danielgtaylor / danielgtaylor/aglio

Vulnerabilities! Even Critical!

Open
#367 2 comments 1 reaction 0 assignees View on GitHub
Dominant language
CoffeeScript
Stars
4.7k
Forks
471
PR merge metrics
No merged PRs in 30d

Description

Critical Sandbox Bypass Leading to Arbitrary Code Execution
Package constantinople
Patched in >=3.1.1
Dependency of aglio [dev]
Path aglio > aglio-theme-olio > jade > constantinople
More info https://nodesecurity.io/advisories/568

Moderate Prototype Pollution
Package hoek
Patched in > 4.2.0 < 5.0.0 || >= 5.0.3
Dependency of aglio [dev]
Path aglio > aglio-theme-olio > less > request > hawk > sntp > hoek
More info https://nodesecurity.io/advisories/566

Moderate Prototype Pollution
Package hoek
Patched in > 4.2.0 < 5.0.0 || >= 5.0.3
Dependency of aglio [dev]
Path aglio > aglio-theme-olio > less > request > hawk > hoek
More info https://nodesecurity.io/advisories/566

Moderate Prototype Pollution
Package hoek
Patched in > 4.2.0 < 5.0.0 || >= 5.0.3
Dependency of aglio [dev]
Path aglio > aglio-theme-olio > less > request > hawk > cryptiles > boom > hoek
More info https://nodesecurity.io/advisories/566

etc.

Contributor guide

No contributing guide indexed for this repository

Research direction

Review the dependency paths and advisory links in the issue, beginning with the project’s dependency declarations and the affected aglio-theme-olio, jade, less, request, hawk, sntp, cryptiles, boom, and hoek chain. Confirm which installed versions are vulnerable, update to patched versions where compatible, and verify that the dependency audit no longer reports these advisories.

Written by the indexing model from the issue text.

Assessment

Tech stack
node.js
Domain
security, tooling
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.