Security vulnerabilities and automated fixes for js yaml issues
4 posts found
A high-severity dependency vulnerability in `js-yaml`, used transitively by `electron-builder`/`electron-updater` inside the DSA Desktop app, allowed attacker-controlled YAML with `!!omap` tags to trigger quadratic-time CPU consumption during parsing. The fix pins `js-yaml` to the patched `4.3.1` (and `3.15.1` for the legacy branch) release via both `package.json` overrides and `package-lock.json`.
A high-severity Denial of Service vulnerability (CVE-2026-59869) in the js-yaml parser allowed specially crafted YAML documents to exhaust CPU and memory when loaded by apps/dsa-desktop. The fix upgrades js-yaml to a patched release via the package-lock.json dependency tree, closing off the unbounded resource consumption path before it reached production.
A high-severity algorithmic complexity vulnerability (GHSA-5p4m-2wfm-xmqj) in js-yaml versions 3.x through 4.3.0 allows attackers to trigger quadratic CPU consumption through specially crafted `!!omap` YAML sequences. The fix upgrades js-yaml to 4.3.1 using a pnpm override in the `e2e/adapter/claude-code` package, ensuring all transitive dependencies also receive the patched version. This proactive patch eliminates an exploit primitive before it can be chained with other weaknesses.
A high-severity denial-of-service vulnerability (GHSA-5p4m-2wfm-xmqj) in js-yaml versions 4.3.0 and 3.x caused quadratic CPU consumption when resolving `!!omap` (ordered map) types in YAML documents. Attackers who could supply crafted YAML input could cause CPU exhaustion proportional to the square of the input size, potentially grinding Node.js services to a halt. The fix upgrades js-yaml to 4.3.1 and pins the version via a `package.json` overrides block to ensure no transitive dependency can r