fix(deps): update dependency darkreader to v4.9.117 [security]#151
Open
fix(deps): update dependency darkreader to v4.9.117 [security]#151
Conversation
0285584 to
fc1d03c
Compare
89ce044 to
fc6b331
Compare
fdf7051 to
78a96ec
Compare
78a96ec to
a98a3c5
Compare
a98a3c5 to
b4c91fd
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

0 New Issues
0 Fixed Issues
0 Accepted Issues
No data about coverage
This PR contains the following updates:
4.9.46→4.9.117Dark Reader gives users the ability to request style sheets from local web servers
CVE-2025-68467 / GHSA-x369-mcw8-8rvj
More information
Details
Description
Dark Reader versions prior to 4.9.117 included a behavior where a website could request a style sheet from a locally running web server, for example
http://localhost:8080/style.css, If an address was available and returned atext/csscontent type.Patches
The problem was fixed in version 4.9.117, released on December 3, 2025. Most users received the update automatically. Users running manual builds must upgrade to version 4.9.117 or later.
The installed extension version number can be verified in Dark Reader's menu (More > All settings > About), browser settings,
chrome://extensionsorabout:addonspages.Users are encouraged not to disable automatic extension updates and use the latest browser version, as browser releases typically include multiple security fixes of varying severity.
NPM package
The issue does not affect developers using the
darkreaderNPM package for website integration. Developers using thesetFetchMethod()API must ensure the cross-origin requests are restricted to the intended scope.Custom forks
Developers using custom forks of earlier versions of Dark Reader to build other extensions, or integrating it into their apps or browsers, should review their implementation to ensure cross-origin requests are handled securely.
Acknowledgements
Security research performed by Brian Carpenter - Deep Fork Cyber.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
darkreader/darkreader (darkreader)
v4.9.117Compare Source
v4.9.114Compare Source
v4.9.113Compare Source
v4.9.112Compare Source
v4.9.109Compare Source
v4.9.108Compare Source
v4.9.105Compare Source
v4.9.104Compare Source
v4.9.101Compare Source
v4.9.100Compare Source
v4.9.96Compare Source
v4.9.95Compare Source
v4.9.94Compare Source
v4.9.92Compare Source
v4.9.89Compare Source
v4.9.87Compare Source
v4.9.86Compare Source
v4.9.85Compare Source
v4.9.84Compare Source
v4.9.83Compare Source
v4.9.82Compare Source
4.9.81 (March 29, 2024)
4.9.80 (March 13, 2024)
4.9.79 (February 29, 2024)
4.9.78 (February 29, 2024)
4.9.77 (February 7, 2024)
4.9.76 (January 17, 2024)
4.9.75 (January 12, 2024)
4.9.74 (January 3, 2024)
4.9.73 (December 6, 2023)
4.9.72 (December 5, 2023)
4.9.71 (December 5, 2023)
4.9.70 (November 22, 2023)
4.9.69 (November 21, 2023)
4.9.68 (November 13, 2023)
constructorpart (#11877).4.9.67 (October 1, 2023)
4.9.66 (September 25, 2023)
4.9.65 (August 7, 2023)
4.9.64 (June 21, 2023)
4.9.63 (Apr 10, 2023)
4.9.62 (Jan 8, 2023)
rgb(0 0 0/0.04). (#10565)4.9.61 (Jan 2, 2023)
4.9.60 (Oct 27, 2022)
4.9.59 (Oct 23, 2022)
darkreader-fallbackwasn't removed from the DOM, when Dark Reader finds a<meta name="darkreader-lock">element.4.9.58 (Sep 22, 2022)
4.9.57 (Aug 23, 2022)
4.9.56 (Aug 16, 2022)
4.9.55 (Aug 10, 2022)
maskis explicitly disabled.4.9.54 (Aug 10, 2022)
4.9.53 (Aug 9, 2022)
hrefattribute.navigator.UserAgentDatawhen possible.<meta name="darkreader-lock">detector, to disable Dark Reader when detected (only dynamic theme).background-imageproperty.4.9.52 (June 28, 2022)
url(...)values.4.9.51 (May 27, 2022)
Dynamic mode improvements:
url(...)and end withscreen.calc(...)color handling by using Shunting Yard algorithm.New translations:
Other:
4.9.50 (May 1, 2022)
4.9.48 (Apr 18, 2022)
4.9.47 (Mar 14, 2022)
4.9.46 (Mar 10, 2022)
4.9.45 (Feb 5, 2022)
4.9.44 (Feb 4, 2022)
4.9.43 (Dec 7, 2021)
4.9.42 (Nov 6, 2021)
4.9.41 (Nov 5, 2021)
4.9.40 (Nov 3, 2021)
4.9.39 (Oct 1, 2021)
4.9.37.1 (Sep 23, 2021)
4.9.36 (Sep 21, 2021)
4.9.35 (Sep 19, 2021)
4.9.34 (Jul 7, 2021)
4.9.33 (May 28, 2021)
4.9.32 (Apr 21, 2021)
4.9.31 (Apr 5, 2021)
4.9.30 (Apr 1, 2021)
4.9.29 (Feb 22, 2021)
4.9.27 (Jan 21, 2021)
4.9.26 (Nov 26, 2020)
4.9.25 (Nov 25, 2020)
4.9.24 (Nov 19, 2020)
4.9.23 (Oct 26, 2020)
4.9.22 (Oct 26, 2020)
4.9.21 (Sep 26, 2020)
v4.9.81Compare Source
v4.9.80Compare Source
v4.9.79Compare Source
v4.9.78Compare Source
v4.9.77Compare Source
v4.9.75Compare Source
v4.9.73Compare Source
v4.9.71Compare Source
v4.9.69Compare Source
v4.9.67Compare Source
v4.9.66Compare Source
v4.9.58Compare Source
v4.9.57Compare Source
v4.9.55Compare Source
maskis explicitly disabled.v4.9.53Compare Source
hrefattribute.navigator.UserAgentDatawhen possible.<meta name="darkreader-lock">detector, to disable Dark Reader when detected (only dynamic theme).background-imageproperty.v4.9.52Compare Source
url(...)values.v4.9.51Compare Source
Dynamic mode improvements:
url(...)and end withscreen.calc(...)color handling by using Shunting Yard algorithm.New translations:
Other:
Configuration
📅 Schedule: (in timezone Europe/Rome)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.