Skip to content

[Aikido] Fix 1 critical issue in sha.js and 6 other issues - #15

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/-security-issue'supdate-packages-11823502-vqKw
Closed

[Aikido] Fix 1 critical issue in sha.js and 6 other issues#15
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/-security-issue'supdate-packages-11823502-vqKw

Conversation

@aikido-autofix

Copy link
Copy Markdown
Contributor

This pull request addresses identified vulnerabilities and implements the necessary fixes to strengthen our security posture. Please review and approve so we can merge these changes promptly and reduce potential risk.

Any issues, please ping me, Alan Sower.

Thanks Team

Upgrading sha.js, axios, glob, es-toolkit, min-document, @metamask/sdk, @metamask/sdk-communication-layer to address vulnerabilities.

🚨 6 CVEs resolved by this upgrade, including 1 critical CVE

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2025-9288
🚨 CRITICAL
Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11.
CVE-2025-58754
HIGH
Axios is a promise based HTTP client for the browser and Node.js. When Axios prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the data: scheme, it does not perform HTTP. Instead, its Node http adapter decodes the entire payload into memory (Buffer/Blob) and returns a...
CVE-2025-64756
HIGH
Glob matches files using patterns the shell uses. Starting in version 10.2.0 and prior to versions 10.5.0 and 11.1.0, the glob CLI contains a command injection vulnerability in its -c/--cmd option that allows arbitrary command execution when processing files with malicious names. When glob -c <comma...
AIKIDO-2025-10391
MEDIUM
Affected versions of this package are vulnerable to potential prototype pollution, which could allow attackers to manipulate object properties and impact application behavior.
CVE-2025-57352
MEDIUM
A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespace operations in the removeAttributeNS method. By processing malicious input involving the proto property, an attacker can manipulate the prototype chain of JavaScript objects,...
GHSA-qj3p-xc97-xw74
MEDIUM
### Who is affected?
This advisory only applies to developers who use MetaMask SDK in the browser and who, on Sept 8th 2025 between 13:00–15:30 UTC, performed one of the following actions and then deployed their application:
- Installed MetaMask SDK into a project with a lockfile for the first time
🔗 Related Tasks

@aikido-autofix aikido-autofix Bot added the aikido Label created by Aikido AutoFix label Dec 10, 2025
@github-actions

This comment was marked as off-topic.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aikido Label created by Aikido AutoFix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant