Skip to content

Security: Update Fastify and dependencies to patch body validation bypass (GHSA-247c-9743-5963) #221

Description

@birme

Summary

npm audit reveals 7 high-severity vulnerabilities in the backend dependency tree. The most critical is a Fastify body schema validation bypass that allows malformed Content-Type headers to skip TypeBox validation entirely.

Affected Packages

Package Severity CVE / GHSA Description
fastify v5.7.3 HIGH (CVSS 7.5) GHSA-247c-9743-5963 Body schema validation bypass via leading space in Content-Type
axios (indirect) HIGH (CVSS 7.5) GHSA-43fc-jf86-j433 DoS via __proto__ key in mergeConfig
flatted (indirect) HIGH (CVSS 7.5) GHSA-25h7-pfq9-p65f Unbounded recursion DoS in parse()
flatted (indirect) HIGH GHSA-rf6f-7fwh-wjgh Prototype pollution
glob (indirect) HIGH (CVSS 8.1) GHSA-xvch-5gqp-84wc Arbitrary command injection

Steps to Remediate

cd intercom-manager
npm audit fix
# If breaking changes:
npm audit fix --force  # review diff carefully
npm test
npm run typecheck

Also verify fastify is upgraded to >=5.8.1 in package.json.

Risk

The Fastify bypass (GHSA-247c-9743-5963) is particularly dangerous because it allows unauthenticated callers to submit unvalidated payloads to any route that relies solely on TypeBox schema validation for sanitisation.

Priority: CRITICAL

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions