Vulnerability Report β rgb-sdk-web-sandbox
Table of Contents
Node.js Β· rgb-sdk-web-demo
|
|
| Path |
. |
| Vulnerabilities |
13 |
| π΄ Critical |
π High |
π‘ Moderate |
π’ Low |
βͺ Info |
| 0 |
1 |
6 |
6 |
0 |
| Package |
Severity |
Range |
Fix |
Via |
nanoid |
π high |
<3.3.18 |
3.3.18 |
nanoid: custom generators can loop indefinitely when size is zero |
postcss |
π‘ moderate |
<=8.5.22 |
β
(auto) |
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q β attacker-controlled sourceMappingURL reads arbitrary .map files when from is unset |
qs |
π‘ moderate |
2.2.5 - 6.15.3 |
6.16.0 |
qs array-limit bypass via bracket-key comma parsing, qs: Denial of Service via Attacker Controlled isBuffer |
react-router |
π‘ moderate |
6.0.0 - 7.17.0 |
7.18.0 |
React Router: Open redirect via backslash in and useNavigate (CVE-2025-68470 bypass), React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration |
react-router-dom |
π‘ moderate |
6.0.0-alpha.0 - 7.17.0 |
β
(auto) |
React Router: Open redirect leading to XSS, react-router |
uuid |
π‘ moderate |
<11.1.1 |
vite-plugin-top-level-await@1.2.2 β οΈ breaking |
uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided |
vite-plugin-top-level-await |
π‘ moderate |
>=1.2.3 |
vite-plugin-top-level-await@1.2.2 β οΈ breaking |
uuid |
browserify-sign |
π’ low |
>=2.4.0 |
vite-plugin-node-polyfills@0.2.0 β οΈ breaking |
elliptic |
create-ecdh |
π’ low |
* |
vite-plugin-node-polyfills@0.2.0 β οΈ breaking |
elliptic |
crypto-browserify |
π’ low |
>=3.4.0 |
vite-plugin-node-polyfills@0.2.0 β οΈ breaking |
browserify-sign, create-ecdh |
elliptic |
π’ low |
* |
vite-plugin-node-polyfills@0.2.0 β οΈ breaking |
Elliptic Uses a Cryptographic Primitive with a Risky Implementation |
node-stdlib-browser |
π’ low |
* |
vite-plugin-node-polyfills@0.2.0 β οΈ breaking |
crypto-browserify |
vite-plugin-node-polyfills |
π’ low |
>=0.3.0 |
vite-plugin-node-polyfills@0.2.0 β οΈ breaking |
node-stdlib-browser |
Recommended fixes:
Automatically fixable β run:
Breaking-change upgrades (semver major β test carefully):
vite-plugin-node-polyfills β 0.2.0
vite-plugin-top-level-await β 1.2.2
npm install vite-plugin-node-polyfills@0.2.0
npm install vite-plugin-top-level-await@1.2.2
Vulnerability Report β rgb-sdk-web-sandbox
Table of Contents
Node.js Β·
rgb-sdk-web-demo.nanoid<3.3.183.3.18postcss<=8.5.22fromis unsetqs2.2.5 - 6.15.36.16.0react-router6.0.0 - 7.17.07.18.0react-router-dom6.0.0-alpha.0 - 7.17.0uuid<11.1.1vite-plugin-top-level-await@1.2.2vite-plugin-top-level-await>=1.2.3vite-plugin-top-level-await@1.2.2browserify-sign>=2.4.0vite-plugin-node-polyfills@0.2.0create-ecdh*vite-plugin-node-polyfills@0.2.0crypto-browserify>=3.4.0vite-plugin-node-polyfills@0.2.0elliptic*vite-plugin-node-polyfills@0.2.0node-stdlib-browser*vite-plugin-node-polyfills@0.2.0vite-plugin-node-polyfills>=0.3.0vite-plugin-node-polyfills@0.2.0Recommended fixes:
Automatically fixable β run:
Breaking-change upgrades (semver major β test carefully):
vite-plugin-node-polyfillsβ0.2.0vite-plugin-top-level-awaitβ1.2.2