chore(deps): update dependency js-yaml to v4.1.1 [security]#42
chore(deps): update dependency js-yaml to v4.1.1 [security]#42renovate[bot] wants to merge 1 commit into
Conversation
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the
Comment |
7756991 to
ce6774b
Compare
ce6774b to
3b87187
Compare
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
7b2728d to
23c963f
Compare
23c963f to
6dd28ea
Compare
c4b5c72 to
7dcfc5a
Compare
7dcfc5a to
d81c3a8
Compare
e87d062 to
da84d19
Compare
da84d19 to
bf78331
Compare
bf78331 to
34c38a2
Compare
68cd39f to
65cfb02
Compare
65cfb02 to
57753bc
Compare
57753bc to
a1e1905
Compare
a1e1905 to
a474ad4
Compare
7960d95 to
75fbaff
Compare
c09e033 to
46e1b84
Compare
46e1b84 to
2bce3ba
Compare
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
2bce3ba to
5c69572
Compare
5c69572 to
fa930c0
Compare
8656eda to
a5df0a1
Compare
a5df0a1 to
c4c4e21
Compare
c4c4e21 to
f749904
Compare
This PR contains the following updates:
4.1.0→4.1.1js-yaml has prototype pollution in merge (<<)
CVE-2025-64718 / GHSA-mh29-5h37-fv8m
More information
Details
Impact
In js-yaml 4.1.0, 4.0.0, and 3.14.1 and below, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (
__proto__). All users who parse untrusted yaml documents may be impacted.Patches
Problem is patched in js-yaml 4.1.1 and 3.14.2.
Workarounds
You can protect against this kind of attack on the server by using
node --disable-proto=deleteordeno(in Deno, pollution protection is on by default).References
https://cheatsheetseries.owasp.org/cheatsheets/Prototype_Pollution_Prevention_Cheat_Sheet.html
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
nodeca/js-yaml (js-yaml)
v4.1.1Compare Source
Security
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.