nodejs / nodejs/nodejs-dependency-vuln-assessments
jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch
Open
Nobody has claimed this yet.
dont-believe-affects-nodejs
- Dominant language
- Python
- Stars
- 22
- Forks
- 7
- PR merge metrics
- No merged PRs in 30d
Description
Version
v22.19.0
Platform
Subsystem
No response
What steps will reproduce the bug?
It seems NodeJS v22.19.0 includes vulnerability
/usr/lib/node_modules/npm/node_modules/diff
https://github.com/advisories/GHSA-73rr-hh4g-fpgx
How often does it reproduce? Is there a required condition?
Scanner
What is the expected behavior? Why is that the expected behavior?
No security
What do you see instead?
Additional information
No response
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading the linked GHSA advisory and checking the reported Node.js npm dependency path for the affected jsdiff version. The issue provides no reproduction or repository file to change, so done would require confirming the vulnerability's relevance and identifying the repository's required remediation or assessment outcome.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, node.js
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100