Skip to content

[Aikido] Fix 9 security issues in lodash, uuid, @octokit/endpoint and 3 more - #22

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-82165193-3vqa
Closed

[Aikido] Fix 9 security issues in lodash, uuid, @octokit/endpoint and 3 more#22
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-82165193-3vqa

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Aug 6, 2026

Copy link
Copy Markdown

Upgrade dependencies to fix critical RCE vulnerability in lodash template injection via options.imports and high-severity buffer overflow in uuid.

⚠️ Incomplete breaking changes analysis (2/6 analyzed)

⚠️ Breaking changes analysis not available for: @octokit/endpoint, @octokit/plugin-paginate-rest, @octokit/request, @octokit/request-error

✅ No breaking changes from any of the package upgrades affect this codebase:

lodash (4.17.21 => 4.18.1): The codebase only uses _.filter() and _.merge() methods (in src/gh.js). The breaking changes to _.unset(), _.omit(), and _.template() do not affect this code.

uuid (8.3.2 => 11.1.1): The uuid package is not used anywhere in the source code.

@octokit packages: These are transitive dependencies through @actions/github v6.0.1, which already uses compatible versions (@octokit/core v5+, @octokit/plugin-paginate-rest v9+). The codebase:

  • Does not configure custom HTTP agents

  • Does not pass custom request options beyond standard parameters (method, headers, body)

  • Runs on Node.js 24, which is fully supported by all upgraded package versions

All Node.js version requirements are satisfied as the action runs on Node.js 24 (specified in action.yml).

All breaking changes by upgrading lodash from version 4.17.21 to 4.18.1 (CHANGELOG)

Version Description
4.18.0
_.unset / _.omit now block constructor and prototype as non-terminal path keys unconditionally. Calls that previously returned true and deleted the property now return false and leave the target untouched.
4.18.0
_.template now throws "Invalid imports option passed into _.template" when imports keys contain forbidden identifier characters, which were previously allowed.

All breaking changes by upgrading uuid from version 8.3.2 to 11.1.1 (CHANGELOG)

Version Description
9.0.0
Drop Node.js 10.x support
9.0.0
Remove the minified UMD build from the package
9.0.0
Drop IE 11 and Safari 10 support, remove msCrypto fallback, and no longer transpile browser build to ES2015
10.0.0
Drop Node.js 12 and 14 support, add Node.js 20 (update node support matrix to only support node 16-20)
11.0.0
Refactor v1 internal state and options logic
11.0.0
Refactor v7 internal state and options logic
11.0.0
Port to TypeScript
11.0.0
Update node support matrix (only support node 16-20)
✅ 9 CVEs resolved by this upgrade, including 1 critical 🚨 CVE

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-4800
🚨 CRITICAL
[lodash] A vulnerability in _.template allows arbitrary code execution through untrusted key names in options.imports or prototype pollution, as validation was incomplete after a prior CVE fix. An attacker can inject malicious code that executes during template compilation.
CVE-2025-13465
MEDIUM
[lodash] A prototype pollution vulnerability in _.unset and _.omit functions allows attackers to delete methods from global prototypes via crafted paths. While this prevents property overwriting, it can cause denial of service by removing critical functionality.
CVE-2026-2950
MEDIUM
[lodash] Prototype pollution vulnerability in _.unset and _.omit functions allows attackers to bypass previous fixes using array-wrapped path segments, enabling deletion of properties from built-in prototypes. While this doesn't allow overwriting prototype behavior, it can cause denial of service or unexpected application behavior.
CVE-2026-41907
HIGH
[uuid] A buffer overflow vulnerability allows v3, v5, and v6 UUID functions to write beyond caller-provided buffer boundaries when given small buffers or large offsets, causing silent data corruption. This can lead to memory corruption and potential code execution or information disclosure.
AIKIDO-2026-10892
MEDIUM
[uuid] UUID functions v3(), v5(), and v6() can write past the end of a caller-provided buffer due to missing offset validation, enabling buffer overflow attacks. The fix adds bounds checks to prevent out-of-range writes.
AIKIDO-2025-10094
LOW
[@octokit/endpoint] Improper header parsing for GraphQL endpoints allows attackers to craft malicious inputs triggering ReDoS through excessive regex backtracking, causing denial of service and performance degradation.
CVE-2025-25288
LOW
[@octokit/plugin-paginate-rest] A ReDoS (Regular Expression Denial of Service) vulnerability exists in the pagination iterator when processing malicious link headers, allowing attackers to cause denial of service through specially crafted requests.
CVE-2025-25290
LOW
[@octokit/request] A ReDoS vulnerability in the link header parsing regex allows attackers to cause excessive CPU usage and service unavailability through specially crafted HTTP responses. The unbounded regex pattern is susceptible to catastrophic backtracking when processing malicious input.
CVE-2025-25289
LOW
[@octokit/request-error] A Regular Expression Denial of Service (ReDoS) vulnerability in HTTP header processing allows attackers to cause excessive resource consumption and DoS by sending malformed authorization headers with long space sequences. This can significantly degrade performance or crash services.
🤖 Remediation details

Fix security vulnerabilities in lodash, uuid, undici, and @octokit/* transitive chain

Short summary

This PR remediates security vulnerabilities in six packages identified in the initial task: lodash, uuid, @octokit/endpoint, @octokit/plugin-paginate-rest, @octokit/request, and @octokit/request-error. A seventh vulnerable package, undici, was introduced as a new transitive dependency by the parent bumps required to fix the @octokit/* chain and was also remediated in the same pass. Changes touch the root package.json (declared version specs for @actions/core, @actions/github, and lodash, plus one targeted overrides entry) and the root package-lock.json (all resolved transitive versions).

lodash

lodash is a direct dependency declared in the root package.json. Its spec was widened from ^4.17.21 to ^4.18.1, causing npm to resolve the lockfile to 4.18.1, which is the patched release. No parent chain traversal was needed.

uuid

uuid appeared in two lockfile instances: one hoisted to node_modules/uuid (pulled in by @actions/core@1.x at 8.3.2) and one nested at node_modules/aws-sdk/node_modules/uuid (pinned by aws-sdk at exactly 8.0.0). The @actions/core instance was eliminated entirely by bumping @actions/core to ^2.0.0 (see below), which drops the uuid dependency altogether. The aws-sdk instance has no fixing parent release across the entire aws-sdk@2.x published history—aws-sdk hard-pins uuid@8.0.0 in every release—so a targeted override "uuid@<11.1.1": "11.1.1" was added to the root package.json as the only viable path for that instance.

@octokit/endpoint

@octokit/endpoint is a transitive dependency pulled in through the chain @actions/github@octokit/core@octokit/request@octokit/endpoint. The installed version 6.0.12 is only reachable via @octokit/request@5.x; the patched floor is 9.0.6. Bumping @actions/github to ^8.0.1 in the root package.json brought in @octokit/core@7.x and @octokit/request@10.x, which resolves @octokit/endpoint to 11.0.4—well above the patched minimum.

@octokit/plugin-paginate-rest

@octokit/plugin-paginate-rest is a transitive dependency of @actions/github. The installed version 2.21.3 is below the patched floor of 9.2.2. Bumping @actions/github to ^8.0.1 in the root package.json resolves @octokit/plugin-paginate-rest to 14.0.0, satisfying the patched requirement. The same parent bump that fixed the @octokit/endpoint chain covers this package.

@octokit/request

@octokit/request is a transitive dependency reachable via @actions/github@octokit/core / @octokit/graphql. The installed version 5.6.3 is below the patched floor of 8.4.1. Bumping @actions/github to ^8.0.1 pulls in @octokit/core@7.x and @octokit/graphql@9.x, both of which declare @octokit/request@^10.x, resolving to 10.0.13 in the lockfile.

@octokit/request-error

@octokit/request-error is a transitive dependency pulled in by @octokit/core and @octokit/request. The installed version 2.1.0 is below the patched floor of 5.1.1. The same @actions/github bump to ^8.0.1 that fixed the broader @octokit/* chain resolves @octokit/request-error to 7.1.1 via @octokit/core@7.x and @octokit/request@10.x.

undici

undici was not in the original task but was introduced as a new transitive vulnerability when @actions/github was bumped from ^4.0.0 to ^6.0.0 (required for the @octokit/* fixes): @actions/github@6.x pulls in @actions/http-client@2.xundici@5.29.0, which is below the patched floor of 6.28.0 for all twelve reported CVEs. Fixing this required walking the full parent chain: @actions/http-client@2.x has no fixing release below 3.0.2 (a major bump), and @actions/core@1.x pins @actions/http-client@^2.x. Bumping @actions/core to ^2.0.0 in the root package.json was therefore necessary—@actions/core@2.x declares @actions/http-client@^3.0.0, which in turn declares undici@^6.23.0, resolving to 6.28.0 in the lockfile and covering all reported CVEs.

Version changes

Package From To Why updated
lodash ^4.17.214.17.21 ^4.18.14.18.1 Direct CVE fix
@actions/core ^1.10.01.10.0 ^2.0.02.0.3 Parent bump required to fix undici (drops uuid, upgrades @actions/http-client to v3)
@actions/github ^4.0.04.0.0 ^8.0.18.0.1 Parent bump required to fix @octokit/endpoint, @octokit/plugin-paginate-rest, @octokit/request, @octokit/request-error
uuid 8.3.2 (hoisted) / 8.0.0 (nested in aws-sdk) 11.1.1 (single instance, override) CVE fix via override (aws-sdk path); hoisted instance eliminated by @actions/core bump
undici 5.29.0 6.28.0 Transitive CVE fix after parent bump (@actions/core@actions/http-client@3.x)
@actions/http-client 2.2.3 3.0.2 Transitive after @actions/core bump; required to resolve undici@^6.23.0
@octokit/core 3.6.0 7.0.7 Transitive after @actions/github bump
@octokit/endpoint 6.0.12 11.0.4 Transitive CVE fix after @actions/github bump
@octokit/graphql 4.8.0 9.0.4 Transitive after @actions/github bump
@octokit/plugin-paginate-rest 2.21.3 14.0.0 Transitive CVE fix after @actions/github bump
@octokit/plugin-rest-endpoint-methods 4.15.1 10.4.1 Transitive after @actions/github bump
@octokit/request 5.6.3 10.0.13 Transitive CVE fix after @actions/github bump
@octokit/request-error 2.1.0 7.1.1 Transitive CVE fix after @actions/github bump

@aikido-autofix

aikido-autofix Bot commented Aug 7, 2026

Copy link
Copy Markdown
Author

Closed by Aikido: a new AutoFix has been created → #23

@aikido-autofix aikido-autofix Bot closed this Aug 7, 2026
@aikido-autofix
aikido-autofix Bot deleted the fix/aikido-security-update-packages-82165193-3vqa branch August 7, 2026 02:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants