Skip to content

[stable31] Fix npm audit#1502

Open
nextcloud-command wants to merge 1 commit intostable31from
automated/noid/stable31-fix-npm-audit
Open

[stable31] Fix npm audit#1502
nextcloud-command wants to merge 1 commit intostable31from
automated/noid/stable31-fix-npm-audit

Conversation

@nextcloud-command
Copy link
Contributor

Audit report

This audit fix resolves 2 of the total 51 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@nextcloud/webpack-vue-config #

fast-xml-parser #

  • fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
  • Severity: critical 🚨 (CVSS 9.3)
  • Reference: GHSA-m7jm-9gc2-mpf2
  • Affected versions: 4.0.0-beta.0 - 4.5.3 || 5.0.0 - 5.3.7
  • Package usage:
    • node_modules/fast-xml-parser
    • node_modules/webdav/node_modules/fast-xml-parser

Signed-off-by: GitHub <noreply@github.com>
@codecov
Copy link

codecov bot commented Mar 8, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant