Skip to content

Known NPM package security vulnerabilities exist in production #2224

Description

@starmanlabsio
  • Know CVEs in pinned versions found package-lock file that is not git ignored. NPM Package needs to be reviewed and updated.

Server (apps/OpenSignServer)

CVE Severity Advisory Description
GHSA-9q82-xgwf-vj6h Moderate @apollo/server Browser bug bypasses XS-Search (read-only CSRF) prevention
CVE-2026-40895 High (CVSS 7.5) follow-redirects Custom auth headers (X-API-Key, etc.) leak on cross-domain redirect
CVE-2026-41907 Moderate uuid Missing buffer bounds check in v3/v5/v6 allows out-of-bounds write
CVE-2026-45736 Moderate ws Uninitialized memory disclosure via TypedArray in websocket.close()
CVE-2026-48779 High (CVSS 7.5) ws Memory exhaustion DoS from tiny fragments and data chunks
CVE-2026-25547 High brace-expansion DoS via unbounded brace range expansion exhausting CPU and memory
CVE-2026-45149 High brace-expansion max option applied too late, allowing ~505MB allocation on small input
CVE-2026-42338 Moderate ip-address XSS in Address6 HTML-emitting methods (group, link, spanAll)

Server (apps/OpenSignServer)

CVE / Advisory Severity Description
CVE-2026-22030 / GHSA-h5cw-625j-3rxh High (CVSS 7.5) CSRF on document POST requests to UI routes with server-side actions
GHSA-qwww-vcr4-c8h2 High RSC Mode CSRF bypass allows action execution before 400 response
GHSA-2w69-qvjg-hvjx High XSS via Open Redirects
GHSA-8v8x-cx79-35w7 High SSRX XSS in ScrollRestoration
GHSA-49rj-9fvp-4h2h High Vendored turbo-stream allows arbitrary constructor invocation (RCE)
GHSA-2j2x-hqr9-3h42 High Same-origin redirect with path starting // causes open redirect
GHSA-8646-j5j9-6r62 High XSS in unstable RSC redirect handling via javascript: targets
GHSA-f22v-gfqf-p8f3 High Stored XSS via unescaped Location header in prerendered redirect HTML
GHSA-8x6r-g9mw-2r78 High DoS via unbounded path expansion in __manifest endpoint
GHSA-rxv8-25v2-qmq8 High DoS via reflected user input in single-fetch
GHSA-wrjc-x8rr-h8h6 High Open redirect via backslash in Link and useNavigate
GHSA-jjmj-jmhj-qwj2 High Open redirect leading to XSS
GHSA-h8fp-f39c-q6mh High RSCErrorHandler missing protocol validation (XSS)
GHSA-337j-9hxr-rhxg High Arbitrary constructor injection via deserializeErrors() in SSR hydration
GHSA-chx6-hx7r-mcp5 High Unauthenticated DoS via inefficient route matching

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions