Skip to content

[GHSA-xm8c-hvjf-c5q9] npm-check-updates through 23.0.2, fixed in commit b554b84... - #9199

Open
antonisloukis wants to merge 1 commit into
antonisloukis/advisory-improvement-9199from
antonisloukis-GHSA-xm8c-hvjf-c5q9
Open

[GHSA-xm8c-hvjf-c5q9] npm-check-updates through 23.0.2, fixed in commit b554b84...#9199
antonisloukis wants to merge 1 commit into
antonisloukis/advisory-improvement-9199from
antonisloukis-GHSA-xm8c-hvjf-c5q9

Conversation

@antonisloukis

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • CVSS v4
  • References
  • Source code location
  • Summary

Comments
The advisory currently has no npm package mapping or affected/patched version information, although the upstream project provides enough information to determine these values.

The affected project is the npm package npm-check-updates.

The advisory states that versions through 23.0.2 are affected. Upstream PR #1994, "Strip terminal escape sequences from package and registry text", was merged as commit b554b84848fc0b08a9d2b3d3db15e351387168cf.

The upstream v23.1.0 tag contains this fix commit, and its package.json identifies the released package as npm-check-updates version 23.1.0.

Therefore the advisory should record:

  • Ecosystem: npm
  • Package: npm-check-updates
  • Affected versions: <= 23.0.2
  • Patched version: 23.1.0

I have also added the tagged v23.1.0 package.json as supporting upstream release evidence.

The existing CVSS v4 vector also contains unsupported supplemental/environmental metrics that the GitHub advisory editor cannot parse. I normalized it to the CNA-published CVSS v4 base vector:

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

This preserves the published 5.3 Moderate base score.

@github-actions
github-actions Bot changed the base branch from main to antonisloukis/advisory-improvement-9199 August 24, 2026 20:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant