Skip to content

Conversation

@snyk-io
Copy link

@snyk-io snyk-io bot commented Sep 27, 2025

snyk-top-banner

Snyk has created this PR to fix 25 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • dapps/web3modal/react/package.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-12704893
  280  
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-12761655
  280  
critical severity Function Call With Incorrect Argument Type
SNYK-JS-SHAJS-12089400
  261  
critical severity Information Exposure
SNYK-JS-ELLIPTIC-8720086
  251  
critical severity Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-8187303
  243  
critical severity Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-7577917
  214  
critical severity Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-7577916
  209  
critical severity Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-7577918
  209  
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
  208  
high severity Infinite loop
SNYK-JS-IMAGESIZE-9634164
  170  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CROSSSPAWN-8303230
  169  
high severity Improper Validation of Integrity Check Value
SNYK-JS-SECP256K1-8237220
  169  
high severity Denial of Service (DoS)
SNYK-JS-WS-7266574
  160  
high severity Excessive Platform Resource Consumption within a Loop
SNYK-JS-BRACES-6838727
  159  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BABELHELPERS-9397697
  140  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BABELRUNTIME-10044504
  140  
medium severity Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
  131  
high severity Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-8172694
  130  
medium severity Server-Side Request Forgery (SSRF)
SNYK-JS-IP-7148531
  114  
low severity Cross-site Scripting
SNYK-JS-SEND-7926862
  69  
low severity Cross-site Scripting
SNYK-JS-SERVESTATIC-7926865
  69  
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BRACEEXPANSION-9789073
  57  
medium severity Improper Handling of Unexpected Data Type
SNYK-JS-ONHEADERS-10773729
  57  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-FASTXMLPARSER-7573289
  45  
medium severity Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
  45  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)
🦉 Server-side Request Forgery (SSRF)
🦉 Cross-site Scripting

@vercel
Copy link

vercel bot commented Sep 27, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Preview Comments Updated (UTC)
web-examples Ready Ready Preview Comment Sep 27, 2025 6:31am

@snyk-io
Copy link
Author

snyk-io bot commented Sep 27, 2025

🎉 Snyk checks have passed. No issues have been found so far.

security/snyk check is complete. No issues have been found. (View Details)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant