danielgtaylor / danielgtaylor/aglio
Vulnerabilities! Even Critical!
- Dominant language
- CoffeeScript
- Stars
- 4.7k
- Forks
- 471
- PR merge metrics
- No merged PRs in 30d
Description
Critical Sandbox Bypass Leading to Arbitrary Code Execution
Package constantinople
Patched in >=3.1.1
Dependency of aglio [dev]
Path aglio > aglio-theme-olio > jade > constantinople
More info https://nodesecurity.io/advisories/568
Moderate Prototype Pollution
Package hoek
Patched in > 4.2.0 < 5.0.0 || >= 5.0.3
Dependency of aglio [dev]
Path aglio > aglio-theme-olio > less > request > hawk > sntp > hoek
More info https://nodesecurity.io/advisories/566
Moderate Prototype Pollution
Package hoek
Patched in > 4.2.0 < 5.0.0 || >= 5.0.3
Dependency of aglio [dev]
Path aglio > aglio-theme-olio > less > request > hawk > hoek
More info https://nodesecurity.io/advisories/566
Moderate Prototype Pollution
Package hoek
Patched in > 4.2.0 < 5.0.0 || >= 5.0.3
Dependency of aglio [dev]
Path aglio > aglio-theme-olio > less > request > hawk > cryptiles > boom > hoek
More info https://nodesecurity.io/advisories/566
etc.
Contributor guide
No contributing guide indexed for this repository
Research direction
Review the dependency paths and advisory links in the issue, beginning with the project’s dependency declarations and the affected aglio-theme-olio, jade, less, request, hawk, sntp, cryptiles, boom, and hoek chain. Confirm which installed versions are vulnerable, update to patched versions where compatible, and verify that the dependency audit no longer reports these advisories.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- node.js
- Domain
- security, tooling
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100