Summary
Dependabot alert #75 flags a high-severity CPU denial of service vulnerability in js-yaml (GHSA-2883-xcg3-v3hh / CVE-2026-84375), affecting versions < 4.3.2.
The dependency is introduced via devDependency pm2@^7.0.4 which pins js-yaml@4.3.1.
Reachability and Impact
In this repository, pm2 is used solely for local process management in npm run start / npm run dev:stop. It processes local trusted ecosystem.config.cjs files rather than untrusted YAML input, so actual runtime reachability and exploit risk in production is negligible.
Resolution Path
Once an upstream pm2 release updates its js-yaml dependency to >= 4.3.2, update pm2. Alternatively, evaluate adding an override for pm2 > js-yaml once tested.
Dispatch justification:
A straightforward package bump or dependency override once upstream publishes a patch.
Summary
Dependabot alert #75 flags a high-severity CPU denial of service vulnerability in
js-yaml(GHSA-2883-xcg3-v3hh/CVE-2026-84375), affecting versions< 4.3.2.The dependency is introduced via devDependency
pm2@^7.0.4which pinsjs-yaml@4.3.1.Reachability and Impact
In this repository,
pm2is used solely for local process management innpm run start/npm run dev:stop. It processes local trustedecosystem.config.cjsfiles rather than untrusted YAML input, so actual runtime reachability and exploit risk in production is negligible.Resolution Path
Once an upstream
pm2release updates itsjs-yamldependency to>= 4.3.2, updatepm2. Alternatively, evaluate adding an override forpm2 > js-yamlonce tested.Dispatch justification:
A straightforward package bump or dependency override once upstream publishes a patch.