily Container Image Security Scan · auto · 295.8 AIC · ⌖ 10.1 AIC · ⊞ 6.9K · ◷
Overview
Image:
ghcr.io/github/serena-mcp-server:sha-891c160— pinned reference:ghcr.io/github/serena-mcp-server:sha-891c160@sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5This is the largest and worst-scoring scanned image (2314 packages). Grype found 31 unique Critical CVEs and 205 unique High CVEs (plus Medium/Low/Negligible/Unknown findings). Grant found 514 license policy violations. This image needs the most urgent remediation attention.
Key metrics (unique CVE/advisory IDs)
Critical vulnerabilities
All 31 unique Critical CVEs
High vulnerabilities
All 205 unique High CVEs (by affected component)
Grouped by component to keep this readable; every CVE/GHSA/GO ID below is a distinct finding:
GO-xxxxIDs — fixes available at various Go point releases.cryptography,starlette,pyjwt,mcp,urllib3,ujson,black,wheel,python-multipart,soupsieve,jaraco-context— each with a GHSA ID and clear fix version.Full per-CVE, per-package detail (371 raw rows / 205 unique IDs) is available in the raw scan log at
/tmp/gh-aw/agent/image-scan/compile-output.txt(grepserena-mcp-server:sha-891c160and\[High\]).Medium / Low / Negligible / Unknown vulnerabilities
423 Medium, 95 Low, 115 Negligible, 39 Unknown raw findings
Given the volume, these are not individually enumerated here; they follow the same component distribution as the Critical/High findings above (Debian base OS packages:
golang-1.24,python3.11,openssl,perl,libcurl,libnode/nodejs, plus transitive npm and Python application dependencies). Full detail available by grepping the raw scan log at/tmp/gh-aw/agent/image-scan/compile-output.txtforserena-mcp-server:sha-891c160combined with[Medium],[Low],[Negligible], or[Unknown].License policy violations
514 rejected/unknown licenses across 507 distinct packages (128 unique license strings)
Dominant patterns:
(Expat)— MIT-style license not on the allow-list.(no licenses found).(Expat, GPL-3.0-only, GPL-3.0-or-later)multi-license combos.GPL-2.0-only/GPL-2.0-or-later,GPL-3.0-only/GPL-3.0-or-later,LGPLfamily,BSDvariants (2/3/4-clause),Artistic/Artistic-2.0,CC0-1.0,MPL-2.0,Zlib,HPND,public-domain, and several vendor-specific compound license strings (e.g. curl's own compound license listing, Python's compound license listing).This image's large Debian + Python + Node.js + Go toolchain stack accounts for the bulk of all 725 license violations found across all 10 scanned images in this run. Full per-package detail available by grepping
/tmp/gh-aw/agent/image-scan/compile-output.txtforserena-mcp-server:sha-891c160:1:1: error: license policy violation.Remediation
openssl>=3.5.5/3.5.6,libgnutls30t64>=+deb13u4,libssh2-1t64>=+deb13u1, and Node.js/libnode>=+deb13u1/+deb13u2 fixes — this resolves the majority of the 31 Critical findings with fixed versions.handlebars>=4.7.9,node-flatted,node-agent-base/data-uri-to-buffer/http-proxy-agent/https-proxy-agent,node-undici,node-brace-expansion,node-postcss,node-tar.serena-agentitself to >=1.5.2 (GHSA-37h2-6p4f-mp3q) andgithub.com/modelcontextprotocol/go-sdkto >=1.3.1 (multiple GHSA advisories).libcurl3t64-gnutls,perlfamily,golang-1.24-go/src,node-lodash) currently have no fixed version upstream — track for distro patches and document explicit risk acceptance per the 7-day Critical SLA if unresolved.Expat/MIT,BSD,Artistic-2.0,CC0-1.0) if they are intentionally acceptable, to reduce noise on future scans, and evaluate switching to a smaller/pinned base image to shrink the package surface.gh aw compile --force-refresh-container-pinsdaily; a pin refresh PR to a newerserena-mcp-serverbuild is the default remediation step once upstream publishes a patched image.