pkg(security): Bump transitive dependency security vulns - #4058
Conversation
Force patched versions via yarn resolutions and example npm overrides, and refresh lockfiles across root and standalone examples. Co-authored-by: Cursor <cursoragent@cursor.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
|
|
Size Change: 0 B Total Size: 81.2 kB ℹ️ View Unchanged
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #4058 +/- ##
=======================================
Coverage 97.84% 97.84%
=======================================
Files 156 156
Lines 3057 3057
Branches 612 612
=======================================
Hits 2991 2991
Misses 18 18
Partials 48 48 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Summary
This PR contains the following updates:
6.2.1/7.5.10→7.5.22yarn.lock)6.0.2→7.0.73.4.8→3.4.12yarn.lock)4.3.8→4.3.9,5.1.5→5.1.94.0.1→4.0.2(3.3.3→3.3.4)1.9.0/4.0.0→5.0.0yarn.lock)2.8.9yarn.lock)9.0.5→10.2.08.3.2→≥11.1.15.1.6/8.0.4/9.0.1→5.1.9/8.0.7/9.0.9yarn.lock)11.0.3→11.1.0yarn.lock)2.8.2→2.9.0yarn.lock)2.0.1/5.0.5→2.1.2/5.0.88.19.0/8.20.1→8.21.11.8.4→1.10.08.4.31/8.5.15→8.5.231.20.5→1.20.60.7.4→0.7.53.1.2→3.1.40.34.5→0.35.3~15.5.18→~15.5.21Also adds yarn
resolutions/ npmoverridesso transitive deps stay on patched ranges.tar
node-tar: Decompression/parse DoS via unlimited input
CVE-2026-59873 / GHSA-23hp-3jrh-7fpw — critical
node-tar: Negative tar entry size causes infinite loop in archive replace
CVE-2026-59874 / GHSA-8x88-c5mf-7j5w — high
node-tar Symlink Path Traversal via Drive-Relative Linkpath
CVE-2026-31802 / GHSA-9ppj-qmqm-q256 — high
Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction
CVE-2026-26960 / GHSA-83g3-92jg-28cx — high
node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal
CVE-2026-24842 / GHSA-34x7-hfp2-rc4v — high
node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization
CVE-2026-23745 / GHSA-8qq5-rm4j-mr97 — high
Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS
CVE-2026-23950 / GHSA-r6q2-hw4h-h46w — high
tar has Hardlink Path Traversal via Drive-Relative Linkpath
CVE-2026-29786 / GHSA-qffp-2rhf-9h96 — high
node-tar applies PAX size override to intermediary GNU long-name/long-link headers (file smuggling)
CVE-2026-53655 / GHSA-vmf3-w455-68vh — medium
node-tar: Process crash via PAX numeric path type confusion
CVE-2026-59871 / GHSA-w8wr-v893-vjvp — medium
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
CVE-2026-59875 / GHSA-gvwx-54wh-qm9j — medium
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS
GHSA-r292-9mhp-454m — medium
serialize-javascript
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
GHSA-5c6j-r48x-rmvq — high
Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
CVE-2026-34043 / GHSA-qj8w-gfj5-8c6v — medium
dompurify
DOMPurify: Permanent
ALLOWED_ATTRpollution viasetConfig()bypassing the hook clone-guardCVE-2026-65898 / GHSA-cmwh-pvxp-8882 — medium
DOMPurify:
CUSTOM_ELEMENT_HANDLINGbypassesafterSanitizeElementsfor allowed custom elementsGHSA-c2j3-45gr-mqc4 — low
DOMPurify: Trusted Types policy survives
clearConfig()and can poison laterRETURN_TRUSTED_TYPEoutputCVE-2026-65899 / GHSA-vxr8-fq34-vvx9 — low
immutable
Immutable.js
List32-bit trie overflow → unrecoverable DoSCVE-2026-59879 / GHSA-v56q-mh7h-f735 — high
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
CVE-2026-59880 / GHSA-xvcm-6775-5m9r — high
svgo
SVGO removeScripts plugin leaves some executable scripts intact
GHSA-2p49-hgcm-8545 — high
sigstore
sigstore's
certificateOIDsverification constraints are silently dropped and never enforcedCVE-2026-48815 / GHSA-52v5-jr5w-gjxr — high
ip-address (via socks)
ip-address has XSS in Address6 HTML-emitting methods
CVE-2026-42338 / GHSA-v2v4-37r5-5v8g — medium
uuid
uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
CVE-2026-41907 / GHSA-w5hq-g745-h8pq — medium
minimatch / glob / brace-expansion
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
CVE-2026-26996 / GHSA-3ppc-4f35-3m26 — high
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
CVE-2026-27903 / GHSA-7r86-cg39-jmmj — high
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
CVE-2026-27904 / GHSA-23c5-xmqv-rm74 — high
glob CLI: Command injection via -c/--cmd executes matches with shell:true
CVE-2025-64756 / GHSA-5j98-mcp5-4vw2 — high
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
CVE-2026-13149 / GHSA-3jxr-9vmj-r5cp — high
brace-expansion: Large numeric range defeats documented
maxDoS protectionCVE-2026-45149 / GHSA-jxxr-4gwj-5jf2 — medium
brace-expansion: Zero-step sequence causes process hang and memory exhaustion
CVE-2026-33750 / GHSA-f886-m6hf-6m8v — medium
yaml
yaml is vulnerable to Stack Overflow via deeply nested YAML collections
CVE-2026-33532 / GHSA-48c2-rrv3-qjmp — medium
ws
ws: Memory exhaustion DoS from tiny fragments and data chunks
CVE-2026-48779 / GHSA-96hv-2xvq-fx4p — high
ws: Uninitialized memory disclosure
CVE-2026-45736 / GHSA-58qx-3vcg-4xpx — medium
shell-quote
shell-quote: Quadratic-complexity Denial of Service in
parse()(CWE-407)CVE-2026-13311 / GHSA-395f-4hp3-45gv — high
postcss
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
CVE-2026-45623 / GHSA-6g55-p6wh-862q — high
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
GHSA-r28c-9q8g-f849 — high
PostCSS has XSS via Unescaped
</style>in its CSS Stringify OutputCVE-2026-41305 / GHSA-qx2v-qp2m-jg93 — medium
body-parser
body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
CVE-2026-12590 / GHSA-v422-hmwv-36x6 — low
websocket-driver
websocket-driver: Message corruption via abuse of protocol length headers
CVE-2026-54466 / GHSA-xv26-6w52-cph6 — critical
websocket-driver: Resource limit bypass via message compression
CVE-2026-54490 / GHSA-mp7j-qc5w-4988 — medium
fast-uri
fast-uri vulnerable to host confusion via literal backslash authority delimiter
CVE-2026-16221 / GHSA-v2hh-gcrm-f6hx — high
fast-uri vulnerable to host confusion via failed IDN canonicalization
CVE-2026-13676 / GHSA-4c8g-83qw-93j6 — high
sharp
sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
GHSA-f88m-g3jw-g9cj — high
next
Next.js: Server-Side Request Forgery in Server Actions on custom servers
CVE-2026-64649 / GHSA-89xv-2m56-2m9x — high
Next.js: Denial of Service in App Router using Server Actions
CVE-2026-64641 / GHSA-m99w-x7hq-7vfj — high
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
CVE-2026-64645 / GHSA-p9j2-gv94-2wf4 — high
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
CVE-2026-64647 / GHSA-4633-3j49-mh5q — medium
Next.js: Unbounded Server Action payload in Edge runtime
CVE-2026-64646 / GHSA-4c39-4ccg-62r3 — medium
Next.js: Cache confusion of response bodies for requests with bodies
CVE-2026-64648 / GHSA-68g3-v927-f742 — medium
Next.js: Unauthenticated disclosure of internal Server Function endpoints
CVE-2026-64643 / GHSA-955p-x3mx-jcvp — medium
Next.js: Denial of Service in the Image Optimization API using SVGs
CVE-2026-64644 / GHSA-q8wf-6r8g-63ch — medium
Remaining (no upstream patch / mis-ranged advisory)
brace-expansion@1.1.16<=5.0.7); no fixed 1.x releaseelliptic@6.6.1Test plan
yarn npm audit --all --recursive --no-deprecationsonly reports brace-expansion / elliptic leftoversnpm audit --omit=devin github-app, todo-app, vue-todo-appMade with Cursor