Skip to content
This repository was archived by the owner on Jun 24, 2026. It is now read-only.

[Aikido] Fix 2 critical issues in minimist, ws#3

Closed
aikido-autofix[bot] wants to merge 1 commit into
masterfrom
fix/aikido-security-CXM-226-update-packages-37391055-7kwt
Closed

[Aikido] Fix 2 critical issues in minimist, ws#3
aikido-autofix[bot] wants to merge 1 commit into
masterfrom
fix/aikido-security-CXM-226-update-packages-37391055-7kwt

Conversation

@aikido-autofix

Copy link
Copy Markdown

Upgrade minimist to fix Prototype Pollution and ws to fix DoS via excessive headers vulnerability.

✅ There are no breaking changes

✅ 2 CVEs resolved by this upgrade, including 1 critical 🚨 CVE

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2021-44906
🚨 CRITICAL
[minimist] <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
CVE-2024-37890
HIGH
[ws] A request with headers exceeding the server.maxHeadersCount threshold can crash a ws server, causing a denial of service. This vulnerability allows attackers to trigger server crashes through malformed HTTP requests.
🔗 Related Tasks

@github-actions

Copy link
Copy Markdown

YARN is no longer allowed. Kindly replace the lockfile using PNPM. Found in ./lighthouse-logger/yarn.lock
YARN is no longer allowed. Kindly replace the lockfile using PNPM. Found in ./lighthouse-core/scripts/legacy-javascript/yarn.lock
YARN is no longer allowed. Kindly replace the lockfile using PNPM. Found in ./yarn.lock

@aikido-autofix

Copy link
Copy Markdown
Author

Closed by Aikido: a new AutoFix has been created → #4

@aikido-autofix aikido-autofix Bot closed this May 23, 2026
@aikido-autofix aikido-autofix Bot deleted the fix/aikido-security-CXM-226-update-packages-37391055-7kwt branch May 23, 2026 00:12
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants