Skip to content

[Aikido] Fix 5 security issues in axios, nx, yaml and 1 more - #1762

Open
aikido-autofix[bot] wants to merge 2 commits into
mainfrom
fix/aikido-security-update-packages-119910793-pmm7
Open

aikido-autofix[bot] wants to merge 2 commits into
mainfrom
fix/aikido-security-update-packages-119910793-pmm7

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Upgrade axios, nx, yaml, and yargs to fix buffer overflow, command injection, prototype pollution, and stack exhaustion vulnerabilities. This update includes breaking changes that require manual migration.

⚠️ Code affected by breaking changes.

⚠️ nx upgrade (20.8.4 => 22.7.8):

  • Where your code is affected: jest.config.ts (line 1)

  • Impact: The getJestProjects function was removed in nx v21.0.0. The code imports and uses this function to configure Jest projects, which will cause a runtime error after the upgrade.

  • Remediation: Replace getJestProjects() with the new approach of manually listing project paths or using the nx jest plugin configuration to auto-discover projects.

All breaking changes by upgrading axios from version 1.18.1 to 1.20.0 (CHANGELOG)

Version Description
1.20.0
Added ContentTooLarge (413) and UnprocessableContent (422) HTTP status codes, while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases.
1.20.0
Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects, with documented compatibility effects on Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection.
1.20.0
Navigation-canceled XHR requests now reject with ECONNABORTED instead of resolving with status 0.
1.20.0
Invalid DNS lookup and httpVersion failures are now standardized as AxiosError.ERR_BAD_OPTION_VALUE.

All breaking changes by upgrading nx from version 20.8.4 to 22.7.8 (CHANGELOG)

Version Description
21.0.0
Removed deprecated functionalities for Angular v21
21.0.0
Removed usage of cli property from migration definitions
21.0.0
Removed deprecated readWorkspaceConfig
21.0.0
Dropped support for create nodes v1 in favor of only calling create nodes v2
21.0.0
Removed legacy cache flag from nx.json
21.0.0
Dropped support for node versions prior to 20.19.0
21.0.0
Removed outputStyle=compact
21.0.0
Removed deprecated getJestProjects
21.0.0
Removed tsConfig option from the @nx/jest:jest executor
21.0.0
Removed tsConfig and copyFiles options from the @nx/cypress:cypress executor
21.0.0
useLegacyVersioning is false by default in release configuration
21.0.0
Support for GitLab releases added (breaking change indicated by warning symbol)
21.0.0
Removed deprecated static-serve target name from inferred targets in Remix
21.0.0
Only provide default value for object properties if object already has value
21.0.0
Respect packageManager field in package.json when detecting version
21.2.0
Support for Angular v17 was dropped
21.2.0
Removed deprecated Storybook generators
21.4.0
Stylus (.styl) files are no longer supported in bundling.
22.0.0
The NX_DISABLE_DB environment variable has been removed.
22.0.0
CreateNodes v1 types have been removed.
22.0.0
The experimental and deprecated inlining feature has been removed from the tsc and swc executors (the external and externalBuildTargets options are no longer available).
22.0.0
The deprecated decorate-cli script has been removed.
22.0.0
The nx format command and generators no longer default to sorting TypeScript path mappings (use --sort-root-tsconfig-paths flag or set NX_FORMAT_SORT_TSCONFIG_PATHS=true to keep previous behavior).
22.0.0
The deprecated deleteOutputPath and sassImplementation options have been removed from webpack executors.
22.0.0
The deprecated deleteOutputPath and sassImplementation options have been removed from rspack executors.
22.0.0
The rspack application generator has been removed in favor of framework-specific options.
22.0.0
The default value for useLegacyTypescriptPlugin has changed to false for bundling.
22.0.0
The deprecated simpleName option has been removed from library generators.
22.0.0
The --legacy-peer-deps behavior is no longer forced by default (configure your package manager if needed).
22.0.0
Deprecated legacy versioning has been removed from release functionality.
22.0.0
Default values changed for fixed release group tag pattern, preserveMatchingDependencyRanges (now true by default), and strictPreid in release configuration.
22.0.0
The updateDependents option now defaults to always instead of auto in release configuration.
22.0.0
Release configuration structure has changed: releaseTag* properties have been refactored to a nested releaseTag object.
22.0.0
The signature of init() on VersionActions has changed (no longer accepts a second argument; validation now occurs via separate validate() method).
22.0.0
More files are now used to determine relevant commits in release, matching nx affected behavior, which may result in more projects receiving version bumps.
22.0.0
The config.conventionalCommitsConfig for DefaultChangelogRenderer is no longer nullable.
22.0.0
Multiline breaking changes are now rendered differently by the changelog renderer.
22.0.0
Version plan file contents are now better respected for changelog entries, which may change changelog output.
22.0.0
Support for non-isolated webpack config has been removed from React's componentTestingPreset.
22.6.0
vitest: reportsDirectory is now resolved against workspace root instead of project root, which may change the output location for Vitest reports (#34720)

All breaking changes by upgrading yargs from version 17.7.2 to 18.1.0 (CHANGELOG)

Version Description
18.0.0
Command names are not derived from modules passed to command.
18.0.0
Singleton usage of yargs yargs.foo, yargs().argv, has been removed.
18.0.0
Minimum node.js versions now ^20.19.0 || ^22.12.0 || >=23.
18.0.0
yargs is now ESM first
✅ 5 CVEs resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2026-60497
MEDIUM
[axios] A flaw in byte size estimation for data URLs allows crafted payloads to bypass maxContentLength checks, causing excessive memory allocation and potential denial of service through buffer exhaustion.
AIKIDO-2026-872099
LOW
[axios] Request interceptors can replace the merged config with a plain object, allowing prototype pollution attacks to hijack transport or rewrite responses through inherited fields like adapter, proxy, or transformResponse.
AIKIDO-2026-373135
MEDIUM
[nx] The CLI constructs git commands with unescaped user-controlled revision and branch values, allowing shell metacharacters to execute arbitrary commands when running affected, graph, format, release, or import commands. This vulnerability enables remote code execution on developer and CI machines through malicious values in configuration files, environment variables, or git refs.
AIKIDO-2026-683761
LOW
[yaml] Recursive merge key aliases bypass the maxAliasCount limit, causing unbounded expansion that exhausts memory or call stack, crashing the process with an uncontrolled RangeError instead of a bounded error.
AIKIDO-2026-922647
LOW
[yargs] A prototype pollution vulnerability exists in the deep merge functionality where __proto__ keys are not filtered, allowing attackers to pollute object prototypes and manipulate property lookups through malicious configuration objects.
🤖 Remediation details

Fix five security advisories in nx, axios, yaml, yargs, and smol-toml

Short summary

This PR remediates security vulnerabilities in five packages: nx, axios, yaml, yargs, and smol-toml. The fix involves bumping nx and all sibling @nx/* devDependencies in the root package.json from 20.8.4 to 22.7.8, and adding four resolutions entries in the root package.json to override exact transitive pins that nx@22.7.8 itself declares and that no published nx release in the reachable range resolves to a patched version. The yarn.lock at the repo root is the only lockfile affected.

nx

nx is declared as a direct devDependency in the root package.json at the exact version 20.8.4, which falls within the vulnerable range. It was bumped to 22.7.8 (the minimum patched release). All seven sibling @nx/* packages (@nx/esbuild, @nx/eslint, @nx/eslint-plugin, @nx/jest, @nx/js, @nx/node, @nx/workspace) were declared at the same exact version and moved together as a group to 22.7.8, since they form a tightly coupled release family and mismatching versions would break the toolchain.

axios

axios is a direct dependency of two workspace packages (@aligent/cdk-header-change-detection and @aligent/cdk-prerender-proxy) under ^1.18.0, and is also pinned exactly at 1.18.1 by nx@22.7.8 itself. The ^1.18.0 workspace ranges were resolved to 1.20.0 via a recursive lockfile refresh (yarn up -R axios). The exact 1.18.1 pin from nx required a resolutions entry ("axios": "1.20.0") because no published nx version in the 20.x–22.x range ships a patched axios, making a parent bump alone insufficient.

yaml

yaml is a direct dependency of the @aligent/cdk-graphql-mesh-server workspace package under ^2.9.0, and is also pinned exactly at 2.9.0 by nx@22.7.8. The ^2.9.0 workspace range was resolved to 2.9.1 via a recursive lockfile refresh (yarn up -R yaml). The exact 2.9.0 pin from nx required a resolutions entry ("yaml": "2.9.1") for the same reason as axios — no nx release in the reachable range declares a patched yaml transitively.

yargs

yargs is a transitive dependency pulled in by both nx (spec ^17.6.2) and jest-cli (spec ^17.3.1). Analysis confirmed that every published version of both parents — including the latest nx and jest-cli releases — still declares yargs at ^17.7.2 or 17.7.2, meaning no parent bump can ever resolve yargs >= 18.1.0. A resolutions entry ("yargs": "18.1.0") was added as the only viable path to the patched version.

smol-toml

smol-toml is a transitive dependency pinned exactly at 1.6.1 by nx@22.7.8. No nx release between 22.7.8 and the latest stable adopts smol-toml >= 1.7.1 (the latest published nx pre-release is the first to declare 1.7.1), so a parent bump within the current nx major cannot resolve the vulnerability. A resolutions entry ("smol-toml": "1.7.1") was added, following the same pattern used for axios and yaml, to override the exact pin.

Version changes

Package From To Why updated
nx 20.8.4 22.7.8 Direct CVE fix (AIKIDO-2026-373135)
@nx/esbuild 20.8.4 22.7.8 Group alignment with nx bump
@nx/eslint 20.8.4 22.7.8 Group alignment with nx bump
@nx/eslint-plugin 20.8.4 22.7.8 Group alignment with nx bump
@nx/jest 20.8.4 22.7.8 Group alignment with nx bump
@nx/js 20.8.4 22.7.8 Group alignment with nx bump
@nx/node 20.8.4 22.7.8 Group alignment with nx bump
@nx/workspace 20.8.4 22.7.8 Group alignment with nx bump
axios 1.18.1 1.20.0 CVE fix; ^1.18.0 workspace ranges refreshed via yarn up -R; exact nx pin overridden via resolutions
yaml 2.9.0 / 2.8.3 2.9.1 CVE fix; ^2.9.0 workspace range refreshed via yarn up -R; exact nx pin overridden via resolutions
yargs 17.7.2 18.1.0 CVE fix; no parent path to patched version exists; resolved via resolutions override
smol-toml 1.6.1 1.7.1 CVE fix; exact nx pin overridden via resolutions

@aikido-autofix
aikido-autofix Bot requested a review from a team as a code owner September 21, 2026 00:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants