Skip to content

[Snyk] Security upgrade eslint from 8.29.0 to 9.0.0#44

Open
karencapiiro wants to merge 1 commit into
mainfrom
snyk-fix-87b62f2250df562a59b63f8c66af799e
Open

[Snyk] Security upgrade eslint from 8.29.0 to 9.0.0#44
karencapiiro wants to merge 1 commit into
mainfrom
snyk-fix-87b62f2250df562a59b63f8c66af799e

Conversation

@karencapiiro

Copy link
Copy Markdown

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • website/package.json
  • website/package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
medium severity Prototype Pollution
SNYK-JS-JSYAML-13961110
  50  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​eslint@​8.29.0 ⏵ 9.0.09710010096 +2100

View full report

@rafikmojr

Copy link
Copy Markdown
Collaborator

Logo
Checkmarx One – Scan Summary & Details7f54f5fc-cf5f-41b0-ae22-7ad48d2068ed

New Issues (40)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
CRITICAL CVE-2025-29927 Npm-next-13.0.6
detailsRecommended version: 14.2.32
Description: Next.js is a React framework for building full-stack web applications. In 11.1.4 through 12.3.5, 13.x prior to 13.5.9, 14.x prior to 14.2.25, 14.3....
Attack Vector: NETWORK
Attack Complexity: LOW

ID: %2BY92hQ5g%2Bs1ClBbQjYjf38YgBZdtn%2FsLIeHyK8C%2B%2BqU%3D
Vulnerable Package
CRITICAL CVE-2025-7783 Npm-form-data-4.0.0
detailsRecommended version: 4.0.4
Description: Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with the pro...
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: IHNvHzAnu923vT92fZZ%2B6SS%2F2tiDWpxAlrcTtBXl1mo%3D
Vulnerable Package
HIGH CVE-2024-12905 Npm-tar-fs-2.1.1
detailsRecommended version: 2.1.4
Description: An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: lkJa9%2FYNIs%2Fmbp5MvHrHRAwSfj9n8oEdvBXoFICLdkY%3D
Vulnerable Package
HIGH CVE-2024-21538 Npm-cross-spawn-7.0.3
detailsRecommended version: 7.0.5
Description: Versions of the package cross-spawn prior to 6.0.6 and 7.x prior to 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS), due to im...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: bynR9gQh2EiZvzrvXkEKm109JgZDL0Xykif6PVvbXE8%3D
Vulnerable Package
HIGH CVE-2024-4068 Npm-braces-3.0.2
detailsRecommended version: 3.0.3
Description: The NPM package "braces", versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: kYDzQq05zBUPjNRxPgGsIVOe4m7%2Ft%2Fc6M2f8aSH7krg%3D
Vulnerable Package
HIGH CVE-2024-47831 Npm-next-13.0.6
detailsRecommended version: 14.2.32
Description: Next.js is a React Framework for the Web. It contains a vulnerability in the image optimization feature that allows for a potential Denial of Servi...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: e%2BFroDUNTBNUxUBoFtAfGoWVSgOr2KGjyFTo8vFc%2Fg8%3D
Vulnerable Package
HIGH CVE-2024-51479 Npm-next-13.0.6
detailsRecommended version: 14.2.32
Description: Next.js is a React framework for building full-stack web applications. In versions 9.5.5-canary.0 through 14.2.14 and 14.3.0-canary.0 through 15.0....
Attack Vector: NETWORK
Attack Complexity: LOW

ID: naXyPTH1J23%2FBRHUAeIKFP9PMb6cmzJmtW3mZjfEbMw%3D
Vulnerable Package
HIGH CVE-2025-27152 Npm-axios-1.2.1
detailsRecommended version: 1.12.0
Description: Axios is a promise-based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: T5JGa%2FPgxVNkl40HZhq5ev2A%2FoJs6r%2BEY5AR65Ih07g%3D
Vulnerable Package
HIGH CVE-2025-48387 Npm-tar-fs-2.1.1
detailsRecommended version: 2.1.4
Description: The package tar-fs provides filesystem bindings for tar-stream. In versions prior to 1.16.5, 2.0.x prior to 2.1.3, and 3.0.x prior to 3.0.9, there ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: %2B%2FOFJkd4G4OyQqhgg%2FPZj%2BJ6fsP6ZxPkYY8lu%2FHq%2BGk%3D
Vulnerable Package
HIGH CVE-2025-57822 Npm-next-13.0.6
detailsRecommended version: 14.2.32
Description: Next.js is a React framework for building full-stack web applications. In versions through 14.2.31, 14.3.0-canary.0 through 15.4.2-canary.42 and 15...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: oFP6vE2wFLfPjBb1r3OXdA7%2F2lwFxwEFZg68GaEPTTY%3D
Vulnerable Package
HIGH CVE-2025-58754 Npm-axios-1.2.1
detailsRecommended version: 1.12.0
Description: Axios is a promise based HTTP client for the browser and Node.js. When Axios prior to version 1.12.0 runs on Node.js and is given a URL with the "d...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: BWet8xT%2BmH%2FjEGkJ%2B%2B2bJPASjLZeNyvI2scbAi01J2c%3D
Vulnerable Package
HIGH CVE-2025-59343 Npm-tar-fs-2.1.1
detailsRecommended version: 2.1.4
Description: tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.4, and 1.16.6 are vulnerable to symlink validation bypass if the d...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: os3ZjOm25XT0BBxcZWqFtQyNTmqDlZrTsZspTDwGB6k%3D
Vulnerable Package
HIGH Cxf4037528-b0ca Npm-next-auth-4.18.6
detailsRecommended version: 4.24.12
Description: NextAuth.js's versions through 4.24.11 and 5.x through 5.0.0-beta.30, email sign-in can be forced to deliver authentication emails to an attacker-c...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: UiGoIxhRHQi0suEgK8KBREyEK3joTAEm%2BxM30dweuAI%3D
Vulnerable Package
HIGH Reflected_XSS /website/src/pages/api/update_task.ts: 25
detailsThe method Cx7b0b8fb6 embeds untrusted data in generated output with json, at line 78 of /website/src/pages/api/update_task.ts. This untrusted d...
ID: xirmicHWO8TwpgnQdFz%2Bm6WUvTk%3D
Attack Vector
HIGH Reflected_XSS /website/src/pages/api/new_task/[task_type].ts: 15
detailsThe method Cx0a033392 embeds untrusted data in generated output with json, at line 71 of /website/src/pages/api/new_task/[task_type].ts. This...
ID: FgP3Hn5pmfWQul9C2QAbLmB7vIc%3D
Attack Vector
MEDIUM CVE-2024-28176 Npm-jose-4.11.1
detailsRecommended version: 4.15.5
Description: The package jose is a JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JW...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 6bpDpbAxk8v%2F1MkWti4VQgQdXkGcMPw%2BwGRQNwSxT80%3D
Vulnerable Package
MEDIUM CVE-2024-28849 Npm-follow-redirects-1.15.2
detailsRecommended version: 1.15.6
Description: follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected ver...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: vmwix4SSDPBDvq2fJgm%2BFBVfRwxH7NBOAcu54wE%2FkRU%3D
Vulnerable Package
MEDIUM CVE-2024-34064 Python-Jinja2-3.1.2
detailsRecommended version: 3.1.6
Description: Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: DdIuoZACrcsY%2F4r0cNRy5fTXOMgTKtjqbXXdhsL67Ik%3D
Vulnerable Package
MEDIUM CVE-2024-35195 Python-requests-2.28.1
detailsRecommended version: 2.32.4
Description: Requests is an HTTP library. In the package requests versions prior to 2.32.0, when making requests through a Requests `Session`, if the first requ...
Attack Vector: LOCAL
Attack Complexity: HIGH

ID: GuaKck5KsN1q2ez4Ect7myNFzJtXSzEsJcFRRQstyBg%3D
Vulnerable Package
MEDIUM CVE-2024-3772 Python-pydantic-1.9.1
detailsRecommended version: 1.10.13
Description: Regular expression denial of service in Pydanic allows remote attackers to cause denial of service via a crafted email string. This issue affects p...
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: c0hnamc37aMy2lbSSH4UMpQlZFONzf8t64K87GPi8RQ%3D
Vulnerable Package
MEDIUM CVE-2024-4067 Npm-micromatch-4.0.5
detailsRecommended version: 4.0.8
Description: The NPM package "micromatch" prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in "micromatch....
Attack Vector: NETWORK
Attack Complexity: LOW

ID: ERoLACfM%2BNQyelaj1LNxyBGL0RK3mUh4k8OrAanM45M%3D
Vulnerable Package
MEDIUM CVE-2024-47081 Python-requests-2.28.1
detailsRecommended version: 2.32.4
Description: Requests is an HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak ".netrc" credentials to third parties for speci...
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: fNdFxlWuRzGVFPplzflBN%2B25CMG2Vw7dlK3mHkaOQoo%3D
Vulnerable Package
MEDIUM CVE-2024-47764 Npm-cookie-0.5.0
detailsRecommended version: 0.7.0
Description: The NPM package cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cook...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: uhT6sXgjL1Y%2Blo52B90JV2F7gaVD%2FBzmHvpG8dBNXQ4%3D
Vulnerable Package
MEDIUM CVE-2024-55565 Npm-nanoid-3.3.4
detailsRecommended version: 3.3.8
Description: The package nanoid versions through 3.3.7 and 4.0.0 through 5.0.8 mishandle non-integer values.
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 5nBu3vpuKG3SS414TRs1G6I1NbQozL3t7k5yzaXWKSE%3D
Vulnerable Package
MEDIUM CVE-2024-56201 Python-Jinja2-3.1.2
detailsRecommended version: 3.1.6
Description: Jinja is an extensible templating engine. In affected versions, a bug in the Jinja compiler allows an attacker that controls both the content and f...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: 2QMsCo8nWPgT3u%2FWaT%2FSVp2yaEFYLxpLIWEKom9w82s%3D
Vulnerable Package
MEDIUM CVE-2024-56326 Python-Jinja2-3.1.2
detailsRecommended version: 3.1.6
Description: Jinja is an extensible templating engine. In affected versions, an oversight in how the Jinja sandboxed environment detects calls to `str.format` a...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: fz2vIZvIXRjp1EnZzOEhhqRgWaEGSGtkDW7zDj%2B6C6Y%3D
Vulnerable Package
MEDIUM CVE-2024-56332 Npm-next-13.0.6
detailsRecommended version: 14.2.32
Description: Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 through 13.5.7, 14.0.0 through 14.2.20, and 15.0....
Attack Vector: NETWORK
Attack Complexity: LOW

ID: yvWwCS98d%2BtdqEEtIWsUPla%2FdcF6gdrKQSJPsO43V%2F8%3D
Vulnerable Package
MEDIUM CVE-2025-27516 Python-Jinja2-3.1.2
detailsRecommended version: 3.1.6
Description: Jinja is an extensible templating engine. In Jinja2 versions prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: pXuw2r2AiOPh0o8lb7RJp0SIqAYCuLM7bYsCJwl4x5s%3D
Vulnerable Package
MEDIUM CVE-2025-27789 Npm-@babel/helpers-7.20.6
detailsRecommended version: 7.26.10
Description: Babel is a compiler for writing next-generation JavaScript. In affected versions of Babel, to compile regular expressions named capturing groups, B...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: c5ZS1%2BafaiRuLV44V%2Fi8znv4cYIHOZZN9AnRbekhGYw%3D
Vulnerable Package
MEDIUM CVE-2025-50181 Python-urllib3-1.26.20
detailsRecommended version: 2.5.0
Description: The package urllib3 is a user-friendly HTTP client library for Python. In versions prior to 2.5.0, it is possible to disable redirects for all requ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: hZ37d%2BwAKVJa%2BxWukzmNbc6I6v1uEOqFAgavkryCQ%2Fk%3D
Vulnerable Package
MEDIUM CVE-2025-54121 Python-starlette-0.22.0
detailsRecommended version: 0.49.1
Description: Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In v...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: LFRePEVgG7yuCY2tyKgPLLdtnLBNzAhd7c7gdSM2LGE%3D
Vulnerable Package
MEDIUM CVE-2025-57752 Npm-next-13.0.6
detailsRecommended version: 14.2.32
Description: Next.js is a React framework for building full-stack web applications. In versions 0.9.9 through 14.2.30, 14.3.0-canary.0 through 15.4.2-canary.18,...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: wKuNtrOsL2Tm1vcrwecBdHo0CZi7maxb%2FTL3d0g1xYs%3D
Vulnerable Package
MEDIUM Cx9b50aef6-319d Npm-nodemailer-6.8.0
detailsRecommended version: 7.0.7
Description: The email parsing library incorrectly handles quoted local-parts containing '@' in versions through 7.0.6. This leads to misrouting of email recipi...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: NWDm8sowtrYoO1eyKBuLHnkKD%2FEsK8gxQ87TLzHapJw%3D
Vulnerable Package
MEDIUM IAM DB Cluster Auth Not Enabled /web-cluster.yml: 85
detailsIAM Authentication should be enabled to verify the access of users and applications to your databases by enabling IAM policies and multi-factor au...
ID: umPAWCcvmYm%2Bcpxtlg7Md%2Bwu%2FK4%3D
MEDIUM Secretsmanager Secret Without KMS /web-cluster.yml: 64
detailsAWS Secretmanager should use AWS KMS customer master key (CMK) to encrypt the secret values in the versions stored in the secret
ID: %2B08oT%2B5wHQUpe%2FF%2BPnMUNZsBc%2Fg%3D
LOW CVE-2025-48068 Npm-next-13.0.6
detailsRecommended version: 14.2.32
Description: Next.js is a React framework for building full-stack web applications. In the next package, versions 13.0.0 through 15.2.2-canary.2 may have allowe...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: iUzOG%2Fcy30Nv8CPuPM%2FIF6l1J82MP7BExLpEYkBq9FU%3D
Vulnerable Package
LOW CVE-2025-55173 Npm-next-13.0.6
detailsRecommended version: 14.2.32
Description: Next.js is a React framework for building full-stack web applications. In versions through 14.2.30, 15.0.0-rc.0 through 15.4.2-canary.18, 15.4.3 an...
Attack Vector: ADJACENT NETWORK
Attack Complexity: LOW

ID: bpOZ8oFLNHyv%2BwHW8KiJeT8a%2FerYd%2FwjccEEewJy9T4%3D
Vulnerable Package
LOW CVE-2025-5889 Npm-brace-expansion-1.1.11
detailsRecommended version: 1.1.12
Description: A vulnerability was found in juliangruber brace-expansion. It has been rated as problematic. Affected by this issue is the function "expand" of the...
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: roCJLgW07uMAFLT06iADF0ZfA9V9DfwWEqWQq288Uyw%3D
Vulnerable Package
LOW Tags Not Copied to RDS Cluster Snapshot /web-cluster.yml: 85
detailsTags of the RDS Cluster should be copied to the respective snapshots to ensure that snapshots retain important metadata for identification, cost al...
ID: cIiazWSQdhdrv9eM1zXp0HUFLp8%3D
LOW Tags Not Copied to RDS Cluster Snapshot /web-cluster.yml: 122
detailsTags of the RDS Cluster should be copied to the respective snapshots to ensure that snapshots retain important metadata for identification, cost al...
ID: oVHDnJaWlkclLyIT%2FYcJ35WCScE%3D
Fixed Issues (39)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
HIGH CVE-2022-46175 Npm-json5-1.0.1
HIGH CVE-2023-26115 Npm-word-wrap-1.2.3
HIGH Cx89601373-08db Npm-debug-2.6.9
HIGH Cx89601373-08db Npm-debug-3.2.7
HIGH Cxab55612e-3a56 Npm-braces-3.0.2
HIGH Cxca84a1c2-1f12 Npm-micromatch-4.0.5
HIGH Reflected_XSS /website/src/pages/api/new_task/[task_type].ts: 28
HIGH Reflected_XSS /website/src/pages/api/update_task.ts: 25
HIGH Reflected_XSS /website/src/pages/api/new_task/[task_type].ts: 15
MEDIUM Host Namespace is Shared /docker-compose.yaml: 11
MEDIUM Host Namespace is Shared /docker-compose.yaml: 5
MEDIUM Host Namespace is Shared /docker-compose.yaml: 11
MEDIUM Host Namespace is Shared /docker-compose.yaml: 50
MEDIUM Host Namespace is Shared /docker-compose.yaml: 19
MEDIUM Host Namespace is Shared /docker-compose.yaml: 19
MEDIUM Host Namespace is Shared /docker-compose.yaml: 18
MEDIUM Host Namespace is Shared /docker-compose.yaml: 27
MEDIUM Host Namespace is Shared /docker-compose.yaml: 18
MEDIUM Host Namespace is Shared /docker-compose.yaml: 26
MEDIUM Host Namespace is Shared /docker-compose.yaml: 27
MEDIUM Host Namespace is Shared /docker-compose.yaml: 4
MEDIUM Host Namespace is Shared /docker-compose.yaml: 5
MEDIUM Networks Not Set /docker-compose.yaml: 27
MEDIUM Networks Not Set /docker-compose.yaml: 11
MEDIUM Networks Not Set /docker-compose.yaml: 5
MEDIUM Networks Not Set /docker-compose.yaml: 18
MEDIUM Networks Not Set /docker-compose.yaml: 4
MEDIUM Networks Not Set /docker-compose.yaml: 19
MEDIUM Networks Not Set /docker-compose.yaml: 5
MEDIUM Networks Not Set /docker-compose.yaml: 26
MEDIUM Networks Not Set /docker-compose.yaml: 27
MEDIUM Networks Not Set /docker-compose.yaml: 18
MEDIUM Networks Not Set /docker-compose.yaml: 50
MEDIUM Networks Not Set /docker-compose.yaml: 11
MEDIUM Networks Not Set /docker-compose.yaml: 19
MEDIUM SSRF /website/src/pages/api/new_task/[task_type].ts: 15
LOW Missing_CSP_Header /website/src/lib/poster.ts: 4
LOW Unsafe_Use_Of_Target_blank /website/src/components/CallToAction.tsx: 19
LOW Unsafe_Use_Of_Target_blank /website/src/components/CallToAction.tsx: 34

Use @Checkmarx to reach out to us for assistance.

Just send a PR comment with @Checkmarx followed by a natural language request.

Examples: @Checkmarx how are you able to help me? @Checkmarx rescan this PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants