# Npm audit reports a vulnerability

**URL:** <https://discourse.nodered.org/t/npm-audit-reports-a-vulnerability/77479>\
**Category:** General\
**Created:** [12 April 2023 07:17 UTC](https://discourse.nodered.org/t/npm-audit-reports-a-vulnerability/77479 "2023-04-12T07:17:03Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![augjoh](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/augjoh/32/26464_2.png) [@augjoh](https://discourse.nodered.org/u/augjoh)\
**Post date:** [12 April 2023 07:17 UTC](https://discourse.nodered.org/t/npm-audit-reports-a-vulnerability/77479/1 "2023-04-12T07:17:03Z")

</div>

When running `npm audit` against latest node-red 3.0.2, it reports a security vulnerability. Is it safe to --force a fix?

```auto
xml2js <0.5.0
Severity: high
xml2js is vulnerable to prototype pollution - https://github.com/advisories/GHSA-776f-qx25-q3cc
fix available via `npm audit fix --force`
Will install node-red@0.19.6, which is a breaking change
node_modules/xml2js
  @node-red/nodes *
  Depends on vulnerable versions of xml2js
  node_modules/@node-red/nodes
    node-red >=0.20.0-beta.2
    Depends on vulnerable versions of @node-red/nodes
    node_modules/node-red

```

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [12 April 2023 08:37 UTC](https://discourse.nodered.org/t/npm-audit-reports-a-vulnerability/77479/2 "2023-04-12T08:37:24Z")

</div>

No, don't do that.

What do these commands show, from your .node-red folder?  
`npm list -g node-red`  
`npm list node-red`

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [12 April 2023 11:14 UTC](https://discourse.nodered.org/t/npm-audit-reports-a-vulnerability/77479/3 "2023-04-12T11:14:18Z")

</div>

As Colin says - that's a no-no. Very likely to break something.

That is probably the worst thing that npm have done.

Dependencies must be managed by the package owner/author. So if you think it a problem, you should raise an issue with the package that has the dependency.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [12 April 2023 11:30 UTC](https://discourse.nodered.org/t/npm-audit-reports-a-vulnerability/77479/4 "2023-04-12T11:30:21Z")

</div>

Can you understand the audit text posted, it doesn't make sense to me?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [12 April 2023 13:25 UTC](https://discourse.nodered.org/t/npm-audit-reports-a-vulnerability/77479/5 "2023-04-12T13:25:02Z")

</div>

Seems to be saying that Node-RED depends on `@node-red/nodes` (part of the monorepo) which in turn has a dependency on a `xml2js` vulnerable version.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [12 April 2023 14:05 UTC](https://discourse.nodered.org/t/npm-audit-reports-a-vulnerability/77479/6 "2023-04-12T14:05:23Z")

</div>

It was the `node-red >=0.20.0-beta.2` that was confusing me, but I see now that the OP must have installed node red locally, and it is saying that any node red above that version has that dependency.  
Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [11 June 2023 14:06 UTC](https://discourse.nodered.org/t/npm-audit-reports-a-vulnerability/77479/7 "2023-06-11T14:06:13Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
