Known Vulnerable Dependency: fast-uri==3.1.0 — 7 advisory(ies): CVE-2026-13676 (fast-uri vulnerable to host confusion via failed IDN canonicalization); CVE-2026-18446 (fast-uri vulnerable to host confusion via backslash authority introducer); CVE-2026-75975 (fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizat) +4 more
- Category
- Supply Chain
- Confidence
- 92% confidence
- Finding
The lockfile includes fast-uri 3.1.0, which has multiple advisories involving URI parsing inconsistencies such as host confusion and malformed authority handling that can enable SSRF or security-filter bypasses. In this skill context, the risk is moderated because the vulnerable package is transitive through ajv and a lockfile entry does not by itself show attacker-controlled URL validation, but consensus-related tooling may process untrusted structured input, making parser confusion more meaningful than in a purely local-only utility.
- Content
