#1467·chatbot

High-severity npm vulnerabilities reported by pnpm audit

Author: kwashamCreated Mar 29, 2026Updated Mar 29, 2026

Summary

  • \┌─────────────────────┬────────────────────────────────────────────────────────┐ │ high │ Playwright downloads and installs browsers without │ │ │ verifying the authenticity of the SSL certificate │

├─────────────────────┼────────────────────────────────────────────────────────┤ │ Package │ playwright │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Vulnerable versions │ <1.55.1 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Patched versions │ >=1.55.1 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Paths │ . > @vercel/[email protected] > [email protected] > │ │ │ @playwright/[email protected] > [email protected] │ │ │ │ │ │ . > [email protected] > [email protected] > │ │ │ @playwright/[email protected] > [email protected] │ │ │ │ │ │ . > [email protected] > @playwright/[email protected] > │ │ │ [email protected] │ │ │ │ │ │ ... Found 5 paths, run pnpm why playwright for more │ │ │ information │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ More info │ https://github.com/advisories/GHSA-7mvr-c777-76hp │ └─────────────────────┴────────────────────────────────────────────────────────┘ ┌─────────────────────┬────────────────────────────────────────────────────────┐ │ high │ Next.js HTTP request deserialization can lead to DoS │ │ │ when using insecure React Server Components │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Package │ next │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Vulnerable versions │ >=16.0.0-beta.0 <16.0.11 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Patched versions │ >=16.0.11 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Paths │ . > @vercel/[email protected] > [email protected] │ │ │ │ │ │ . > [email protected] > [email protected] │ │ │ │ │ │ . > [email protected] │ │ │ │ │ │ ... Found 4 paths, run pnpm why next for more │ │ │ information │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ More info │ https://github.com/advisories/GHSA-h25m-26qc-wcjf │ └─────────────────────┴────────────────────────────────────────────────────────┘ ┌─────────────────────┬────────────────────────────────────────────────────────┐ │ high │ @isaacs/brace-expansion has Uncontrolled Resource │ │ │ Consumption │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Package │ @isaacs/brace-expansion │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Vulnerable versions │ <=5.0.0 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Patched versions │ >=5.0.1 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Paths │ . > [email protected] > [email protected] > [email protected] │ │ │ > @isaacs/[email protected] │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ More info │ https://github.com/advisories/GHSA-7h2j-956f-4vf2 │ └─────────────────────┴────────────────────────────────────────────────────────┘ ┌─────────────────────┬────────────────────────────────────────────────────────┐ │ high │ minimatch has a ReDoS via repeated wildcards with │ │ │ non-matching literal in pattern │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Package │ minimatch │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Vulnerable versions │ >=10.0.0 <10.2.1 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Patched versions │ >=10.2.1 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Paths │ . > [email protected] > [email protected] > [email protected] │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ More info │ https://github.com/advisories/GHSA-3ppc-4f35-3m26 │ └─────────────────────┴────────────────────────────────────────────────────────┘ ┌─────────────────────┬────────────────────────────────────────────────────────┐ │ high │ minimatch has ReDoS: matchOne() combinatorial │ │ │ backtracking via multiple non-adjacent GLOBSTAR │ │ │ segments │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Package │ minimatch │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Vulnerable versions │ >=10.0.0 <10.2.3 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Patched versions │ >=10.2.3 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Paths │ . > [email protected] > [email protected] > [email protected] │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ More info │ https://github.com/advisories/GHSA-7r86-cg39-jmmj │ └─────────────────────┴────────────────────────────────────────────────────────┘ ┌─────────────────────┬────────────────────────────────────────────────────────┐ │ high │ minimatch ReDoS: nested *() extglobs generate │ │ │ catastrophically backtracking regular expressions │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Package │ minimatch │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Vulnerable versions │ >=10.0.0 <10.2.3 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Patched versions │ >=10.2.3 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Paths │ . > [email protected] > [email protected] > [email protected] │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ More info │ https://github.com/advisories/GHSA-23c5-xmqv-rm74 │ └─────────────────────┴────────────────────────────────────────────────────────┘ ┌─────────────────────┬────────────────────────────────────────────────────────┐ │ high │ Undici has Unbounded Memory Consumption in WebSocket │ │ │ permessage-deflate Decompression │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Package │ undici │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Vulnerable versions │ <6.24.0 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Patched versions │ >=6.24.0 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Paths │ . > @vercel/[email protected] > [email protected] │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ More info │ https://github.com/advisories/GHSA-vrm6-8vpv-qv8q │ └─────────────────────┴────────────────────────────────────────────────────────┘ ┌─────────────────────┬────────────────────────────────────────────────────────┐ │ high │ Undici has Unhandled Exception in WebSocket Client Due │ │ │ to Invalid server_max_window_bits Validation │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Package │ undici │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Vulnerable versions │ <6.24.0 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Patched versions │ >=6.24.0 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Paths │ . > @vercel/[email protected] > [email protected] │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ More info │ https://github.com/advisories/GHSA-v9p9-hfj2-hcw8 │ └─────────────────────┴────────────────────────────────────────────────────────┘ ┌─────────────────────┬────────────────────────────────────────────────────────┐ │ moderate │ esbuild enables any website to send any requests to │ │ │ the development server and read the response │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Package │ esbuild │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Vulnerable versions │ <=0.24.2 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Patched versions │ >=0.25.0 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Paths │ . > [email protected] > @esbuild-kit/[email protected] │ │ │ > @esbuild-kit/[email protected] > [email protected] │ │ │ │ │ │ . > [email protected] > [email protected] │ │ │ │ │ │ . > [email protected] > [email protected] > │ │ │ [email protected] │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ More info │ https://github.com/advisories/GHSA-67mh-4wv8-2f99 │ └─────────────────────┴────────────────────────────────────────────────────────┘ ┌─────────────────────┬────────────────────────────────────────────────────────┐ │ moderate │ PrismJS DOM Clobbering vulnerability │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Package │ prismjs │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Vulnerable versions │ <1.30.0 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Patched versions │ >=1.30.0 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Paths │ . > [email protected] > [email protected] │ │ │ > [email protected] │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ More info │ https://github.com/advisories/GHSA-x7hr-w5r2-h6wg │ └─────────────────────┴────────────────────────────────────────────────────────┘ ┌─────────────────────┬────────────────────────────────────────────────────────┐ │ moderate │ NextAuthjs Email misdelivery Vulnerability │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Package │ next-auth │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Vulnerable versions │ >=5.0.0-beta.0 <5.0.0-beta.30 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Patched versions │ >=5.0.0-beta.30 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Paths │ . > [email protected] │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ More info │ https://github.com/advisories/GHSA-5jpx-9hw9-2fx4 │ └─────────────────────┴────────────────────────────────────────────────────────┘ ┌─────────────────────┬────────────────────────────────────────────────────────┐ │ moderate │ Undici has an unbounded decompression chain in HTTP │ │ │ responses on Node.js Fetch API via Content-Encoding │ │ │ leads to resource exhaustion │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Package │ undici │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Vulnerable versions │ <6.23.0 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Patched versions │ >=6.23.0 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Paths │ . > @vercel/[email protected] > [email protected] │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ More info │ https://github.com/advisories/GHSA-g9mf-h72j-4rw9 │ └─────────────────────┴────────────────────────────────────────────────────────┘ ┌─────────────────────┬────────────────────────────────────────────────────────┐ │ moderate │ Next.js self-hosted applications vulnerable to DoS via │ │ │ Image Optimizer remotePatterns configuration │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Package │ next │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Vulnerable versions │ >=15.6.0-canary.0 <16.1.5 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Patched versions │ >=16.1.5 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Paths │ . > @vercel/[email protected] > [email protected] │ │ │ │ │ │ . > [email protected] > [email protected] │ │ │ │ │ │ . > [email protected] │ │ │ │ │ │ ... Found 4 paths, run pnpm why next for more │ │ │ information │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ More info │ https://github.com/advisories/GHSA-9g9p-9gw9-jx7f │ └─────────────────────┴────────────────────────────────────────────────────────┘ ┌─────────────────────┬────────────────────────────────────────────────────────┐ │ moderate │ Next.js has Unbounded Memory Consumption via PPR │ │ │ Resume Endpoint │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Package │ next │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Vulnerable versions │ >=16.0.0-beta.0 <16.1.5 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Patched versions │ >=16.1.5 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Paths │ . > @vercel/[email protected] > [email protected] │ │ │ │ │ │ . > [email protected] > [email protected] │ │ │ │ │ │ . > [email protected] │ │ │ │ │ │ ... Found 4 paths, run pnpm why next for more │ │ │ information │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ More info │ https://github.com/advisories/GHSA-5f7q-jpqc-wp7h │ └─────────────────────┴────────────────────────────────────────────────────────┘ ┌─────────────────────┬────────────────────────────────────────────────────────┐ │ moderate │ mdast-util-to-hast has unsanitized class attribute │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Package │ mdast-util-to-hast │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Vulnerable versions │ >=13.0.0 <13.2.1 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Patched versions │ >=13.2.1 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Paths │ . > [email protected] > @shikijs/[email protected] > │ │ │ [email protected] > [email protected] │ │ │