# Low severity vulnerability that won't go away

**URL:** <https://discourse.nodered.org/t/low-severity-vulnerability-that-wont-go-away/51358>\
**Category:** General\
**Created:** [21 September 2021 20:22 UTC](https://discourse.nodered.org/t/low-severity-vulnerability-that-wont-go-away/51358 "2021-09-21T20:22:05Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [21 September 2021 20:22 UTC](https://discourse.nodered.org/t/low-severity-vulnerability-that-wont-go-away/51358/1 "2021-09-21T20:22:05Z")

</div>

For a long time npm audit on my main Node-Red machine has reported 1 vulnerability in node-red-node-email:

 ![Untitled 4](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/6/a/6ada733938c125fa9b7f18adbbef9d5809c875cc.jpeg)

 ![Untitled 5](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/7/0/7024cd6e91f403f2a4c0abf5c04be133c28fe988.jpeg)

I have run the Raspberry install script several times, which has updated to the latest Node-Red but not fixed the issue.  
Other Raspberry Pies with the same version of Node-Red show "0 vulnerabilities".

How can I resolve this?

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [21 September 2021 20:41 UTC](https://discourse.nodered.org/t/low-severity-vulnerability-that-wont-go-away/51358/2 "2021-09-21T20:41:18Z")

</div>

Are you using the latest version of the email node? Check in manage palette.

If yes then go into your .node-red folder and run  
`npm list minimist`  
and paste the section for the email node.

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [21 September 2021 21:03 UTC](https://discourse.nodered.org/t/low-severity-vulnerability-that-wont-go-away/51358/3 "2021-09-21T21:03:20Z")

</div>

Yes it's the latest version.  
I discovered that the problem doesn't arise on the other Pies because the node isn't installed. (Could have sworn it was part of the core) 😊

```auto
pi@GlassPi:~/.node-red $ npm list minimist
node-red-project@0.0.1 /home/pi/.node-red
├─┬ node-red-node-email@1.12.3
│ ├─┬ mailparser@3.2.0
│ │ └─┬ html-to-text@7.0.0
│ │ └── minimist@1.2.5
│ └─┬ poplib@0.1.7
│ └─┬ optimist@0.6.1
│ └── minimist@0.0.10
└─┬ node-red-node-serialport@0.14.1
  └─┬ serialport@9.2.1
    └─┬ @serialport/bindings@9.2.1
      └─┬ prebuild-install@6.1.4
        ├── minimist@1.2.5
        └─┬ rc@1.2.8
          └── minimist@1.2.5 deduped

```

Poplib - last updated 8 years ago. I guess the answer is to find a different email solution.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [21 September 2021 21:09 UTC](https://discourse.nodered.org/t/low-severity-vulnerability-that-wont-go-away/51358/4 "2021-09-21T21:09:42Z")

</div>

> [@jbudd](#):
>
> I guess the answer is to find a different email solution

Or you could CD to node-red-node-email \> poplib \> optimist and update minimist to latest 0.x version

Note: This would only be good until the next email node update.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [21 September 2021 21:38 UTC](https://discourse.nodered.org/t/low-severity-vulnerability-that-wont-go-away/51358/5 "2021-09-21T21:38:03Z")

</div>

The big problem with `npm audit` is that lacks all context.

The "vulnerable" package listed there is `minimist`. Its a library used to parse command-line arguments.

Working up the stack, we see it is used by `poplib` - the pop3 client library the email node uses. On further investigation, we see that module includes a couple examples of its use. These examples are run on the command line. [node-poplib/demos at master · ditesh/node-poplib · GitHub](https://github.com/ditesh/node-poplib/tree/master/demos)

The core of that module - the code that actually gets loaded when you require it - _doesn't_ use minimist.

Thus that vulnerability is completely irrelevant in the context of the Node-RED node.

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [21 September 2021 21:47 UTC](https://discourse.nodered.org/t/low-severity-vulnerability-that-wont-go-away/51358/6 "2021-09-21T21:47:14Z")

</div>

Thanks for looking into it.

Even if the vulnerability was relevant to the node it wouldn't be much of a worry since my Node-Red isn't public.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [20 November 2021 21:47 UTC](https://discourse.nodered.org/t/low-severity-vulnerability-that-wont-go-away/51358/7 "2021-11-20T21:47:20Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
