Skip to content

High-severity npm vulnerabilities reported by pnpm audit #1467

Description

@kwasham

Summary

  • \┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ high │ Playwright downloads and installs browsers without │
    │ │ verifying the authenticity of the SSL certificate │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ playwright │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ <1.55.1 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=1.55.1 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > @vercel/analytics@1.5.0 > next@16.0.10 > │
    │ │ @playwright/test@1.51.0 > playwright@1.51.0 │
    │ │ │
    │ │ . > geist@1.3.1 > next@16.0.10 > │
    │ │ @playwright/test@1.51.0 > playwright@1.51.0 │
    │ │ │
    │ │ . > next@16.0.10 > @playwright/test@1.51.0 > │
    │ │ playwright@1.51.0 │
    │ │ │
    │ │ ... Found 5 paths, run pnpm why playwright for more │
    │ │ information │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-7mvr-c777-76hp
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ high │ Next.js HTTP request deserialization can lead to DoS │
    │ │ when using insecure React Server Components │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ next │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ >=16.0.0-beta.0 <16.0.11 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=16.0.11 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > @vercel/analytics@1.5.0 > next@16.0.10 │
    │ │ │
    │ │ . > geist@1.3.1 > next@16.0.10 │
    │ │ │
    │ │ . > next@16.0.10 │
    │ │ │
    │ │ ... Found 4 paths, run pnpm why next for more │
    │ │ information │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-h25m-26qc-wcjf
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ high │ @isaacs/brace-expansion has Uncontrolled Resource │
    │ │ Consumption │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ @isaacs/brace-expansion │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ <=5.0.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=5.0.1 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > ultracite@7.0.11 > glob@13.0.0 > minimatch@10.1.1 │
    │ │ > @isaacs/brace-expansion@5.0.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-7h2j-956f-4vf2
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ high │ minimatch has a ReDoS via repeated wildcards with │
    │ │ non-matching literal in pattern │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ minimatch │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ >=10.0.0 <10.2.1 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=10.2.1 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > ultracite@7.0.11 > glob@13.0.0 > minimatch@10.1.1 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-3ppc-4f35-3m26
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ high │ minimatch has ReDoS: matchOne() combinatorial │
    │ │ backtracking via multiple non-adjacent GLOBSTAR │
    │ │ segments │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ minimatch │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ >=10.0.0 <10.2.3 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=10.2.3 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > ultracite@7.0.11 > glob@13.0.0 > minimatch@10.1.1 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-7r86-cg39-jmmj
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ high │ minimatch ReDoS: nested *() extglobs generate │
    │ │ catastrophically backtracking regular expressions │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ minimatch │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ >=10.0.0 <10.2.3 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=10.2.3 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > ultracite@7.0.11 > glob@13.0.0 > minimatch@10.1.1 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-23c5-xmqv-rm74
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ high │ Undici has Unbounded Memory Consumption in WebSocket │
    │ │ permessage-deflate Decompression │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ undici │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ <6.24.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=6.24.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > @vercel/blob@0.24.1 > undici@5.28.5 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-vrm6-8vpv-qv8q
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ high │ Undici has Unhandled Exception in WebSocket Client Due │
    │ │ to Invalid server_max_window_bits Validation │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ undici │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ <6.24.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=6.24.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > @vercel/blob@0.24.1 > undici@5.28.5 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-v9p9-hfj2-hcw8
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ moderate │ esbuild enables any website to send any requests to │
    │ │ the development server and read the response │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ esbuild │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ <=0.24.2 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=0.25.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > drizzle-kit@0.25.0 > @esbuild-kit/esm-loader@2.6.5 │
    │ │ > @esbuild-kit/core-utils@3.3.2 > esbuild@0.18.20 │
    │ │ │
    │ │ . > drizzle-kit@0.25.0 > esbuild@0.19.12 │
    │ │ │
    │ │ . > drizzle-kit@0.25.0 > esbuild-register@3.6.0 > │
    │ │ esbuild@0.19.12 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-67mh-4wv8-2f99
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ moderate │ PrismJS DOM Clobbering vulnerability │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ prismjs │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ <1.30.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=1.30.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > react-syntax-highlighter@15.6.6 > refractor@3.6.0 │
    │ │ > prismjs@1.27.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-x7hr-w5r2-h6wg
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ moderate │ NextAuthjs Email misdelivery Vulnerability │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ next-auth │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ >=5.0.0-beta.0 <5.0.0-beta.30 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=5.0.0-beta.30 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > next-auth@5.0.0-beta.25 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-5jpx-9hw9-2fx4
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ moderate │ Undici has an unbounded decompression chain in HTTP │
    │ │ responses on Node.js Fetch API via Content-Encoding │
    │ │ leads to resource exhaustion │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ undici │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ <6.23.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=6.23.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > @vercel/blob@0.24.1 > undici@5.28.5 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-g9mf-h72j-4rw9
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ moderate │ Next.js self-hosted applications vulnerable to DoS via │
    │ │ Image Optimizer remotePatterns configuration │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ next │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ >=15.6.0-canary.0 <16.1.5 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=16.1.5 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > @vercel/analytics@1.5.0 > next@16.0.10 │
    │ │ │
    │ │ . > geist@1.3.1 > next@16.0.10 │
    │ │ │
    │ │ . > next@16.0.10 │
    │ │ │
    │ │ ... Found 4 paths, run pnpm why next for more │
    │ │ information │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-9g9p-9gw9-jx7f
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ moderate │ Next.js has Unbounded Memory Consumption via PPR │
    │ │ Resume Endpoint │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ next │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ >=16.0.0-beta.0 <16.1.5 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=16.1.5 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > @vercel/analytics@1.5.0 > next@16.0.10 │
    │ │ │
    │ │ . > geist@1.3.1 > next@16.0.10 │
    │ │ │
    │ │ . > next@16.0.10 │
    │ │ │
    │ │ ... Found 4 paths, run pnpm why next for more │
    │ │ information │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-5f7q-jpqc-wp7h
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ moderate │ mdast-util-to-hast has unsanitized class attribute │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ mdast-util-to-hast │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ >=13.0.0 <13.2.1 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=13.2.1 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > shiki@3.21.0 > @shikijs/core@3.21.0 > │
    │ │ hast-util-to-html@9.0.5 > mdast-util-to-hast@13.2.0 │
    │ │ │
    │ │ . > streamdown@2.0.1 > rehype-raw@7.0.0 > │
    │ │ hast-util-raw@9.1.0 > mdast-util-to-hast@13.2.0 │
    │ │ │
    │ │ . > streamdown@2.0.1 > remark-rehype@11.1.2 > │
    │ │ mdast-util-to-hast@13.2.0 │
    │ │ │
    │ │ ... Found 4 paths, run pnpm why mdast-util-to-hast
    │ │ for more information │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-4fh9-h7wg-q85m
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ moderate │ markdown-it is has a Regular Expression Denial of │
    │ │ Service (ReDoS) │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ markdown-it │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ >=13.0.0 <14.1.1 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=14.1.1 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > prosemirror-markdown@1.13.1 > markdown-it@14.1.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-38c4-r59v-3vqw
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ moderate │ Undici has an HTTP Request/Response Smuggling issue │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ undici │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ <6.24.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=6.24.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > @vercel/blob@0.24.1 > undici@5.28.5 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-2mjp-6q6p-2qxm
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ moderate │ Undici has CRLF Injection in undici via upgrade
    │ │ option │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ undici │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ <6.24.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=6.24.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > @vercel/blob@0.24.1 > undici@5.28.5 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-4992-7rv2-5pvq
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ moderate │ Next.js: HTTP request smuggling in rewrites │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ next │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ >=16.0.0-beta.0 <16.1.7 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=16.1.7 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > @vercel/analytics@1.5.0 > next@16.0.10 │
    │ │ │
    │ │ . > geist@1.3.1 > next@16.0.10 │
    │ │ │
    │ │ . > next@16.0.10 │
    │ │ │
    │ │ ... Found 4 paths, run pnpm why next for more │
    │ │ information │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-ggv3-7p47-pfv8
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ moderate │ Next.js: Unbounded next/image disk cache growth can │
    │ │ exhaust storage │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ next │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ >=16.0.0-beta.0 <16.1.7 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=16.1.7 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > @vercel/analytics@1.5.0 > next@16.0.10 │
    │ │ │
    │ │ . > geist@1.3.1 > next@16.0.10 │
    │ │ │
    │ │ . > next@16.0.10 │
    │ │ │
    │ │ ... Found 4 paths, run pnpm why next for more │
    │ │ information │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-3x4c-7xq6-9pq8
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ moderate │ Next.js: Unbounded postponed resume buffering can lead │
    │ │ to DoS │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ next │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ >=16.0.1 <16.1.7 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=16.1.7 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > @vercel/analytics@1.5.0 > next@16.0.10 │
    │ │ │
    │ │ . > geist@1.3.1 > next@16.0.10 │
    │ │ │
    │ │ . > next@16.0.10 │
    │ │ │
    │ │ ... Found 4 paths, run pnpm why next for more │
    │ │ information │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-h27x-g6w4-24gq
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ moderate │ Next.js: null origin can bypass Server Actions CSRF │
    │ │ checks │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ next │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ >=16.0.1 <16.1.7 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=16.1.7 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > @vercel/analytics@1.5.0 > next@16.0.10 │
    │ │ │
    │ │ . > geist@1.3.1 > next@16.0.10 │
    │ │ │
    │ │ . > next@16.0.10 │
    │ │ │
    │ │ ... Found 4 paths, run pnpm why next for more │
    │ │ information │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-mq59-m269-xvcx
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ low │ undici Denial of Service attack via bad certificate │
    │ │ data │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ undici │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ <5.29.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=5.29.0 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > @vercel/blob@0.24.1 > undici@5.28.5 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-cxrh-j4jr-qwg3
    └─────────────────────┴────────────────────────────────────────────────────────┘
    ┌─────────────────────┬────────────────────────────────────────────────────────┐
    │ low │ Next.js: null origin can bypass dev HMR websocket CSRF │
    │ │ checks │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Package │ next │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Vulnerable versions │ >=16.0.1 <16.1.7 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Patched versions │ >=16.1.7 │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ Paths │ . > @vercel/analytics@1.5.0 > next@16.0.10 │
    │ │ │
    │ │ . > geist@1.3.1 > next@16.0.10 │
    │ │ │
    │ │ . > next@16.0.10 │
    │ │ │
    │ │ ... Found 4 paths, run pnpm why next for more │
    │ │ information │
    ├─────────────────────┼────────────────────────────────────────────────────────┤
    │ More info │ GHSA-jcc7-9wpm-mj36
    └─────────────────────┴────────────────────────────────────────────────────────┘
    25 vulnerabilities found
    Severity: 2 low | 15 moderate | 8 high (2026-03-29) reports 25 vulnerabilities, including 8 high severity findings affecting Playwright, Next.js, @isaacs/brace-expansion, minimatch, and undici.
  • High severity advisories: GHSA-7mvr-c777-76hp, GHSA-h25m-26qc-wcjf, GHSA-7h2j-956f-4vf2, GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj, GHSA-23c5-xmqv-rm74, GHSA-vrm6-8vpv-qv8q, GHSA-v9p9-hfj2-hcw8.
  • They come via @vercel/analytics + geist (Next + Playwright) and @vercel/blob / ultracite (undici/minimatch).

Repro

  1. cd vercel-ai-chatbot
  2. pnpm install
  3. pnpm audit

Recommended actions

  1. Upgrade Next / @vercel/analytics / geist to a release that depends on Next >=16.0.11 (preferably >=16.1.7) and @playwright/test >=1.55.1 so Playwright pulls in 1.55.1 or later.
  2. Bump undici to >=6.24.0 (e.g., via @vercel/blob or another direct consumer that currently provides 5.28.5).
  3. Resolve the @isaacs/brace-expansion / minimatch chain by bumping glob / ultracite so brace-expansion >=5.0.1 and minimatch >=10.2.3 are used in the tree.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions