Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Update dependency js-yaml to v4.1.1 [SECURITY]#133

Open
renovate[bot] wants to merge 1 commit intomain from
renovate/npm-js-yaml-vulnerability
Open

Update dependency js-yaml to v4.1.1 [SECURITY] #133
renovate[bot] wants to merge 1 commit intomain from
renovate/npm-js-yaml-vulnerability

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Nov 14, 2025
edited
Loading

This PR contains the following updates:

Package Change Age Confidence
js-yaml 4.1.04.1.1 age confidence

GitHub Vulnerability Alerts

CVE-2025-64718

Impact

In js-yaml 4.1.0, 4.0.0, and 3.14.1 and below, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (__proto__). All users who parse untrusted yaml documents may be impacted.

Patches

Problem is patched in js-yaml 4.1.1 and 3.14.2.

Workarounds

You can protect against this kind of attack on the server by using node --disable-proto=delete or deno (in Deno, pollution protection is on by default).

References

https://cheatsheetseries.owasp.org/cheatsheets/Prototype_Pollution_Prevention_Cheat_Sheet.html


Release Notes

nodeca/js-yaml (js-yaml)

v4.1.1

Compare Source

Security
  • Fix prototype pollution issue in yaml merge (<<) operator.

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies third-party dependencies label Nov 14, 2025
@renovate renovate bot force-pushed the renovate/npm-js-yaml-vulnerability branch from f0ed998 to 92529b4 Compare November 18, 2025 14:48
@renovate renovate bot force-pushed the renovate/npm-js-yaml-vulnerability branch from 92529b4 to 40adef4 Compare December 31, 2025 14:56
@renovate renovate bot force-pushed the renovate/npm-js-yaml-vulnerability branch 2 times, most recently from eda7ae6 to 257e948 Compare January 23, 2026 18:36
@renovate renovate bot force-pushed the renovate/npm-js-yaml-vulnerability branch from 257e948 to 87e924e Compare February 2, 2026 20:27
@renovate renovate bot force-pushed the renovate/npm-js-yaml-vulnerability branch from 87e924e to 83a18eb Compare February 12, 2026 16:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

No reviews

Assignees

No one assigned

Labels

dependencies third-party dependencies

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

0 participants

Comments

AltStyle によって変換されたページ (->オリジナル) /