High-severity npm vulnerabilities reported by pnpm audit
Summary
- \┌─────────────────────┬────────────────────────────────────────────────────────┐ │ high │ Playwright downloads and installs browsers without │ │ │ verifying the authenticity of the SSL certificate │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ playwright │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <1.55.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.55.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/[email protected] > [email protected] > │
│ │ @playwright/[email protected] > [email protected] │
│ │ │
│ │ . > [email protected] > [email protected] > │
│ │ @playwright/[email protected] > [email protected] │
│ │ │
│ │ . > [email protected] > @playwright/[email protected] > │
│ │ [email protected] │
│ │ │
│ │ ... Found 5 paths, run pnpm why playwright for more │
│ │ information │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-7mvr-c777-76hp │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Next.js HTTP request deserialization can lead to DoS │
│ │ when using insecure React Server Components │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=16.0.0-beta.0 <16.0.11 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=16.0.11 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/[email protected] > [email protected] │
│ │ │
│ │ . > [email protected] > [email protected] │
│ │ │
│ │ . > [email protected] │
│ │ │
│ │ ... Found 4 paths, run pnpm why next for more │
│ │ information │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-h25m-26qc-wcjf │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ @isaacs/brace-expansion has Uncontrolled Resource │
│ │ Consumption │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ @isaacs/brace-expansion │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=5.0.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=5.0.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > [email protected] > [email protected] > [email protected] │
│ │ > @isaacs/[email protected] │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-7h2j-956f-4vf2 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ minimatch has a ReDoS via repeated wildcards with │
│ │ non-matching literal in pattern │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ minimatch │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=10.0.0 <10.2.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=10.2.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > [email protected] > [email protected] > [email protected] │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-3ppc-4f35-3m26 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ minimatch has ReDoS: matchOne() combinatorial │
│ │ backtracking via multiple non-adjacent GLOBSTAR │
│ │ segments │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ minimatch │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=10.0.0 <10.2.3 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=10.2.3 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > [email protected] > [email protected] > [email protected] │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-7r86-cg39-jmmj │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ minimatch ReDoS: nested *() extglobs generate │
│ │ catastrophically backtracking regular expressions │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ minimatch │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=10.0.0 <10.2.3 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=10.2.3 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > [email protected] > [email protected] > [email protected] │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-23c5-xmqv-rm74 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Undici has Unbounded Memory Consumption in WebSocket │
│ │ permessage-deflate Decompression │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ undici │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <6.24.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=6.24.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/[email protected] > [email protected] │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-vrm6-8vpv-qv8q │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Undici has Unhandled Exception in WebSocket Client Due │
│ │ to Invalid server_max_window_bits Validation │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ undici │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <6.24.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=6.24.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/[email protected] > [email protected] │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-v9p9-hfj2-hcw8 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ esbuild enables any website to send any requests to │
│ │ the development server and read the response │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ esbuild │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=0.24.2 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=0.25.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > [email protected] > @esbuild-kit/[email protected] │
│ │ > @esbuild-kit/[email protected] > [email protected] │
│ │ │
│ │ . > [email protected] > [email protected] │
│ │ │
│ │ . > [email protected] > [email protected] > │
│ │ [email protected] │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-67mh-4wv8-2f99 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ PrismJS DOM Clobbering vulnerability │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ prismjs │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <1.30.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.30.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > [email protected] > [email protected] │
│ │ > [email protected] │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-x7hr-w5r2-h6wg │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ NextAuthjs Email misdelivery Vulnerability │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next-auth │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=5.0.0-beta.0 <5.0.0-beta.30 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=5.0.0-beta.30 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > [email protected] │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-5jpx-9hw9-2fx4 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ Undici has an unbounded decompression chain in HTTP │
│ │ responses on Node.js Fetch API via Content-Encoding │
│ │ leads to resource exhaustion │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ undici │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <6.23.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=6.23.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/[email protected] > [email protected] │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-g9mf-h72j-4rw9 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ Next.js self-hosted applications vulnerable to DoS via │
│ │ Image Optimizer remotePatterns configuration │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=15.6.0-canary.0 <16.1.5 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=16.1.5 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/[email protected] > [email protected] │
│ │ │
│ │ . > [email protected] > [email protected] │
│ │ │
│ │ . > [email protected] │
│ │ │
│ │ ... Found 4 paths, run pnpm why next for more │
│ │ information │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-9g9p-9gw9-jx7f │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ Next.js has Unbounded Memory Consumption via PPR │
│ │ Resume Endpoint │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=16.0.0-beta.0 <16.1.5 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=16.1.5 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/[email protected] > [email protected] │
│ │ │
│ │ . > [email protected] > [email protected] │
│ │ │
│ │ . > [email protected] │
│ │ │
│ │ ... Found 4 paths, run pnpm why next for more │
│ │ information │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-5f7q-jpqc-wp7h │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ mdast-util-to-hast has unsanitized class attribute │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ mdast-util-to-hast │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.0.0 <13.2.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=13.2.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > [email protected] > @shikijs/[email protected] > │
│ │ [email protected] > [email protected] │
│ │
Source: vercel/chatbot