MetaMask / MetaMask/metamask-extension

Yarn Audit: new or newly blocking advisories on main (7b6c1c6713)

Open
#44,996 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
13.2k
Forks
5.6k
Avg merge
2d 5h
Merged PRs (30d)
451

Description

**31** new or newly blocking advisories detected on push to `main` (0 release-blocking).

CI run: https://github.com/MetaMask/metamask-extension/actions/runs/30457439310

## Informational (dev-only or low severity)

- **@tootallnate/once** (low, dev-only) — @tootallnate/once vulnerable to Incorrect Control Flow Scoping
https://github.com/advisories/GHSA-vpq2-c234-7xj6
- **bigint-buffer** (high, dev-only) — bigint-buffer Vulnerable to Buffer Overflow via toBigIntLE() Function
https://github.com/advisories/GHSA-3gc7-fjrx-p6mg
- **brace-expansion** (low, dev-only) — brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
https://github.com/advisories/GHSA-mh99-v99m-4gvg
- **electron** (moderate, dev-only) — Electron vulnerable to out-of-package code execution when launched with arbitrary cwd
https://github.com/advisories/GHSA-7x97-j373-85x5
- **electron** (moderate, dev-only) — ASAR Integrity bypass via filetype confusion in electron
https://github.com/advisories/GHSA-7m48-wc93-9g85
- **electron** (moderate, dev-only) — Electron vulnerable to Heap Buffer Overflow in NativeImage
https://github.com/advisories/GHSA-6r2x-8pq8-9489
- **electron** (moderate, dev-only) — Electron has ASAR Integrity Bypass via resource modification
https://github.com/advisories/GHSA-vmqv-hx8q-j7mg
- **electron** (moderate, dev-only) — Electron: AppleScript injection in app.moveToApplicationsFolder on macOS
https://github.com/advisories/GHSA-5rqw-r77c-jp79
- **electron** (moderate, dev-only) — Electron: Service worker can spoof executeJavaScript IPC replies
https://github.com/advisories/GHSA-xj5x-m3f3-5x3h
- **electron** (moderate, dev-only) — Electron: Incorrect origin passed to permission request handler for iframe requests
https://github.com/advisories/GHSA-r5p7-gp4j-qhrx
- **electron** (moderate, dev-only) — Electron: Out-of-bounds read in second-instance IPC on macOS and Linux
https://github.com/advisories/GHSA-3c8v-cfp5-9885
- **electron** (moderate, dev-only) — Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
https://github.com/advisories/GHSA-xwr5-m59h-vwqr
- **electron** (high, dev-only) — Electron: Use-after-free in offscreen child window paint callback
https://github.com/advisories/GHSA-532v-xpq5-8h95
- **electron** (moderate, dev-only) — Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
https://github.com/advisories/GHSA-mwmh-mq4g-g6gr
- **electron** (moderate, dev-only) — Electron: Use-after-free in download save dialog callback
https://github.com/advisories/GHSA-9w97-2464-8783
- **electron** (high, dev-only) — Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
https://github.com/advisories/GHSA-8337-3p73-46f4
- **electron** (high, dev-only) — Electron: Use-after-free in PowerMonitor on Windows and macOS
https://github.com/advisories/GHSA-jjp3-mq3x-295m
- **electron** (low, dev-only) — Electron: Unquoted executable path in app.setLoginItemSettings on Windows
https://github.com/advisories/GHSA-jfqx-fxh3-c62j
- **electron** (moderate, dev-only) — Electron: HTTP Response Header Injection in custom protocol handlers and webRequest
https://github.com/advisories/GHSA-4p4r-m79c-wq3v
- **electron** (low, dev-only) — Electron: USB device selection not validated against filtered device list
https://github.com/advisories/GHSA-9899-m83m-qhpj
- **electron** (low, dev-only) — Electron: Crash in clipboard.readImage() on malformed clipboard image data
https://github.com/advisories/GHSA-f37v-82c4-4x64
- **electron** (moderate, dev-only) — Electron: Named window.open targets not scoped to the opener's browsing context
https://github.com/advisories/GHSA-f3pv-wv63-48x8
- **electron** (high, dev-only) — Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
https://github.com/advisories/GHSA-9wfr-w7mm-pc7f
- **got** (moderate, dev-only) — Got allows a redirect to a UNIX socket
https://github.com/advisories/GHSA-pfrx-2q88-qq97
- **ip** (high, dev-only) — ip SSRF improper categorization in isPublic
https://github.com/advisories/GHSA-2p57-rm9w-gvfp
- **ip** (low, dev-only) — NPM IP package incorrectly identifies some private IP addresses as public
https://github.com/advisories/GHSA-78xj-cgh5-2h22
- **nanoid** (moderate, dev-only) — Predictable results in nanoid generation when given non-integer values
https://github.com/advisories/GHSA-mwcw-c2x4-8c55
- **postcss** (moderate, dev-only) — PostCSS line return parsing error
https://github.com/advisories/GHSA-7fh5-64p2-3v2j
- **postcss** (moderate, dev-only) — PostCSS has XSS via Unescaped in its CSS Stringify Output
https://github.com/advisories/GHSA-qx2v-qp2m-jg93
- **postcss** (high, dev-only) — PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
https://github.com/advisories/GHSA-6g55-p6wh-862q
- **postcss** (high, dev-only) — PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
https://github.com/advisories/GHSA-r28c-9q8g-f849

Native audit tree

```
├─ @tootallnate/once
│ ├─ ID: 1119438
│ ├─ Issue: @tootallnate/once vulnerable to Incorrect Control Flow Scoping
│ ├─ URL: https://github.com/advisories/GHSA-vpq2-c234-7xj6
│ ├─ Severity: low
│ ├─ Vulnerable Versions: <2.0.1
│ │
│ ├─ Tree Versions
│ │ ├─ 1.1.2
│ │ └─ 2.0.0
│ │
│ └─ Dependents
│ ├─ http-proxy-agent@npm:4.0.1
│ └─ http-proxy-agent@npm:5.0.0

├─ bigint-buffer
│ ├─ ID: 1103747
│ ├─ Issue: bigint-buffer Vulnerable to Buffer Overflow via toBigIntLE() Function
│ ├─ URL: https://github.com/advisories/GHSA-3gc7-fjrx-p6mg
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <=1.1.5
│ │
│ ├─ Tree Versions
│ │ └─ 1.1.5
│ │
│ └─ Dependents
│ └─ @solana/buffer-layout-utils@npm:0.2.0

├─ brace-expansion
│ ├─ ID: 1124334
│ ├─ Issue: brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
│ ├─ URL: https://github.com/advisories/GHSA-mh99-v99m-4gvg
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <=5.0.7
│ │
│ ├─ Tree Versions
│ │ ├─ 1.1.16
│ │ └─ 2.1.2
│ │
│ └─ Dependents
│ ├─ minimatch@npm:3.1.5
│ └─ minimatch@npm:9.0.9

├─ electron
│ ├─ ID: 1094578
│ ├─ Issue: Electron vulnerable to out-of-package code execution when launched with arbitrary cwd
│ ├─ URL: https://github.com/advisories/GHSA-7x97-j373-85x5
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: >=23.0.0-alpha.1 <23.3.13
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1099652
│ ├─ Issue: ASAR Integrity bypass via filetype confusion in electron
│ ├─ URL: https://github.com/advisories/GHSA-7m48-wc93-9g85
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: >=23.0.0-alpha.1 <=23.3.13
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1105820
│ ├─ Issue: Electron vulnerable to Heap Buffer Overflow in NativeImage
│ ├─ URL: https://github.com/advisories/GHSA-6r2x-8pq8-9489
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <28.3.2
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1107272
│ ├─ Issue: Electron has ASAR Integrity Bypass via resource modification
│ ├─ URL: https://github.com/advisories/GHSA-vmqv-hx8q-j7mg
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <35.7.5
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116041
│ ├─ Issue: Electron: AppleScript injection in app.moveToApplicationsFolder on macOS
│ ├─ URL: https://github.com/advisories/GHSA-5rqw-r77c-jp79
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116045
│ ├─ Issue: Electron: Service worker can spoof executeJavaScript IPC replies
│ ├─ URL: https://github.com/advisories/GHSA-xj5x-m3f3-5x3h
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116049
│ ├─ Issue: Electron: Incorrect origin passed to permission request handler for iframe requests
│ ├─ URL: https://github.com/advisories/GHSA-r5p7-gp4j-qhrx
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116053
│ ├─ Issue: Electron: Out-of-bounds read in second-instance IPC on macOS and Linux
│ ├─ URL: https://github.com/advisories/GHSA-3c8v-cfp5-9885
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116057
│ ├─ Issue: Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
│ ├─ URL: https://github.com/advisories/GHSA-xwr5-m59h-vwqr
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116060
│ ├─ Issue: Electron: Use-after-free in offscreen child window paint callback
│ ├─ URL: https://github.com/advisories/GHSA-532v-xpq5-8h95
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <39.8.1
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116064
│ ├─ Issue: Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
│ ├─ URL: https://github.com/advisories/GHSA-mwmh-mq4g-g6gr
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116068
│ ├─ Issue: Electron: Use-after-free in download save dialog callback
│ ├─ URL: https://github.com/advisories/GHSA-9w97-2464-8783
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116072
│ ├─ Issue: Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
│ ├─ URL: https://github.com/advisories/GHSA-8337-3p73-46f4
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116076
│ ├─ Issue: Electron: Use-after-free in PowerMonitor on Windows and macOS
│ ├─ URL: https://github.com/advisories/GHSA-jjp3-mq3x-295m
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116084
│ ├─ Issue: Electron: Unquoted executable path in app.setLoginItemSettings on Windows
│ ├─ URL: https://github.com/advisories/GHSA-jfqx-fxh3-c62j
│ ├─ Severity: low
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116088
│ ├─ Issue: Electron: HTTP Response Header Injection in custom protocol handlers and webRequest
│ ├─ URL: https://github.com/advisories/GHSA-4p4r-m79c-wq3v
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116092
│ ├─ Issue: Electron: USB device selection not validated against filtered device list
│ ├─ URL: https://github.com/advisories/GHSA-9899-m83m-qhpj
│ ├─ Severity: low
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116259
│ ├─ Issue: Electron: Crash in clipboard.readImage() on malformed clipboard image data
│ ├─ URL: https://github.com/advisories/GHSA-f37v-82c4-4x64
│ ├─ Severity: low
│ ├─ Vulnerable Versions: <39.8.5
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116320
│ ├─ Issue: Electron: Named window.open targets not scoped to the opener's browsing context
│ ├─ URL: https://github.com/advisories/GHSA-f3pv-wv63-48x8
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.5
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1117459
│ ├─ Issue: Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
│ ├─ URL: https://github.com/advisories/GHSA-9wfr-w7mm-pc7f
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ got
│ ├─ ID: 1088948
│ ├─ Issue: Got allows a redirect to a UNIX socket
│ ├─ URL: https://github.com/advisories/GHSA-pfrx-2q88-qq97
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <11.8.5
│ │
│ ├─ Tree Versions
│ │ ├─ 6.7.1
│ │ └─ 9.6.0
│ │
│ └─ Dependents
│ ├─ package-json@npm:4.0.1
│ └─ package-json@npm:6.5.0

├─ ip
│ ├─ ID: 1101851
│ ├─ Issue: ip SSRF improper categorization in isPublic
│ ├─ URL: https://github.com/advisories/GHSA-2p57-rm9w-gvfp
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <=2.0.1
│ │
│ ├─ Tree Versions
│ │ └─ 1.1.8
│ │
│ └─ Dependents
│ └─ pac-resolver@npm:7.0.0

├─ ip
│ ├─ ID: 1114831
│ ├─ Issue: NPM IP package incorrectly identifies some private IP addresses as public
│ ├─ URL: https://github.com/advisories/GHSA-78xj-cgh5-2h22
│ ├─ Severity: low
│ ├─ Vulnerable Versions: <1.1.9
│ │
│ ├─ Tree Versions
│ │ └─ 1.1.8
│ │
│ └─ Dependents
│ └─ pac-resolver@npm:7.0.0

├─ nanoid
│ ├─ ID: 1109563
│ ├─ Issue: Predictable results in nanoid generation when given non-integer values
│ ├─ URL: https://github.com/advisories/GHSA-mwcw-c2x4-8c55
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <3.3.8
│ │
│ ├─ Tree Versions
│ │ └─ 2.1.11
│ │
│ └─ Dependents
│ └─ redux-devtools-core@npm:0.2.1

├─ postcss
│ ├─ ID: 1109574
│ ├─ Issue: PostCSS line return parsing error
│ ├─ URL: https://github.com/advisories/GHSA-7fh5-64p2-3v2j
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <8.4.31
│ │
│ ├─ Tree Versions
│ │ └─ 7.0.39
│ │
│ └─ Dependents
│ └─ resolve-url-loader@npm:3.1.5

├─ postcss
│ ├─ ID: 1117015
│ ├─ Issue: PostCSS has XSS via Unescaped in its CSS Stringify Output
│ ├─ URL: https://github.com/advisories/GHSA-qx2v-qp2m-jg93
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <8.5.10
│ │
│ ├─ Tree Versions
│ │ └─ 7.0.39
│ │
│ └─ Dependents
│ └─ resolve-url-loader@npm:3.1.5

├─ postcss
│ ├─ ID: 1124252
│ ├─ Issue: PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
│ ├─ URL: https://github.com/advisories/GHSA-6g55-p6wh-862q
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <=8.5.11
│ │
│ ├─ Tree Versions
│ │ └─ 7.0.39
│ │
│ └─ Dependents
│ └─ resolve-url-loader@npm:3.1.5

├─ postcss
│ ├─ ID: 1124288
│ ├─ Issue: PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
│ ├─ URL: https://github.com/advisories/GHSA-r28c-9q8g-f849
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <=8.5.17
│ │
│ ├─ Tree Versions
│ │ └─ 7.0.39
│ │
│ └─ Dependents
│ └─ resolve-url-loader@npm:3.1.5

```

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the linked CI run and the native audit tree in this issue to understand which dependency paths produced the 31 advisories. Trace the affected dependencies in the repository's dependency configuration, then confirm that the audit no longer reports the listed advisories and that the existing CI checks pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
electron, typescript
Domain
devops, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.