chore(deps): update dependency js-yaml to v4.1.1 [security]#42
chore(deps): update dependency js-yaml to v4.1.1 [security]#42renovate[bot] wants to merge 1 commit into
Conversation
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the
Comment |
7756991 to
ce6774b
Compare
ce6774b to
3b87187
Compare
|
All alerts resolved. Learn more about Socket for GitHub. This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. |
7b2728d to
23c963f
Compare
23c963f to
6dd28ea
Compare
c4b5c72 to
7dcfc5a
Compare
7dcfc5a to
d81c3a8
Compare
e87d062 to
da84d19
Compare
da84d19 to
bf78331
Compare
bf78331 to
34c38a2
Compare
68cd39f to
65cfb02
Compare
65cfb02 to
57753bc
Compare
57753bc to
a1e1905
Compare
a1e1905 to
a474ad4
Compare
a474ad4 to
7960d95
Compare
This PR contains the following updates:
4.1.0→4.1.1js-yaml has prototype pollution in merge (<<)
CVE-2025-64718 / GHSA-mh29-5h37-fv8m
More information
Details
Impact
In js-yaml 4.1.0, 4.0.0, and 3.14.1 and below, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (
__proto__). All users who parse untrusted yaml documents may be impacted.Patches
Problem is patched in js-yaml 4.1.1 and 3.14.2.
Workarounds
You can protect against this kind of attack on the server by using
node --disable-proto=deleteordeno(in Deno, pollution protection is on by default).References
https://cheatsheetseries.owasp.org/cheatsheets/Prototype_Pollution_Prevention_Cheat_Sheet.html
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
nodeca/js-yaml (js-yaml)
v4.1.1Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.