[Aikido] Fix 23 security issues in fast-xml-parser, fast-uri, aws-cdk-lib and 6 more - #46
Closed
aikido-autofix[bot] wants to merge 1 commit into
Closed
Conversation
Package lock diff2.4.1 -> 2.6.1 node_modules/@ampproject/remapping removed node_modules/@aws-cdk/asset-awscli-v1 2.2.242 -> 2.2.282 node_modules/@aws-cdk/asset-node-proxy-agent-v6 2.1.0 -> 2.1.2 node_modules/@aws-cdk/cloud-assembly-schema 45.2.0 -> 54.12.0 node_modules/@aws-cdk/cloud-assembly-schema/node_modules/jsonschema 1.4.1 -> 1.5.0 node_modules/@aws-cdk/cloud-assembly-schema/node_modules/semver 7.7.2 -> 7.8.5 node_modules/@aws-crypto/sha256-browser removed node_modules/@aws-crypto/sha256-browser/node_modules/@smithy/is-array-buffer removed node_modules/@aws-crypto/sha256-browser/node_modules/@smithy/util-buffer-from removed node_modules/@aws-crypto/sha256-browser/node_modules/@smithy/util-utf8 removed node_modules/@aws-crypto/sha256-js removed node_modules/@aws-crypto/supports-web-crypto removed node_modules/@aws-crypto/util removed node_modules/@aws-crypto/util/node_modules/@smithy/is-array-buffer removed node_modules/@aws-crypto/util/node_modules/@smithy/util-buffer-from removed node_modules/@aws-crypto/util/node_modules/@smithy/util-utf8 removed node_modules/@aws-sdk/client-cognito-identity removed node_modules/@aws-sdk/client-secrets-manager 3.840.0 -> 3.1090.0 node_modules/@aws-sdk/client-sso removed node_modules/@aws-sdk/core 3.840.0 -> 3.975.3 node_modules/@aws-sdk/credential-provider-cognito-identity 3.840.0 -> 3.972.58 node_modules/@aws-sdk/credential-provider-env 3.840.0 -> 3.972.59 node_modules/@aws-sdk/credential-provider-http 3.840.0 -> 3.972.61 node_modules/@aws-sdk/credential-provider-ini 3.840.0 -> 3.973.4 node_modules/@aws-sdk/credential-provider-node 3.840.0 -> 3.972.70 node_modules/@aws-sdk/credential-provider-process 3.840.0 -> 3.972.59 node_modules/@aws-sdk/credential-provider-sso 3.840.0 -> 3.973.3 node_modules/@aws-sdk/credential-provider-web-identity 3.840.0 -> 3.972.65 node_modules/@aws-sdk/credential-providers 3.840.0 -> 3.1090.0 node_modules/@aws-sdk/middleware-host-header removed node_modules/@aws-sdk/middleware-logger removed node_modules/@aws-sdk/middleware-recursion-detection removed node_modules/@aws-sdk/middleware-user-agent removed node_modules/@aws-sdk/nested-clients 3.840.0 -> 3.997.33 node_modules/@aws-sdk/region-config-resolver removed node_modules/@aws-sdk/token-providers 3.840.0 -> 3.1088.0 node_modules/@aws-sdk/types 3.840.0 -> 3.974.2 node_modules/@aws-sdk/util-endpoints removed node_modules/@aws-sdk/util-locate-window removed node_modules/@aws-sdk/util-user-agent-browser removed node_modules/@aws-sdk/util-user-agent-node removed node_modules/@aws-sdk/xml-builder 3.821.0 -> 3.972.36 node_modules/@babel/code-frame 7.27.1 -> 7.29.7 node_modules/@babel/compat-data 7.28.0 -> 7.29.7 node_modules/@babel/core 7.28.0 -> 7.29.7 node_modules/@babel/generator 7.28.0 -> 7.29.7 node_modules/@babel/helper-compilation-targets 7.27.2 -> 7.29.7 node_modules/@babel/helper-globals 7.28.0 -> 7.29.7 node_modules/@babel/helper-module-imports 7.27.1 -> 7.29.7 node_modules/@babel/helper-module-transforms 7.27.3 -> 7.29.7 node_modules/@babel/helper-plugin-utils 7.27.1 -> 7.29.7 node_modules/@babel/helper-string-parser 7.27.1 -> 7.29.7 node_modules/@babel/helper-validator-identifier 7.27.1 -> 7.29.7 node_modules/@babel/helper-validator-option 7.27.1 -> 7.29.7 node_modules/@babel/helpers 7.27.6 -> 7.29.7 node_modules/@babel/parser 7.28.0 -> 7.29.7 node_modules/@babel/plugin-syntax-import-attributes 7.27.1 -> 7.29.7 node_modules/@babel/plugin-syntax-jsx 7.27.1 -> 7.29.7 node_modules/@babel/plugin-syntax-typescript 7.27.1 -> 7.29.7 node_modules/@babel/template 7.27.2 -> 7.29.7 node_modules/@babel/traverse 7.28.0 -> 7.29.7 node_modules/@babel/types 7.28.0 -> 7.29.7 node_modules/@eslint-community/eslint-utils 4.7.0 -> 4.9.1 node_modules/@eslint-community/regexpp 4.12.1 -> 4.12.2 node_modules/@istanbuljs/load-nyc-config/node_modules/js-yaml 3.14.1 -> 3.15.0 node_modules/@istanbuljs/schema 0.1.3 -> 0.1.6 node_modules/@jridgewell/gen-mapping 0.3.12 -> 0.3.13 node_modules/@jridgewell/sourcemap-codec 1.5.4 -> 1.5.5 node_modules/@jridgewell/trace-mapping 0.3.29 -> 0.3.31 node_modules/@sinclair/typebox 0.27.8 -> 0.27.12 node_modules/@smithy/abort-controller removed node_modules/@smithy/config-resolver removed node_modules/@smithy/core 3.6.0 -> 3.29.5 node_modules/@smithy/credential-provider-imds 4.0.6 -> 4.4.10 node_modules/@smithy/fetch-http-handler 5.0.4 -> 5.6.7 node_modules/@smithy/hash-node removed node_modules/@smithy/invalid-dependency removed node_modules/@smithy/is-array-buffer removed node_modules/@smithy/middleware-content-length removed node_modules/@smithy/middleware-endpoint removed node_modules/@smithy/middleware-retry removed node_modules/@smithy/middleware-serde removed node_modules/@smithy/middleware-stack removed node_modules/@smithy/node-config-provider removed node_modules/@smithy/node-http-handler 4.0.6 -> 4.9.7 node_modules/@smithy/property-provider removed node_modules/@smithy/protocol-http removed node_modules/@smithy/querystring-builder removed node_modules/@smithy/querystring-parser removed node_modules/@smithy/service-error-classification removed node_modules/@smithy/shared-ini-file-loader removed node_modules/@smithy/signature-v4 5.1.2 -> 5.6.6 node_modules/@smithy/smithy-client removed node_modules/@smithy/types 4.3.1 -> 4.16.1 node_modules/@smithy/url-parser removed node_modules/@smithy/util-base64 removed node_modules/@smithy/util-body-length-browser removed node_modules/@smithy/util-body-length-node removed node_modules/@smithy/util-buffer-from removed node_modules/@smithy/util-config-provider removed node_modules/@smithy/util-defaults-mode-browser removed node_modules/@smithy/util-defaults-mode-node removed node_modules/@smithy/util-endpoints removed node_modules/@smithy/util-hex-encoding removed node_modules/@smithy/util-middleware removed node_modules/@smithy/util-retry removed node_modules/@smithy/util-stream removed node_modules/@smithy/util-uri-escape removed node_modules/@smithy/util-utf8 removed node_modules/@tsconfig/node10 1.0.11 -> 1.0.12 node_modules/@types/babel__traverse 7.20.7 -> 7.28.0 node_modules/@types/node 18.19.117 -> 18.19.130 node_modules/@types/semver 7.7.0 -> 7.7.1 node_modules/@types/uuid removed node_modules/@types/yargs 17.0.33 -> 17.0.35 node_modules/@ungap/structured-clone 1.3.0 -> 1.3.3 node_modules/acorn 8.15.0 -> 8.17.0 node_modules/acorn-walk 8.3.4 -> 8.3.5 node_modules/ajv 6.12.6 -> 6.15.0 node_modules/async removed node_modules/aws-cdk-lib 2.204.0 -> 2.261.0 node_modules/aws-cdk-lib/node_modules/ajv removed node_modules/aws-cdk-lib/node_modules/ansi-regex removed node_modules/aws-cdk-lib/node_modules/ansi-styles removed node_modules/aws-cdk-lib/node_modules/astral-regex removed node_modules/aws-cdk-lib/node_modules/balanced-match 1.0.2 -> 4.0.4 node_modules/aws-cdk-lib/node_modules/brace-expansion 1.1.12 -> 5.0.6 node_modules/aws-cdk-lib/node_modules/color-convert removed node_modules/aws-cdk-lib/node_modules/color-name removed node_modules/aws-cdk-lib/node_modules/concat-map removed node_modules/aws-cdk-lib/node_modules/emoji-regex removed node_modules/aws-cdk-lib/node_modules/fast-deep-equal removed node_modules/aws-cdk-lib/node_modules/fast-uri removed node_modules/aws-cdk-lib/node_modules/fs-extra 11.3.0 -> 11.3.5 node_modules/aws-cdk-lib/node_modules/is-fullwidth-code-point removed node_modules/aws-cdk-lib/node_modules/json-schema-traverse removed node_modules/aws-cdk-lib/node_modules/jsonfile 6.1.0 -> 6.2.1 node_modules/aws-cdk-lib/node_modules/lodash.truncate removed node_modules/aws-cdk-lib/node_modules/minimatch 3.1.2 -> 10.2.5 node_modules/aws-cdk-lib/node_modules/require-from-string removed node_modules/aws-cdk-lib/node_modules/semver 7.7.2 -> 7.8.1 node_modules/aws-cdk-lib/node_modules/slice-ansi removed node_modules/aws-cdk-lib/node_modules/string-width removed node_modules/aws-cdk-lib/node_modules/strip-ansi removed node_modules/aws-cdk-lib/node_modules/table removed node_modules/aws-cdk-lib/node_modules/yaml 1.10.2 -> 1.10.3 node_modules/babel-preset-current-node-syntax 1.1.0 -> 1.2.0 node_modules/bowser 2.11.0 -> 2.14.1 node_modules/brace-expansion 1.1.12 -> 1.1.16 node_modules/browserslist 4.25.1 -> 4.28.6 node_modules/caniuse-lite 1.0.30001727 -> 1.0.30001806 node_modules/collect-v8-coverage 1.0.2 -> 1.0.3 node_modules/constructs 10.4.2 -> 10.7.0 node_modules/debug 4.4.1 -> 4.4.3 node_modules/dedent 1.6.0 -> 1.7.2 node_modules/diff 4.0.2 -> 4.0.4 node_modules/ejs removed node_modules/electron-to-chromium 1.5.180 -> 1.5.393 node_modules/error-ex 1.3.2 -> 1.3.4 node_modules/eslint-config-prettier 8.10.0 -> 8.10.2 node_modules/eslint-plugin-prettier 4.2.1 -> 4.2.5 node_modules/esquery 1.6.0 -> 1.7.0 node_modules/fast-xml-parser removed node_modules/fastq 1.19.1 -> 1.20.1 node_modules/filelist removed node_modules/filelist/node_modules/brace-expansion removed node_modules/filelist/node_modules/minimatch removed node_modules/flatted 3.3.3 -> 3.4.2 node_modules/hasown 2.0.2 -> 2.0.4 node_modules/is-core-module 2.16.1 -> 2.16.2 node_modules/istanbul-reports 3.1.7 -> 3.2.0 node_modules/jake removed node_modules/js-yaml 4.1.0 -> 4.3.0 node_modules/minimatch 3.1.2 -> 3.1.5 node_modules/node-releases 2.0.19 -> 2.0.51 node_modules/picomatch 2.3.1 -> 2.3.2 node_modules/prettier-linter-helpers 1.0.0 -> 1.0.1 node_modules/resolve 1.22.10 -> 1.22.12 node_modules/semver 7.7.2 -> 7.8.5 node_modules/strnum removed node_modules/ts-jest 29.4.0 -> 29.4.11 node_modules/typescript 5.8.3 -> 5.9.3 node_modules/update-browserslist-db 1.1.3 -> 1.2.3 node_modules/uuid removed node_modules/yargs 17.7.2 -> 17.7.3 node_modules/@aws-sdk/credential-provider-login added node_modules/@aws-sdk/signature-v4-multi-region added node_modules/@aws/lambda-invoke-store added node_modules/@jridgewell/remapping added node_modules/aws-cdk-lib/node_modules/@aws-cdk/cloud-assembly-api added node_modules/baseline-browser-mapping added node_modules/es-errors added node_modules/handlebars added node_modules/minimist added node_modules/neo-async added node_modules/uglify-js added node_modules/wordwrap added |
Author
|
Closed by Aikido: a new AutoFix has been created → #47 |
aikido-autofix
Bot
deleted the
fix/aikido-security-update-packages-70602530-8n4q
branch
July 21, 2026 23:36
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Upgrade dependencies to fix critical XSS via XML entity shadowing, XML entity expansion DoS attacks, stack overflow in XML builder, SSRF bypass via URI parsing, and other security vulnerabilities.
✅ No breaking changes for: fast-xml-parser, fast-uri, brace-expansion, yaml, @smithy/config-resolver
✅ 23 CVEs resolved by this upgrade, including 1 critical 🚨 CVE
This PR will resolve the following CVEs:
preserveOrder:truecauses stack overflow leading to denial of service when processing certain inputs. The application crashes due to improper recursion handling during XML construction.*()and+()) generate regexps with catastrophic backtracking, causing severe ReDoS denial-of-service attacks with minimal input patterns triggering multi-second hangs.$dataoption is enabled by using inherited property names likeconstructorortoStringas format values, causing unexpected validation behavior or errors.🤖 Remediation details
Fix multiple critical/high/medium/low severity vulnerabilities in transitive and direct dependencies
This PR remediates security vulnerabilities in nine packages:
fast-xml-parser,fast-uri,aws-cdk-lib,brace-expansion,yaml,minimatch,@smithy/config-resolver,ajv, andfs-extra. Changes touch the rootpackage.json(three direct dependency version bumps) andpackage-lock.json(lockfile-only resolution updates for all transitive instances).fast-xml-parser
fast-xml-parserwas a transitive dependency pulled in by@aws-sdk/core, which itself was pinned to an exact version by@aws-sdk/client-secrets-managerand@aws-sdk/credential-providers. Bumping both of those direct dependencies inpackage.jsonfrom^3.348.0to^3.844.0caused npm to resolve@aws-sdk/coreto3.975.3, which shipsfast-xml-parser@5.x(well above the patched floor of4.5.5). After the parent bump the vulnerable package no longer appears as a separate lockfile entry.fast-uri
fast-uriwas a transitive dependency ofajv@8.x, which was itself nested underaws-cdk-lib. Bumpingaws-cdk-libinpackage.jsonfrom^2.78.0to^2.260.0resolvedaws-cdk-libto2.261.0, which no longer carries a separately-resolvedfast-urientry at a vulnerable version. The package no longer appears in the lockfile tree.aws-cdk-lib
aws-cdk-libis a direct dependency declared inpackage.json. Its version spec was raised from^2.78.0to^2.260.0, resolving to2.261.0in the lockfile. This was required both to fix the vulnerabilities attributed directly toaws-cdk-liband to pull in patched versions of several of its bundled transitives (yaml,minimatch,ajv,fast-uri,fs-extra).brace-expansion
brace-expansionappears in three lockfile locations. The root instance (underminimatch@3.x) was updated from1.1.12to1.1.16and thefilelist-nested instance (underminimatch@5.x) from2.0.2to2.1.2vianpm update brace-expansion minimatch --package-lock-onlyafter theaws-cdk-libparent bump freed up resolution. The third instance nested underaws-cdk-lib/node_modules/minimatch(a5.xcopy) moved from1.1.12to5.0.6; the parentminimatch@10.2.5declares^5.0.5which permits5.0.7, but npm resolved to the minimum satisfying version and no override shape successfully forced a higher patch — this instance is a partial fix at5.0.6.yaml
yamlwas a transitive dependency pinned exactly as1.10.2byaws-cdk-lib@2.204.0. Bumpingaws-cdk-libto^2.260.0(resolving to2.261.0) caused the nestedyamlcopy to move to1.10.3, which is the patched version.minimatch
minimatchappears in multiple lockfile locations. The root instance (shared byeslint,glob,jake, and others) moved from3.1.2to3.1.5vianpm update minimatch --package-lock-only, satisfying the patched floor of3.1.4. Theaws-cdk-lib-nested instance moved from3.1.2to10.2.5as a result of theaws-cdk-libparent bump. Thefilelist-nested instance moved from5.1.6to5.1.9, also via the lockfile update.@smithy/config-resolver
@smithy/config-resolverwas a transitive dependency of@aws-sdk/client-secrets-managerand related AWS SDK packages, declared as^4.1.4. The patched floor is4.4.0, which falls within that declared range. Bumping@aws-sdk/client-secrets-managerand@aws-sdk/credential-providersto^3.844.0inpackage.jsoncaused npm to resolve the AWS SDK suite to3.1090.0, which pulls in@smithy/config-resolverat a version satisfying>=4.4.0. The package no longer appears as a separately-tracked vulnerable instance in the lockfile.ajv
ajvappears in two lockfile locations. The root instance (used byeslintand@eslint/eslintrc, declared as^6.12.4) moved from6.12.6to6.15.0vianpm update ajv --package-lock-only, satisfying the patched floor of6.14.0. Theaws-cdk-lib-nested8.xinstance was resolved away entirely by theaws-cdk-libparent bump to2.261.0.fs-extra
fs-extrais a transitive dependency nested underaws-cdk-lib. Theaws-cdk-libparent bump to2.261.0updated the declared range forfs-extrato^11.3.5. The patched floor is11.3.6;aws-cdk-lib@2.261.0permits11.3.6under its declared range, but npm resolved to the minimum satisfying version11.3.5. Multiplenpm updateinvocations and override shapes were attempted without success in advancing this patch; this instance is a partial fix at11.3.5.Version changes
aws-cdk-lib^2.78.0→2.204.0^2.260.0→2.261.0@aws-sdk/client-secrets-manager^3.348.0→3.840.0^3.844.0→3.1090.0fast-xml-parserand@smithy/config-resolvertransitives@aws-sdk/credential-providers^3.348.0→3.840.0^3.844.0→3.1090.0fast-xml-parserand@smithy/config-resolvertransitives@aws-sdk/core3.840.03.975.3@aws-sdk/client-secrets-managerfast-xml-parser4.4.1@aws-sdk/coreupgrade; no longer a separate lockfile entryfast-uri3.0.6aws-cdk-libupgrade; no longer a separate lockfile entryyaml(aws-cdk-lib nested)1.10.21.10.3aws-cdk-libminimatch(aws-cdk-lib nested)3.1.210.2.5aws-cdk-libminimatch(root)3.1.23.1.5npm update minimatchminimatch(filelist nested)5.1.65.1.9npm update minimatchbrace-expansion(root)1.1.121.1.16minimatchroot lockfile updatebrace-expansion(filelist nested)2.0.22.1.2minimatchfilelist lockfile updatebrace-expansion(aws-cdk-lib nested)1.1.125.0.6aws-cdk-lib; partial fix (5.0.7 target not achievable)ajv(root)6.12.66.15.0npm update ajvajv(aws-cdk-lib nested)8.17.1aws-cdk-libupgrade@smithy/config-resolver4.1.4@aws-sdk/client-secrets-managerfs-extra(aws-cdk-lib nested)11.3.011.3.5aws-cdk-lib; partial fix (11.3.6 target not achievable)@aws-sdk/client-cognito-identity3.840.03.1090.0@aws-sdk/credential-providers@aws-sdk/client-sso3.840.0@aws-sdk/nested-clients3.840.03.997.33@aws-sdk/token-providers3.840.03.1088.0