Skip to content

v1: js-yaml overrides pin vulnerable versions, making npm audit fix a no-op (dev-only exposure) #2072

Description

@cliffhall

Summary

The root overrides block in package.json pins js-yaml to versions that are themselves inside the advisory range, so npm audit fix reports "fix available" and then changes nothing — the overrides win over anything audit tries to do.

"js-yaml@<4":  "3.15.0",   // advisory range: 3.0.0 - 3.15.0
"js-yaml@>=4": "4.2.0"     // advisory range: 4.0.0 - 4.3.0

Advisories

Severity: high (per npm audit). Impact class: CPU-exhaustion DoS when parsing untrusted YAML.

Exposure assessment

Development-only. Nothing reaches published-package consumers.

npm ls js-yaml --omit=dev is empty. Both copies are reachable only through dev tooling:

eslint@9.39.4 -> @eslint/eslintrc@3.3.6 -> js-yaml@4.2.0
ts-jest -> @jest/transform -> babel-plugin-istanbul -> @istanbuljs/load-nyc-config -> js-yaml@3.15.0

Neither is in the package's files list, so neither ships. The only YAML these parse is the repo's own eslint / nyc configuration, which is not attacker-controlled. There is no runtime path by which a third party feeds YAML to either copy.

Filing under v1 for audit hygiene rather than as a user-facing security exposure — this does not on its own warrant a v1 release.

Fix

Bump both override pins to the patched releases (v3-legacy / v4-legacy tags):

"js-yaml@<4":  "3.15.1",
"js-yaml@>=4": "4.3.1"

Both patched versions have an identical dependency and bin shape to the versions they replace, so the lockfile change is limited to version / resolved / integrity on the two existing entries — 6 lines, no transitive churn.

Note for anyone reproducing this: a plain rm -rf node_modules package-lock.json && npm install re-resolves the entire tree and produces a ~2450-line lock diff touching 164 packages, including production deps (@modelcontextprotocol/sdk, hono, @hono/node-server 1.x -> 2.x major, jose, ws). That is not acceptable on a deprecated branch. The two lock entries must be patched in place instead.

Verification

With the surgical change applied: js-yaml no longer appears in npm audit; build, lint, and all suites pass (539 client + 37 server + 85 CLI); the app starts, serves the client, gates the proxy correctly (401 without token / 200 with), and completes a full MCP tools/list + tools/call round-trip through the CLI.

Out of scope

npm audit against unmodified v1/main currently reports 7 further advisories that postdate this one, several of which are production-reachable in the proxy server (hono, @hono/node-server, ip-address, fast-uri — SSRF / host-confusion class). Those are being assessed separately and are more likely to warrant a v1 release than this one.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

dependenciesPull requests that update a dependency filev1

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions