chore(deps): Bump agents from 0.13.0 to 0.20.1 - #70
Fencer Scan Results
Checks
0 checks failed · 0 failing · 1 passing
- Audit mode —
PASS— 14 vulnerabilities found. Scan is in audit mode and will not fail. Configure thresholds to enable checks.
Hint: You can configure the checks on the repository settings page.
Scan metadata
- scan:
#626368· branchdependabot/npm_and_yarn/agents-0.20.1· sha31092f1b65cc - open: 14 —
critical=0 high=6 medium=5 low=3 info=0 - new: 0 —
critical=0 high=0 medium=0 low=0 info=0 - new-secrets: 0
- resolved: 0
- ignored: 1
Pre-existing vulnerabilities (14, showing 10)
Present on the base branch before this scan.
VULN-D99 — HIGH
- id:
VULN-D99 - rule: IDN hostname canonicalization bypass in URL parsing library
- severity:
HIGH - state:
pre-existing(present on the base branch) - scope:
repo - location:
demo/pnpm-lock.yaml - title: Vulnerable package: fast-uri@3.1.2
- description: Found 3 vulnerabilities in package fast-uri version 3.1.2. Upgrade to version 3.1.5 to fix these issues.
- remediation: Update dependency. References: GHSA-4c8g-83qw-93j6, https://nvd.nist.gov/vuln/detail/CVE-2026-13676, fastify/fast-uri#188, fastify/fast-uri@2a6d357, fastify/fast-uri@21ea1f9, fastify/fast-uri@01db480, https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13676.json, https://github.com/fastify/fast-uri/releases/tag/v4.0.1, https://github.com/fastify/fast-uri/releases/tag/v3.1.3, https://github.com/fastify/fast-uri/releases/tag/v2.4.2, https://cna.openjsf.org/security-advisories.html, https://bugzilla.redhat.com/show_bug.cgi?id=2494197, https://access.redhat.com/security/cve/CVE-2026-13676, https://access.redhat.com/errata/RHSA-2026:41929, https://access.redhat.com/errata/RHSA-2026:41928, https://access.redhat.com/errata/RHSA-2026:41066, https://access.redhat.com/errata/RHSA-2026:40945, https://access.redhat.com/errata/RHSA-2026:40262, https://access.redhat.com/errata/RHSA-2026:40118, https://access.redhat.com/errata/RHSA-2026:37628, https://access.redhat.com/errata/RHSA-2026:37585, https://access.redhat.com/errata/RHSA-2026:37186, https://access.redhat.com/errata/RHSA-2026:43038, https://access.redhat.com/errata/RHSA-2026:42815, https://access.redhat.com/errata/RHSA-2026:40765, https://access.redhat.com/errata/RHSA-2026:44239, https://access.redhat.com/errata/RHSA-2026:44268, https://access.redhat.com/errata/RHSA-2026:48126, https://access.redhat.com/errata/RHSA-2026:48124, https://access.redhat.com/errata/RHSA-2026:49642
VULN-D9A — HIGH
- id:
VULN-D9A - rule: brace-expansion can be abused for DoS via unbounded intermediate arrays
- severity:
HIGH - state:
pre-existing(present on the base branch) - scope:
repo - location:
pnpm-lock.yaml - title: Vulnerable package: brace-expansion@1.1.14
- description: Found 3 vulnerabilities in package brace-expansion version 1.1.14. Upgrade to version 1.1.18 to fix these issues.
- remediation: Update dependency. References: GHSA-rgw5-rvv9-x895, juliangruber/brace-expansion@139d015, juliangruber/brace-expansion@1e30c93, juliangruber/brace-expansion@688a99e, juliangruber/brace-expansion@cb4b9e4, https://nvd.nist.gov/vuln/detail/CVE-2026-69152
VULN-E2X — HIGH
- id:
VULN-E2X - rule: postcss can load unintended source-map files when 'from' is unset, exposing .map contents
- severity:
HIGH - state:
pre-existing(present on the base branch) - scope:
repo - location:
demo/pnpm-lock.yaml - title: Vulnerable package: postcss@8.5.14
- description: Found 2 vulnerabilities in package postcss version 8.5.14. Upgrade to version 8.5.23 to fix these issues.
- remediation: Update dependency. References: GHSA-fxqj-rqcc-2cmp, postcss/postcss@7beca13, https://github.com/postcss/postcss/releases/tag/8.5.19
VULN-FS0 — HIGH
- id:
VULN-FS0 - rule: fast-uri parses backslash authority introducers differently than WHATWG parser, causing host confusion
- severity:
HIGH - state:
pre-existing(present on the base branch) - scope:
repo - location:
pnpm-lock.yaml - title: Vulnerable package: fast-uri@3.1.4
- description: Found 1 vulnerability in package fast-uri version 3.1.4. Upgrade to version 3.1.5 to fix these issues.
- remediation: Update dependency. References: GHSA-7p8r-x3mc-p8w7, https://nvd.nist.gov/vuln/detail/CVE-2026-18446, fastify/fast-uri@f3c6c90, https://cna.openjsf.org/security-advisories.html, https://github.com/fastify/fast-uri/releases/tag/v4.1.2
VULN-FS1 — HIGH
- id:
VULN-FS1 - rule: ip-address decodes leading-zero IPv4 octets as decimal, causing host mismatch and SSRF bypass
- severity:
HIGH - state:
pre-existing(present on the base branch) - scope:
repo - location:
pnpm-lock.yaml - title: Vulnerable package: ip-address@10.2.0
- description: Found 3 vulnerabilities in package ip-address version 10.2.0. Upgrade to version 10.3.1 to fix these issues.
- remediation: Update dependency. References: GHSA-mwp4-54f8-5fhr, beaugunderson/ip-address@56368cb, https://github.com/beaugunderson/ip-address/releases/tag/v10.3.1
VULN-GBM — HIGH
- id:
VULN-GBM - rule: undici cache interceptor stores private responses and can crash on malformed Cache-Control directives
- severity:
HIGH - state:
pre-existing(present on the base branch) - scope:
repo - location:
pnpm-lock.yaml - title: Vulnerable package: undici@7.28.0
- description: Found 5 vulnerabilities in package undici version 7.28.0. Upgrade to version 7.29.0 to fix these issues.
- remediation: Update dependency. References: GHSA-4cwx-7wf7-3272, https://nvd.nist.gov/vuln/detail/CVE-2026-13697, nodejs/undici@4fe5bc5, https://cna.openjsf.org/security-advisories.html, https://github.com/nodejs/undici/releases/tag/v7.29.0, https://github.com/nodejs/undici/releases/tag/v8.9.0
VULN-9VQ — MEDIUM
- id:
VULN-9VQ - rule: Dependabot configuration missing cooldown period for new packages
- severity:
MEDIUM - state:
pre-existing(present on the base branch) - scope:
repo - location:
.github/dependabot.yml:3-13 - title: Inclusion of Functionality from Untrusted Control Sphere
- description: This Dependabot configuration does not set a cooldown period. Newly published packages can be malicious or unstable. Add a
cooldownblock withdefault-days: 7to eachpackage-ecosystementry underupdatesto wait 7 days before proposing updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown - remediation: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown
VULN-9VR — MEDIUM
- id:
VULN-9VR - rule: Dependabot configuration missing cooldown period for new packages
- severity:
MEDIUM - state:
pre-existing(present on the base branch) - scope:
repo - location:
.github/dependabot.yml:15-19 - title: Inclusion of Functionality from Untrusted Control Sphere
- description: This Dependabot configuration does not set a cooldown period. Newly published packages can be malicious or unstable. Add a
cooldownblock withdefault-days: 7to eachpackage-ecosystementry underupdatesto wait 7 days before proposing updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown - remediation: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown
VULN-AEH — MEDIUM
- id:
VULN-AEH - rule: pnpm missing trustPolicy (no-downgrade recommended)
- severity:
MEDIUM - state:
pre-existing(present on the base branch) - scope:
repo - location:
pnpm-workspace.yaml:1 - title: Inclusion of Functionality from Untrusted Control Sphere
- description: Missing or incorrect trustPolicy. Set
trustPolicy: no-downgradeto prevent malicious package updates from downgrading security settings. Added in: v10.21.0 Reference: https://pnpm.io/settings#trustpolicy - remediation: https://pnpm.io/settings#minimumreleaseage
VULN-AG4 — MEDIUM
- id:
VULN-AG4 - rule: pnpm workspace missing minimumReleaseAge allowing immediate installs of new packages
- severity:
MEDIUM - state:
pre-existing(present on the base branch) - scope:
repo - location:
pnpm-workspace.yaml:21 - title: Inclusion of Functionality from Untrusted Control Sphere
- description: This pnpm workspace configuration does not set a minimum release age. Newly published packages can be malicious or unstable. Add
minimumReleaseAge: 10080(minutes) to wait at least seven days before installing newly published package versions. Added in: v10.16.0 Reference: https://pnpm.io/settings#minimumreleaseage - remediation: https://pnpm.io/settings#minimumreleaseage
Showing the first 10 of 14 pre-existing vulnerabilities — see the scan for the rest.
Annotations
Check notice on line 0 in pnpm-lock.yaml
fencer-code / Fencer
Vulnerability: #VULN-D9B
Found 1 vulnerability in package body-parser version 2.2.2. Upgrade to version 2.3.0 to fix these issues.
This check detects when body-parser accepts an invalid limit configuration value that causes the library to skip request body size enforcement. If an unparseable or non-finite limit disables the size check, applications relying on that option can receive arbitrarily large request bodies. Excessive request payloads can exhaust memory or CPU and lead to denial-of-service of the hosting process. The affected resource is the Node.js body-parser middleware used to parse incoming HTTP request bodies.
Check failure on line 0 in pnpm-lock.yaml
fencer-code / Fencer
Vulnerability: #VULN-FS1
Found 3 vulnerabilities in package ip-address version 10.2.0. Upgrade to version 10.3.1 to fix these issues.
This check detects incorrect parsing of IPv4 octets with leading zeros by the ip-address library: leading-zero octets are decoded as decimal rather than octal. Because system resolvers and WHATWG parsers decode leading-zero octets as octal, the library and the network stack can produce different resolved hosts for the same input string. This discrepancy can allow SSRF and trust-boundary bypasses when the library's classification is used to approve network requests.
Check failure on line 0 in pnpm-lock.yaml
fencer-code / Fencer
Vulnerability: #VULN-FS0
Found 1 vulnerability in package fast-uri version 3.1.4. Upgrade to version 3.1.5 to fix these issues.
This check identifies a discrepancy between fast-uri and the WHATWG URL parser in how backslashes are treated as authority introducers. fast-uri requires a literal '//' to recognize an authority, so inputs using backslash variants fold the authority into the path; the WHATWG parser treats backslashes as equivalent to forward slashes for special schemes and extracts a host. The mismatch can lead to host confusion that defeats host-based allowlists, SSRF filters, or redirect validation when different parsers are used in validation and request handling.
Check warning on line 0 in pnpm-lock.yaml
fencer-code / Fencer
Vulnerability: #VULN-FS2
Found 1 vulnerability in package hono version 4.12.33. Upgrade to version 4.12.34 to fix these issues.
This check detects a regular-expression or parsing weakness in Hono's CORS middleware where specially crafted Access-Control-Request-Headers values can trigger catastrophic backtracking or exponential processing time (ReDoS). An attacker can supply header values that cause excessive CPU consumption when the middleware parses or validates them, potentially leading to denial-of-service for affected servers. The issue affects versions of Hono that include the vulnerable CORS code path.
Check failure on line 0 in pnpm-lock.yaml
fencer-code / Fencer
Vulnerability: #VULN-D9A
Found 3 vulnerabilities in package brace-expansion version 1.1.14. Upgrade to version 1.1.18 to fix these issues.
This check detects cases where the brace-expansion algorithm can allocate unbounded intermediate arrays that grow exponentially with crafted input, resulting in high CPU and memory usage. An attacker-supplied pattern can therefore cause denial-of-service by exhausting resources during expansion. The vulnerability affects applications and build tooling that use the brace-expansion library to expand patterns without input size limits or safeguards.
Check notice on line 0 in pnpm-lock.yaml
fencer-code / Fencer
Vulnerability: #VULN-BXD
Found 1 vulnerability in package @babel/core version 7.29.0. Upgrade to version 7.29.6 to fix these issues.
This check detects a version of @babel/core that allows arbitrary file reads via sourceMappingURL comments. When a build or transformation tool fetches source maps from untrusted inputs, attackers can cause the tool to read arbitrary files on the host, leaking sensitive data. The affected technology is JavaScript build/transformation toolchains that process sourceMappingURL entries with @babel/core.
Check failure on line 0 in pnpm-lock.yaml
fencer-code / Fencer
Vulnerability: #VULN-GBM
Found 5 vulnerabilities in package undici version 7.28.0. Upgrade to version 7.29.0 to fix these issues.
This check detects improper handling of malformed Cache-Control private directives by the undici cache interceptor. Degenerate qualified private directives (for example, empty values) can cause private responses and headers to be stored in a shared cache and later served to other callers, disclosing sensitive data. In addition, certain combinations of qualified and unqualified private directives can trigger an uncaught parser TypeError that rejects requests and may terminate the process depending on consumer error handling. The issue affects applications that use undici's cache interceptor in shared mode (including default configurations).