Skip to content

Mitigate or upgrade js-yaml high severity vulnerability (GHSA-2883-xcg3-v3hh) in pm2 #215

Description

@atomantic

Summary

Dependabot alert #75 flags a high-severity CPU denial of service vulnerability in js-yaml (GHSA-2883-xcg3-v3hh / CVE-2026-84375), affecting versions < 4.3.2.
The dependency is introduced via devDependency pm2@^7.0.4 which pins js-yaml@4.3.1.

Reachability and Impact

In this repository, pm2 is used solely for local process management in npm run start / npm run dev:stop. It processes local trusted ecosystem.config.cjs files rather than untrusted YAML input, so actual runtime reachability and exploit risk in production is negligible.

Resolution Path

Once an upstream pm2 release updates its js-yaml dependency to >= 4.3.2, update pm2. Alternatively, evaluate adding an override for pm2 > js-yaml once tested.

Dispatch justification:
A straightforward package bump or dependency override once upstream publishes a patch.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    effort:lowLow reasoning budgetmodel:lightMechanical or config changesplanner:gemini-3-8-flashPlan authored by the gemini-3-8-flash model

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions