Skip to content

[Snyk] Fix for 42 vulnerabilities#84

Open
talhabalaj wants to merge 1 commit intomasterfrom
snyk-fix-e3f6bc53dbfeab1bc3f75e5d97270685
Open

[Snyk] Fix for 42 vulnerabilities#84
talhabalaj wants to merge 1 commit intomasterfrom
snyk-fix-e3f6bc53dbfeab1bc3f75e5d97270685

Conversation

@talhabalaj
Copy link
Contributor

snyk-top-banner

Snyk has created this PR to fix 42 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • package.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
critical severity Function Call With Incorrect Argument Type
SNYK-JS-SHAJS-12089400
  776  
high severity Denial of Service (DoS)
SNYK-JS-DICER-2311764
  761  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CROSSSPAWN-8303230
  756  
high severity Prototype Pollution
SNYK-JS-ASYNC-2441827
  696  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MOMENT-2944238
  696  
high severity Prototype Poisoning
SNYK-JS-QS-3153490
  696  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BABELRUNTIME-10044504
  666  
medium severity Prototype Pollution
SNYK-JS-PARSEGITCONFIG-9403763
  666  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-7925106
  666  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-8482416
  666  
medium severity Symlink Attack
SNYK-JS-TMP-11501554
  661  
medium severity Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
  631  
high severity Asymmetric Resource Consumption (Amplification)
SNYK-JS-BODYPARSER-7926860
  624  
high severity Denial of Service (DoS)
SNYK-JS-APOLLOSERVERCORE-2928764
  589  
high severity Directory Traversal
SNYK-JS-MOMENT-2440688
  589  
high severity Improper Verification of Cryptographic Signature
SNYK-JS-NODEFORGE-2430339
  579  
medium severity Cross-site Scripting (XSS)
SNYK-JS-ROLLUP-8073097
  576  
medium severity Use of a Broken or Risky Cryptographic Algorithm
SNYK-JS-JSONWEBTOKEN-3180026
  554  
medium severity Cache Poisoning
SNYK-JS-APOLLOSERVERCORE-3098876
  539  
medium severity Improper Restriction of Security Token Assignment
SNYK-JS-JSONWEBTOKEN-3180024
  539  
medium severity Unchecked Input for Loop Condition
SNYK-JS-KATEX-6483835
  539  
medium severity Information Exposure
SNYK-JS-NODEFETCH-2342118
  539  
medium severity Remote Code Execution (RCE)
SNYK-JS-SHARP-2848109
  539  
medium severity Improper Authentication
SNYK-JS-JSONWEBTOKEN-3180022
  534  
medium severity Cross-site Scripting (XSS)
SNYK-JS-COOKIE-8163060
  529  
medium severity Improper Encoding or Escaping of Output
SNYK-JS-KATEX-6483831
  529  
medium severity Open Redirect
SNYK-JS-EXPRESS-6474509
  519  
low severity Prototype Pollution
SNYK-JS-MINIMIST-2429795
  506  
medium severity Improper Verification of Cryptographic Signature
SNYK-JS-NODEFORGE-2430337
  494  
medium severity Improper Verification of Cryptographic Signature
SNYK-JS-NODEFORGE-2430341
  494  
medium severity Incomplete List of Disallowed Inputs
SNYK-JS-KATEX-6483834
  489  
medium severity Open Redirect
SNYK-JS-GOT-2932019
  484  
medium severity Improper Encoding or Escaping of Output
SNYK-JS-KATEX-8647963
  479  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
  479  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-TERSER-2806366
  479  
medium severity Cross-site Scripting
SNYK-JS-EXPRESS-7926867
  469  
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BRACEEXPANSION-9789073
  436  
low severity Arbitrary Code Injection
SNYK-JS-PRISMJS-9055448
  436  
medium severity Cross-site Scripting (XSS)
SNYK-JS-APOLLOSERVERCORE-2979828
  424  
low severity Information Exposure
SNYK-JS-APOLLOSERVERCORE-5876618
  399  
low severity Cross-site Scripting
SNYK-JS-SEND-7926862
  319  
low severity Cross-site Scripting
SNYK-JS-SERVESTATIC-7926865
  319  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Snyk has automatically assigned this pull request, set who gets assigned.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
👩‍💻 Set who automatically gets assigned
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Denial of Service (DoS)
🦉 Cross-site Scripting (XSS)
🦉 Prototype Pollution
🦉 More lessons are available in Snyk Learn

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-SHAJS-12089400
- https://snyk.io/vuln/SNYK-JS-DICER-2311764
- https://snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230
- https://snyk.io/vuln/SNYK-JS-ASYNC-2441827
- https://snyk.io/vuln/SNYK-JS-MOMENT-2944238
- https://snyk.io/vuln/SNYK-JS-QS-3153490
- https://snyk.io/vuln/SNYK-JS-BABELRUNTIME-10044504
- https://snyk.io/vuln/SNYK-JS-PARSEGITCONFIG-9403763
- https://snyk.io/vuln/SNYK-JS-PATHTOREGEXP-7925106
- https://snyk.io/vuln/SNYK-JS-PATHTOREGEXP-8482416
- https://snyk.io/vuln/SNYK-JS-TMP-11501554
- https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116
- https://snyk.io/vuln/SNYK-JS-BODYPARSER-7926860
- https://snyk.io/vuln/SNYK-JS-APOLLOSERVERCORE-2928764
- https://snyk.io/vuln/SNYK-JS-MOMENT-2440688
- https://snyk.io/vuln/SNYK-JS-NODEFORGE-2430339
- https://snyk.io/vuln/SNYK-JS-ROLLUP-8073097
- https://snyk.io/vuln/SNYK-JS-JSONWEBTOKEN-3180026
- https://snyk.io/vuln/SNYK-JS-APOLLOSERVERCORE-3098876
- https://snyk.io/vuln/SNYK-JS-JSONWEBTOKEN-3180024
- https://snyk.io/vuln/SNYK-JS-KATEX-6483835
- https://snyk.io/vuln/SNYK-JS-NODEFETCH-2342118
- https://snyk.io/vuln/SNYK-JS-SHARP-2848109
- https://snyk.io/vuln/SNYK-JS-JSONWEBTOKEN-3180022
- https://snyk.io/vuln/SNYK-JS-COOKIE-8163060
- https://snyk.io/vuln/SNYK-JS-KATEX-6483831
- https://snyk.io/vuln/SNYK-JS-EXPRESS-6474509
- https://snyk.io/vuln/SNYK-JS-MINIMIST-2429795
- https://snyk.io/vuln/SNYK-JS-NODEFORGE-2430337
- https://snyk.io/vuln/SNYK-JS-NODEFORGE-2430341
- https://snyk.io/vuln/SNYK-JS-KATEX-6483834
- https://snyk.io/vuln/SNYK-JS-GOT-2932019
- https://snyk.io/vuln/SNYK-JS-KATEX-8647963
- https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818
- https://snyk.io/vuln/SNYK-JS-TERSER-2806366
- https://snyk.io/vuln/SNYK-JS-EXPRESS-7926867
- https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-9789073
- https://snyk.io/vuln/SNYK-JS-PRISMJS-9055448
- https://snyk.io/vuln/SNYK-JS-APOLLOSERVERCORE-2979828
- https://snyk.io/vuln/SNYK-JS-APOLLOSERVERCORE-5876618
- https://snyk.io/vuln/SNYK-JS-SEND-7926862
- https://snyk.io/vuln/SNYK-JS-SERVESTATIC-7926865
@talhabalaj talhabalaj self-assigned this Oct 1, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants