lodash vulnerable to Code Injection via `_.template` imports key names
Affects 3 install paths
These advisories have no fix version Arguss can apply automatically. Review and remediate manually.
The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed based on step 3.2 of RFC 6979 https://datatracker.ietf.org/doc/html/rfc6979 ) has leading zeros and is susceptible to cryptanalysis, which can lead to secret key exposure. This happens, because the byte-length of 'k' is incorrectly computed, resulting in its getting truncated during the computation. Legitimate transactions or communications will be broken as a result. Furthermore, due to the nature of the fault, attackers could–under certain conditions–derive the secret key, if they could get their hands on both a faulty signature generated by a vulnerable version of Elliptic and a correct signature for the same inputs. This issue affects all known versions of Elliptic (at the time of writing, versions less than or equal to 6.6.1).
Dependency path: root → node-polyfill-webpack-plugin → crypto-browserify → browserify-sign → elliptic
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions `pick`, `set`, `setWith`, `update`, `updateWith`, and `zipObjectDeep` allow a malicious user to modify the prototype of Object if the property identifiers are user-supplied. Being affected by this issue requires manipulating objects based on user-provided property values or arrays. This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances.
Dependency path: root → cheerio → lodash.pick
Affects 3 install paths
Affects 3 install paths
Upgrade lodash from 4.17.23 to 4.18.0 or later
View advisoryPaths from project root to lodash - which dependencies pulled this package in?
Upgrade underscore from 1.4.4 to 1.12.1 or later
View advisoryPaths from project root to underscore - which dependencies pulled this package in?
Upgrade axios from 0.21.4 to 0.32.0 or later
View advisoryPaths from project root to axios - which dependencies pulled this package in?
Upgrade nth-check from 1.0.2 to 2.0.1 or later
View advisoryPaths from project root to nth-check - which dependencies pulled this package in?
Upgrade cross-spawn from 5.1.0 to 6.0.6 or later
View advisoryPaths from project root to cross-spawn - which dependencies pulled this package in?
Upgrade diff from 7.0.0 to 8.0.3 or later
View advisoryPaths from project root to diff - which dependencies pulled this package in?
Upgrade serialize-javascript from 6.0.2 to 7.0.3 or later
View advisoryPaths from project root to serialize-javascript - which dependencies pulled this package in?
Upgrade js-yaml from 4.1.1 to 4.3.0 or later
View advisoryPaths from project root to js-yaml - which dependencies pulled this package in?
Upgrade qs from 6.14.2 to 6.15.2 or later
View advisoryPaths from project root to qs - which dependencies pulled this package in?
Upgrade uuid from 8.3.2 to 11.1.1 or later
View advisoryPaths from project root to uuid - which dependencies pulled this package in?
Upgrade markdown-it from 14.1.1 to 14.2.0 or later
View advisoryPaths from project root to markdown-it - which dependencies pulled this package in?
1155 packages scanned.
Review auto-merge candidates and open PRs in a guided flow.
What the labels and signals mean.
fix_kind.majortrust.new_maintainertrust.ownership_transferredtrust.new_maintainer, this is the highest-risk trust combination, typical of the xz-utils style attacks and historical npm credential theft incidents.pipeline.test_realitypackage.json, it isn't a no-op, real test files exist, and a workflow actually invokes them. If any fail, the fix cannot qualify for AUTO_MERGE because there's no way to verify the upgrade didn't break the user's project.Full-project map of transitive dependencies. Severity colors reflect vulnerabilities; trust rings apply only to direct dependencies analyzed by OpenSSF Scorecard (higher = riskier).