Skip to content

fix(deps): vuln major upgrades — 4 packages (major: 1 · minor: 2 · patch: 1) - #20

Draft
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/major/npm/2-1781534215
Draft

fix(deps): vuln major upgrades — 4 packages (major: 1 · minor: 2 · patch: 1) #20
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/major/npm/2-1781534215

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: Critical-severity security update — 5 packages upgraded (MAJOR changes included)

Manifests changed:

  • . (yarn)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
jspdf 2.5.2 4.2.1 major Direct 4 CRITICAL, 16 HIGH, 4 MEDIUM
@babel/runtime 7.5.5 7.29.7 minor Transitive 2 MEDIUM
core-js 3.19.1 3.49.0 minor Transitive -
stackblur-canvas 2.5.0 2.7.0 minor Transitive -
core-js 3.19.1 3.19.3 patch Transitive -

Warning

Major Version Upgrade

This update includes major version changes that may contain breaking changes. Please:

  • Review the changelog/release notes for breaking changes
  • Test thoroughly in a staging environment
  • Update any code that depends on changed APIs
  • Ensure all tests pass before merging

Security Details

🚨 Critical & High Severity (20 fixed)
Package CVE Severity Summary Unsafe Version Fixed In
jspdf GHSA-f8cm-6447-x5h2 CRITICAL jsPDF has Local File Inclusion/Path Traversal vulnerability 2.5.2 4.0.0
jspdf CVE-2026-31938 CRITICAL jsPDF has HTML Injection in New Window paths 2.5.2 -
jspdf GHSA-wfv2-pwc8-crg5 CRITICAL jsPDF has HTML Injection in New Window paths 2.5.2 4.2.1
jspdf CVE-2025-68428 CRITICAL jsPDF has Local File Inclusion/Path Traversal vulnerability 2.5.2 -
jspdf GHSA-67pg-wm7f-q7fj HIGH jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions 2.5.2 4.2.0
jspdf CVE-2026-31898 HIGH jsPDF has a PDF Object Injection via FreeText color 2.5.2 -
jspdf CVE-2026-25940 HIGH jsPDF's PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property) 2.5.2 -
jspdf GHSA-p5xg-68wr-hm3m HIGH jsPDF has a PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property) 2.5.2 4.2.0
jspdf GHSA-pqxr-3g65-p328 HIGH jsPDF has PDF Injection in AcroFormChoiceField that allows Arbitrary JavaScript Execution 2.5.2 4.1.0
jspdf CVE-2026-24737 HIGH jsPDF has a PDF Injection in AcroFormChoiceField which allows Arbitrary JavaScript Execution 2.5.2 -
jspdf GHSA-9vjf-qc39-jprp HIGH jsPDF has a PDF Object Injection via Unsanitized Input in addJS Method 2.5.2 4.2.0
jspdf CVE-2026-25755 HIGH jsPDF has PDF Object Injection via Unsanitized Input in addJS Method 2.5.2 -
jspdf GHSA-8mvj-3j78-4qmw HIGH jsPDF Denial of Service (DoS) 2.5.2 3.0.2
jspdf CVE-2026-25535 HIGH jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions 2.5.2 -
jspdf GHSA-7x6v-j9x4-qf24 HIGH jsPDF has a PDF Object Injection via FreeText color 2.5.2 4.2.1
jspdf CVE-2025-29907 HIGH jsPDF Bypass Regular Expression Denial of Service (ReDoS) 2.5.2 -
jspdf GHSA-95fx-jjr5-f39c HIGH jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder 2.5.2 4.1.0
jspdf CVE-2026-24133 HIGH jsPDF Affected by Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder 2.5.2 -
jspdf GHSA-w532-jxjh-hjhj HIGH jsPDF Bypass Regular Expression Denial of Service (ReDoS) 2.5.2 3.0.1
jspdf CVE-2025-57810 HIGH jsPDF Parsing of Corrupt PNGs Leads to Potential Denial of Service (DoS) 2.5.2 -
ℹ️ Other Vulnerabilities (6)
Package CVE Severity Summary Unsafe Version Fixed In
@babel/runtime GHSA-968p-4wvh-cqc8 MODERATE Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups 7.5.5 7.26.10
@babel/runtime CVE-2025-27789 MODERATE Inefficient RexExp complexity in generated code with .replace when transpiling named capturing groups 7.5.5 -
jspdf GHSA-vm32-vv63-w422 MODERATE jsPDF Vulnerable to Stored XMP Metadata Injection (Spoofing & Integrity Violation) 2.5.2 4.1.0
jspdf CVE-2026-24043 MODERATE jsPDF Affected by Stored XMP Metadata Injection (Spoofing & Integrity Violation) 2.5.2 -
jspdf CVE-2026-24040 MODERATE jsPDF has a Shared State Race Condition in addJS Plugin 2.5.2 -
jspdf GHSA-cjw8-79x6-5cj4 MODERATE jsPDF has Shared State Race Condition in addJS Plugin 2.5.2 4.1.0

Review Checklist

Extra review is recommended for this update:

  • Review changes for compatibility with your code
  • Check release notes for breaking changes
  • Run integration tests to verify service behavior
  • Test in staging environment before production
  • Monitor key metrics after deployment
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

@datadog-datadog-prod-us1

datadog-datadog-prod-us1 Bot commented Jun 15, 2026

Copy link
Copy Markdown

Pipelines

Fix all issues with BitsAI

⚠️ Warnings

🚦 7 Pipeline jobs failed

Frontend | fe-lint   View in Datadog   GitHub Actions

Frontend | fe-type-check   View in Datadog   GitHub Actions

i18n | verify-i18n-files   View in Datadog   GitHub Actions

View all 7 failed jobs.

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: ef3dd5e | Docs | Datadog PR Page | Give us feedback!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants