ui icon indicating copy to clipboard operation
ui copied to clipboard

[bug]: There is a vulnerability in [email protected] > [email protected]

Open tar-aldev opened this issue 1 year ago • 4 comments

Describe the bug

When running pnpm audit Ican see that there is a vulnerabilty in lodash and lodash is used by shadcn-ui under the hood. high │ Command Injection in lodash
│ Package │ lodash.template │ Vulnerable versions │ <=4.5.0 │ Patched versions │ <0.0.0 │ Paths │ . > [email protected] > [email protected] │ More info │ https://github.com/advisories/GHSA-35jh-r3h4-6jhm

Affected component/components

shadcn-ui

How to reproduce

Install "shadcn-ui": "^0.8.0" using pnpm

Codesandbox/StackBlitz link

No response

Logs

No response

System Info

"shadcn-ui": "^0.8.0",

Before submitting

  • [X] I've made research efforts and searched the documentation
  • [X] I've searched for existing issues

tar-aldev avatar Jun 12 '24 18:06 tar-aldev

Hi shadcn team, could you help to address this high security issue?

jimmyntu avatar Jun 20 '24 15:06 jimmyntu

Bumping this as it's high severity, any timeline on upgrading the dependency? I'm happy to open a PR if one isn't already opened

JensAstrup avatar Jul 19 '24 02:07 JensAstrup

The PR in #4397 looks great, thanks @JensAstrup. Any news on the approval status?

gdragotto avatar Sep 06 '24 12:09 gdragotto

I have no idea who I'm waiting on for approval 😛

JensAstrup avatar Sep 07 '24 03:09 JensAstrup

@shadcn ?

gdragotto avatar Oct 16 '24 16:10 gdragotto

Guys, it is a high vulnerability. any updates?

vikasbhandari2 avatar Oct 30 '24 21:10 vikasbhandari2

+1

ecsbeats avatar Nov 10 '24 06:11 ecsbeats

also waiting here

mynlexi avatar Dec 05 '24 17:12 mynlexi

Same!

SMaurischat avatar Dec 06 '24 10:12 SMaurischat

+1 Better question, why even rely on Lodash. Seems to me it isn't well maintained. I always avoid Lodash due to frequent high severity vuln issues like this with it. Looks like we're all just supposed to head back to shadcn 1.0 for now?

rjsprague avatar Dec 08 '24 07:12 rjsprague

+1

dcollien avatar Dec 09 '24 07:12 dcollien

+1

marulijames avatar Dec 09 '24 07:12 marulijames

May I add, there is the same problem in the shadcn package itself (not the cli) in the current main: https://github.com/shadcn-ui/ui/blob/1081536246b44b6664f4c99bc3f1b3614e632841/packages/shadcn/package.json#L62

Should I open another GH issue?

Thank you in advance!

js-4 avatar Jan 09 '25 13:01 js-4