| critical |
#145 |
protobufjs |
pnpm-lock.yaml |
< 7.5.5 |
7.5.5 |
GHSA-xq3m-2v4x-88gg |
Arbitrary code execution in protobufjs |
| critical |
#212 |
vitest |
pnpm-lock.yaml |
< 3.2.6 |
3.2.6 |
GHSA-5xrq-8626-4rwp |
When Vitest UI server is listening, arbitrary file can be read and executed |
| high |
#162 |
@babel/plugin-transform-modules-systemjs |
pnpm-lock.yaml |
>= 7.12.0, <= 7.29.3 |
7.29.4 |
GHSA-fv7c-fp4j-7gwp |
@babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input |
| high |
#95 |
axios |
pnpm-lock.yaml |
>= 1.0.0, <= 1.13.4 |
1.13.5 |
GHSA-43fc-jf86-j433 |
Axios is Vulnerable to Denial of Service via proto Key in mergeConfig |
| high |
#152 |
axios |
pnpm-lock.yaml |
>= 1.0.0, < 1.15.1 |
1.15.1 |
GHSA-6chq-wfr3-2hj9 |
Axios: Header Injection via Prototype Pollution |
| high |
#155 |
axios |
pnpm-lock.yaml |
>= 1.0.0, < 1.15.1 |
1.15.1 |
GHSA-pf86-5x62-jrwf |
Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking |
| high |
#185 |
axios |
pnpm-lock.yaml |
>= 1.0.0, < 1.15.2 |
1.15.2 |
GHSA-q8qp-cvcw-x6jj |
Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking |
| high |
#194 |
axios |
pnpm-lock.yaml |
>= 1.0.0, < 1.15.1 |
1.15.1 |
GHSA-pmwg-cvhr-8vh7 |
Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0 |
| high |
#203 |
axios |
pnpm-lock.yaml |
>= 1.0.0, < 1.16.0 |
1.16.0 |
GHSA-pjwm-pj3p-43mv |
axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718) |
| high |
#204 |
axios |
pnpm-lock.yaml |
>= 1.0.0, < 1.16.0 |
1.16.0 |
GHSA-35jp-ww65-95wh |
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in config.proxy |
| high |
#205 |
axios |
pnpm-lock.yaml |
>= 1.0.0, < 1.15.2 |
1.15.2 |
GHSA-3g43-6gmg-66jw |
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge |
| high |
#208 |
axios |
pnpm-lock.yaml |
>= 1.7.0, < 1.16.0 |
1.16.0 |
GHSA-777c-7fjr-54vf |
Allocation of Resources Without Limits or Throttling in Axios |
| high |
#209 |
axios |
pnpm-lock.yaml |
>= 1.0.0, < 1.16.0 |
1.16.0 |
GHSA-hfxv-24rg-xrqf |
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection |
| high |
#210 |
axios |
pnpm-lock.yaml |
>= 1.0.0, < 1.16.0 |
1.16.0 |
GHSA-j5f8-grm9-p9fc |
Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection |
| high |
#211 |
axios |
pnpm-lock.yaml |
>= 1.0.0, < 1.16.0 |
1.16.0 |
GHSA-p92q-9vqr-4j8v |
Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter |
| high |
#160 |
fast-uri |
pnpm-lock.yaml |
<= 3.1.0 |
3.1.1 |
GHSA-q3j6-qgpj-74h6 |
fast-uri vulnerable to path traversal via percent-encoded dot segments |
| high |
#161 |
fast-uri |
pnpm-lock.yaml |
<= 3.1.1 |
3.1.2 |
GHSA-v39h-62p7-jpjc |
fast-uri vulnerable to host confusion via percent-encoded authority delimiters |
| high |
#159 |
fast-xml-builder |
pnpm-lock.yaml |
<= 1.1.6 |
1.1.7 |
GHSA-5wm8-gmm8-39j9 |
fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributes |
| high |
#226 |
form-data |
pnpm-lock.yaml |
< 2.5.6 |
2.5.6 |
GHSA-hmw2-7cc7-3qxx |
form-data: CRLF injection in form-data via unescaped multipart field names and filenames |
| high |
#227 |
form-data |
pnpm-lock.yaml |
>= 4.0.0, < 4.0.6 |
4.0.6 |
GHSA-hmw2-7cc7-3qxx |
form-data: CRLF injection in form-data via unescaped multipart field names and filenames |
| high |
#92 |
glob |
packages/bruno-api-typescript/package-lock.json |
>= 10.2.0, < 10.5.0 |
10.5.0 |
GHSA-5j98-mcp5-4vw2 |
glob CLI: Command injection via -c/--cmd executes matches with shell:true |
| high |
#98 |
minimatch |
pnpm-lock.yaml |
>= 9.0.0, < 9.0.6 |
9.0.6 |
GHSA-3ppc-4f35-3m26 |
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern |
| high |
#99 |
minimatch |
packages/bruno-api-typescript/package-lock.json |
>= 9.0.0, < 9.0.6 |
9.0.6 |
GHSA-3ppc-4f35-3m26 |
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern |
| high |
#101 |
minimatch |
pnpm-lock.yaml |
>= 9.0.0, < 9.0.7 |
9.0.7 |
GHSA-7r86-cg39-jmmj |
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments |
| high |
#102 |
minimatch |
packages/bruno-api-typescript/package-lock.json |
>= 9.0.0, < 9.0.7 |
9.0.7 |
GHSA-7r86-cg39-jmmj |
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments |
| high |
#103 |
minimatch |
pnpm-lock.yaml |
>= 9.0.0, < 9.0.7 |
9.0.7 |
GHSA-23c5-xmqv-rm74 |
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions |
| high |
#104 |
minimatch |
packages/bruno-api-typescript/package-lock.json |
>= 9.0.0, < 9.0.7 |
9.0.7 |
GHSA-23c5-xmqv-rm74 |
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions |
| high |
#124 |
picomatch |
pnpm-lock.yaml |
>= 4.0.0, < 4.0.4 |
4.0.4 |
GHSA-c2c7-rcm5-vvqj |
Picomatch has a ReDoS vulnerability via extglob quantifiers |
| high |
#130 |
picomatch |
pnpm-lock.yaml |
< 2.3.2 |
2.3.2 |
GHSA-c2c7-rcm5-vvqj |
Picomatch has a ReDoS vulnerability via extglob quantifiers |
| high |
#165 |
protobufjs |
pnpm-lock.yaml |
<= 7.5.5 |
7.5.6 |
GHSA-75px-5xx7-5xc7 |
protobuf.js: Code generation gadget after prototype pollution |
| high |
#166 |
protobufjs |
pnpm-lock.yaml |
<= 7.5.5 |
7.5.6 |
GHSA-jvwf-75h9-cwgg |
protobuf.js: Process-wide denial of service through unsafe option paths |
| high |
#169 |
protobufjs |
pnpm-lock.yaml |
<= 7.5.5 |
7.5.6 |
GHSA-66ff-xgx4-vchm |
protobuf.js: Code injection through bytes field defaults in generated toObject code |
| high |
#100 |
rollup |
pnpm-lock.yaml |
>= 4.0.0, < 4.59.0 |
4.59.0 |
GHSA-mw96-cpmx-2vgc |
Rollup 4 has Arbitrary File Write via Path Traversal |
| high |
#106 |
svgo |
pnpm-lock.yaml |
>= 3.0.0, < 3.3.3 |
3.3.3 |
GHSA-xpqw-6gx7-v673 |
SVGO DoS through entity expansion in DOCTYPE (Billion Laughs) |
| high |
#136 |
vite |
pnpm-lock.yaml |
>= 7.1.0, <= 7.3.1 |
7.3.2 |
GHSA-v2wj-q39q-566r |
Vite: server.fs.deny bypassed with queries |
| high |
#138 |
vite |
pnpm-lock.yaml |
>= 7.0.0, <= 7.3.1 |
7.3.2 |
GHSA-p9ff-h696-f583 |
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket |
| high |
#216 |
vite |
pnpm-lock.yaml |
>= 8.0.0, <= 8.0.15 |
8.0.16 |
GHSA-fx2h-pf6j-xcff |
vite: server.fs.deny bypass on Windows alternate paths |
| high |
#224 |
vite |
pnpm-lock.yaml |
>= 7.0.0, <= 7.3.4 |
7.3.5 |
GHSA-fx2h-pf6j-xcff |
vite: server.fs.deny bypass on Windows alternate paths |
| high |
#220 |
ws |
pnpm-lock.yaml |
>= 7.0.0, < 7.5.11 |
7.5.11 |
GHSA-96hv-2xvq-fx4p |
ws: Memory exhaustion DoS from tiny fragments and data chunks |
| high |
#221 |
ws |
pnpm-lock.yaml |
>= 8.0.0, < 8.21.0 |
8.21.0 |
GHSA-96hv-2xvq-fx4p |
ws: Memory exhaustion DoS from tiny fragments and data chunks |
배경
GitHub Security 탭의 Dependabot open alert가 77건으로 쌓여 있어, 수정 전에 현재 상태와 처리 계획을 한 이슈에 정리합니다.
많아 보이는 이유는 실제 패키지 77개가 아니라 advisory 단위로 alert가 쪼개지기 때문입니다. 예를 들어
axios하나가 24건,protobufjs가 7건,vite가 7건으로 집계됩니다. 또한pnpm-lock.yaml과packages/bruno-api-typescript/package-lock.json처럼 manifest가 나뉘어 같은 계열 취약점이 중복 집계되는 케이스가 있습니다.solid-connection/solid-connect-webDependabot open alertsSeverity 요약
패키지별 집계
Critical / High 상세
< 7.5.57.5.5< 3.2.63.2.6>= 7.12.0, <= 7.29.37.29.4>= 1.0.0, <= 1.13.41.13.5>= 1.0.0, < 1.15.11.15.1>= 1.0.0, < 1.15.11.15.1>= 1.0.0, < 1.15.21.15.2>= 1.0.0, < 1.15.11.15.1>= 1.0.0, < 1.16.01.16.0>= 1.0.0, < 1.16.01.16.0config.proxy>= 1.0.0, < 1.15.21.15.2>= 1.7.0, < 1.16.01.16.0>= 1.0.0, < 1.16.01.16.0>= 1.0.0, < 1.16.01.16.0>= 1.0.0, < 1.16.01.16.0<= 3.1.03.1.1<= 3.1.13.1.2<= 1.1.61.1.7< 2.5.62.5.6>= 4.0.0, < 4.0.64.0.6>= 10.2.0, < 10.5.010.5.0>= 9.0.0, < 9.0.69.0.6>= 9.0.0, < 9.0.69.0.6>= 9.0.0, < 9.0.79.0.7>= 9.0.0, < 9.0.79.0.7>= 9.0.0, < 9.0.79.0.7>= 9.0.0, < 9.0.79.0.7>= 4.0.0, < 4.0.44.0.4< 2.3.22.3.2<= 7.5.57.5.6<= 7.5.57.5.6<= 7.5.57.5.6>= 4.0.0, < 4.59.04.59.0>= 3.0.0, < 3.3.33.3.3>= 7.1.0, <= 7.3.17.3.2server.fs.denybypassed with queries>= 7.0.0, <= 7.3.17.3.2>= 8.0.0, <= 8.0.158.0.16server.fs.denybypass on Windows alternate paths>= 7.0.0, <= 7.3.47.3.5server.fs.denybypass on Windows alternate paths>= 7.0.0, < 7.5.117.5.11>= 8.0.0, < 8.21.08.21.0Medium / Low 상세 목록
< 2.8.02.8.0<= 1.1.01.1.1>= 1.0.0, < 1.15.01.15.0>= 1.0.0, < 1.15.01.15.0>= 1.0.0, < 1.15.11.15.1>= 1.0.0, < 1.15.21.15.2parseReviver>= 1.0.0, < 1.15.11.15.1>= 1.0.0, < 1.15.11.15.1>= 1.0.0, < 1.15.11.15.1>= 1.0.0, < 1.15.11.15.1withXSRFTokenBoolean Coercion>= 1.0.0, < 1.15.11.15.1validateStatusMerge Strategy>= 1.0.0, < 1.15.11.15.1>= 1.0.0, < 1.16.01.16.0>= 2.0.0, < 2.0.32.0.3>= 2.0.0, < 2.0.32.0.3< 5.7.05.7.0<= 1.15.111.16.0<= 4.1.14.2.0>= 4.0.0, < 4.0.44.0.4< 2.3.22.3.2< 8.5.108.5.10<= 7.5.57.5.6<= 7.5.57.5.6<= 7.5.57.5.6<= 2.9.132.9.14< 11.1.111.1.1>= 7.0.0, <= 7.3.17.3.2.mapHandling>= 8.0.0, <= 8.0.158.0.16>= 7.0.0, <= 7.3.47.3.5>= 8.0.0, < 8.20.18.20.1>= 2.0.0, < 2.8.32.8.3>= 2.0.0, < 2.8.32.8.3<= 7.29.07.29.6< 2.0.12.0.1>= 1.0.0, < 1.15.11.15.1>= 0.27.3, < 0.28.10.28.1>= 1.1.0, < 2.9.142.9.141차 처리 계획
axios: workspace 직접 의존성 전체를 patched range인>=1.16.0기준으로 갱신한다.apps/admin의vite:>=8.0.16기준으로 갱신한다.apps/admin의vitest:>=3.2.6기준으로 갱신한다.turbo:>=2.9.14기준으로 갱신한다.pnpm.overrides를 최소 범위로 추가한다.firebase-admin/Google Cloud 계열:protobufjs,form-data,fast-xml-parser,fast-xml-builder확인@commitlint/ajv계열:fast-uri확인rollup,picomatch,ws,svgo,postcss,@babel/*확인packages/bruno-api-typescript/package-lock.json는 별도 npm lockfile이므로,glob,minimatch,brace-expansion,yaml을 npm lockfile 기준으로 별도 갱신한다.pnpm install --frozen-lockfilepnpm --filter @solid-connect/web run ci:checkpnpm --filter @solid-connect/university-web run ci:checkpnpm --filter @solid-connect/admin run ci:check작업 순서 제안
axios,vite,vitest,turbo처럼 직접 의존성 위주로 큰 덩어리 제거firebase-admin/Google Cloud transitive 취약점과pnpm.overrides필요 여부 정리packages/bruno-api-typescript/package-lock.json별도 lockfile 취약점 정리완료 조건
ci:check와 필요한 production build 통과