Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)
High
- Category
- Supply Chain
- Confidence
- 98% confidence
- Finding
- The lockfile pins `ws` to version 8.19.0, and the supplied finding identifies known advisories affecting that exact version: uninitialized memory disclosure and memory-exhaustion denial of service. Because this skill provides browser control over a Chrome DevTools Protocol connection using WebSockets, the dependency sits directly on a network-facing and security-relevant code path, which makes exploitation more plausible and the impact more serious than in a non-networked utility.
