Skip to content

chore: fix security vulnerabilities via npm audit fix#149

Open
mattpodwysocki wants to merge 1 commit intomainfrom
chore/update-dependencies
Open

chore: fix security vulnerabilities via npm audit fix#149
mattpodwysocki wants to merge 1 commit intomainfrom
chore/update-dependencies

Conversation

@mattpodwysocki
Copy link
Contributor

Summary

Runs npm audit fix to address 3 high severity vulnerabilities flagged by Dependabot:

Package Vulnerability Severity
@hono/node-server < 1.19.10 Authorization bypass for protected static paths via encoded slashes High
@modelcontextprotocol/sdk 1.10.0–1.25.3 Cross-client data leak via shared server/transport instance reuse High
hono <= 4.12.6 JWT algorithm confusion, XSS via ErrorBoundary component High

Only package-lock.json changed — no code changes.

Test plan

  • All 612 tests pass

🤖 Generated with Claude Code

Addresses 3 high severity vulnerabilities:
- @hono/node-server < 1.19.10 (authorization bypass via encoded slashes)
- @modelcontextprotocol/sdk 1.10.0–1.25.3 (cross-client data leak)
- hono <= 4.12.6 (JWT algorithm confusion, XSS)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@mattpodwysocki mattpodwysocki requested a review from a team as a code owner March 17, 2026 23:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant