Skip to content
This repository was archived by the owner on Jun 24, 2026. It is now read-only.

[Aikido] Fix critical issue in minimist via minor version upgrade from 1.2.5 to 1.2.6#2

Closed
aikido-autofix[bot] wants to merge 1 commit into
masterfrom
fix/aikido-security-CXM-225-update-packages-37104079-3ypa
Closed

[Aikido] Fix critical issue in minimist via minor version upgrade from 1.2.5 to 1.2.6#2
aikido-autofix[bot] wants to merge 1 commit into
masterfrom
fix/aikido-security-CXM-225-update-packages-37104079-3ypa

Conversation

@aikido-autofix

Copy link
Copy Markdown

Upgrade minimist to fix critical Prototype Pollution vulnerability that could allow arbitrary code execution through malicious input.

✅ There are no breaking changes

✅ 1 CVE resolved by this upgrade, including 1 critical 🚨 CVE

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2021-44906
🚨 CRITICAL
[minimist] <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
🔗 Related Tasks

@github-actions

Copy link
Copy Markdown

YARN is no longer allowed. Kindly replace the lockfile using PNPM. Found in ./lighthouse-logger/yarn.lock
YARN is no longer allowed. Kindly replace the lockfile using PNPM. Found in ./lighthouse-core/scripts/legacy-javascript/yarn.lock
YARN is no longer allowed. Kindly replace the lockfile using PNPM. Found in ./yarn.lock

@aikido-autofix

Copy link
Copy Markdown
Author

Closed by Aikido: a new AutoFix has been created → #3

@aikido-autofix aikido-autofix Bot closed this May 21, 2026
@aikido-autofix aikido-autofix Bot deleted the fix/aikido-security-CXM-225-update-packages-37104079-3ypa branch May 21, 2026 00:34
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants