Skip to content

[Aikido] Fix 8 security issues in lodash, uuid, @octokit/endpoint and 3 more - #12

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-37940236-owt4
Closed

[Aikido] Fix 8 security issues in lodash, uuid, @octokit/endpoint and 3 more#12
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-37940236-owt4

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented May 22, 2026

Copy link
Copy Markdown

Upgrade dependencies to fix critical RCE vulnerability in lodash template injection and prototype pollution attacks in Octokit packages.

⚠️ Incomplete breaking changes analysis (2/6 analyzed)

⚠️ Breaking changes analysis not available for: @octokit/endpoint, @octokit/plugin-paginate-rest, @octokit/request, @octokit/request-error

✅ No breaking changes from any of the package upgrades affect this codebase.

lodash: The codebase only uses _.filter() and _.merge() methods. The breaking changes in lodash 4.18.x affect _.unset(), _.omit(), and _.template(), which are not used in this project.

uuid: This package is not directly imported or used in the source code; it only appears as a transitive dependency.

@octokit packages: The action runs on Node.js 24 (specified in action.yml), which satisfies all Node.js version requirements. The code uses the high-level @actions/github wrapper and doesn't pass custom HTTP agents or non-standard request options. The removed OAuth Authorizations APIs and required workflow endpoints are not used in this codebase.

All breaking changes by upgrading lodash from version 4.17.21 to 4.18.1 (CHANGELOG)

Version Description
4.18.0
_.unset / _.omit now block constructor and prototype as non-terminal path keys unconditionally. Calls that previously returned true and deleted the property now return false and leave the target untouched.
4.18.0
_.template now throws "Invalid imports option passed into _.template" when imports keys contain forbidden identifier characters, which were previously allowed.

All breaking changes by upgrading uuid from version 8.3.2 to 11.1.1 (CHANGELOG)

Version Description
9.0.0
Drop Node.js 10.x support
9.0.0
Remove the minified UMD build from the package
9.0.0
Drop IE 11 and Safari 10 support, remove msCrypto fallback, and no longer transpile browser build to ES2015
10.0.0
Drop Node.js 12 and 14 support, add Node.js 20 (update node support matrix to only support node 16-20)
11.0.0
Refactor v1 internal state and options logic
11.0.0
Refactor v7 internal state and options logic
11.0.0
Port to TypeScript
11.0.0
Update node support matrix (only support node 16-20)
✅ 8 CVEs resolved by this upgrade, including 1 critical 🚨 CVE

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-4800
🚨 CRITICAL
[lodash] A vulnerability in _.template allows arbitrary code execution through untrusted key names in options.imports or prototype pollution, as validation was incomplete after a prior CVE fix. An attacker can inject malicious code that executes during template compilation.
CVE-2025-13465
MEDIUM
[lodash] A prototype pollution vulnerability in _.unset and _.omit functions allows attackers to delete methods from global prototypes via crafted paths. While this prevents property overwriting, it can cause denial of service by removing critical functionality.
CVE-2026-2950
MEDIUM
[lodash] Prototype pollution vulnerability in _.unset and _.omit functions allows attackers to bypass previous fixes using array-wrapped path segments, enabling deletion of properties from built-in prototypes. While this doesn't allow overwriting prototype behavior, it can cause denial of service or unexpected application behavior.
AIKIDO-2026-10892
MEDIUM
[uuid] UUID functions v3(), v5(), and v6() can write past the end of a caller-provided buffer due to missing offset validation, enabling buffer overflow attacks. The fix adds bounds checks to prevent out-of-range writes.
AIKIDO-2025-10094
LOW
[@octokit/endpoint] Improper header parsing for GraphQL endpoints allows attackers to craft malicious inputs triggering ReDoS through excessive regex backtracking, causing denial of service and performance degradation.
CVE-2025-25288
LOW
[@octokit/plugin-paginate-rest] A ReDoS (Regular Expression Denial of Service) vulnerability exists in the pagination iterator when processing malicious link headers, allowing attackers to cause denial of service through specially crafted requests.
CVE-2025-25290
LOW
[@octokit/request] A ReDoS vulnerability in the link header parsing regex allows attackers to cause excessive CPU usage and service unavailability through specially crafted HTTP responses. The unbounded regex pattern is susceptible to catastrophic backtracking when processing malicious input.
CVE-2025-25289
LOW
[@octokit/request-error] A Regular Expression Denial of Service (ReDoS) vulnerability in HTTP header processing allows attackers to cause excessive resource consumption and DoS by sending malformed authorization headers with long space sequences. This can significantly degrade performance or crash services.
🤖 Remediation details

Fix security vulnerabilities in lodash, uuid, @octokit/endpoint, @octokit/plugin-paginate-rest, @octokit/request, @octokit/request-error, and undici

Short summary

This PR remediates security vulnerabilities in seven npm packages: lodash, uuid, @octokit/endpoint, @octokit/plugin-paginate-rest, @octokit/request, @octokit/request-error, and undici (introduced transitively by the parent bumps required to fix the other packages). All fixes are applied via direct dependency version spec changes in the root package.json, one targeted overrides entry for a case where no parent bump was possible, and a corresponding package-lock.json refresh.

lodash

lodash is a direct dependency declared in the root package.json. Its spec was raised from ^4.17.21 to ^4.18.1, resolving to 4.18.1 in the lockfile. Version 4.18.1 is the minimum patched release that satisfies all three lodash advisories; no parent chain was involved.

uuid

uuid appears as a transitive dependency in two places. The instance under @actions/core was eliminated by bumping @actions/core to ^2.0.0 (that major release dropped the uuid dependency entirely). The instance nested under aws-sdk cannot be fixed via a parent bump because no published version of aws-sdk upgrades past uuid@8.x; a targeted override "uuid@<11.1.1": "11.1.1" was added to the root package.json to force that nested copy to the patched version.

@octokit/endpoint

@octokit/endpoint is a transitive dependency pulled in through the @actions/github@octokit/request chain. Bumping @actions/github to ^8.0.0 brought in @octokit/request@^10.x, which depends on @octokit/endpoint@^11.x, resolving to 11.0.3—well above the required minimum of 9.0.6.

@octokit/plugin-paginate-rest

@octokit/plugin-paginate-rest is a transitive dependency of @actions/github. Bumping @actions/github to ^8.0.0 resolved @octokit/plugin-paginate-rest to 14.0.0, which exceeds the required minimum of 9.2.2.

@octokit/request

@octokit/request is a transitive dependency pulled in by @actions/github, @octokit/core, and @octokit/graphql. Bumping @actions/github to ^8.0.0 caused all three importers to resolve @octokit/request to 10.0.9, which exceeds the required minimum of 8.4.1.

@octokit/request-error

@octokit/request-error is a transitive dependency pulled in by @actions/github, @octokit/core, and @octokit/request. Bumping @actions/github to ^8.0.0 resolved @octokit/request-error to 7.1.0 across all importers, exceeding the required minimum of 5.1.1.

undici

undici was not in the original advisory list but was introduced as a vulnerable transitive dependency (5.29.0) when @actions/github was first bumped to ^6.0.0, because that version's @actions/http-client@2.x depends on undici@^5.x. Fixing this required two further major parent bumps: @actions/github raised to ^8.0.0 (which directly depends on undici@^6.23.0) and @actions/core raised to ^2.0.0 (which brings @actions/http-client@^3.0.2, also depending on undici@^6.23.0). Both bumps were necessary to eliminate the single remaining undici@5.29.0 instance; the lockfile now resolves a single undici@6.25.0.

Version changes

Package From To Why updated
lodash ^4.17.214.17.21 ^4.18.14.18.1 Direct CVE fix
@actions/core ^1.10.01.10.0 ^2.0.02.0.3 Parent bump to drop vulnerable uuid and fix undici via @actions/http-client@3.x
@actions/github ^4.0.04.0.0 ^8.0.08.0.1 Parent bump to fix @octokit/endpoint, @octokit/plugin-paginate-rest, @octokit/request, @octokit/request-error, and undici
uuid 8.0.0 / 8.3.2 11.1.1 CVE fix — aws-sdk instance via override; @actions/core instance dropped by parent bump
@octokit/endpoint 6.0.12 11.0.3 Transitive CVE fix after @actions/github parent bump
@octokit/plugin-paginate-rest 2.21.3 14.0.0 Transitive CVE fix after @actions/github parent bump
@octokit/request 5.6.3 10.0.9 Transitive CVE fix after @actions/github parent bump
@octokit/request-error 2.1.0 7.1.0 Transitive CVE fix after @actions/github parent bump
undici 5.29.0 6.25.0 Transitive CVE fix after @actions/github and @actions/core parent bumps
@actions/http-client 2.2.3 3.0.2 Transitive after @actions/core and @actions/github parent bumps (carries fixed undici@^6.23.0)
@octokit/core 3.6.0 7.0.6 Transitive after @actions/github parent bump
@octokit/graphql 4.8.0 9.0.3 Transitive after @actions/github parent bump
@octokit/plugin-rest-endpoint-methods 5.x 17.x Transitive after @actions/github parent bump

@aikido-autofix

Copy link
Copy Markdown
Author

Closed by Aikido: a new AutoFix has been created → #13

@aikido-autofix aikido-autofix Bot closed this May 22, 2026
@aikido-autofix
aikido-autofix Bot deleted the fix/aikido-security-update-packages-37940236-owt4 branch May 22, 2026 23:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants