Skip to content

Add Socket patch for CVE-2025-9288 in pkg:npm/sha.js@2.2.6#1

Open
socket-security[bot] wants to merge 2 commits intomasterfrom
socket/autopatch-1774305946398-ba3ee699
Open

Add Socket patch for CVE-2025-9288 in pkg:npm/sha.js@2.2.6#1
socket-security[bot] wants to merge 2 commits intomasterfrom
socket/autopatch-1774305946398-ba3ee699

Conversation

@socket-security
Copy link
Copy Markdown

Summary

This PR updates Socket security patches for your dependencies.

Changes

  • Added: CVE-2025-9288 in pkg:npm/sha.js@2.2.6 (Socket Patch)
    • Severity: CRITICAL
    • Summary: sha.js is missing type checks leading to hash rewind and passing on crafted data

📦 Package.json Updates

This PR automatically configures your postinstall script to apply Socket patches:

  • Updated: 1 file
    • package.json

After merging, patches will automatically apply on npm install.

Testing

Review the patches and test your application to ensure compatibility.


🔒 Powered by Socket Security

Updates:
- 196 blob(s) added
- 0 blob(s) removed
- Manifest updated
Configures package.json postinstall scripts to automatically apply Socket security patches.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants