Skip to content

chore: upgrade js-yaml to 4.3.2 to address CVE-2026-84375 - #1636

Merged
brendan-kellam merged 6 commits into
mainfrom
cursor/cve/js-yaml
Sep 9, 2026
Merged

chore: upgrade js-yaml to 4.3.2 to address CVE-2026-84375#1636
brendan-kellam merged 6 commits into
mainfrom
cursor/cve/js-yaml

Conversation

@claude

@claude claude Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-2194

Summary

Refreshes the yarn.lock entry for js-yaml from 4.3.1 to 4.3.2 to address CVE-2026-84375 (GHSA-2883-xcg3-v3hh), a denial-of-service in YAML merge-key (<<) processing where maxTotalMergeKeys does not count empty mapping sources, allowing a small document to cause prolonged CPU consumption.

This is a lockfile-only change. The existing js-yaml@npm:^4.1.0^4.1.1 resolution already admits the patched 4.3.2 release, so no package.json change and no new resolutions override are needed.

Verification

yarn why js-yaml shows every instance resolved to the patched version:

├─ @apidevtools/json-schema-ref-parser@npm:11.9.3
│  └─ js-yaml@npm:4.3.2 (via npm:^4.1.1)
├─ @eslint/eslintrc@npm:3.3.1
│  └─ js-yaml@npm:4.3.2 (via npm:^4.1.1)
├─ @eslint/eslintrc@npm:3.3.4
│  └─ js-yaml@npm:4.3.2 (via npm:^4.1.1)
└─ json-schema-to-typescript@npm:15.0.4
   └─ js-yaml@npm:4.3.2 (via npm:^4.1.1)
  • yarn install clean
  • yarn build:deps clean
  • yarn test — 2153 tests passed across all 4 workspaces

🤖 Generated with Claude Code


Note

Low Risk
Lockfile-only patch bump for a transitive YAML parser; no application code or dependency range changes.

Overview
Bumps the resolved js-yaml dependency from 4.3.1 to 4.3.2 in yarn.lock to address CVE-2026-84375 (DoS via YAML merge-key << handling when maxTotalMergeKeys under-counts empty mapping sources). No package.json changes—the existing ^4.1.1 resolution already permits 4.3.2.

Documents the upgrade under Fixed in CHANGELOG.md.

Reviewed by Cursor Bugbot for commit 0952740. Bugbot is set up for automated code reviews on this repo. Configure here.


Summary by cubic

Upgrades js-yaml from 4.3.1 to 4.3.2 in yarn.lock to fix CVE-2026-84375, a denial-of-service in YAML merge-key processing. This is a lockfile-only change; the existing ^4.1.1 range already admits 4.3.2, so no package.json change is needed. Adds a changelog entry.

Written for commit 0952740. Summary will update on new commits.

Review in cubic

github-actions Bot and others added 5 commits August 7, 2026 08:48
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Refreshes the yarn.lock entry for js-yaml. The existing `^4.1.1`
resolution range already admits the patched 4.3.2 release, so no
package.json change is required.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@claude
claude Bot requested a review from brendan-kellam September 9, 2026 12:38
@brendan-kellam
brendan-kellam merged commit ce39b19 into main Sep 9, 2026
10 checks passed
@brendan-kellam
brendan-kellam deleted the cursor/cve/js-yaml branch September 9, 2026 18:35
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️ Status: PASS

Metric Count
Total packages 2174
Resolved (non-standard) 8
Unresolved 0
Strong copyleft 0
Weak copyleft 28

Weak Copyleft Packages (informational)

Package Version License
@img/sharp-libvips-darwin-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-wasm32 0.35.3 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm64 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
axe-core 4.10.3 MPL-2.0
dompurify 3.4.13 (MPL-2.0 OR Apache-2.0)
lightningcss 1.32.0 MPL-2.0
lightningcss-android-arm64 1.32.0 MPL-2.0
lightningcss-darwin-arm64 1.32.0 MPL-2.0
lightningcss-darwin-x64 1.32.0 MPL-2.0
lightningcss-freebsd-x64 1.32.0 MPL-2.0
lightningcss-linux-arm-gnueabihf 1.32.0 MPL-2.0
lightningcss-linux-arm64-gnu 1.32.0 MPL-2.0
lightningcss-linux-arm64-musl 1.32.0 MPL-2.0
lightningcss-linux-x64-gnu 1.32.0 MPL-2.0
lightningcss-linux-x64-musl 1.32.0 MPL-2.0
lightningcss-win32-arm64-msvc 1.32.0 MPL-2.0
lightningcss-win32-x64-msvc 1.32.0 MPL-2.0
Resolved Packages (8)
Package Version Original Resolved Source
codemirror-lang-elixir 4.0.0 UNKNOWN Apache-2.0 Apache-2.0 license text shipped as LICENSE in the package tarball; corroborated by npm registry metadata for the package (Apache-2.0)
khroma 2.1.0 UNKNOWN MIT MIT license text shipped as 'license' file in the package tarball
lezer-elixir 1.1.2 UNKNOWN Apache-2.0 Apache-2.0 license text shipped as LICENSE in the package tarball; corroborated by npm registry metadata for the package (Apache-2.0)
map-stream 0.1.0 UNKNOWN MIT MIT license text shipped as LICENCE in the package tarball; corroborated by npm registry metadata (MIT)
memorystream 0.3.1 UNKNOWN MIT extracted from object: legacy licenses: [{"type":"MIT","url":"..."}] field in package.json; corroborated by MIT license text in LICENSE
pause-stream 0.0.11 ["MIT", "Apache2"] MIT OR Apache-2.0 extracted from object: license array ["MIT","Apache2"] in package.json; LICENSE file states 'Dual Licensed MIT and Apache 2' (normalized 'Apache2' to SPDX 'Apache-2.0')
posthog-js 1.369.0 SEE LICENSE IN LICENSE Apache-2.0 AND MIT LICENSE file referenced by 'SEE LICENSE IN LICENSE': Apache-2.0 for PostHog/Mixpanel code plus bundled third-party MIT notices; matches npm registry metadata '(Apache-2.0 AND MIT)'
valid-url 1.0.9 UNKNOWN MIT MIT license text shipped as LICENSE in the package tarball

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant