fix(deps): patch 6 security alerts across 4 packages (1 critical, 5 medium) (#478)
## Security Alert Patch Resolves 6 open Dependabot security alerts (**1 critical, 5 medium**). ### Packages Updated | Package | Old → New | Strategy | Scope | CVEs Resolved | |---------|-----------|----------|-------|---------------| | `protobufjs` | 7.5.4 → 7.5.5 | C (pnpm override) — parent ranges already accept 7.5.5 | transitive (via modal, @grpc/proto-loader, @opentelemetry/otlp-transformer) | **CVE-2026-41242** (critical) | | `axios` | 1.13.6 → 1.15.1 | C (pnpm override) — @daytonaio/sdk `^1.13.5` already accepts 1.15.x | transitive (via @daytonaio/sdk, @daytonaio/api-client, @daytonaio/toolbox-api-client) | CVE-2025-62718, CVE-2026-40175 | | `follow-redirects` | 1.15.11 → 1.16.0 | C (pnpm override) — axios `^1.15.11` already accepts 1.16.0 | transitive (via axios) | GHSA-r4q5-vmmm-2653 | | `langsmith` | floor raised to 0.5.19 | A (direct bump) — `libs/deepagents` peerDep, `internal/eval-harness` dep | direct, published | CVE-2026-40190, GHSA-rr7j-v2q5-chgv | ### Why pnpm.overrides for transitives The three transitive bumps (protobufjs, axios, follow-redirects) use pnpm.overrides because the parent packages' version ranges **already allow the patched versions** — this is a lockfile refresh, not a published-constraint change. End users installing `@langchain/daytona` or `@langchain/modal` resolve their own lockfile and naturally get the patched transitive versions; the overrides here just bring our lockfile up to date. For `langsmith`, the vulnerable 0.5.15 was pinned in `libs/deepagents/peerDependencies` with floor `>=0.5.15`. Raising to `>=0.5.19` closes the window for downstream consumers with stale lockfiles. ### CVE Details | ID | Package | Severity | Summary | |----|---------|----------|---------| | CVE-2026-41242 / GHSA-xq3m-2v4x-88gg | protobufjs | critical | Arbitrary code execution in protobufjs | | CVE-2025-62718 / GHSA-3p68-rc4w-qgx5 | axios | medium | NO_PROXY hostname normalization bypass leading to SSRF | | CVE-2026-40175 / GHSA-fvcv-3m26-pcqx | axios | medium | Unrestricted cloud metadata exfiltration via header injection chain | | GHSA-r4q5-vmmm-2653 | follow-redirects | medium | Leaks custom authentication headers to cross-domain redirect targets | | CVE-2026-40190 / GHSA-fw9q-39r9-c252 | langsmith | medium | Prototype pollution via incomplete `__proto__` guard in internal lodash `set()` | | GHSA-rr7j-v2q5-chgv | langsmith | medium | Streaming token events bypass output redaction | ### Linear Tickets No matching Linear tickets found (CLI unauthenticated in this environment). ### Verification - [x] `pnpm install --lockfile-only` clean — new lockfile contains axios@1.15.1, protobufjs@7.5.5, follow-redirects@1.16.0, langsmith@0.5.20 & 0.5.21 (vulnerable 0.5.15 fully removed) - [x] `pnpm format:check` passes (313 files) - [x] `pnpm lint` (oxlint) passes (0 warnings, 0 errors) - [x] `pnpm test:unit` — 829/830 unit tests pass; the 1 failure and 6 unhandled errors are **pre-existing** on `main` (tied to recent `ls_agent_type` feature #470 and broken `@langchain/sandbox-standard-tests` module resolution), unrelated to this patch - [x] `pnpm typecheck` failure in `libs/standard-tests` is pre-existing on `main`, unrelated to this patch - [x] No major-version bumps; minimum-safe versions used throughout 🤖 Submitted by langster-patch
J
John Kennedy committed
6eb421ff9e8ce5b0207c773a64da1dea05916d72
Parent: 4c0c219
Committed by GitHub <noreply@github.com>
on 4/21/2026, 9:39:29 PM