microsoft / microsoft/react-native-windows

[0.81][0.80][0.79]Component Governance critical alert Upgrade js-yaml from 4.1.0 to 4.1.1

Open
#15,458 0 comments 0 reactions 1 assignee View on GitHub

@HariniMalothu17 is already working on this.

Since Dec 8, 2025.

bug security
Dominant language
C++
Stars
17.3k
Forks
1.2k
Avg merge
1d 13h
Merged PRs (30d)
33

Description

Impact
In js-yaml 4.1.0, 4.0.0, and 3.14.1 and below, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (proto). All users who parse untrusted yaml documents may be impacted.

Patches
Problem is patched in js-yaml 4.1.1 and 3.14.2.

Workarounds
You can protect against this kind of attack on the server by using node --disable-proto=delete or deno (in Deno, pollution protection is on by default).
Recommendation
Upgrade js-yaml from 4.1.0 to 4.1.1 to fix the vulnerability.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.