Skip to content

Conversation

@rezib
Copy link
Contributor

@rezib rezib commented Oct 14, 2025

Fix the following security issues in bundled dependencies:

axios 1.0.0 - 1.11.0
Severity: high
Axios is vulnerable to DoS attack through lack of data size check -
GHSA-4hjh-wcwx-xvwj

brace-expansion 1.0.0 - 1.1.11 || 2.0.0 - 2.0.1
brace-expansion Regular Expression Denial of Service vulnerability -
GHSA-v6h2-p8h4-qcjw

form-data 4.0.0 - 4.0.3
Severity: critical
form-data uses unsafe random function in form-data for choosing
boundary - GHSA-fjxv-7rqg-78g4

vite 6.0.0 - 6.3.5
Severity: moderate
Vite has a server.fs.deny bypassed for inline and raw with
?import query - GHSA-4r4m-qw57-chr8
Vite has an server.fs.deny bypass with an invalid request-target

Fix the following security issues in bundled dependencies:

  axios  1.0.0 - 1.11.0
  Severity: high
  Axios is vulnerable to DoS attack through lack of data size check -
  GHSA-4hjh-wcwx-xvwj

  brace-expansion  1.0.0 - 1.1.11 || 2.0.0 - 2.0.1
  brace-expansion Regular Expression Denial of Service vulnerability -
  GHSA-v6h2-p8h4-qcjw

  form-data  4.0.0 - 4.0.3
  Severity: critical
  form-data uses unsafe random function in form-data for choosing
  boundary - GHSA-fjxv-7rqg-78g4

  vite  6.0.0 - 6.3.5
  Severity: moderate
  Vite has a `server.fs.deny` bypassed for `inline` and `raw` with
  `?import` query - GHSA-4r4m-qw57-chr8
  Vite has an `server.fs.deny` bypass with an invalid `request-target`
  - GHSA-356w-63v5-8wf4
  Vite's server.fs.deny bypassed with /. for files under project root -
  GHSA-859w-5945-r5v3
  Vite allows server.fs.deny to be bypassed with .svg or relative paths
  - GHSA-xcj6-pq6g-qj4x
  Vite middleware may serve files starting with the same name with the
  public directory - GHSA-g4jq-h2w9-997c
  Vite's `server.fs` settings were not applied to HTML files -
  GHSA-jqfw-vq24-v9c3
@rezib rezib added this to the v0.6.0 milestone Oct 14, 2025
@rezib rezib self-assigned this Oct 14, 2025
@rezib rezib merged commit 3f628da into main Oct 14, 2025
34 of 35 checks passed
@rezib rezib deleted the pr/audit-fix branch October 14, 2025 19:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants