Skip to content

[Snyk] Fix for 92 vulnerabilities - #1

Open
snyk-io-eu[bot] wants to merge 1 commit into
trunkfrom
snyk-fix-2b793b58f61a41cea88d69b5811b1955
Open

[Snyk] Fix for 92 vulnerabilities#1
snyk-io-eu[bot] wants to merge 1 commit into
trunkfrom
snyk-fix-2b793b58f61a41cea88d69b5811b1955

Conversation

@snyk-io-eu

@snyk-io-eu snyk-io-eu Bot commented Apr 16, 2026

Copy link
Copy Markdown

snyk-top-banner

Snyk has created this PR to fix 92 vulnerabilities in the yarn dependencies of this project.

Snyk changed the following file(s):

  • packages/client/package.json

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

⚠️ Warning
Failed to update the yarn.lock, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-SERIALIZEJAVASCRIPT-15809196
  ****  
high severity Arbitrary Code Injection
SNYK-JS-SERIALIZEJAVASCRIPT-570062
  ****  
medium severity Cross-site Scripting (XSS)
SNYK-JS-SERIALIZEJAVASCRIPT-6147607
  ****  
high severity Remote Code Execution (RCE)
SNYK-JS-SHELLQUOTE-1766506
  ****  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-TERSER-2806366
  ****  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-TMPL-1583443
  ****  
medium severity Incorrect Control Flow Scoping
SNYK-JS-TOOTALLNATEONCE-15250612
  ****  
medium severity Prototype Pollution
SNYK-JS-TOUGHCOOKIE-5672873
  ****  
high severity Denial of Service (DoS)
SNYK-JS-TRIMNEWLINES-1298042
  ****  
high severity Prototype Pollution
SNYK-JS-UNSETVALUE-2400660
  ****  
medium severity Cross-site Scripting (XSS)
SNYK-JS-WEBPACK-7840298
  ****  
high severity Path Traversal
SNYK-JS-WEBPACKDEVMIDDLEWARE-6476555
  ****  
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-WORDWRAP-3149973
  ****  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-WS-1296835
  ****  
high severity Denial of Service (DoS)
SNYK-JS-WS-7266574
  ****  
medium severity Uncontrolled Recursion
SNYK-JS-YAML-15765520
  ****  
critical severity Improper Certificate Validation
SNYK-JS-NODEFORGE-15789771
  848  
high severity Improper Verification of Cryptographic Signature
SNYK-JS-NODEFORGE-15789767
  828  
high severity Infinite loop
SNYK-JS-NODEFORGE-15789769
  828  
high severity Improper Verification of Cryptographic Signature
SNYK-JS-NODEFORGE-15789773
  828  
critical severity Predictable Value Range from Previous Values
SNYK-JS-FORMDATA-10841150
  791  
critical severity Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962462
  786  
critical severity Prototype Pollution
SNYK-JS-FLATTED-15700433
  786  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CROSSSPAWN-8303230
  756  
high severity Uncontrolled Recursion
SNYK-JS-FLATTED-15518041
  756  
high severity Denial of Service (DoS)
SNYK-JS-HTTPPROXYMIDDLEWARE-8229906
  756  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-15309438
  756  
high severity Inefficient Algorithmic Complexity
SNYK-JS-MINIMATCH-15353389
  756  
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-QS-14724253
  756  
high severity Prototype Pollution
SNYK-JS-PROTOBUFJS-5756498
  751  
high severity Directory Traversal
SNYK-JS-ROLLUP-15340920
  746  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-AJV-15274295
  731  
high severity Prototype Pollution
SNYK-JS-PROTOBUFJS-2441248
  731  
high severity Remote Code Execution (RCE)
SNYK-JS-EJS-2803307
  726  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PICOMATCH-15765511
  721  
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-12704893
  716  
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-12761655
  716  
high severity Arbitrary Code Injection
SNYK-JS-LODASH-15869625
  716  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIHTML-1296849
  696  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
  696  
high severity Prototype Pollution
SNYK-JS-ASYNC-2441827
  696  
high severity Excessive Platform Resource Consumption within a Loop
SNYK-JS-BRACES-6838727
  696  
high severity Denial of Service (DoS)
SNYK-JS-DECODEURICOMPONENT-3149970
  696  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MOMENT-2944238
  696  
high severity Prototype Poisoning
SNYK-JS-QS-3153490
  696  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
  696  
high severity Code Injection
SNYK-JS-LODASHTEMPLATE-1088054
  681  
critical severity Interpretation Conflict
SNYK-JS-NODEFORGE-14114940
  679  
high severity Cross-site Request Forgery (CSRF)
SNYK-JS-AXIOS-6032459
  676  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BABELRUNTIME-10044504
  666  
medium severity Infinite loop
SNYK-JS-BNJS-15274301
  666  
high severity Uncontrolled Recursion
SNYK-JS-NODEFORGE-14125745
  649  
medium severity Server-Side Request Forgery (SSRF)
SNYK-JS-IP-7148531
  646  
medium severity Server-side Request Forgery (SSRF)
SNYK-JS-REQUEST-3361831
  646  
high severity Prototype Pollution
SNYK-JS-JSONSCHEMA-1920922
  644  
medium severity Prototype Pollution
SNYK-JS-JSON5-3182856
  641  
medium severity Cross-site Scripting (XSS)
SNYK-JS-APEXCHARTS-1300579
  636  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-DIFF-14917201
  636  
medium severity Use of a Cryptographic Primitive with a Risky Implementation
SNYK-JS-ELLIPTIC-14908844
  636  
medium severity Prototype Pollution
SNYK-JS-LODASH-15869619
  631  
medium severity Prototype Pollution
SNYK-JS-PICOMATCH-15765513
  631  
high severity Improper Verification of Cryptographic Signature
SNYK-JS-JWS-14188253
  624  
medium severity Prototype Pollution
SNYK-JS-IMMER-1540542
  601  
high severity Prototype Pollution
SNYK-JS-LOADERUTILS-3043105
  589  
high severity Directory Traversal
SNYK-JS-MOMENT-2440688
  589  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BROWSERSLIST-1090194
  586  
medium severity Improper Control of Dynamically-Managed Code Resources
SNYK-JS-EJS-6689533
  586  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
  586  
medium severity Open Redirect
SNYK-JS-NODEFORGE-2330875
  586  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHPARSE-1077067
  586  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PROMPTS-1729737
  586  
high severity Improper Verification of Cryptographic Signature
SNYK-JS-NODEFORGE-2430339
  579  
medium severity Cross-site Scripting (XSS)
SNYK-JS-ROLLUP-8073097
  576  
medium severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JS-GRPCGRPCJS-7242922
  559  
medium severity Prototype Pollution
SNYK-JS-JSYAML-13961110
  559  
medium severity Prototype Pollution
SNYK-JS-LODASH-15053838
  559  
medium severity Uncontrolled Recursion
SNYK-JS-ESLINT-15102420
  551  
medium severity Information Exposure
SNYK-JS-NODEFETCH-2342118
  539  
medium severity Integer Overflow or Wraparound
SNYK-JS-NODEFORGE-14125097
  529  
medium severity Prototype Pollution
SNYK-JS-NODEFORGE-2331908
  529  
medium severity Arbitrary Code Injection
SNYK-JS-EJS-1049328
  526  
medium severity Denial of Service (DoS)
SNYK-JS-NWSAPI-2841516
  524  
low severity Prototype Pollution
SNYK-JS-MINIMIST-2429795
  506  
medium severity Improper Verification of Cryptographic Signature
SNYK-JS-NODEFORGE-2430337
  494  
medium severity Improper Verification of Cryptographic Signature
SNYK-JS-NODEFORGE-2430341
  494  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-RAMDA-1582370
  490  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3042992
  479  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3105943
  479  
medium severity Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
  479  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
  479  
medium severity Improper Input Validation
SNYK-JS-POSTCSS-5926692
  479  
medium severity Reverse Tabnabbing
SNYK-JS-ISTANBULREPORTS-2328088
  429  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)
🦉 Cross-site Scripting (XSS)
🦉 Prototype Pollution
🦉 More lessons are available in Snyk Learn

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-SERIALIZEJAVASCRIPT-15809196
- https://snyk.io/vuln/SNYK-JS-SERIALIZEJAVASCRIPT-570062
- https://snyk.io/vuln/SNYK-JS-SERIALIZEJAVASCRIPT-6147607
- https://snyk.io/vuln/SNYK-JS-SHELLQUOTE-1766506
- https://snyk.io/vuln/SNYK-JS-TERSER-2806366
- https://snyk.io/vuln/SNYK-JS-TMPL-1583443
- https://snyk.io/vuln/SNYK-JS-TOOTALLNATEONCE-15250612
- https://snyk.io/vuln/SNYK-JS-TOUGHCOOKIE-5672873
- https://snyk.io/vuln/SNYK-JS-TRIMNEWLINES-1298042
- https://snyk.io/vuln/SNYK-JS-UNSETVALUE-2400660
- https://snyk.io/vuln/SNYK-JS-WEBPACK-7840298
- https://snyk.io/vuln/SNYK-JS-WEBPACKDEVMIDDLEWARE-6476555
- https://snyk.io/vuln/SNYK-JS-WORDWRAP-3149973
- https://snyk.io/vuln/SNYK-JS-WS-1296835
- https://snyk.io/vuln/SNYK-JS-WS-7266574
- https://snyk.io/vuln/SNYK-JS-YAML-15765520
- https://snyk.io/vuln/SNYK-JS-NODEFORGE-15789771
- https://snyk.io/vuln/SNYK-JS-NODEFORGE-15789767
- https://snyk.io/vuln/SNYK-JS-NODEFORGE-15789769
- https://snyk.io/vuln/SNYK-JS-NODEFORGE-15789773
- https://snyk.io/vuln/SNYK-JS-FORMDATA-10841150
- https://snyk.io/vuln/SNYK-JS-BABELTRAVERSE-5962462
- https://snyk.io/vuln/SNYK-JS-FLATTED-15700433
- https://snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230
- https://snyk.io/vuln/SNYK-JS-FLATTED-15518041
- https://snyk.io/vuln/SNYK-JS-HTTPPROXYMIDDLEWARE-8229906
- https://snyk.io/vuln/SNYK-JS-MINIMATCH-15309438
- https://snyk.io/vuln/SNYK-JS-MINIMATCH-15353389
- https://snyk.io/vuln/SNYK-JS-QS-14724253
- https://snyk.io/vuln/SNYK-JS-PROTOBUFJS-5756498
- https://snyk.io/vuln/SNYK-JS-ROLLUP-15340920
- https://snyk.io/vuln/SNYK-JS-AJV-15274295
- https://snyk.io/vuln/SNYK-JS-PROTOBUFJS-2441248
- https://snyk.io/vuln/SNYK-JS-EJS-2803307
- https://snyk.io/vuln/SNYK-JS-PICOMATCH-15765511
- https://snyk.io/vuln/SNYK-JS-IP-12704893
- https://snyk.io/vuln/SNYK-JS-IP-12761655
- https://snyk.io/vuln/SNYK-JS-LODASH-15869625
- https://snyk.io/vuln/SNYK-JS-ANSIHTML-1296849
- https://snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908
- https://snyk.io/vuln/SNYK-JS-ASYNC-2441827
- https://snyk.io/vuln/SNYK-JS-BRACES-6838727
- https://snyk.io/vuln/SNYK-JS-DECODEURICOMPONENT-3149970
- https://snyk.io/vuln/SNYK-JS-MOMENT-2944238
- https://snyk.io/vuln/SNYK-JS-QS-3153490
- https://snyk.io/vuln/SNYK-JS-SEMVER-3247795
- https://snyk.io/vuln/SNYK-JS-LODASHTEMPLATE-1088054
- https://snyk.io/vuln/SNYK-JS-NODEFORGE-14114940
- https://snyk.io/vuln/SNYK-JS-AXIOS-6032459
- https://snyk.io/vuln/SNYK-JS-BABELRUNTIME-10044504
- https://snyk.io/vuln/SNYK-JS-BNJS-15274301
- https://snyk.io/vuln/SNYK-JS-NODEFORGE-14125745
- https://snyk.io/vuln/SNYK-JS-IP-7148531
- https://snyk.io/vuln/SNYK-JS-REQUEST-3361831
- https://snyk.io/vuln/SNYK-JS-JSONSCHEMA-1920922
- https://snyk.io/vuln/SNYK-JS-JSON5-3182856
- https://snyk.io/vuln/SNYK-JS-APEXCHARTS-1300579
- https://snyk.io/vuln/SNYK-JS-DIFF-14917201
- https://snyk.io/vuln/SNYK-JS-ELLIPTIC-14908844
- https://snyk.io/vuln/SNYK-JS-LODASH-15869619
- https://snyk.io/vuln/SNYK-JS-PICOMATCH-15765513
- https://snyk.io/vuln/SNYK-JS-JWS-14188253
- https://snyk.io/vuln/SNYK-JS-IMMER-1540542
- https://snyk.io/vuln/SNYK-JS-LOADERUTILS-3043105
- https://snyk.io/vuln/SNYK-JS-MOMENT-2440688
- https://snyk.io/vuln/SNYK-JS-BROWSERSLIST-1090194
- https://snyk.io/vuln/SNYK-JS-EJS-6689533
- https://snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905
- https://snyk.io/vuln/SNYK-JS-NODEFORGE-2330875
- https://snyk.io/vuln/SNYK-JS-PATHPARSE-1077067
- https://snyk.io/vuln/SNYK-JS-PROMPTS-1729737
- https://snyk.io/vuln/SNYK-JS-NODEFORGE-2430339
- https://snyk.io/vuln/SNYK-JS-ROLLUP-8073097
- https://snyk.io/vuln/SNYK-JS-GRPCGRPCJS-7242922
- https://snyk.io/vuln/SNYK-JS-JSYAML-13961110
- https://snyk.io/vuln/SNYK-JS-LODASH-15053838
- https://snyk.io/vuln/SNYK-JS-ESLINT-15102420
- https://snyk.io/vuln/SNYK-JS-NODEFETCH-2342118
- https://snyk.io/vuln/SNYK-JS-NODEFORGE-14125097
- https://snyk.io/vuln/SNYK-JS-NODEFORGE-2331908
- https://snyk.io/vuln/SNYK-JS-EJS-1049328
- https://snyk.io/vuln/SNYK-JS-NWSAPI-2841516
- https://snyk.io/vuln/SNYK-JS-MINIMIST-2429795
- https://snyk.io/vuln/SNYK-JS-NODEFORGE-2430337
- https://snyk.io/vuln/SNYK-JS-NODEFORGE-2430341
- https://snyk.io/vuln/SNYK-JS-RAMDA-1582370
- https://snyk.io/vuln/SNYK-JS-LOADERUTILS-3042992
- https://snyk.io/vuln/SNYK-JS-LOADERUTILS-3105943
- https://snyk.io/vuln/SNYK-JS-MICROMATCH-6838728
- https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818
- https://snyk.io/vuln/SNYK-JS-POSTCSS-5926692
- https://snyk.io/vuln/SNYK-JS-ISTANBULREPORTS-2328088
@snyk-io-eu

snyk-io-eu Bot commented Apr 16, 2026

Copy link
Copy Markdown
Author

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants