github / github/local-action

Security: transitive undici@5.29.0 vulnerabilities via @github/local-action@7.0.1

Open
#295 0 comments 2 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
451
Forks
28
PR merge metrics
No merged PRs in 30d

Description

## Summary

`@github/local-action@7.0.1` pulls in a vulnerable `undici@5.29.0` through several `@actions/*` dependencies. Snyk reports **10 transitive issues** (Risk Score MAX **170**), of which **9 have no supported fix** in the current dependency tree (0 fixable via a direct bump).

All high-severity findings trace back to a single package: **`undici@5.29.0`**.

## Affected package

- **Direct dependency:** `@github/local-action@7.0.1`
- **Vulnerable transitive package:** `undici@5.29.0`
- **Fixed in:** `undici@6.24.0`, `undici@7.24.0`

## Vulnerabilities

| Issue | CWE | CVE | CVSS | Snyk ID |
|-------|-----|-----|------|---------|
| Uncaught Exception | [CWE-248](https://cwe.mitre.org/data/definitions/248.html) | CVE-2026-2229 | 8.7 (High) | SNYK-JS-UNDICI-15518070 |
| CRLF Injection | [CWE-93](https://cwe.mitre.org/data/definitions/93.html) | — | 9.2 (Critical) | — |
| Permissive List of Allowed Inputs | [CWE-183](https://cwe.mitre.org/data/definitions/183.html) | — | 8.3 (High) | — |

Contributor guide

Open the contributing guide

Research direction

Start by inspecting the repository's dependency manifests and lockfile to trace how @github/local-action@7.0.1 brings in undici@5.29.0. Determine whether an available dependency update or other supported resolution removes the reported vulnerabilities, then rerun the project's dependency security scan and confirm the findings are addressed.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
devops, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.