MetaMask / MetaMask/metamask-extension

Yarn Audit: new or newly blocking advisories on main (0b2b4dc224)

Open
#46,071 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
13.2k
Forks
5.6k
Avg merge
2d 5h
Merged PRs (30d)
451

Description

**54** new or newly blocking advisories detected on push to `main` (0 release-blocking).

CI run: https://github.com/MetaMask/metamask-extension/actions/runs/33875350750

## Informational (dev-only or low severity)

- **@tootallnate/once** (low, dev-only) — @tootallnate/once vulnerable to Incorrect Control Flow Scoping
https://github.com/advisories/GHSA-vpq2-c234-7xj6
- **bigint-buffer** (high, dev-only) — bigint-buffer Vulnerable to Buffer Overflow via toBigIntLE() Function
https://github.com/advisories/GHSA-3gc7-fjrx-p6mg
- **decode-uri-component** (moderate, dev-only) — decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
https://github.com/advisories/GHSA-vcc3-ghjq-m6fr
- **electron** (moderate, dev-only) — Electron vulnerable to out-of-package code execution when launched with arbitrary cwd
https://github.com/advisories/GHSA-7x97-j373-85x5
- **electron** (moderate, dev-only) — ASAR Integrity bypass via filetype confusion in electron
https://github.com/advisories/GHSA-7m48-wc93-9g85
- **electron** (moderate, dev-only) — Electron vulnerable to Heap Buffer Overflow in NativeImage
https://github.com/advisories/GHSA-6r2x-8pq8-9489
- **electron** (moderate, dev-only) — Electron has ASAR Integrity Bypass via resource modification
https://github.com/advisories/GHSA-vmqv-hx8q-j7mg
- **electron** (moderate, dev-only) — Electron: AppleScript injection in app.moveToApplicationsFolder on macOS
https://github.com/advisories/GHSA-5rqw-r77c-jp79
- **electron** (moderate, dev-only) — Electron: Service worker can spoof executeJavaScript IPC replies
https://github.com/advisories/GHSA-xj5x-m3f3-5x3h
- **electron** (moderate, dev-only) — Electron: Incorrect origin passed to permission request handler for iframe requests
https://github.com/advisories/GHSA-r5p7-gp4j-qhrx
- **electron** (moderate, dev-only) — Electron: Out-of-bounds read in second-instance IPC on macOS and Linux
https://github.com/advisories/GHSA-3c8v-cfp5-9885
- **electron** (moderate, dev-only) — Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
https://github.com/advisories/GHSA-xwr5-m59h-vwqr
- **electron** (high, dev-only) — Electron: Use-after-free in offscreen child window paint callback
https://github.com/advisories/GHSA-532v-xpq5-8h95
- **electron** (moderate, dev-only) — Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
https://github.com/advisories/GHSA-mwmh-mq4g-g6gr
- **electron** (moderate, dev-only) — Electron: Use-after-free in download save dialog callback
https://github.com/advisories/GHSA-9w97-2464-8783
- **electron** (high, dev-only) — Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
https://github.com/advisories/GHSA-8337-3p73-46f4
- **electron** (high, dev-only) — Electron: Use-after-free in PowerMonitor on Windows and macOS
https://github.com/advisories/GHSA-jjp3-mq3x-295m
- **electron** (low, dev-only) — Electron: Unquoted executable path in app.setLoginItemSettings on Windows
https://github.com/advisories/GHSA-jfqx-fxh3-c62j
- **electron** (moderate, dev-only) — Electron: HTTP Response Header Injection in custom protocol handlers and webRequest
https://github.com/advisories/GHSA-4p4r-m79c-wq3v
- **electron** (low, dev-only) — Electron: USB device selection not validated against filtered device list
https://github.com/advisories/GHSA-9899-m83m-qhpj
- **electron** (low, dev-only) — Electron: Crash in clipboard.readImage() on malformed clipboard image data
https://github.com/advisories/GHSA-f37v-82c4-4x64
- **electron** (moderate, dev-only) — Electron: Named window.open targets not scoped to the opener's browsing context
https://github.com/advisories/GHSA-f3pv-wv63-48x8
- **electron** (high, dev-only) — Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
https://github.com/advisories/GHSA-9wfr-w7mm-pc7f
- **electron** (moderate, dev-only) — Electron: Parent process code-sign check is spoofable
https://github.com/advisories/GHSA-jm7p-cc5g-qwxx
- **electron** (high, dev-only) — Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
https://github.com/advisories/GHSA-v3j7-r9gq-3gjw
- **electron** (moderate, dev-only) — Electron: Extension tab APIs operate across session boundaries
https://github.com/advisories/GHSA-m55f-7gqj-fr98
- **electron** (moderate, dev-only) — Electron: shell.openPath path validation bypass via embedded null byte
https://github.com/advisories/GHSA-5c9j-mhmv-5xgx
- **electron** (high, dev-only) — Electron: Context isolation bypass via Function.prototype.bind hijack
https://github.com/advisories/GHSA-h7rp-cf8h-j98x
- **electron** (low, dev-only) — Electron: Cross-origin iframe can position native autofill popup
https://github.com/advisories/GHSA-x8rc-wpg4-grpf
- **electron** (moderate, dev-only) — Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
https://github.com/advisories/GHSA-9pf5-hg6p-4pwp
- **electron** (low, dev-only) — Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
https://github.com/advisories/GHSA-pfmc-3mgc-p6fp
- **electron** (moderate, dev-only) — Electron: HTTP redirect followed into local file loader
https://github.com/advisories/GHSA-v64r-4m7r-3mvq
- **electron** (moderate, dev-only) — Electron: window.open features string controls some window options considered privileged
https://github.com/advisories/GHSA-v93f-fgjr-hjrj
- **electron** (high, dev-only) — Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
https://github.com/advisories/GHSA-9f4c-93c8-jc8g
- **electron** (moderate, dev-only) — Electron: Sandboxed iframes can launch external protocol handlers
https://github.com/advisories/GHSA-p2rr-rvmm-c5fp
- **electron** (moderate, dev-only) — Electron: DevTools embedder handler executes arbitrary files via shell open
https://github.com/advisories/GHSA-f2r8-jv7c-xqmp
- **electron** (moderate, dev-only) — Electron: contextBridge object copy honors prototype setters
https://github.com/advisories/GHSA-ff2p-hmqr-hxm4
- **electron** (moderate, dev-only) — Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
https://github.com/advisories/GHSA-4f78-qhmw-8j8m
- **extract-zip** (high, dev-only) — extract-zip unvalidated symlink path traversal
https://github.com/advisories/GHSA-jmr9-qjv8-65gv
- **got** (moderate, dev-only) — Got allows a redirect to a UNIX socket
https://github.com/advisories/GHSA-pfrx-2q88-qq97
- **image-size** (high, dev-only) — image-size: ICNS parser allows denial of service through an infinite loop
https://github.com/advisories/GHSA-w3rx-r6r6-pgpr
- **image-size** (high, dev-only) — image-size: JXL and HEIF parsers allow denial of service through infinite loops
https://github.com/advisories/GHSA-5p2g-fcmc-qvqq
- **ip** (high, dev-only) — ip SSRF improper categorization in isPublic
https://github.com/advisories/GHSA-2p57-rm9w-gvfp
- **ip** (low, dev-only) — NPM IP package incorrectly identifies some private IP addresses as public
https://github.com/advisories/GHSA-78xj-cgh5-2h22
- **nanoid** (moderate, dev-only) — Predictable results in nanoid generation when given non-integer values
https://github.com/advisories/GHSA-mwcw-c2x4-8c55
- **nanoid** (high, dev-only) — nanoid: non-secure generators can loop indefinitely with negative size
https://github.com/advisories/GHSA-28wg-ghj8-5hjv
- **nanoid** (high, dev-only) — nanoid: custom generators can loop indefinitely when size is zero
https://github.com/advisories/GHSA-2v37-7h3g-55p8
- **nanoid** (high, dev-only) — nanoid: Integer Overflow or Wraparound
https://github.com/advisories/GHSA-xwg4-73v4-xw9w
- **postcss** (moderate, dev-only) — PostCSS line return parsing error
https://github.com/advisories/GHSA-7fh5-64p2-3v2j
- **postcss** (moderate, dev-only) — PostCSS has XSS via Unescaped in its CSS Stringify Output
https://github.com/advisories/GHSA-qx2v-qp2m-jg93
- **postcss** (high, dev-only) — PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
https://github.com/advisories/GHSA-6g55-p6wh-862q
- **postcss** (moderate, dev-only) — PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset
https://github.com/advisories/GHSA-fxqj-rqcc-2cmp
- **postcss** (high, dev-only) — PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
https://github.com/advisories/GHSA-r28c-9q8g-f849
- **stream-json** (moderate, dev-only) — stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)
https://github.com/advisories/GHSA-528h-pc64-c93x

Native audit tree

```
├─ @tootallnate/once
│ ├─ ID: 1119438
│ ├─ Issue: @tootallnate/once vulnerable to Incorrect Control Flow Scoping
│ ├─ URL: https://github.com/advisories/GHSA-vpq2-c234-7xj6
│ ├─ Severity: low
│ ├─ Vulnerable Versions: <2.0.1
│ │
│ ├─ Tree Versions
│ │ ├─ 1.1.2
│ │ └─ 2.0.0
│ │
│ └─ Dependents
│ ├─ http-proxy-agent@npm:4.0.1
│ └─ http-proxy-agent@npm:5.0.0

├─ bigint-buffer
│ ├─ ID: 1103747
│ ├─ Issue: bigint-buffer Vulnerable to Buffer Overflow via toBigIntLE() Function
│ ├─ URL: https://github.com/advisories/GHSA-3gc7-fjrx-p6mg
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <=1.1.5
│ │
│ ├─ Tree Versions
│ │ └─ 1.1.5
│ │
│ └─ Dependents
│ └─ @solana/buffer-layout-utils@npm:0.2.0

├─ decode-uri-component
│ ├─ ID: 1147955
│ ├─ Issue: decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
│ ├─ URL: https://github.com/advisories/GHSA-vcc3-ghjq-m6fr
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <=0.4.2
│ │
│ ├─ Tree Versions
│ │ └─ 0.2.2
│ │
│ └─ Dependents
│ └─ source-map-resolve@npm:0.6.0

├─ electron
│ ├─ ID: 1094578
│ ├─ Issue: Electron vulnerable to out-of-package code execution when launched with arbitrary cwd
│ ├─ URL: https://github.com/advisories/GHSA-7x97-j373-85x5
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: >=23.0.0-alpha.1 <23.3.13
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1099652
│ ├─ Issue: ASAR Integrity bypass via filetype confusion in electron
│ ├─ URL: https://github.com/advisories/GHSA-7m48-wc93-9g85
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: >=23.0.0-alpha.1 <=23.3.13
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1105820
│ ├─ Issue: Electron vulnerable to Heap Buffer Overflow in NativeImage
│ ├─ URL: https://github.com/advisories/GHSA-6r2x-8pq8-9489
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <28.3.2
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1107272
│ ├─ Issue: Electron has ASAR Integrity Bypass via resource modification
│ ├─ URL: https://github.com/advisories/GHSA-vmqv-hx8q-j7mg
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <35.7.5
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116041
│ ├─ Issue: Electron: AppleScript injection in app.moveToApplicationsFolder on macOS
│ ├─ URL: https://github.com/advisories/GHSA-5rqw-r77c-jp79
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116045
│ ├─ Issue: Electron: Service worker can spoof executeJavaScript IPC replies
│ ├─ URL: https://github.com/advisories/GHSA-xj5x-m3f3-5x3h
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116049
│ ├─ Issue: Electron: Incorrect origin passed to permission request handler for iframe requests
│ ├─ URL: https://github.com/advisories/GHSA-r5p7-gp4j-qhrx
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116053
│ ├─ Issue: Electron: Out-of-bounds read in second-instance IPC on macOS and Linux
│ ├─ URL: https://github.com/advisories/GHSA-3c8v-cfp5-9885
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116057
│ ├─ Issue: Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
│ ├─ URL: https://github.com/advisories/GHSA-xwr5-m59h-vwqr
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116060
│ ├─ Issue: Electron: Use-after-free in offscreen child window paint callback
│ ├─ URL: https://github.com/advisories/GHSA-532v-xpq5-8h95
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <39.8.1
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116064
│ ├─ Issue: Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
│ ├─ URL: https://github.com/advisories/GHSA-mwmh-mq4g-g6gr
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116068
│ ├─ Issue: Electron: Use-after-free in download save dialog callback
│ ├─ URL: https://github.com/advisories/GHSA-9w97-2464-8783
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116072
│ ├─ Issue: Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
│ ├─ URL: https://github.com/advisories/GHSA-8337-3p73-46f4
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116076
│ ├─ Issue: Electron: Use-after-free in PowerMonitor on Windows and macOS
│ ├─ URL: https://github.com/advisories/GHSA-jjp3-mq3x-295m
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116084
│ ├─ Issue: Electron: Unquoted executable path in app.setLoginItemSettings on Windows
│ ├─ URL: https://github.com/advisories/GHSA-jfqx-fxh3-c62j
│ ├─ Severity: low
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116088
│ ├─ Issue: Electron: HTTP Response Header Injection in custom protocol handlers and webRequest
│ ├─ URL: https://github.com/advisories/GHSA-4p4r-m79c-wq3v
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116092
│ ├─ Issue: Electron: USB device selection not validated against filtered device list
│ ├─ URL: https://github.com/advisories/GHSA-9899-m83m-qhpj
│ ├─ Severity: low
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116259
│ ├─ Issue: Electron: Crash in clipboard.readImage() on malformed clipboard image data
│ ├─ URL: https://github.com/advisories/GHSA-f37v-82c4-4x64
│ ├─ Severity: low
│ ├─ Vulnerable Versions: <39.8.5
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1116320
│ ├─ Issue: Electron: Named window.open targets not scoped to the opener's browsing context
│ ├─ URL: https://github.com/advisories/GHSA-f3pv-wv63-48x8
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.5
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1117459
│ ├─ Issue: Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
│ ├─ URL: https://github.com/advisories/GHSA-9wfr-w7mm-pc7f
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <38.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136551
│ ├─ Issue: Electron: Parent process code-sign check is spoofable
│ ├─ URL: https://github.com/advisories/GHSA-jm7p-cc5g-qwxx
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.8
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136552
│ ├─ Issue: Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
│ ├─ URL: https://github.com/advisories/GHSA-v3j7-r9gq-3gjw
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <39.8.10
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136559
│ ├─ Issue: Electron: Extension tab APIs operate across session boundaries
│ ├─ URL: https://github.com/advisories/GHSA-m55f-7gqj-fr98
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.8
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136560
│ ├─ Issue: Electron: shell.openPath path validation bypass via embedded null byte
│ ├─ URL: https://github.com/advisories/GHSA-5c9j-mhmv-5xgx
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136567
│ ├─ Issue: Electron: Context isolation bypass via Function.prototype.bind hijack
│ ├─ URL: https://github.com/advisories/GHSA-h7rp-cf8h-j98x
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <39.8.9
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136571
│ ├─ Issue: Electron: Cross-origin iframe can position native autofill popup
│ ├─ URL: https://github.com/advisories/GHSA-x8rc-wpg4-grpf
│ ├─ Severity: low
│ ├─ Vulnerable Versions: <39.8.8
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136575
│ ├─ Issue: Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
│ ├─ URL: https://github.com/advisories/GHSA-9pf5-hg6p-4pwp
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.7
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136579
│ ├─ Issue: Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
│ ├─ URL: https://github.com/advisories/GHSA-pfmc-3mgc-p6fp
│ ├─ Severity: low
│ ├─ Vulnerable Versions: <39.8.10
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136590
│ ├─ Issue: Electron: HTTP redirect followed into local file loader
│ ├─ URL: https://github.com/advisories/GHSA-v64r-4m7r-3mvq
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.8
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136597
│ ├─ Issue: Electron: window.open features string controls some window options considered privileged
│ ├─ URL: https://github.com/advisories/GHSA-v93f-fgjr-hjrj
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.8
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136607
│ ├─ Issue: Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
│ ├─ URL: https://github.com/advisories/GHSA-9f4c-93c8-jc8g
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <39.8.10
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136634
│ ├─ Issue: Electron: Sandboxed iframes can launch external protocol handlers
│ ├─ URL: https://github.com/advisories/GHSA-p2rr-rvmm-c5fp
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.8
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136647
│ ├─ Issue: Electron: DevTools embedder handler executes arbitrary files via shell open
│ ├─ URL: https://github.com/advisories/GHSA-f2r8-jv7c-xqmp
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.9
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136651
│ ├─ Issue: Electron: contextBridge object copy honors prototype setters
│ ├─ URL: https://github.com/advisories/GHSA-ff2p-hmqr-hxm4
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.9
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136659
│ ├─ Issue: Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
│ ├─ URL: https://github.com/advisories/GHSA-4f78-qhmw-8j8m
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.7
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ extract-zip
│ ├─ ID: 1139346
│ ├─ Issue: extract-zip unvalidated symlink path traversal
│ ├─ URL: https://github.com/advisories/GHSA-jmr9-qjv8-65gv
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <=2.0.1
│ │
│ ├─ Tree Versions
│ │ └─ 2.0.1
│ │
│ └─ Dependents
│ └─ electron@npm:23.3.0

├─ got
│ ├─ ID: 1088948
│ ├─ Issue: Got allows a redirect to a UNIX socket
│ ├─ URL: https://github.com/advisories/GHSA-pfrx-2q88-qq97
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <11.8.5
│ │
│ ├─ Tree Versions
│ │ ├─ 6.7.1
│ │ └─ 9.6.0
│ │
│ └─ Dependents
│ ├─ package-json@npm:4.0.1
│ └─ package-json@npm:6.5.0

├─ image-size
│ ├─ ID: 1138808
│ ├─ Issue: image-size: ICNS parser allows denial of service through an infinite loop
│ ├─ URL: https://github.com/advisories/GHSA-w3rx-r6r6-pgpr
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <=2.0.2
│ │
│ ├─ Tree Versions
│ │ └─ 2.0.2
│ │
│ └─ Dependents
│ └─ addons-linter@npm:9.8.0

├─ image-size
│ ├─ ID: 1138809
│ ├─ Issue: image-size: JXL and HEIF parsers allow denial of service through infinite loops
│ ├─ URL: https://github.com/advisories/GHSA-5p2g-fcmc-qvqq
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <=2.0.2
│ │
│ ├─ Tree Versions
│ │ └─ 2.0.2
│ │
│ └─ Dependents
│ └─ addons-linter@npm:9.8.0

├─ ip
│ ├─ ID: 1101851
│ ├─ Issue: ip SSRF improper categorization in isPublic
│ ├─ URL: https://github.com/advisories/GHSA-2p57-rm9w-gvfp
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <=2.0.1
│ │
│ ├─ Tree Versions
│ │ └─ 1.1.8
│ │
│ └─ Dependents
│ └─ pac-resolver@npm:7.0.0

├─ ip
│ ├─ ID: 1114831
│ ├─ Issue: NPM IP package incorrectly identifies some private IP addresses as public
│ ├─ URL: https://github.com/advisories/GHSA-78xj-cgh5-2h22
│ ├─ Severity: low
│ ├─ Vulnerable Versions: <1.1.9
│ │
│ ├─ Tree Versions
│ │ └─ 1.1.8
│ │
│ └─ Dependents
│ └─ pac-resolver@npm:7.0.0

├─ nanoid
│ ├─ ID: 1109563
│ ├─ Issue: Predictable results in nanoid generation when given non-integer values
│ ├─ URL: https://github.com/advisories/GHSA-mwcw-c2x4-8c55
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <3.3.8
│ │
│ ├─ Tree Versions
│ │ └─ 2.1.11
│ │
│ └─ Dependents
│ └─ redux-devtools-core@npm:0.2.1

├─ nanoid
│ ├─ ID: 1138811
│ ├─ Issue: nanoid: non-secure generators can loop indefinitely with negative size
│ ├─ URL: https://github.com/advisories/GHSA-28wg-ghj8-5hjv
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <3.3.16
│ │
│ ├─ Tree Versions
│ │ └─ 2.1.11
│ │
│ └─ Dependents
│ └─ redux-devtools-core@npm:0.2.1

├─ nanoid
│ ├─ ID: 1139427
│ ├─ Issue: nanoid: custom generators can loop indefinitely when size is zero
│ ├─ URL: https://github.com/advisories/GHSA-2v37-7h3g-55p8
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <3.3.18
│ │
│ ├─ Tree Versions
│ │ └─ 2.1.11
│ │
│ └─ Dependents
│ └─ redux-devtools-core@npm:0.2.1

├─ nanoid
│ ├─ ID: 1153189
│ ├─ Issue: nanoid: Integer Overflow or Wraparound
│ ├─ URL: https://github.com/advisories/GHSA-xwg4-73v4-xw9w
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <3.3.12
│ │
│ ├─ Tree Versions
│ │ └─ 2.1.11
│ │
│ └─ Dependents
│ └─ redux-devtools-core@npm:0.2.1

├─ postcss
│ ├─ ID: 1109574
│ ├─ Issue: PostCSS line return parsing error
│ ├─ URL: https://github.com/advisories/GHSA-7fh5-64p2-3v2j
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <8.4.31
│ │
│ ├─ Tree Versions
│ │ └─ 7.0.39
│ │
│ └─ Dependents
│ └─ resolve-url-loader@npm:3.1.5

├─ postcss
│ ├─ ID: 1117015
│ ├─ Issue: PostCSS has XSS via Unescaped in its CSS Stringify Output
│ ├─ URL: https://github.com/advisories/GHSA-qx2v-qp2m-jg93
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <8.5.10
│ │
│ ├─ Tree Versions
│ │ └─ 7.0.39
│ │
│ └─ Dependents
│ └─ resolve-url-loader@npm:3.1.5

├─ postcss
│ ├─ ID: 1124252
│ ├─ Issue: PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
│ ├─ URL: https://github.com/advisories/GHSA-6g55-p6wh-862q
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <=8.5.11
│ │
│ ├─ Tree Versions
│ │ └─ 7.0.39
│ │
│ └─ Dependents
│ └─ resolve-url-loader@npm:3.1.5

├─ postcss
│ ├─ ID: 1130709
│ ├─ Issue: PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset
│ ├─ URL: https://github.com/advisories/GHSA-fxqj-rqcc-2cmp
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <=8.5.22
│ │
│ ├─ Tree Versions
│ │ └─ 7.0.39
│ │
│ └─ Dependents
│ └─ resolve-url-loader@npm:3.1.5

├─ postcss
│ ├─ ID: 1139510
│ ├─ Issue: PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
│ ├─ URL: https://github.com/advisories/GHSA-r28c-9q8g-f849
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <=8.5.17
│ │
│ ├─ Tree Versions
│ │ └─ 7.0.39
│ │
│ └─ Dependents
│ └─ resolve-url-loader@npm:3.1.5

├─ stream-json
│ ├─ ID: 1164823
│ ├─ Issue: stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)
│ ├─ URL: https://github.com/advisories/GHSA-528h-pc64-c93x
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <=3.4.0
│ │
│ ├─ Tree Versions
│ │ └─ 1.9.1
│ │
│ └─ Dependents
│ └─ jayson@npm:4.2.0

```

Contributor guide

Open the contributing guide

Research direction

Start with the linked CI run and the Native audit tree to trace the 54 advisories through their dependent packages. Determine which dependency updates or resolutions are possible and verify the audit result again; done means the newly detected advisories are addressed or explicitly explained, with no release-blocking advisories remaining.

Written by the indexing model from the issue text.

Assessment

Tech stack
electron, github-actions, typescript
Domain
ci-cd, devtools, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.