Skip to content

[stable33] Fix npm audit - #1509

Merged
danxuliu merged 1 commit into
stable33from
automated/noid/stable33-fix-npm-audit
Aug 9, 2026
Merged

[stable33] Fix npm audit#1509
danxuliu merged 1 commit into
stable33from
automated/noid/stable33-fix-npm-audit

Conversation

@nextcloud-command

Copy link
Copy Markdown
Contributor

Audit report

This audit fix resolves 2 of the total 57 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@nextcloud/dialogs #

  • Caused by vulnerable dependency:
  • Affected versions: 7.0.0-rc.0 - 7.1.0
  • Package usage:
    • node_modules/@nextcloud/dialogs

axios #

  • Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
  • Severity: moderate (CVSS 4.8)
  • Reference: GHSA-3p68-rc4w-qgx5
  • Affected versions: 1.0.0 - 1.17.0
  • Package usage:
    • node_modules/axios

Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Aug 8, 2026
@danxuliu
danxuliu merged commit 09e6a4f into stable33 Aug 9, 2026
34 checks passed
@danxuliu
danxuliu deleted the automated/noid/stable33-fix-npm-audit branch August 9, 2026 15:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants