Skip to content

fix: patch handlebars GHSA-2w6w-674q-4c4q (CVSS 9.8) — verify 4.7.9 in lockfile#1501

Draft
Copilot wants to merge 1 commit intomainfrom
copilot/ghsa-2w6w-674q-fix-handlebars-injection
Draft

fix: patch handlebars GHSA-2w6w-674q-4c4q (CVSS 9.8) — verify 4.7.9 in lockfile#1501
Copilot wants to merge 1 commit intomainfrom
copilot/ghsa-2w6w-674q-fix-handlebars-injection

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented Mar 30, 2026

handlebars@4.7.8 (transitive via ts-jest) carried a critical JS injection vulnerability (GHSA-2w6w-674q-4c4q, CVSS 9.8) enabling arbitrary code execution via AST type confusion. Affects CI/dev environments only — not shipped in production or container images.

Changes

The fix was already present in the dependency tree. This PR closes the security issue formally raised by the Dependency Security Monitor.


🔒 GitHub Advanced Security automatically protects Copilot coding agent pull requests. You can protect all pull requests by enabling Advanced Security for your repositories. Learn more about Advanced Security.

Copilot AI changed the title [WIP] Fix critical JavaScript injection vulnerability in handlebars fix: patch handlebars GHSA-2w6w-674q-4c4q (CVSS 9.8) — verify 4.7.9 in lockfile Mar 30, 2026
Copilot AI requested a review from lpcox March 30, 2026 04:31
@github-actions

This comment has been minimized.

@github-actions
Copy link
Copy Markdown
Contributor

Smoke test matrix:
PR titles: feat: add volume mount for ~/.copilot/session-state to persist events.jsonl; [WIP] Fix failing GitHub Actions workflow Audit Main Package; fix: patch handlebars GHSA-2w6w-674q-4c4q (CVSS 9.8) — verify 4.7.9 in lockfile; chore(deps): bump the all-npm-dependencies group with 10 updates

  1. GitHub MCP merged PR review ✅
  2. safeinputs-gh PR list ❌
  3. Playwright github.com title check ✅
  4. Tavily search ❌
  5. Temp file write/read + bash cat ✅
  6. Discussion oracle comment ✅
  7. npm ci && npm run build ✅
    Overall status: FAIL

🔮 The oracle has spoken through Smoke Codex

@github-actions
Copy link
Copy Markdown
Contributor

🏗️ Build Test Suite Results

Ecosystem Project Build/Install Tests Status
Bun elysia 1/1 passed ✅ PASS
Bun hono 1/1 passed ✅ PASS
C++ fmt N/A ✅ PASS
C++ json N/A ✅ PASS
Deno oak N/A 1/1 passed ✅ PASS
Deno std N/A 1/1 passed ✅ PASS
.NET hello-world N/A ✅ PASS
.NET json-parse N/A ✅ PASS
Go color passed ✅ PASS
Go env passed ✅ PASS
Go uuid passed ✅ PASS
Java gson 1/1 passed ✅ PASS
Java caffeine 1/1 passed ✅ PASS
Node.js clsx passed ✅ PASS
Node.js execa passed ✅ PASS
Node.js p-limit passed ✅ PASS
Rust fd 1/1 passed ✅ PASS
Rust zoxide 1/1 passed ✅ PASS

Overall: 8/8 ecosystems passed — ✅ PASS

Generated by Build Test Suite for issue #1501 ·

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security] [GHSA-2w6w-674q-4c4q] CRITICAL: JavaScript Injection in handlebars (CVSS 9.8)

2 participants