Summary
npm audit reveals 7 high-severity vulnerabilities in the backend dependency tree. The most critical is a Fastify body schema validation bypass that allows malformed Content-Type headers to skip TypeBox validation entirely.
Affected Packages
| Package |
Severity |
CVE / GHSA |
Description |
fastify v5.7.3 |
HIGH (CVSS 7.5) |
GHSA-247c-9743-5963 |
Body schema validation bypass via leading space in Content-Type |
axios (indirect) |
HIGH (CVSS 7.5) |
GHSA-43fc-jf86-j433 |
DoS via __proto__ key in mergeConfig |
flatted (indirect) |
HIGH (CVSS 7.5) |
GHSA-25h7-pfq9-p65f |
Unbounded recursion DoS in parse() |
flatted (indirect) |
HIGH |
GHSA-rf6f-7fwh-wjgh |
Prototype pollution |
glob (indirect) |
HIGH (CVSS 8.1) |
GHSA-xvch-5gqp-84wc |
Arbitrary command injection |
Steps to Remediate
cd intercom-manager
npm audit fix
# If breaking changes:
npm audit fix --force # review diff carefully
npm test
npm run typecheck
Also verify fastify is upgraded to >=5.8.1 in package.json.
Risk
The Fastify bypass (GHSA-247c-9743-5963) is particularly dangerous because it allows unauthenticated callers to submit unvalidated payloads to any route that relies solely on TypeBox schema validation for sanitisation.
Priority: CRITICAL
Summary
npm auditreveals 7 high-severity vulnerabilities in the backend dependency tree. The most critical is a Fastify body schema validation bypass that allows malformedContent-Typeheaders to skip TypeBox validation entirely.Affected Packages
fastifyv5.7.3axios(indirect)__proto__key inmergeConfigflatted(indirect)parse()flatted(indirect)glob(indirect)Steps to Remediate
Also verify
fastifyis upgraded to>=5.8.1inpackage.json.Risk
The Fastify bypass (GHSA-247c-9743-5963) is particularly dangerous because it allows unauthenticated callers to submit unvalidated payloads to any route that relies solely on TypeBox schema validation for sanitisation.
Priority: CRITICAL