Skip to content

fix: server/package.json & server/yarn.lock to reduce vulnerabilities

0d03e18
Select commit
Loading
Failed to load commit list.
Open

[Snyk] Fix for 1 vulnerabilities #27

fix: server/package.json & server/yarn.lock to reduce vulnerabilities
0d03e18
Select commit
Loading
Failed to load commit list.
Mend Bolt for GitHub / WhiteSource Security Check failed Feb 13, 2026 in 9m 44s

Security Report

You have successfully remediated 33 vulnerabilities, but introduced 20 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2021-42740

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> npm-run-all-4.1.5.tgz (Root Library)

   -> ❌ shell-quote-1.6.1.tgz (Vulnerable Library)

Critical 9.8 Transitive shell-quote-1.6.1.tgz npm-run-all-4.1.5.tgz Transitive 1.7.3 None
CVE-2024-48949

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

Critical 9.1 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive 6.5.6 None
CVE-2023-46233

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ crypto-js-3.1.9-1.tgz (Vulnerable Library)

Critical 9.1 Direct crypto-js-3.1.9-1.tgz crypto-js-3.1.9-1.tgz crypto-js - 4.2.0 None
WS-2025-0006

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

High 8.6 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive 6.6.1 None
CVE-2020-13822

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

High 7.7 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive 6.5.3 None
CVE-2025-27611

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> bs58check-2.1.2.tgz

     -> bs58-4.0.1.tgz

       -> ❌ base-x-3.0.5.tgz (Vulnerable Library)

High 7.5 Transitive base-x-3.0.5.tgz bitcoinjs-message-2.0.0.tgz Transitive 3.0.11 None
CVE-2024-48930

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> ❌ secp256k1-3.7.0.tgz (Vulnerable Library)

High 7.5 Transitive secp256k1-3.7.0.tgz bitcoinjs-message-2.0.0.tgz Transitive secp256k1 - 5.0.1,secp256k1 - 3.8.1,secp256k1 - 4.0.4 None
CVE-2022-31129

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ moment-2.24.0.tgz (Vulnerable Library)

High 7.5 Direct moment-2.24.0.tgz moment-2.24.0.tgz 2.29.4 None
CVE-2022-24785

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ moment-2.24.0.tgz (Vulnerable Library)

High 7.5 Direct moment-2.24.0.tgz moment-2.24.0.tgz 2.29.2 None
CVE-2020-28498

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

Medium 6.8 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive 6.5.4 None
WS-2019-0427

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

Medium 5.9 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive 6.5.2 None
WS-2019-0424

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

Medium 5.9 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive 6.5.3 None
CVE-2025-14505

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

Medium 5.6 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz None
CVE-2024-42461

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

Medium 5.3 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive elliptic - 6.5.7,elliptic - 6.5.7 None
CVE-2024-42460

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

Medium 5.3 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive elliptic - 6.5.7,elliptic - 6.5.7 None
CVE-2024-42459

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

Medium 5.3 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive elliptic - 6.5.7,elliptic - 6.5.7 None
CVE-2022-25883

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> npm-run-all-4.1.5.tgz (Root Library)

   -> read-pkg-3.0.0.tgz

     -> normalize-package-data-2.5.0.tgz

       -> ❌ semver-5.7.0.tgz (Vulnerable Library)

Medium 5.3 Transitive semver-5.7.0.tgz npm-run-all-4.1.5.tgz Transitive 5.7.2 None
CVE-2021-23362

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> npm-run-all-4.1.5.tgz (Root Library)

   -> read-pkg-3.0.0.tgz

     -> normalize-package-data-2.5.0.tgz

       -> ❌ hosted-git-info-2.7.1.tgz (Vulnerable Library)

Medium 5.3 Transitive hosted-git-info-2.7.1.tgz npm-run-all-4.1.5.tgz Transitive 2.8.9 None
CVE-2020-36732

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ crypto-js-3.1.9-1.tgz (Vulnerable Library)

Medium 5.3 Direct crypto-js-3.1.9-1.tgz crypto-js-3.1.9-1.tgz crypto-js - 3.2.1,crypto-js - 3.2.1 None
CVE-2024-48948

Path to dependency file: /server/package.json

Path to vulnerable library: /server/package.json

Dependency Hierarchy:

-> bitcoinjs-message-2.0.0.tgz (Root Library)

   -> secp256k1-3.7.0.tgz

     -> ❌ elliptic-6.4.1.tgz (Vulnerable Library)

Medium 4.8 Transitive elliptic-6.4.1.tgz bitcoinjs-message-2.0.0.tgz Transitive elliptic - 6.6.0 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2025-14505 elliptic-6.5.3.tgz
CVE-2020-28469 glob-parent-3.1.0.tgz
CVE-2021-44906 minimist-1.2.5.tgz
CVE-2017-16137 debug-3.2.6.tgz
CVE-2021-23362 hosted-git-info-2.8.8.tgz
CVE-2024-47764 cookie-0.4.0.tgz
CVE-2021-3807 ansi-regex-3.0.0.tgz
CVE-2024-45590 body-parser-1.19.0.tgz
CVE-2020-28498 elliptic-6.5.3.tgz
WS-2025-0006 elliptic-6.5.3.tgz
CVE-2025-15284 qs-6.7.0.tgz
CVE-2024-43799 send-0.17.1.tgz
CVE-2022-25883 semver-5.7.1.tgz
CVE-2022-33987 got-6.7.1.tgz
CVE-2024-48930 secp256k1-3.8.0.tgz
CVE-2024-29041 express-4.17.1.tgz
CVE-2025-27611 base-x-3.0.8.tgz
CVE-2022-24785 moment-2.27.0.tgz
CVE-2022-31129 moment-2.27.0.tgz
CVE-2024-43800 serve-static-1.14.1.tgz
CVE-2024-21538 cross-spawn-5.1.0.tgz
CVE-2024-42460 elliptic-6.5.3.tgz
CVE-2022-38900 decode-uri-component-0.2.0.tgz
CVE-2021-42740 shell-quote-1.7.2.tgz
CVE-2024-42461 elliptic-6.5.3.tgz
CVE-2020-7788 ini-1.3.5.tgz
CVE-2024-42459 elliptic-6.5.3.tgz
CVE-2024-48948 elliptic-6.5.3.tgz
CVE-2024-43796 express-4.17.1.tgz
CVE-2024-48949 elliptic-6.5.3.tgz
CVE-2022-24999 qs-6.7.0.tgz
CVE-2024-52798 path-to-regexp-0.1.7.tgz
CVE-2024-45296 path-to-regexp-0.1.7.tgz

Base branch total remaining vulnerabilities: 42
Base branch commit: null


Total libraries scanned: 190

Scan token: 2bb8d5cd2811486dadaec8b74405dc19