High-severity npm vulnerabilities reported by pnpm audit
Open
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 21k
- Forks
- 6.8k
- PR merge metrics
- No merged PRs in 30d
Description
Summary
- \┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Playwright downloads and installs browsers without │
│ │ verifying the authenticity of the SSL certificate │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ playwright │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <1.55.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.55.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/analytics@1.5.0 > next@16.0.10 > │
│ │ @playwright/test@1.51.0 > playwright@1.51.0 │
│ │ │
│ │ . > geist@1.3.1 > next@16.0.10 > │
│ │ @playwright/test@1.51.0 > playwright@1.51.0 │
│ │ │
│ │ . > next@16.0.10 > @playwright/test@1.51.0 > │
│ │ playwright@1.51.0 │
│ │ │
│ │ ... Found 5 paths, runpnpm why playwrightfor more │
│ │ information │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-7mvr-c777-76hp │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Next.js HTTP request deserialization can lead to DoS │
│ │ when using insecure React Server Components │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=16.0.0-beta.0 <16.0.11 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=16.0.11 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/analytics@1.5.0 > next@16.0.10 │
│ │ │
│ │ . > geist@1.3.1 > next@16.0.10 │
│ │ │
│ │ . > next@16.0.10 │
│ │ │
│ │ ... Found 4 paths, runpnpm why nextfor more │
│ │ information │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-h25m-26qc-wcjf │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ @isaacs/brace-expansion has Uncontrolled Resource │
│ │ Consumption │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ @isaacs/brace-expansion │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=5.0.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=5.0.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > ultracite@7.0.11 > glob@13.0.0 > minimatch@10.1.1 │
│ │ > @isaacs/brace-expansion@5.0.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-7h2j-956f-4vf2 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ minimatch has a ReDoS via repeated wildcards with │
│ │ non-matching literal in pattern │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ minimatch │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=10.0.0 <10.2.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=10.2.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > ultracite@7.0.11 > glob@13.0.0 > minimatch@10.1.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-3ppc-4f35-3m26 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ minimatch has ReDoS: matchOne() combinatorial │
│ │ backtracking via multiple non-adjacent GLOBSTAR │
│ │ segments │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ minimatch │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=10.0.0 <10.2.3 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=10.2.3 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > ultracite@7.0.11 > glob@13.0.0 > minimatch@10.1.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-7r86-cg39-jmmj │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ minimatch ReDoS: nested *() extglobs generate │
│ │ catastrophically backtracking regular expressions │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ minimatch │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=10.0.0 <10.2.3 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=10.2.3 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > ultracite@7.0.11 > glob@13.0.0 > minimatch@10.1.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-23c5-xmqv-rm74 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Undici has Unbounded Memory Consumption in WebSocket │
│ │ permessage-deflate Decompression │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ undici │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <6.24.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=6.24.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/blob@0.24.1 > undici@5.28.5 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-vrm6-8vpv-qv8q │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Undici has Unhandled Exception in WebSocket Client Due │
│ │ to Invalid server_max_window_bits Validation │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ undici │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <6.24.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=6.24.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/blob@0.24.1 > undici@5.28.5 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-v9p9-hfj2-hcw8 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ esbuild enables any website to send any requests to │
│ │ the development server and read the response │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ esbuild │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=0.24.2 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=0.25.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > drizzle-kit@0.25.0 > @esbuild-kit/esm-loader@2.6.5 │
│ │ > @esbuild-kit/core-utils@3.3.2 > esbuild@0.18.20 │
│ │ │
│ │ . > drizzle-kit@0.25.0 > esbuild@0.19.12 │
│ │ │
│ │ . > drizzle-kit@0.25.0 > esbuild-register@3.6.0 > │
│ │ esbuild@0.19.12 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-67mh-4wv8-2f99 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ PrismJS DOM Clobbering vulnerability │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ prismjs │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <1.30.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.30.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > react-syntax-highlighter@15.6.6 > refractor@3.6.0 │
│ │ > prismjs@1.27.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-x7hr-w5r2-h6wg │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ NextAuthjs Email misdelivery Vulnerability │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next-auth │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=5.0.0-beta.0 <5.0.0-beta.30 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=5.0.0-beta.30 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > next-auth@5.0.0-beta.25 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-5jpx-9hw9-2fx4 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ Undici has an unbounded decompression chain in HTTP │
│ │ responses on Node.js Fetch API via Content-Encoding │
│ │ leads to resource exhaustion │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ undici │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <6.23.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=6.23.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/blob@0.24.1 > undici@5.28.5 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-g9mf-h72j-4rw9 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ Next.js self-hosted applications vulnerable to DoS via │
│ │ Image Optimizer remotePatterns configuration │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=15.6.0-canary.0 <16.1.5 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=16.1.5 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/analytics@1.5.0 > next@16.0.10 │
│ │ │
│ │ . > geist@1.3.1 > next@16.0.10 │
│ │ │
│ │ . > next@16.0.10 │
│ │ │
│ │ ... Found 4 paths, runpnpm why nextfor more │
│ │ information │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-9g9p-9gw9-jx7f │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ Next.js has Unbounded Memory Consumption via PPR │
│ │ Resume Endpoint │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=16.0.0-beta.0 <16.1.5 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=16.1.5 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/analytics@1.5.0 > next@16.0.10 │
│ │ │
│ │ . > geist@1.3.1 > next@16.0.10 │
│ │ │
│ │ . > next@16.0.10 │
│ │ │
│ │ ... Found 4 paths, runpnpm why nextfor more │
│ │ information │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-5f7q-jpqc-wp7h │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ mdast-util-to-hast has unsanitized class attribute │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ mdast-util-to-hast │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.0.0 <13.2.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=13.2.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > shiki@3.21.0 > @shikijs/core@3.21.0 > │
│ │ hast-util-to-html@9.0.5 > mdast-util-to-hast@13.2.0 │
│ │ │
│ │ . > streamdown@2.0.1 > rehype-raw@7.0.0 > │
│ │ hast-util-raw@9.1.0 > mdast-util-to-hast@13.2.0 │
│ │ │
│ │ . > streamdown@2.0.1 > remark-rehype@11.1.2 > │
│ │ mdast-util-to-hast@13.2.0 │
│ │ │
│ │ ... Found 4 paths, runpnpm why mdast-util-to-hast│
│ │ for more information │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-4fh9-h7wg-q85m │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ markdown-it is has a Regular Expression Denial of │
│ │ Service (ReDoS) │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ markdown-it │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.0.0 <14.1.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=14.1.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > prosemirror-markdown@1.13.1 > markdown-it@14.1.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-38c4-r59v-3vqw │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ Undici has an HTTP Request/Response Smuggling issue │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ undici │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <6.24.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=6.24.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/blob@0.24.1 > undici@5.28.5 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-2mjp-6q6p-2qxm │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ Undici has CRLF Injection in undici viaupgrade│
│ │ option │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ undici │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <6.24.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=6.24.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/blob@0.24.1 > undici@5.28.5 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-4992-7rv2-5pvq │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ Next.js: HTTP request smuggling in rewrites │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=16.0.0-beta.0 <16.1.7 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=16.1.7 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/analytics@1.5.0 > next@16.0.10 │
│ │ │
│ │ . > geist@1.3.1 > next@16.0.10 │
│ │ │
│ │ . > next@16.0.10 │
│ │ │
│ │ ... Found 4 paths, runpnpm why nextfor more │
│ │ information │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-ggv3-7p47-pfv8 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ Next.js: Unbounded next/image disk cache growth can │
│ │ exhaust storage │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=16.0.0-beta.0 <16.1.7 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=16.1.7 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/analytics@1.5.0 > next@16.0.10 │
│ │ │
│ │ . > geist@1.3.1 > next@16.0.10 │
│ │ │
│ │ . > next@16.0.10 │
│ │ │
│ │ ... Found 4 paths, runpnpm why nextfor more │
│ │ information │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-3x4c-7xq6-9pq8 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ Next.js: Unbounded postponed resume buffering can lead │
│ │ to DoS │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=16.0.1 <16.1.7 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=16.1.7 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/analytics@1.5.0 > next@16.0.10 │
│ │ │
│ │ . > geist@1.3.1 > next@16.0.10 │
│ │ │
│ │ . > next@16.0.10 │
│ │ │
│ │ ... Found 4 paths, runpnpm why nextfor more │
│ │ information │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-h27x-g6w4-24gq │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ Next.js: null origin can bypass Server Actions CSRF │
│ │ checks │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=16.0.1 <16.1.7 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=16.1.7 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/analytics@1.5.0 > next@16.0.10 │
│ │ │
│ │ . > geist@1.3.1 > next@16.0.10 │
│ │ │
│ │ . > next@16.0.10 │
│ │ │
│ │ ... Found 4 paths, runpnpm why nextfor more │
│ │ information │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-mq59-m269-xvcx │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ low │ undici Denial of Service attack via bad certificate │
│ │ data │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ undici │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <5.29.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=5.29.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/blob@0.24.1 > undici@5.28.5 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-cxrh-j4jr-qwg3 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ low │ Next.js: null origin can bypass dev HMR websocket CSRF │
│ │ checks │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=16.0.1 <16.1.7 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=16.1.7 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ . > @vercel/analytics@1.5.0 > next@16.0.10 │
│ │ │
│ │ . > geist@1.3.1 > next@16.0.10 │
│ │ │
│ │ . > next@16.0.10 │
│ │ │
│ │ ... Found 4 paths, runpnpm why nextfor more │
│ │ information │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-jcc7-9wpm-mj36 │
└─────────────────────┴────────────────────────────────────────────────────────┘
25 vulnerabilities found
Severity: 2 low | 15 moderate | 8 high (2026-03-29) reports 25 vulnerabilities, including 8 high severity findings affecting Playwright, Next.js, @isaacs/brace-expansion, minimatch, and undici. - High severity advisories: GHSA-7mvr-c777-76hp, GHSA-h25m-26qc-wcjf, GHSA-7h2j-956f-4vf2, GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj, GHSA-23c5-xmqv-rm74, GHSA-vrm6-8vpv-qv8q, GHSA-v9p9-hfj2-hcw8.
- They come via @vercel/analytics + geist (Next + Playwright) and @vercel/blob / ultracite (undici/minimatch).
Repro
- cd vercel-ai-chatbot
- pnpm install
- pnpm audit
Recommended actions
- Upgrade Next / @vercel/analytics / geist to a release that depends on Next >=16.0.11 (preferably >=16.1.7) and @playwright/test >=1.55.1 so Playwright pulls in 1.55.1 or later.
- Bump undici to >=6.24.0 (e.g., via @vercel/blob or another direct consumer that currently provides 5.28.5).
- Resolve the @isaacs/brace-expansion / minimatch chain by bumping glob / ultracite so brace-expansion >=5.0.1 and minimatch >=10.2.3 are used in the tree.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by running pnpm audit and the suggested pnpm why playwright and pnpm why next commands to trace the vulnerable dependency paths. Review the dependency manifests and lockfile involved in those paths, then verify that all listed high-severity advisories resolve to patched versions when pnpm audit is run again.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- nextjs, playwright, typescript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 45/100