Skip to content

[Aikido] Fix 4 security issues in nx, axios, yaml and 1 more - #1761

Open
aikido-autofix[bot] wants to merge 2 commits into
mainfrom
fix/aikido-security-update-packages-116777337-g5sn
Open

aikido-autofix[bot] wants to merge 2 commits into
mainfrom
fix/aikido-security-update-packages-116777337-g5sn

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Upgrade nx, axios, yaml, and yargs to fix command injection (RCE), prototype pollution, and denial-of-service vulnerabilities. This update includes breaking changes that require manual migration.

⚠️ Code affected by breaking changes.

⚠️ ## Breaking Changes That Affect This Codebase

nx (20.8.4 => 22.7.8)

1. Removed deprecated getJestProjects function (21.0.0)

  • Where your code is affected: jest.config.ts:1 - The root Jest configuration imports and uses getJestProjects from @nx/jest

  • Impact: The getJestProjects() function has been removed in nx v21.0.0, which will cause the Jest configuration to fail when loading, breaking all test execution across the monorepo

  • Remediation: Replace getJestProjects() with the new approach using Nx's inference plugins or manually configure Jest projects array

2. Node.js version requirement (21.0.0)

  • Where your code is affected: .nvmrc specifies v24.15.0, but nx v21+ requires Node.js ^20.19.0 minimum

  • Impact: While the current Node.js version (24.15.0) meets the minimum requirement, the breaking change enforces stricter version checking that could affect CI/CD pipelines or developer environments using older Node.js versions

  • Remediation: Ensure all environments use Node.js >= 20.19.0; current .nvmrc version is already compliant


Other Packages

axios (1.18.1 => 1.20.0): No breaking changes affect this codebase. The code uses basic axios functionality (axios.get(), axios.create(), validateStatus, maxRedirects) which remain unchanged. The breaking changes around navigation-canceled XHR requests, DNS lookup errors, and status code additions don't impact the current usage patterns.

yargs (17.7.2 => 18.1.0): Not used in this codebase.

All breaking changes by upgrading nx from version 20.8.4 to 22.7.8 (CHANGELOG)

Version Description
21.0.0
Removed deprecated functionalities for Angular v21
21.0.0
Removed usage of cli property from migration definitions
21.0.0
Removed deprecated readWorkspaceConfig
21.0.0
Dropped support for create nodes v1 in favor of only calling create nodes v2
21.0.0
Removed legacy cache flag from nx.json
21.0.0
Dropped support for node versions prior to 20.19.0
21.0.0
Removed outputStyle=compact
21.0.0
Removed deprecated getJestProjects
21.0.0
Removed tsConfig option from the @nx/jest:jest executor
21.0.0
Removed tsConfig and copyFiles options from the @nx/cypress:cypress executor
21.0.0
useLegacyVersioning is false by default in release configuration
21.0.0
Support for GitLab releases added (breaking change indicated by warning symbol)
21.0.0
Removed deprecated static-serve target name from inferred targets in Remix
21.0.0
Only provide default value for object properties if object already has value
21.0.0
Respect packageManager field in package.json when detecting version
21.2.0
Support for Angular v17 was dropped
21.2.0
Removed deprecated Storybook generators
21.4.0
Stylus (.styl) files are no longer supported in bundling.
22.0.0
The NX_DISABLE_DB environment variable has been removed.
22.0.0
CreateNodes v1 types have been removed.
22.0.0
The experimental and deprecated inlining feature has been removed from the tsc and swc executors (the external and externalBuildTargets options are no longer available).
22.0.0
The deprecated decorate-cli script has been removed.
22.0.0
The nx format command and generators no longer default to sorting TypeScript path mappings (use --sort-root-tsconfig-paths flag or set NX_FORMAT_SORT_TSCONFIG_PATHS=true to keep previous behavior).
22.0.0
The deprecated deleteOutputPath and sassImplementation options have been removed from webpack executors.
22.0.0
The deprecated deleteOutputPath and sassImplementation options have been removed from rspack executors.
22.0.0
The rspack application generator has been removed in favor of framework-specific options.
22.0.0
The default value for useLegacyTypescriptPlugin has changed to false for bundling.
22.0.0
The deprecated simpleName option has been removed from library generators.
22.0.0
The --legacy-peer-deps behavior is no longer forced by default (configure your package manager if needed).
22.0.0
Deprecated legacy versioning has been removed from release functionality.
22.0.0
Default values changed for fixed release group tag pattern, preserveMatchingDependencyRanges (now true by default), and strictPreid in release configuration.
22.0.0
The updateDependents option now defaults to always instead of auto in release configuration.
22.0.0
Release configuration structure has changed: releaseTag* properties have been refactored to a nested releaseTag object.
22.0.0
The signature of init() on VersionActions has changed (no longer accepts a second argument; validation now occurs via separate validate() method).
22.0.0
More files are now used to determine relevant commits in release, matching nx affected behavior, which may result in more projects receiving version bumps.
22.0.0
The config.conventionalCommitsConfig for DefaultChangelogRenderer is no longer nullable.
22.0.0
Multiline breaking changes are now rendered differently by the changelog renderer.
22.0.0
Version plan file contents are now better respected for changelog entries, which may change changelog output.
22.0.0
Support for non-isolated webpack config has been removed from React's componentTestingPreset.
22.6.0
vitest: reportsDirectory is now resolved against workspace root instead of project root, which may change the output location for Vitest reports (#34720)

All breaking changes by upgrading axios from version 1.18.1 to 1.20.0 (CHANGELOG)

Version Description
1.20.0
Added ContentTooLarge (413) and UnprocessableContent (422) HTTP status codes, while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases.
1.20.0
Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects, with documented compatibility effects on Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection.
1.20.0
Navigation-canceled XHR requests now reject with ECONNABORTED instead of resolving with status 0.
1.20.0
Invalid DNS lookup and httpVersion failures are now standardized as AxiosError.ERR_BAD_OPTION_VALUE.

All breaking changes by upgrading yargs from version 17.7.2 to 18.1.0 (CHANGELOG)

Version Description
18.0.0
Command names are not derived from modules passed to command.
18.0.0
Singleton usage of yargs yargs.foo, yargs().argv, has been removed.
18.0.0
Minimum node.js versions now ^20.19.0 || ^22.12.0 || >=23.
18.0.0
yargs is now ESM first
✅ 4 CVEs resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2026-373135
MEDIUM
[nx] The CLI constructs git commands with unescaped user-controlled revision and branch values, allowing shell metacharacters to execute arbitrary commands when running affected, graph, format, release, or import commands. This vulnerability enables remote code execution on developer and CI machines through malicious values in configuration files, environment variables, or git refs.
AIKIDO-2026-872099
LOW
[axios] Request interceptors can replace the merged config with a plain object, allowing prototype pollution attacks to hijack transport or rewrite responses through inherited fields like adapter, proxy, or transformResponse.
AIKIDO-2026-683761
LOW
[yaml] Recursive merge key aliases bypass the maxAliasCount limit, causing unbounded expansion that exhausts memory or call stack, crashing the process with an uncontrolled RangeError instead of a bounded error.
AIKIDO-2026-922647
LOW
[yargs] A prototype pollution vulnerability exists in the deep merge functionality where __proto__ keys are not filtered, allowing attackers to pollute object prototypes and manipulate property lookups through malicious configuration objects.
🤖 Remediation details

Fix five transitive security vulnerabilities introduced via nx and jest dependency chains

Short summary

This PR remediates security vulnerabilities in five packages: nx, axios, yaml, yargs, and smol-toml. The root package.json was updated to bump nx and all @nx/* sibling packages from 20.8.4 to 22.7.8, and four resolutions entries were added to force patched versions of transitive dependencies that nx@22.7.8 pins exactly. The yarn.lock was refreshed to reflect all resolved version changes.

nx

nx is declared directly in the root package.json at an exact version (20.8.4), which falls within the vulnerable range. It was bumped to 22.7.8 (the minimum patched release in the 22.x line) as a direct manifest edit. All seven @nx/* sibling packages (@nx/esbuild, @nx/eslint, @nx/eslint-plugin, @nx/jest, @nx/js, @nx/node, @nx/workspace) were pinned at the same exact version and moved to 22.7.8 in the same edit, as required by the group-alignment policy for packages sharing an identical declared version.

axios

axios@1.18.1 was a transitive dependency pulled in by both workspace packages (@aligent/cdk-header-change-detection, @aligent/cdk-prerender-proxy) via ^1.18.0 and by nx via an exact pin of 1.18.1. The workspace ^1.18.0 selector was refreshed to resolve 1.20.0 via yarn up -R axios. However, nx@22.7.8 continued to pin axios at the exact version 1.18.1 in its own published dependencies, which no parent bump can override; a resolutions entry ("axios": "1.20.0") was therefore added as a last resort to force the single consolidated lockfile entry to 1.20.0.

yaml

Two vulnerable yaml@2.x instances existed: one at 2.8.3 (selectors * and ^2.6.0) and one at 2.9.0 (selectors ^2.9.0 and an exact 2.9.0 pin from nx@22.7.8). The ^2.9.0 and * selectors were refreshed to 2.9.1 via yarn up -R yaml. The exact 2.9.0 pin from nx could not be resolved by a parent bump, so targeted resolutions entries (yaml@npm:^2.6.0, yaml@npm:^2.9.0, yaml@npm:2.9.0) were added to force all 2.x selectors to 2.9.1. A separate yaml@1.10.3 instance (requested by aws-cdk-lib and cosmiconfig via ^1.10.0) is outside the vulnerable range (>=2.0.0) and was intentionally preserved by using targeted rather than blanket resolutions.

yargs

yargs@17.7.2 is a transitive dependency of both jest-cli@29.7.0 (via ^17.3.1) and nx@22.7.8 (via ^17.6.2). Analysis confirmed that no published version of either parent — up to jest-cli@30.5.1 and nx@23.x — ships yargs@18.x; both chains declare yargs at ^17.x throughout. With no viable parent-bump path, a resolutions entry ("yargs": "18.1.0") was added as a last resort to force the resolved version to the minimum patched release.

smol-toml

smol-toml@1.6.1 is a transitive dependency pulled in by nx@22.7.8 via an exact pin of 1.6.1. Because the pin is exact, no parent bump can resolve it to a higher version. A targeted resolutions entry ("smol-toml@npm:1.6.1": "1.7.1") was added to override only that specific selector and bring the resolved version to the minimum patched release 1.7.1.

Version changes

Package From To Why updated
nx 20.8.4 22.7.8 Direct CVE fix
@nx/esbuild 20.8.4 22.7.8 Group alignment with nx
@nx/eslint 20.8.4 22.7.8 Group alignment with nx
@nx/eslint-plugin 20.8.4 22.7.8 Group alignment with nx
@nx/jest 20.8.4 22.7.8 Group alignment with nx
@nx/js 20.8.4 22.7.8 Group alignment with nx
@nx/node 20.8.4 22.7.8 Group alignment with nx
@nx/workspace 20.8.4 22.7.8 Group alignment with nx
axios 1.18.1 1.20.0 Direct CVE fix; override required for exact pin from nx
yaml (v2.x instances) 2.8.3 / 2.9.0 2.9.1 Direct CVE fix; override required for exact pin from nx
yargs 17.7.2 18.1.0 Direct CVE fix via resolution (no parent ships yargs@18.x)
smol-toml 1.6.1 1.7.1 Direct CVE fix via resolution; override required for exact pin from nx

@aikido-autofix
aikido-autofix Bot requested a review from a team as a code owner September 17, 2026 01:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants