Skip to content

[stable33] Fix npm audit - #3318

Open
nextcloud-command wants to merge 1 commit into
stable33from
automated/noid/stable33-fix-npm-audit
Open

[stable33] Fix npm audit#3318
nextcloud-command wants to merge 1 commit into
stable33from
automated/noid/stable33-fix-npm-audit

Conversation

@nextcloud-command

@nextcloud-command nextcloud-command commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Audit report

This audit fix resolves 3 of the total 46 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@nextcloud/cypress #

  • Caused by vulnerable dependency:
  • Affected versions:
  • Package usage:
    • node_modules/@nextcloud/cypress

dompurify #

  • DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound instanceof checks
  • Severity: moderate (CVSS 6.1)
  • Reference: GHSA-hpcv-96wg-7vj8
  • Affected versions: <=3.4.12
  • Package usage:
    • node_modules/dompurify

vite #

  • launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
  • Severity: moderate
  • Reference: GHSA-v6wh-96g9-6wx3
  • Affected versions: 7.0.0 - 7.3.3
  • Package usage:
    • node_modules/vite

@nextcloud-command nextcloud-command added 3. to review Waiting for reviews dependencies Pull requests that update a dependency file labels Aug 2, 2026
Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command
nextcloud-command force-pushed the automated/noid/stable33-fix-npm-audit branch from 8b4f639 to 0372dac Compare August 9, 2026 04:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant