Skip to content

[Aikido] Fix 9 security issues in lodash, uuid, @octokit/endpoint and 3 more - #15

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-39512577-irv8
Closed

[Aikido] Fix 9 security issues in lodash, uuid, @octokit/endpoint and 3 more#15
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-39512577-irv8

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented May 25, 2026

Copy link
Copy Markdown

Upgrade dependencies to fix critical RCE vulnerability in lodash template injection via options.imports and high-severity buffer overflow in uuid.

⚠️ Incomplete breaking changes analysis (2/6 analyzed)

⚠️ Breaking changes analysis not available for: @octokit/endpoint, @octokit/plugin-paginate-rest, @octokit/request, @octokit/request-error

✅ No breaking changes from the package upgrades affect this codebase.

lodash (4.17.21 => 4.18.1):

  • The codebase only uses _.filter() (line 12 in src/gh.js) and _.merge() (line 44 in src/gh.js)

  • The breaking changes in lodash 4.18.0 only affect _.unset(), _.omit(), and _.template(), which are not used in this codebase

uuid (8.3.2 => 11.1.1):

  • The uuid package is not used anywhere in the source code

@octokit packages:

  • These packages are consumed indirectly through @actions/github v6.0.1, which already bundles the upgraded versions (@octokit/endpoint 9.0.6, @octokit/plugin-paginate-rest 9.2.2, @octokit/request 8.4.1, @octokit/request-error 5.1.1)

  • The action uses Node.js 24 runtime (node24 in action.yml), which satisfies all Node.js version requirements

  • No custom HTTP agents or custom request options are passed to octokit - only standard parameters like method, headers, and body are used

  • The breaking changes related to Node.js http(s) Agents and custom request options do not affect this codebase

All breaking changes by upgrading lodash from version 4.17.21 to 4.18.1 (CHANGELOG)

Version Description
4.18.0
_.unset / _.omit now block constructor and prototype as non-terminal path keys unconditionally. Calls that previously returned true and deleted the property now return false and leave the target untouched.
4.18.0
_.template now throws "Invalid imports option passed into _.template" when imports keys contain forbidden identifier characters, which were previously allowed.

All breaking changes by upgrading uuid from version 8.3.2 to 11.1.1 (CHANGELOG)

Version Description
9.0.0
Drop Node.js 10.x support
9.0.0
Remove the minified UMD build from the package
9.0.0
Drop IE 11 and Safari 10 support, remove msCrypto fallback, and no longer transpile browser build to ES2015
10.0.0
Drop Node.js 12 and 14 support, add Node.js 20 (update node support matrix to only support node 16-20)
11.0.0
Refactor v1 internal state and options logic
11.0.0
Refactor v7 internal state and options logic
11.0.0
Port to TypeScript
11.0.0
Update node support matrix (only support node 16-20)
✅ 9 CVEs resolved by this upgrade, including 1 critical 🚨 CVE

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-4800
🚨 CRITICAL
[lodash] A vulnerability in _.template allows arbitrary code execution through untrusted key names in options.imports or prototype pollution, as validation was incomplete after a prior CVE fix. An attacker can inject malicious code that executes during template compilation.
CVE-2025-13465
MEDIUM
[lodash] A prototype pollution vulnerability in _.unset and _.omit functions allows attackers to delete methods from global prototypes via crafted paths. While this prevents property overwriting, it can cause denial of service by removing critical functionality.
CVE-2026-2950
MEDIUM
[lodash] Prototype pollution vulnerability in _.unset and _.omit functions allows attackers to bypass previous fixes using array-wrapped path segments, enabling deletion of properties from built-in prototypes. While this doesn't allow overwriting prototype behavior, it can cause denial of service or unexpected application behavior.
CVE-2026-41907
HIGH
[uuid] A buffer overflow vulnerability allows v3, v5, and v6 UUID functions to write beyond caller-provided buffer boundaries when given small buffers or large offsets, causing silent data corruption. This can lead to memory corruption and potential code execution or information disclosure.
AIKIDO-2026-10892
MEDIUM
[uuid] UUID functions v3(), v5(), and v6() can write past the end of a caller-provided buffer due to missing offset validation, enabling buffer overflow attacks. The fix adds bounds checks to prevent out-of-range writes.
AIKIDO-2025-10094
LOW
[@octokit/endpoint] Improper header parsing for GraphQL endpoints allows attackers to craft malicious inputs triggering ReDoS through excessive regex backtracking, causing denial of service and performance degradation.
CVE-2025-25288
LOW
[@octokit/plugin-paginate-rest] A ReDoS (Regular Expression Denial of Service) vulnerability exists in the pagination iterator when processing malicious link headers, allowing attackers to cause denial of service through specially crafted requests.
CVE-2025-25290
LOW
[@octokit/request] A ReDoS vulnerability in the link header parsing regex allows attackers to cause excessive CPU usage and service unavailability through specially crafted HTTP responses. The unbounded regex pattern is susceptible to catastrophic backtracking when processing malicious input.
CVE-2025-25289
LOW
[@octokit/request-error] A Regular Expression Denial of Service (ReDoS) vulnerability in HTTP header processing allows attackers to cause excessive resource consumption and DoS by sending malformed authorization headers with long space sequences. This can significantly degrade performance or crash services.
🤖 Remediation details

Fix security vulnerabilities in lodash, uuid, @octokit/endpoint, @octokit/plugin-paginate-rest, @octokit/request, and @octokit/request-error; remediate newly introduced undici vulnerabilities as a result of parent-chain bumps. Changes touch the root package.json (four direct-dependency spec updates and one overrides entry) and package-lock.json (lockfile refreshed to reflect all resolved version changes).

lodash

lodash is a direct dependency declared in the root package.json. Its spec was widened from ^4.17.21 to ^4.18.1 so that npm resolves it to 4.18.1, the minimum patched release covering all three lodash advisories. No parent bump was required.

uuid

uuid appeared as two transitive instances: one pulled by @actions/core@1.10.0 (spec ^8.3.2) and one nested under aws-sdk (exact-pinned at 8.0.0). The @actions/core instance was eliminated by bumping that direct dependency to ^1.11.0 (the first release that drops uuid entirely). The aws-sdk-nested instance has no fixing parent version across any published release of aws-sdk, so a targeted overrides entry ("uuid@<11.1.1": "11.1.1") was added to the root package.json as a last resort, resolving both instances to a single uuid@11.1.1 copy.

@octokit/endpoint

@octokit/endpoint is a transitive dependency pulled through @octokit/request. Fixing it required bumping @actions/github from ^4.0.0 to ^6.0.0 (and later to ^8.0.1), which brought in @octokit/core@^5 and @octokit/request@^8; @octokit/request@8.x declares @octokit/endpoint@^9.0.0, allowing npm to resolve it to 9.0.6 (the minimum patched version). The intermediate @octokit/request parent bump was the necessary vehicle for this fix.

@octokit/plugin-paginate-rest

@octokit/plugin-paginate-rest is a transitive dependency pulled by @actions/github. Bumping @actions/github from ^4.0.0 to ^6.0.0 was the first fixing parent version, as @actions/github@6.x declares @octokit/plugin-paginate-rest@^9.0.0, which npm resolves to 9.2.2 (the minimum patched version). The subsequent bump to ^8.0.1 (for undici) resolved it further to 14.0.0, which also satisfies the patched requirement.

@octokit/request

@octokit/request is a transitive dependency pulled by @octokit/core and @octokit/graphql, both of which are themselves pulled by @actions/github. Bumping @actions/github to ^6.0.0 brought @octokit/core@^5, whose ^8.0.2 range for @octokit/request allows npm to resolve it to 8.4.1 (the minimum patched version). The @actions/github parent bump was the necessary vehicle; no direct manifest entry for @octokit/request was needed.

@octokit/request-error

@octokit/request-error is a transitive dependency pulled by @octokit/core and @octokit/request. Bumping @actions/github to ^6.0.0 brought @octokit/core@^5, which declares @octokit/request-error@^5.0.0; npm resolves this to 5.1.1 (the minimum patched version). As with @octokit/request, the @actions/github parent bump was the necessary and sufficient vehicle.

undici

undici was not in the original task but was introduced as a new vulnerable transitive dependency by the @actions/github and @actions/core parent bumps performed to fix the octokit and uuid advisories. Two instances appeared at 5.29.0: one via @actions/github@6.0.1 and one via @actions/core@1.11.1@actions/http-client@2.2.3. Fixing both required further parent bumps: @actions/github was raised to ^8.0.1 (the first version declaring undici@^6.23.0 directly) and @actions/core was raised to ^2.0.0 (the first version declaring @actions/http-client@^3.0.0, which in turn declares undici@^6.23.0). Both changes are manifest edits in the root package.json; npm resolves the single consolidated undici instance to 6.25.0, satisfying the ≥6.24.0 patched floor for all five undici advisories.

Version changes

Package From To Why updated
lodash ^4.17.21 / 4.17.21 ^4.18.1 / 4.18.1 Direct CVE fix
uuid 8.3.2 + 8.0.0 (nested) 11.1.1 (single instance) Override (aws-sdk exact-pins; no fixing parent exists)
@actions/core ^1.10.0 / 1.10.0 ^2.0.0 / 2.0.3 Parent bump required to fix undici via @actions/http-client@3.x
@actions/github ^4.0.0 / 4.0.0 ^8.0.1 / 8.0.1 Parent bump required to fix @octokit/plugin-paginate-rest, @octokit/request, @octokit/request-error, @octokit/endpoint, and undici
@actions/http-client 2.2.3 3.0.2 Transitive after parent bump (@actions/core@2.x); brings undici@^6.23.0
undici 5.29.0 6.25.0 Transitive CVE fix after parent bumps (@actions/github@8.x, @actions/core@2.x)
@octokit/endpoint 6.0.12 11.0.3 Transitive after parent bump (@actions/github@8.x@octokit/request@10.x)
@octokit/plugin-paginate-rest 2.21.3 14.0.0 Transitive CVE fix after parent bump (@actions/github@8.x)
@octokit/request 5.6.3 10.0.9 Transitive CVE fix after parent bump (@actions/github@8.x@octokit/core@7.x)
@octokit/request-error 2.1.0 7.1.0 Transitive CVE fix after parent bump (@actions/github@8.x@octokit/core@7.x)
@octokit/core 3.6.0 7.0.6 Transitive after parent bump (@actions/github@8.x)
@octokit/graphql 4.8.0 9.0.3 Transitive after parent bump (@actions/github@8.x)
@octokit/plugin-rest-endpoint-methods (prior version) 17.0.0 Transitive after parent bump (@actions/github@8.x)
@octokit/types (prior version) 13.x Transitive after parent bump (@actions/github@8.x)

@aikido-autofix

Copy link
Copy Markdown
Author

Closed by Aikido: a new AutoFix has been created → #16

@aikido-autofix aikido-autofix Bot closed this May 28, 2026
@aikido-autofix
aikido-autofix Bot deleted the fix/aikido-security-update-packages-39512577-irv8 branch May 28, 2026 23:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants