Skip to content

Update Socket patches: +11 patches - #259

Open
socket-security[bot] wants to merge 1 commit into
mainfrom
socket/autopatch-1786551759097-217e070e
Open

Update Socket patches: +11 patches#259
socket-security[bot] wants to merge 1 commit into
mainfrom
socket/autopatch-1786551759097-217e070e

Conversation

@socket-security

Copy link
Copy Markdown

Summary

This PR updates Socket security patches for your dependencies.

These patches are applied via the Socket patch agent — .socket/manifest.json + a package.json postinstall hook.

Changes

  • Added: CVE-2026-4800 in pkg:npm/lodash-es@4.17.21 (Socket Patch)
    • Severity: HIGH
    • Summary: lodash vulnerable to Code Injection via _.template imports key names
  • Added: CVE-2026-4800 in pkg:npm/lodash-es@4.17.23 (Socket Patch)
    • Severity: HIGH
    • Summary: lodash vulnerable to Code Injection via _.template imports key names
  • Added: CVE-2026-6322 in pkg:npm/fast-uri@3.0.1 (Socket Patch)
    • Severity: HIGH
    • Summary: fast-uri vulnerable to host confusion via percent-encoded authority delimiters
  • Added: CVE-2026-4800 in pkg:npm/lodash@4.17.21 (Socket Patch)
    • Severity: HIGH
    • Summary: lodash vulnerable to Code Injection via _.template imports key names
  • Added: CVE-2026-6321 in pkg:npm/fast-uri@3.0.1 (Socket Patch)
    • Severity: HIGH
    • Summary: fast-uri vulnerable to path traversal via percent-encoded dot segments
  • Added: CVE-2026-33671 in pkg:npm/picomatch@2.3.1 (Socket Patch)
    • Severity: HIGH
    • Summary: Picomatch has a ReDoS vulnerability via extglob quantifiers
  • Added: CVE-2026-33937 in pkg:npm/handlebars@4.7.8 (Socket Patch)
    • Severity: CRITICAL
    • Summary: Handlebars.js has JavaScript Injection via AST Type Confusion
  • Added: CVE-2022-37601 in pkg:npm/loader-utils@1.4.0 (Socket Patch)
    • Severity: CRITICAL
    • Summary: Prototype pollution in webpack loader-utils
  • Added: CVE-2026-9277 in pkg:npm/shell-quote@1.8.1 (Socket Patch)
    • Severity: CRITICAL
    • Summary: shell-quote quote() does not escape newlines in object .op values
  • Added: CVE-2022-25883 in pkg:npm/semver@5.7.1 (Socket Patch)
    • Severity: HIGH
    • Summary: semver vulnerable to Regular Expression Denial of Service
  • Added: CVE-2022-46175 in pkg:npm/json5@1.0.1 (Socket Patch)
    • Severity: HIGH
    • Summary: Prototype Pollution in JSON5 via Parse Method

Testing

Review the patches and test your application to ensure compatibility.


🔒 Powered by Socket Security

Updates:
- 22 blob(s) added
- 0 blob(s) removed
- Manifest updated
@linux-foundation-easycla

Copy link
Copy Markdown

CLA Not Signed

@codecov

codecov Bot commented Aug 12, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 14.75%. Comparing base (95079c4) to head (64efaad).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #259   +/-   ##
=======================================
  Coverage   14.75%   14.75%           
=======================================
  Files           9        9           
  Lines         732      732           
  Branches      166      168    +2     
=======================================
  Hits          108      108           
  Misses        543      543           
  Partials       81       81           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant