diff --git a/audit.log b/audit.log index 2b09bf892..60cf916e2 100644 --- a/audit.log +++ b/audit.log @@ -4,20 +4,149 @@ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Package │ brace-expansion │ ├─────────────────────┼────────────────────────────────────────────────────────┤ -│ Vulnerable versions │ <=5.0.7 │ +│ Vulnerable versions │ <1.1.17 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ -│ Patched versions │ >=5.0.8 │ +│ Patched versions │ >=1.1.17 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Paths │ .>ejs>jake>minimatch>brace-expansion │ +│ │ │ +│ │ .>jslint>glob>minimatch>brace-expansion │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ More info │ https://github.com/advisories/GHSA-mh99-v99m-4gvg │ +└─────────────────────┴────────────────────────────────────────────────────────┘ +┌─────────────────────┬────────────────────────────────────────────────────────┐ +│ high │ brace-expansion: DoS via unbounded expansion length │ +│ │ causing an out-of-memory process crash │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Package │ brace-expansion │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Vulnerable versions │ >=2.0.0 <2.1.3 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Patched versions │ >=2.1.3 │ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ Paths │ .>ejs>jake>filelist>minimatch>brace-expansion │ │ │ │ │ │ .>mocha>minimatch>brace-expansion │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ More info │ https://github.com/advisories/GHSA-mh99-v99m-4gvg │ +└─────────────────────┴────────────────────────────────────────────────────────┘ +┌─────────────────────┬────────────────────────────────────────────────────────┐ +│ high │ undici vulnerable to cross-user information disclosure │ +│ │ and parse-time crash via degenerate private cache │ +│ │ directives │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Package │ undici │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Vulnerable versions │ >=7.0.0 <7.29.0 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Patched versions │ >=7.29.0 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Paths │ .>cheerio>undici │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ More info │ https://github.com/advisories/GHSA-4cwx-7wf7-3272 │ +└─────────────────────┴────────────────────────────────────────────────────────┘ +┌─────────────────────┬────────────────────────────────────────────────────────┐ +│ high │ brace-expansion: DoS via unbounded intermediate │ +│ │ arrays, bypassing the CVE-2026-14257 mitigation │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Package │ brace-expansion │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Vulnerable versions │ >=4.0.0 <5.0.9 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Patched versions │ >=5.0.9 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Paths │ .>mocha>glob>minimatch>brace-expansion │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ More info │ https://github.com/advisories/GHSA-rgw5-rvv9-x895 │ +└─────────────────────┴────────────────────────────────────────────────────────┘ +┌─────────────────────┬────────────────────────────────────────────────────────┐ +│ high │ brace-expansion: DoS via unbounded intermediate │ +│ │ arrays, bypassing the CVE-2026-14257 mitigation │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Package │ brace-expansion │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Vulnerable versions │ >=2.0.0 <2.1.4 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Patched versions │ >=2.1.4 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Paths │ .>ejs>jake>filelist>minimatch>brace-expansion │ │ │ │ -│ │ .>ejs>jake>minimatch>brace-expansion │ +│ │ .>mocha>minimatch>brace-expansion │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ More info │ https://github.com/advisories/GHSA-rgw5-rvv9-x895 │ +└─────────────────────┴────────────────────────────────────────────────────────┘ +┌─────────────────────┬────────────────────────────────────────────────────────┐ +│ high │ brace-expansion: DoS via unbounded intermediate │ +│ │ arrays, bypassing the CVE-2026-14257 mitigation │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Package │ brace-expansion │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Vulnerable versions │ <1.1.18 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Patched versions │ >=1.1.18 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Paths │ .>ejs>jake>minimatch>brace-expansion │ │ │ │ -│ │ ... Found 4 paths, run `pnpm why brace-expansion` for │ -│ │ more information │ +│ │ .>jslint>glob>minimatch>brace-expansion │ ├─────────────────────┼────────────────────────────────────────────────────────┤ -│ More info │ https://github.com/advisories/GHSA-mh99-v99m-4gvg │ +│ More info │ https://github.com/advisories/GHSA-rgw5-rvv9-x895 │ +└─────────────────────┴────────────────────────────────────────────────────────┘ +┌─────────────────────┬────────────────────────────────────────────────────────┐ +│ moderate │ undici vulnerable to downstream response │ +│ │ desynchronization via retry interceptor │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Package │ undici │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Vulnerable versions │ >=7.0.0 <7.29.0 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Patched versions │ >=7.29.0 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Paths │ .>cheerio>undici │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ More info │ https://github.com/advisories/GHSA-8xcm-r25x-g524 │ +└─────────────────────┴────────────────────────────────────────────────────────┘ +┌─────────────────────┬────────────────────────────────────────────────────────┐ +│ moderate │ undici vulnerable to CRLF Injection via blob-like body │ +│ │ 'type' property │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Package │ undici │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Vulnerable versions │ >=7.0.0 <7.29.0 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Patched versions │ >=7.29.0 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Paths │ .>cheerio>undici │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ More info │ https://github.com/advisories/GHSA-m8rv-5g2x-5cg5 │ +└─────────────────────┴────────────────────────────────────────────────────────┘ +┌─────────────────────┬────────────────────────────────────────────────────────┐ +│ moderate │ undici vulnerable to cross-user information disclosure │ +│ │ via whitespace around equals in Cache-Control │ +│ │ directives │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Package │ undici │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Vulnerable versions │ >=7.0.0 <7.29.0 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Patched versions │ >=7.29.0 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Paths │ .>cheerio>undici │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ More info │ https://github.com/advisories/GHSA-jr45-8vmc-qm54 │ +└─────────────────────┴────────────────────────────────────────────────────────┘ +┌─────────────────────┬────────────────────────────────────────────────────────┐ +│ moderate │ undici vulnerable to cookie attribute injection via │ +│ │ unsanitized domain and unparsed setCookie fields │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Package │ undici │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Vulnerable versions │ >=7.0.0 <7.29.0 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Patched versions │ >=7.29.0 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Paths │ .>cheerio>undici │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ More info │ https://github.com/advisories/GHSA-v3r7-h72x-cjcm │ └─────────────────────┴────────────────────────────────────────────────────────┘ -1 vulnerabilities found -Severity: 1 high +10 vulnerabilities found +Severity: 4 moderate | 6 high diff --git a/lib/loader/pluginLoader.js b/lib/loader/pluginLoader.js index 497f2bf8a..ed70eb45e 100644 --- a/lib/loader/pluginLoader.js +++ b/lib/loader/pluginLoader.js @@ -249,7 +249,8 @@ } // Check if have required method. - var hasSign = PLUGINS_FIELDS.some(sign => sign in plugin); + var hasSign = PLUGINS_FIELDS.some(sign => sign in plugin) + || (CONFIG.GET_VARS_METHODS && Object.keys(CONFIG.GET_VARS_METHODS).some(sign => sign in plugin)); if (!hasSign) { console.warn("No plugin methods in " + pluginPath + ". Add exports.notPlugin = true; to skip this warning."); return;