Skip to content

Conversation

@ynhhoJ
Copy link

@ynhhoJ ynhhoJ commented Nov 24, 2025

Also, this should fix two high vulnerabilities:

  1. GHSA-5j98-mcp5-4vw2 - glob CLI: Command injection via -c/--cmd executes matches with shell:true
  2. GHSA-3xgq-45jj-v275 - Regular Expression Denial of Service (ReDoS) in cross-spawn

In total, there are:

9 vulnerabilities found
Severity: 2 low | 5 moderate | 2 high

After upgrading all dependencies to latest versions, there were 2 more vulnerabilities which wasn't fixed with dependencies upgrade:

  1. GHSA-mh29-5h37-fv8m - js-yaml has prototype pollution in merge (<<)
  2. GHSA-3xgq-45jj-v275 - Regular Expression Denial of Service (ReDoS) in cross-spawn

To fix them, I used pnpm audit --fix

Initial pnpm outdated:
image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant