# Npm audit fails after new installation

**URL:** <https://discourse.nodered.org/t/npm-audit-fails-after-new-installation/82940>\
**Category:** Feature Requests\
**Created:** [16 November 2023 19:08 UTC](https://discourse.nodered.org/t/npm-audit-fails-after-new-installation/82940 "2023-11-16T19:08:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![augjoh](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/augjoh/32/26464_2.png) [@augjoh](https://discourse.nodered.org/u/augjoh)\
**Post date:** [16 November 2023 19:08 UTC](https://discourse.nodered.org/t/npm-audit-fails-after-new-installation/82940/1 "2023-11-16T19:08:23Z")

</div>

When installing Node-RED, I got audit findings:

```auto
> npm install node-red

added 302 packages, and audited 303 packages in 29s

45 packages are looking for funding
  run `npm fund` for details

3 moderate severity vulnerabilities

To address all issues, run:
  npm audit fix

Run `npm audit` for details.
> npm audit
# npm audit report

axios 0.8.1 - 1.5.1
Severity: moderate
Axios Cross-Site Request Forgery Vulnerability - https://github.com/advisories/GHSA-wf5p-g6vw-rhxx
fix available via `npm audit fix --force`
Will install node-red@1.0.6, which is a breaking change
node_modules/axios
  node-red-admin >=0.2.0
  Depends on vulnerable versions of axios
  node_modules/node-red-admin
    node-red >=1.1.0-beta.1
    Depends on vulnerable versions of node-red-admin
    node_modules/node-red

3 moderate severity vulnerabilities

To address all issues (including breaking changes), run:
  npm audit fix --force
(venv) node@nodejs /u/h/n/.n/p/n/new-node-red (development) [0|1]> npm ls
@platynum/new-node-red@1.0.0 /usr/home/node/.node-red/projects/node-red-ca/new-node-red
└── node-red@3.1.0

```

Is Node-Red affected by this vulnerability? Is there going to be a new Node-RED version for this?

---

<div class="post-metadata">

**Author:** ![ralphwetzel](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ralphwetzel/32/53713_2.png) [@ralphwetzel](https://discourse.nodered.org/u/ralphwetzel)\
**Post date:** [16 November 2023 19:46 UTC](https://discourse.nodered.org/t/npm-audit-fails-after-new-installation/82940/2 "2023-11-16T19:46:54Z")

</div>

I did a fast scan of the NR code base.

Two findings:

- A lot of modules (in folder `node_modules`) define `axios` as their dependency. Those had to be updated first.
- NR uses `axios` as well. I yet didn't find any place where `the withCredentials setting is turned on`.

> [@augjoh](#):
>
> Is Node-Red affected by this vulnerability?

The maintainers will have the final call, yet it looks as if the prerequisites for this vulnerability are not given in (current) Node-Red.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [16 November 2023 22:22 UTC](https://discourse.nodered.org/t/npm-audit-fails-after-new-installation/82940/3 "2023-11-16T22:22:26Z")

</div>

I just ran npm audit on my node-red installation and got a different result.

```auto
D:\src\nr>npm audit
# npm audit report

axios 0.8.1 - 1.5.1
Severity: moderate
Axios Cross-Site Request Forgery Vulnerability - https://github.com/advisories/GHSA-wf5p-g6vw-rhxx
fix available via `npm audit fix --force`
Will install node-red-admin@0.1.8, which is a breaking change
node_modules/axios
  node-red-admin >=0.2.0
  Depends on vulnerable versions of axios
  node_modules/node-red-admin
    node-red >=1.1.0-beta.1
    Depends on vulnerable versions of node-red-admin
    node_modules/node-red

3 moderate severity vulnerabilities

To address all issues (including breaking changes), run:
  npm audit fix --force

D:\src\nr>

```

Since node-red-admin isn't really needed for the most part by most people, that wouldn't really be much of an issue.

When I run audit on my userDir, I get more results. But still only one against axios and that is a contributed node.

* * *

Ah, that's interesting, I get a slightly different result on Linux.

On windows, the "fix" offers to update just node-red-admin, on Linux it offers to "fix" node-red.

Either way, the axios dependency is on node-red-admin only. Which doesn't seem much of a risk to me.

* * *

Shouldn't really need to say this but - **don't ever run `npm audit fix`** - if you do, you will almost certainly break something. It is a nefarious part of npm.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [15 January 2024 22:23 UTC](https://discourse.nodered.org/t/npm-audit-fails-after-new-installation/82940/4 "2024-01-15T22:23:16Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
