Skip to content

Conversation

@q1blue
Copy link
Collaborator

@q1blue q1blue commented Jan 13, 2026

snyk-top-banner

Snyk has created this PR to fix 17 vulnerabilities in the pnpm dependencies of this project.

Snyk changed the following file(s):

  • packages/email-server/package.json
⚠️ Warning
Failed to update the pnpm-lock.yaml, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
critical severity Remote Code Execution (RCE)
SNYK-JS-MYSQL2-6591085
  658  
critical severity Improper Authorization
SNYK-JS-NEXT-9508709
  529  
high severity Prototype Pollution
SNYK-JS-MYSQL2-6861580
  510  
critical severity Arbitrary Code Injection
SNYK-JS-MYSQL2-6670046
  432  
medium severity Server-side Request Forgery (SSRF)
SNYK-JS-AXIOS-9292519
  310  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LUXON-3225081
  266  
high severity Cross-site Request Forgery (CSRF)
SNYK-JS-AXIOS-6032459
  258  
medium severity Server-side Request Forgery (SSRF)
SNYK-JS-AXIOS-9403194
  215  
high severity Improper Validation of Specified Type of Input
SNYK-JS-FASTIFY-9788069
  206  
medium severity Prototype Poisoning
SNYK-JS-MYSQL2-6591084
  186  
medium severity Use of Web Browser Cache Containing Sensitive Information
SNYK-JS-MYSQL2-6591300
  185  
medium severity Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
  131  
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JS-AXIOS-12613773
  111  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-AXIOS-6124857
  105  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-NODEMAILER-6219989
  105  
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BRACEEXPANSION-9789073
  57  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-FINDMYWAY-8055229
  45  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Allocation of Resources Without Limits or Throttling
🦉 Cross-site Request Forgery (CSRF)
🦉 Regular Expression Denial of Service (ReDoS)
🦉 More lessons are available in Snyk Learn

@changeset-bot
Copy link

changeset-bot bot commented Jan 13, 2026

⚠️ No Changeset found

Latest commit: c37e56b

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@socket-security
Copy link

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​webpack-cli@​3.3.129710010083100
Addednpm/​webpack-dev-server@​3.11.3969810091100
Addednpm/​webpack@​4.46.09510010096100

View full report

@socket-security
Copy link

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
Critical CVE: Authorization Bypass Through User-Controlled Key in npm url-parse

CVE: GHSA-hgjh-723h-mx2j Authorization Bypass Through User-Controlled Key in url-parse (CRITICAL)

Affected versions: < 1.5.8

Patched version: 1.5.8

From: ?npm/webpack-dev-server@3.11.3npm/url-parse@1.5.3

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/url-parse@1.5.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants