Skip to content

πŸ” Security Scan β€” 2026-09-24Β #10

Description

@maksym-neboha

Vulnerability Report β€” rgb-sdk-web-sandbox

Date 2026-09-24 12:35 UTC
Repo https://github.com/UTEXO-Protocol/rgb-sdk-web-sandbox
Summary Node.js: 13 vulns

Table of Contents


Node.js Β· rgb-sdk-web-demo

Path .
Vulnerabilities 13
πŸ”΄ Critical 🟠 High 🟑 Moderate 🟒 Low βšͺ Info
0 1 6 6 0
Package Severity Range Fix Via
nanoid 🟠 high <3.3.18 3.3.18 nanoid: custom generators can loop indefinitely when size is zero
postcss 🟑 moderate <=8.5.22 βœ… (auto) PostCSS: incomplete fix of GHSA-6g55-p6wh-862q β€” attacker-controlled sourceMappingURL reads arbitrary .map files when from is unset
qs 🟑 moderate 2.2.5 - 6.15.3 6.16.0 qs array-limit bypass via bracket-key comma parsing, qs: Denial of Service via Attacker Controlled isBuffer
react-router 🟑 moderate 6.0.0 - 7.17.0 7.18.0 React Router: Open redirect via backslash in and useNavigate (CVE-2025-68470 bypass), React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
react-router-dom 🟑 moderate 6.0.0-alpha.0 - 7.17.0 βœ… (auto) React Router: Open redirect leading to XSS, react-router
uuid 🟑 moderate <11.1.1 vite-plugin-top-level-await@1.2.2 ⚠️ breaking uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
vite-plugin-top-level-await 🟑 moderate >=1.2.3 vite-plugin-top-level-await@1.2.2 ⚠️ breaking uuid
browserify-sign 🟒 low >=2.4.0 vite-plugin-node-polyfills@0.2.0 ⚠️ breaking elliptic
create-ecdh 🟒 low * vite-plugin-node-polyfills@0.2.0 ⚠️ breaking elliptic
crypto-browserify 🟒 low >=3.4.0 vite-plugin-node-polyfills@0.2.0 ⚠️ breaking browserify-sign, create-ecdh
elliptic 🟒 low * vite-plugin-node-polyfills@0.2.0 ⚠️ breaking Elliptic Uses a Cryptographic Primitive with a Risky Implementation
node-stdlib-browser 🟒 low * vite-plugin-node-polyfills@0.2.0 ⚠️ breaking crypto-browserify
vite-plugin-node-polyfills 🟒 low >=0.3.0 vite-plugin-node-polyfills@0.2.0 ⚠️ breaking node-stdlib-browser

Recommended fixes:

Automatically fixable β€” run:

npm audit fix

Breaking-change upgrades (semver major β€” test carefully):

  • vite-plugin-node-polyfills β†’ 0.2.0
  • vite-plugin-top-level-await β†’ 1.2.2
npm install vite-plugin-node-polyfills@0.2.0
npm install vite-plugin-top-level-await@1.2.2

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions