Skip to content

security: fix form-data CRLF injection (GHSA-hmw2-7cc7-3qxx)#6

Merged
stackedsax merged 1 commit into
mainfrom
security/fix-form-data-cve-2026
Jun 17, 2026
Merged

security: fix form-data CRLF injection (GHSA-hmw2-7cc7-3qxx)#6
stackedsax merged 1 commit into
mainfrom
security/fix-form-data-cve-2026

Conversation

@pavlovic-ivan

Copy link
Copy Markdown
Contributor

Bumps transitive form-data 4.0.4 → 4.0.6 via npm audit fix to clear GHSA-hmw2-7cc7-3qxx. Only package-lock.json changes. Unblocks the PR Checks --audit-level=high gate.

CRLF injection in form-data via unescaped multipart field names and filenames
(form-data 4.0.0 - 4.0.5). Transitive dependency; only package-lock.json changes.

Applied via npm audit fix (no --force). After this:
  before: 22 advisories (1 high, 20 moderate, 1 low)
  after:  18 advisories (0 high, 18 moderate)

Unblocks the 'Check for known vulnerabilities' gate on PR Checks.
@netlify

netlify Bot commented Jun 17, 2026

Copy link
Copy Markdown

Deploy Preview for mlops-studio ready!

Name Link
🔨 Latest commit 91b6d12
🔍 Latest deploy log https://app.netlify.com/projects/mlops-studio/deploys/6a32e3bc10fbe80008f90080
😎 Deploy Preview https://deploy-preview-6--mlops-studio.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@pavlovic-ivan pavlovic-ivan marked this pull request as ready for review June 17, 2026 18:15
@pavlovic-ivan pavlovic-ivan requested a review from stackedsax June 17, 2026 18:17

@stackedsax stackedsax left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@stackedsax stackedsax merged commit 64f7235 into main Jun 17, 2026
17 checks passed
@stackedsax stackedsax deleted the security/fix-form-data-cve-2026 branch June 17, 2026 18:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants