Vulnerabilities

3 via 5 paths

Dependencies

212

Source

GitHub

Find, fix and prevent vulnerabilities in your code.

Severity
  • 1
  • 1
  • 1
Status
  • 3
  • 0
  • 0

critical severity
new

Arbitrary Code Injection

  • Vulnerable module: gray-matter
  • Introduced through: moleculer-cli@0.9.1

Detailed paths

  • Introduced through: moleculer-db-addons@moleculerjs/moleculer-db › moleculer-cli@0.9.1 › metalsmith@2.7.0 › gray-matter@4.0.3

Overview

gray-matter is a Parse front-matter from a string or file. Fast, reliable and easy to use. Parses YAML front matter by default, but also has support for YAML, JSON, TOML or Coffee Front-Matter, with options to set custom delimiters. Used by metalsmith, assemble, verb and

Affected versions of this package are vulnerable to Arbitrary Code Injection via the eval process in lib/engines.js when parsing front matter with the language set to js or javascript. An attacker can execute arbitrary code by supplying crafted input that is evaluated by the JavaScript engine.

Remediation

There is no fixed version for gray-matter.

References

high severity
new

Uncontrolled Recursion

  • Vulnerable module: braces
  • Introduced through: moleculer-cli@0.9.1

Detailed paths

  • Introduced through: moleculer-db-addons@moleculerjs/moleculer-db › moleculer-cli@0.9.1 › fast-glob@3.3.3 › micromatch@4.0.8 › braces@3.0.3
  • Introduced through: moleculer-db-addons@moleculerjs/moleculer-db › moleculer-cli@0.9.1 › metalsmith@2.7.0 › micromatch@4.0.8 › braces@3.0.3
  • Introduced through: moleculer-db-addons@moleculerjs/moleculer-db › moleculer-cli@0.9.1 › moleculer-repl@0.8.0 › fast-glob@3.3.3 › micromatch@4.0.8 › braces@3.0.3

Overview

braces is a Bash-like brace expansion, implemented in JavaScript.

Affected versions of this package are vulnerable to Uncontrolled Recursion in the recursive AST walkers, which lack depth guards. An attacker can supply deeply nested brace patterns that stay within the character limit to exhaust the call stack and crash the Node.js process with an uncaught RangeError.

Remediation

There is no fixed version for braces.

References

medium severity
new

Improper Validation of Specified Quantity in Input

  • Vulnerable module: sprintf-js
  • Introduced through: moleculer-cli@0.9.1

Detailed paths

  • Introduced through: moleculer-db-addons@moleculerjs/moleculer-db › moleculer-cli@0.9.1 › metalsmith@2.7.0 › gray-matter@4.0.3 › js-yaml@3.15.2 › argparse@1.0.10 › sprintf-js@1.0.3

Overview

Affected versions of this package are vulnerable to Improper Validation of Specified Quantity in Input via unbounded precision specifiers passed without validation to the toFixed, toExponential, and toPrecision methods. An attacker who controls a format string can inject precision values exceeding ECMAScript limits, causing uncaught RangeError exceptions that abort the calling operation.

Remediation

There is no fixed version for sprintf-js.

References