Skip to content

security: bump 14 vulnerable dependencies (critical and below) - #13

Closed
Andrew Elkins (andrewelkins) wants to merge 1 commit into
mainfrom
secfix/batch-14-deps
Closed

Andrew Elkins (andrewelkins) wants to merge 1 commit into
mainfrom
secfix/batch-14-deps

Conversation

@andrewelkins

@andrewelkins Andrew Elkins (andrewelkins) commented Aug 17, 2026 •

Copy link
Copy Markdown

Security fix (draft for review)

Pins 14 vulnerable transitive dependencies in yarn.lock via resolutions and regenerates the lockfile.

Package Severity Patched Advisories
@babel/traverse critical >= 7.23.2 CVE-2023-45133
@xmldom/xmldom critical >= 0.7.7 CVE-2026-41675, CVE-2026-41674, CVE-2026-41672, CVE-2026-34601, CVE-2022-39353
cipher-base critical >= 1.0.5 CVE-2025-9287
elliptic critical >= 6.5.7 CVE-2025-14505, GHSA-vjh7-7g9h-fjfh, CVE-2024-48948, CVE-2024-48949, CVE-2024-42460 …
form-data critical >= 3.0.4 CVE-2026-12143, CVE-2025-7783
handlebars critical >= 4.7.9 GHSA-7rx3-28cr-v5wh, GHSA-442j-39wm-28r2, CVE-2026-33937, CVE-2026-33938, CVE-2026-33941 …
loader-utils critical >= 2.0.3 CVE-2022-37599, CVE-2022-37603, CVE-2022-37601
minimist critical >= 0.2.4 CVE-2021-44906
pbkdf2 critical >= 3.1.3 CVE-2025-6547, CVE-2025-6545
sha.js critical >= 2.4.12 CVE-2025-9288
shell-quote critical >= 1.8.4 CVE-2026-13311, CVE-2026-9277
socket.io-parser critical >= 4.0.5 CVE-2026-69185, CVE-2023-32695, CVE-2022-2421
webpack critical >= 5.76.0 CVE-2025-68157, CVE-2025-68458, CVE-2024-43788, CVE-2023-28154
websocket-driver critical >= 0.7.5 CVE-2026-54466

Not fixed by this PR

No patched version exists yet for babel-traverse — still vulnerable after merge.

These are batched into one PR because each pin adds a key to the same override block in package.json — as separate PRs they would conflict with each other on merge.

Pins 14 vulnerable transitive dependencies to patched versions via the ecosystem override mechanism and regenerates yarn.lock once.

- @babel/traverse -> >=7.23.2 (critical)
- @xmldom/xmldom -> >=0.7.7 (critical)
- cipher-base -> >=1.0.5 (critical)
- elliptic -> >=6.5.7 (critical)
- form-data -> >=3.0.4 (critical)
- handlebars -> >=4.7.9 (critical)
- loader-utils -> >=2.0.3 (critical)
- minimist -> >=0.2.4 (critical)
- pbkdf2 -> >=3.1.3 (critical)
- sha.js -> >=2.4.12 (critical)
- shell-quote -> >=1.8.4 (critical)
- socket.io-parser -> >=4.0.5 (critical)
- webpack -> >=5.76.0 (critical)
- websocket-driver -> >=0.7.5 (critical)

Batched into a single commit so the pins land together instead of as N PRs that each edit the same override block. Auto-drafted for security review.
@andrewelkins

Copy link
Copy Markdown
Author

Closing — this PR does not do what its description claims.

webpack is not actually fixed. The advisory requires >= 5.76.0. Yarn 1 resolutions applied to one descriptor but left the bare webpack@5 descriptor alone, so the lockfile on this branch still carries the vulnerable version:

webpack@5:
  version "5.65.0"        <- still vulnerable, unchanged from main

"webpack@>=5.76.0 <6.0.0", webpack@^4.43.0:
  version "5.109.2"

Worse, that same resolution captured webpack@^4.43.0 and dragged it from 4.46.0 to 5.109.2 — a major-version upgrade of webpack that nothing here asked for.

@xmldom/xmldom overshot. Pinned >=0.7.7 <1.0.0, which resolved 0.7.5 -> 0.9.11. Under semver, 0.x treats the minor as the breaking boundary, so the cap should have been <0.8.0. The advisory only needed 0.7.7.

The remaining 12 pins resolved correctly and in-range.

None of this was caught before opening because CI on this repo cannot run: actions/setup-node@v2 with cache: yarn fails at Cache service responded with 400 (the retired Actions Cache v1 API), so yarn install --frozen-lockfile never executes. That is a pre-existing failure unrelated to this branch.

The generating tool has been fixed on both counts — semver-correct caps for 0.x, plus a post-regeneration check that re-parses the lockfile and refuses to open a PR when a pin did not actually take. A corrected PR will follow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant