Skip to content

fix(deps): update dependency validator to v13.15.20 [security]#1675

Merged
renovate[bot] merged 1 commit into
masterfrom
renovate/npm-validator-vulnerability
Oct 29, 2025
Merged

fix(deps): update dependency validator to v13.15.20 [security]#1675
renovate[bot] merged 1 commit into
masterfrom
renovate/npm-validator-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 28, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
validator 13.15.0 -> 13.15.20 age confidence

GitHub Vulnerability Alerts

CVE-2025-56200

A URL validation bypass vulnerability exists in validator.js prior to version 13.15.20. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use ':' as the delimiter. This parsing difference allows attackers to bypass protocol and domain validation by crafting URLs leading to XSS and Open Redirect attacks.


Release Notes

validatorjs/validator.js (validator)

v13.15.20

Compare Source

Fixes, New Locales and Enhancements

v13.15.15

Compare Source

Fixes, New Locales and Enhancements

Configuration

📅 Schedule: Branch creation - "" in timezone Europe/London, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@cypress

cypress Bot commented Oct 28, 2025

Copy link
Copy Markdown

BanManager-WebUI    Run #8987

Run Properties:  status check passed Passed #8987  •  git commit 330298f58b ℹ️: Merge bf76a3934e72fc1c2eaa6442d229961e1c767b05 into 689563af9f90993a1ad11cbdb85f...
Project BanManager-WebUI
Branch Review refs/pull/1675/merge
Run status status check passed Passed #8987
Run duration 00m 45s
Commit git commit 330298f58b ℹ️: Merge bf76a3934e72fc1c2eaa6442d229961e1c767b05 into 689563af9f90993a1ad11cbdb85f...
Committer renovate[bot]
View all properties for this run ↗︎

Test results
Tests that failed  Failures 0
Tests that were flaky  Flaky 0
Tests that did not run due to a developer annotating a test with .skip  Pending 0
Tests that did not run due to a failure in a mocha hook  Skipped 0
Tests that passed  Passing 15
View all changes introduced in this branch ↗︎

@renovate renovate Bot merged commit 817ff14 into master Oct 29, 2025
6 checks passed
@renovate renovate Bot deleted the renovate/npm-validator-vulnerability branch October 29, 2025 01:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants