Skip to content

vulnerable transitive devDependency js-yaml #6115

@ankitdn

Description

@ankitdn

What happened?

While working on opentelemetry-js project, I discovered a security vulnerability (CVE-2025-64718) in the js-yaml package. Versions 4.1.0 and below are affected by a prototype pollution issue that allows attackers to modify the object prototype through crafted YAML input. This can lead to unexpected or unsafe application behavior.

CVE Link
CVE Report

OpenTelemetry Setup Code

package.json

Relevant log output

Operating System and Version

No response

Runtime and Version

No response

Tip

React with 👍 to help prioritize this issue. Please use comments to provide useful context, avoiding +1 or me too, to help us triage it. Learn more here.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions