Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
55 changes: 35 additions & 20 deletions package-lock.json

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Plerion found 41 security issues.

These do not block merging, but we recommend reviewing and resolving them:

Vulnerability ID Issue Affected version Remediation
Severity: Critical undici - undici: Information disclosure and Denial of Service via malformed Cache-Control directives undici@7.28.0 Upgrade to 7.29.0, 8.9.0 or higher
Severity: High brace-expansion - Brace-expansion: Denial of Service due to exponential-time complexity brace-expansion@5.0.6 Upgrade to 5.0.7, 1.1.16, 2.1.2 or higher
Severity: High fast-uri - fast-uri: Security policy bypass due to improper Unicode hostname canonicalization fast-uri@3.1.2 Upgrade to 4.0.1, 3.1.3, 2.4.2 or higher
Severity: High brace-expansion - Brace-expansion: Denial of Service via memory exhaustion in expand() function brace-expansion@5.0.6 Upgrade to 5.0.8, 3.0.3, 2.1.3, 1.1.17 or higher
Severity: High undici - undici: Cross-user information disclosure due to improper Cache-Control directive parsing undici@7.28.0 Upgrade to 7.29.0, 8.9.0 or higher
Show 36 more issues
Vulnerability ID Issue Affected version Remediation
Severity: High fast-uri - Fast-uri: Security policy bypass due to URL parsing inconsistency fast-uri@3.1.2 Upgrade to 2.4.3, 3.1.4, 4.1.1 or higher
Severity: High fast-uri - fast-uri: Host confusion vulnerability via backslash in URI authority fast-uri@3.1.2 Upgrade to 2.4.4, 3.1.5, 4.1.2 or higher
Severity: High extract-zip - github.com/maxogden/extract-zip: extract-zip: Arbitrary file write and information disclosure via symlink validation bypass extract-zip@2.0.1 Upgrade to null or higher
Severity: High js-yaml - js-yaml: Denial of Service via crafted YAML documents js-yaml@4.2.0 Upgrade to 3.15.0, 4.3.0 or higher
Severity: High tar - node-tar: Denial of Service due to incorrect PAX path handling tar@7.5.16 Upgrade to 7.5.18 or higher
Severity: High tar - node-tar: Denial of Service via crafted gzip bomb tar@7.5.16 Upgrade to 7.5.19 or higher
Severity: High tar - Node-tar: Denial of Service via malformed tar archive header tar@7.5.16 Upgrade to 7.5.18 or higher
Severity: High immutable - Immutable.js provides many Persistent Immutable data structures. Prior ... immutable@5.1.6 Upgrade to 4.3.9, 5.1.8 or higher
Severity: High immutable - Immutable.js provides many Persistent Immutable data structures. Prior ... immutable@5.1.6 Upgrade to 4.3.9, 5.1.8 or higher
Severity: High nanoid - nanoid: Denial of Service via infinite loop in random ID generation nanoid@3.3.15 Upgrade to 3.3.18, 5.1.6 or higher
Severity: High nanoid - nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ... nanoid@3.3.15 Upgrade to 3.3.16, 5.1.16 or higher
Severity: High brace-expansion - DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation brace-expansion@5.0.6 Upgrade to 1.1.18, 2.1.4, 3.0.6, 5.0.9 or higher
Severity: High postcss - Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure postcss@8.5.15 Upgrade to 8.5.18 or higher
Severity: High svgo - SVGO removeScripts plugin leaves some executable scripts intact svgo@3.3.3 Upgrade to 2.8.3, 3.3.4, 4.0.2 or higher
Severity: High svgo - SVGO removeScripts plugin leaves some executable scripts intact svgo@4.0.1 Upgrade to 2.8.3, 3.3.4, 4.0.2 or higher
Severity: High js-yaml - Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported js-yaml@4.2.0 Upgrade to 4.3.1, 3.15.1 or higher
Severity: High sharp - CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591 sharp@0.34.5 Upgrade to 0.35.0 or higher
Severity: Medium undici - undici: HTTP header injection via unvalidated blob-like body type property undici@7.28.0 Upgrade to 6.28.0, 7.29.0, 8.9.0 or higher
Severity: Medium undici - undici: Response desynchronization via retry interceptor with mismatched Content-Length undici@7.28.0 Upgrade to 6.28.0, 7.29.0, 8.9.0 or higher
Severity: Medium undici - Undici: Cookie attribute injection allows bypassing security protections undici@7.28.0 Upgrade to 6.28.0, 7.29.0, 8.9.0 or higher
Severity: Medium yaml - yaml: Denial of Service via deeply nested YAML document parsing yaml@2.7.1 Upgrade to 2.8.3, 1.10.3 or higher
Severity: Medium mermaid - Mermaid: CSS injection allows altering page elements via diagram input mermaid@11.15.0 Upgrade to 11.16.1, 10.9.8 or higher
Severity: Medium @astrojs/rss - XML Injection via Unescaped RSS Feed Fields @astrojs/rss@4.0.18 Upgrade to 4.0.19 or higher
Severity: Medium astro - XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298) astro@7.0.0 Upgrade to 7.0.6 or higher
Severity: Medium tar - node-tar: Denial of Service via crafted archive with NUL bytes in metadata tar@7.5.16 Upgrade to 7.5.17 or higher
Severity: Medium postcss - PostCSS: Information disclosure via crafted sourceMappingURL postcss@8.5.15 Upgrade to 8.5.23 or higher
Severity: Medium mermaid - Mermaid XY Charts: Denial of Service via invalid X-Axis parameters mermaid@11.15.0 Upgrade to 10.9.8, 11.16.1 or higher
Severity: Medium mermaid - Mermaid: Prototype pollution vulnerability allows potential arbitrary code execution mermaid@11.15.0 Upgrade to 11.16.1 or higher
Severity: Medium mermaid - Mermaid: Denial of Service via Radar Diagrams 'ticks' parameter mermaid@11.15.0 Upgrade to 11.16.1 or higher
Severity: Medium astro - Reflected XSS via unescaped View Transition animation properties astro@7.0.0 Upgrade to 7.1.0 or higher
Severity: Medium astro - composable astro/hono pipeline bypasses security.checkOrigin when middleware() is absent or misordered astro@7.0.0 Upgrade to 7.0.6 or higher
Severity: Medium dompurify - IN_PLACE hook removal leaves a detached subtree executable, causing XSS dompurify@3.4.11 Upgrade to 3.4.13 or higher
Severity: Medium tar - Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection tar@7.5.16 Upgrade to 7.5.21 or higher
Severity: Low astro - Cross-site scripting via unescaped transition:* directive values on hydrated islands astro@7.0.0 Upgrade to 7.0.4 or higher
Severity: Low mermaid - Mermaid: Prototype pollution vulnerability via configuration APIs mermaid@11.15.0 Upgrade to 11.16.1, 10.9.8 or higher
Severity: Low dompurify - CUSTOM_ELEMENT_HANDLING bypasses afterSanitizeElements for allowed custom elements. dompurify@3.4.11 Upgrade to 3.4.12 or higher

View in Plerion

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading