Skip to content

[Aikido] Fix 9 security issues in lodash, uuid, @octokit/endpoint and 3 more - #25

Open
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-97600133-edrm
Open

[Aikido] Fix 9 security issues in lodash, uuid, @octokit/endpoint and 3 more#25
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-97600133-edrm

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Aug 26, 2026

Copy link
Copy Markdown

Upgrade dependencies to fix critical RCE vulnerability in lodash template injection via options.imports and high-severity buffer overflow in uuid.

⚠️ Incomplete breaking changes analysis (2/6 analyzed)

⚠️ Breaking changes analysis not available for: @octokit/endpoint, @octokit/plugin-paginate-rest, @octokit/request, @octokit/request-error

✅ No breaking changes affect this codebase.

The lodash upgrade's breaking changes to _.unset, _.omit, and _.template do not impact the code, which only uses _.filter() and _.merge(). The uuid package is not used in the source code. The @octokit packages are transitive dependencies accessed only through @actions/github's getOctokit() method, and the codebase does not use any of the deprecated features (HTTP agents, custom request options, or removed API endpoints). The action runs on Node.js 24, which satisfies all version requirements.

All breaking changes by upgrading lodash from version 4.17.21 to 4.18.1 (CHANGELOG)

Version Description
4.18.0
_.unset / _.omit now block constructor and prototype as non-terminal path keys unconditionally. Calls that previously returned true and deleted the property now return false and leave the target untouched.
4.18.0
_.template now throws "Invalid imports option passed into _.template" when imports keys contain forbidden identifier characters, which were previously allowed.

All breaking changes by upgrading uuid from version 8.3.2 to 11.1.1 (CHANGELOG)

Version Description
9.0.0
Drop Node.js 10.x support
9.0.0
Remove the minified UMD build from the package
9.0.0
Drop IE 11 and Safari 10 support, remove msCrypto fallback, and no longer transpile browser build to ES2015
10.0.0
Drop Node.js 12 and 14 support, add Node.js 20 (update node support matrix to only support node 16-20)
11.0.0
Refactor v1 internal state and options logic
11.0.0
Refactor v7 internal state and options logic
11.0.0
Port to TypeScript
11.0.0
Update node support matrix (only support node 16-20)
✅ 9 CVEs resolved by this upgrade, including 1 critical 🚨 CVE

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-4800
🚨 CRITICAL
[lodash] A vulnerability in _.template allows arbitrary code execution through untrusted key names in options.imports or prototype pollution, as validation was incomplete after a prior CVE fix. An attacker can inject malicious code that executes during template compilation.
CVE-2025-13465
MEDIUM
[lodash] A prototype pollution vulnerability in _.unset and _.omit functions allows attackers to delete methods from global prototypes via crafted paths. While this prevents property overwriting, it can cause denial of service by removing critical functionality.
CVE-2026-2950
MEDIUM
[lodash] Prototype pollution vulnerability in _.unset and _.omit functions allows attackers to bypass previous fixes using array-wrapped path segments, enabling deletion of properties from built-in prototypes. While this doesn't allow overwriting prototype behavior, it can cause denial of service or unexpected application behavior.
CVE-2026-41907
HIGH
[uuid] A buffer overflow vulnerability allows v3, v5, and v6 UUID functions to write beyond caller-provided buffer boundaries when given small buffers or large offsets, causing silent data corruption. This can lead to memory corruption and potential code execution or information disclosure.
AIKIDO-2026-10892
MEDIUM
[uuid] UUID functions v3(), v5(), and v6() can write past the end of a caller-provided buffer due to missing offset validation, enabling buffer overflow attacks. The fix adds bounds checks to prevent out-of-range writes.
AIKIDO-2025-10094
LOW
[@octokit/endpoint] Improper header parsing for GraphQL endpoints allows attackers to craft malicious inputs triggering ReDoS through excessive regex backtracking, causing denial of service and performance degradation.
CVE-2025-25288
LOW
[@octokit/plugin-paginate-rest] A ReDoS (Regular Expression Denial of Service) vulnerability exists in the pagination iterator when processing malicious link headers, allowing attackers to cause denial of service through specially crafted requests.
CVE-2025-25290
LOW
[@octokit/request] A ReDoS vulnerability in the link header parsing regex allows attackers to cause excessive CPU usage and service unavailability through specially crafted HTTP responses. The unbounded regex pattern is susceptible to catastrophic backtracking when processing malicious input.
CVE-2025-25289
LOW
[@octokit/request-error] A Regular Expression Denial of Service (ReDoS) vulnerability in HTTP header processing allows attackers to cause excessive resource consumption and DoS by sending malformed authorization headers with long space sequences. This can significantly degrade performance or crash services.
🤖 Remediation details

Fix security vulnerabilities in lodash, uuid, @octokit/endpoint, @octokit/plugin-paginate-rest, @octokit/request, @octokit/request-error, and undici

Short summary

This PR remediates security vulnerabilities in seven npm packages: lodash, uuid, @octokit/endpoint, @octokit/plugin-paginate-rest, @octokit/request, @octokit/request-error, and undici. Changes are applied to the root package.json (four direct-dependency version spec bumps and one overrides entry) with package-lock.json updated accordingly. All vulnerable instances are resolved to patched versions with no use of lockfile-only workarounds beyond what parent bumps naturally produce.

lodash

lodash is a direct dependency declared in the root package.json. Its spec was raised from ^4.17.21 to ^4.18.1, resolving to 4.18.1 in the lockfile. Version 4.18.1 is the minimum that satisfies all three advisories targeting this package.

uuid

uuid appears as two transitive instances: one hoisted to the root (pulled in by @actions/core@1.x) and one nested under aws-sdk (pinned at 8.0.0). The root instance was eliminated by bumping @actions/core to ^2.0.0, whose 2.x line no longer depends on uuid at all. The aws-sdk-nested copy cannot be fixed via any parent bump because every published version of aws-sdk pins uuid at 8.0.0; an overrides entry "uuid@>=0.0.1 <=10.0.0": "11.1.1" was added to the root package.json to force that instance to the patched 11.1.1, targeting only the vulnerable range without globally overriding unrelated consumers.

@octokit/endpoint

@octokit/endpoint is a transitive dependency pulled in through the @actions/github@octokit/core@octokit/request chain. Bumping @actions/github to ^8.0.1 brought in @octokit/core@7.x, which depends on @octokit/request@^10.x, which in turn declares @octokit/endpoint@^11.x; the lockfile resolved to 11.0.4, well above the 9.0.6 patched floor. No direct manifest entry for @octokit/endpoint was needed.

@octokit/plugin-paginate-rest

@octokit/plugin-paginate-rest is a transitive dependency of @actions/github. Bumping @actions/github to ^8.0.1 brought its ^14.0.0 range into the tree, resolving to 14.0.0 in the lockfile, which exceeds the 9.2.2 patched minimum. The prior @actions/github@4.x pinned this package at 2.21.3, which was below the patched floor.

@octokit/request

@octokit/request is a transitive dependency shared across @octokit/core and @octokit/graphql, both of which are brought in by @actions/github. Bumping @actions/github to ^8.0.1 pulled in @octokit/core@7.x and @octokit/graphql@9.x, both of which declare @octokit/request@^10.x; the lockfile resolved to 10.0.15, above the 8.4.1 patched minimum. The prior chain was stuck at 5.6.3 because @actions/github@4.x brought @octokit/core@3.x, which only ranged over @octokit/request@^5.x.

@octokit/request-error

@octokit/request-error is a transitive dependency of @octokit/core and @octokit/request. The same @actions/github bump to ^8.0.1 that fixed @octokit/request also resolved @octokit/request-error to 7.1.1 via the updated @octokit/core@7.x and @octokit/request@10.x ranges, both of which declare @octokit/request-error@^7.x. The prior version 2.1.0 was below the 5.1.1 patched floor.

undici

undici is a transitive dependency introduced by the @actions/github and @actions/http-client packages. After the initial round bumped @actions/github to ^6.0.0, that version still pulled in undici@5.29.0 (below all patched floors), introducing 12 new advisories. Fixing this required two further parent bumps: @actions/github was raised to ^8.0.1 (which declares undici@^6.23.0 directly and also brings @actions/http-client@^3.0.2), and @actions/core was raised to ^2.0.0 (whose 2.x line declares @actions/http-client@^3.0.0, also resolving to 3.0.2). Both @actions/http-client@3.x edges now share a single hoisted undici@6.28.0, which satisfies all patched version floors across the 12 advisories.

Version changes

Package From To Why updated
lodash ^4.17.214.17.21 ^4.18.14.18.1 Direct CVE fix
@actions/core ^1.10.01.10.0 ^2.0.02.0.3 Parent bump to drop uuid dep and pull in @actions/http-client@3.x for undici fix
@actions/github ^4.0.04.0.0 ^8.0.18.0.1 Parent bump required to fix @octokit/plugin-paginate-rest, @octokit/request, @octokit/request-error, @octokit/endpoint, and undici
uuid (aws-sdk nested) 8.0.0 11.1.1 Override — no fixing aws-sdk parent version exists
uuid (root, via @actions/core) 8.3.2 (removed) Eliminated; @actions/core@2.x no longer depends on uuid
@actions/http-client 2.2.3 3.0.2 Transitive after @actions/core and @actions/github parent bumps; brings undici@^6.23.0
undici 5.29.0 6.28.0 Transitive after @actions/github and @actions/http-client parent bumps
@octokit/endpoint 6.0.12 11.0.4 Transitive after @actions/github parent bump
@octokit/plugin-paginate-rest 2.21.3 14.0.0 Transitive after @actions/github parent bump
@octokit/request 5.6.3 10.0.15 Transitive after @actions/github parent bump
@octokit/request-error 2.1.0 7.1.1 Transitive after @actions/github parent bump
@octokit/core 3.6.0 7.0.7 Transitive after @actions/github parent bump
@octokit/graphql 4.8.0 9.0.4 Transitive after @actions/github parent bump
@octokit/plugin-rest-endpoint-methods 5.x 17.0.0 Transitive after @actions/github parent bump

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants