Repository navigation
[Snyk] Security upgrade @xmldom/xmldom from 0.8.15 to 0.9.12 - #4638
chelojimenez wants to merge 1 commit into
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-XMLDOMXMLDOM-19498551
|
The upgrade of Key Breaking Changes:
Recommendation: Source: Release notes
|
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_ed8df85d-e2b6-4b82-b9e8-35fe5321a0b2) |
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
There was a problem hiding this comment.
2 issues found across 1 file
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="sdk/package.json">
<violation number="1" location="sdk/package.json:181">
P1: Because this workspace uses the root lockfile, this manifest change makes reproducible installs fail and leaves CI unable to install the SDK. Regenerate and commit `package-lock.json` with `@xmldom/xmldom` 0.9.12.</violation>
<violation number="2" location="sdk/package.json:181">
P1: Updating only the SDK leaves the inspector able to install and load the vulnerable 0.8.x copy of `@xmldom/xmldom`. Bump the inspector's direct dependency as well, then regenerate the lockfile so the security fix covers the workspace runtime.</violation>
</file>
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
| "@noble/hashes": "^2.3.0", | ||
| "@openrouter/ai-sdk-provider": "^2.2.0", | ||
| "@xmldom/xmldom": "^0.8.13", | ||
| "@xmldom/xmldom": "^0.9.12", |
There was a problem hiding this comment.
P1: Because this workspace uses the root lockfile, this manifest change makes reproducible installs fail and leaves CI unable to install the SDK. Regenerate and commit package-lock.json with @xmldom/xmldom 0.9.12.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At sdk/package.json, line 181:
<comment>Because this workspace uses the root lockfile, this manifest change makes reproducible installs fail and leaves CI unable to install the SDK. Regenerate and commit `package-lock.json` with `@xmldom/xmldom` 0.9.12.</comment>
<file context>
@@ -178,7 +178,7 @@
"@noble/hashes": "^2.3.0",
"@openrouter/ai-sdk-provider": "^2.2.0",
- "@xmldom/xmldom": "^0.8.13",
+ "@xmldom/xmldom": "^0.9.12",
"ai": "^6.0.141",
"ajv": "^8.17.1",
</file context>
| "@noble/hashes": "^2.3.0", | ||
| "@openrouter/ai-sdk-provider": "^2.2.0", | ||
| "@xmldom/xmldom": "^0.8.13", | ||
| "@xmldom/xmldom": "^0.9.12", |
There was a problem hiding this comment.
P1: Updating only the SDK leaves the inspector able to install and load the vulnerable 0.8.x copy of @xmldom/xmldom. Bump the inspector's direct dependency as well, then regenerate the lockfile so the security fix covers the workspace runtime.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At sdk/package.json, line 181:
<comment>Updating only the SDK leaves the inspector able to install and load the vulnerable 0.8.x copy of `@xmldom/xmldom`. Bump the inspector's direct dependency as well, then regenerate the lockfile so the security fix covers the workspace runtime.</comment>
<file context>
@@ -178,7 +178,7 @@
"@noble/hashes": "^2.3.0",
"@openrouter/ai-sdk-provider": "^2.2.0",
- "@xmldom/xmldom": "^0.8.13",
+ "@xmldom/xmldom": "^0.9.12",
"ai": "^6.0.141",
"ajv": "^8.17.1",
</file context>
Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
sdk/package.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-XMLDOMXMLDOM-19498551
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Regular Expression Denial of Service (ReDoS)
Note
Medium Risk
Crossing 0.8→0.9 may change XML parsing behavior on the SVG dimension path even though the diff is only a version pin; worth a quick regression check on malformed SVG handling.
Overview
Bumps the
@xmldom/xmldomdependency insdk/package.jsonfrom^0.8.13to^0.9.12. This is a Snyk-driven security fix for a high-severity ReDoS issue (SNYK-JS-XMLDOMXMLDOM-19498551).There are no application code changes—only the declared npm version. The library is used on the Node entry path for SVG XML parsing (
xmldomParseXml/ openai-readiness), not in the browser bundle.Reviewed by Cursor Bugbot for commit 921d8d5. Bugbot is set up for automated code reviews on this repo. Configure here.
Summary by cubic
Updates
@xmldom/xmldomfrom^0.8.13to^0.9.12in the SDK to fix a high-severity Regular Expression Denial of Service vulnerability.Written for commit 921d8d5. Summary will update on new commits.