# Npm "high" security vulnerabilities?

**URL:** <https://discourse.nodered.org/t/npm-high-security-vulnerabilities/90624>\
**Category:** General\
**Created:** [1 September 2024 18:48 UTC](https://discourse.nodered.org/t/npm-high-security-vulnerabilities/90624 "2024-09-01T18:48:15Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![wb666greene](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/wb666greene/32/6534_2.png) [@wb666greene](https://discourse.nodered.org/u/wb666greene)\
**Post date:** [1 September 2024 18:48 UTC](https://discourse.nodered.org/t/npm-high-security-vulnerabilities/90624/1 "2024-09-01T18:48:15Z")

</div>

Just did a fresh node-red installation on a virgin install of Ubuntu-Mate 22.04. When I did the npm install of dashboard and a few other extra modules:

```auto
npm i node-red-dashboard node-red-node-email node-red-contrib-image-output node-red-node-base64

```

I got:

```auto
added 62 packages, and audited 109 packages in 3s

11 packages are looking for funding
  run `npm fund` for details

4 high severity vulnerabilities

To address all issues (including breaking changes), run:
  npm audit fix --force

Run `npm audit` for details.

```

When I run 'npm audit' I got:

```auto
# npm audit report

semver <5.7.2
Severity: high
semver vulnerable to Regular Expression Denial of Service - https://github.com/advisories/GHSA-c2qf-rxjj-qqgw
fix available via `npm audit fix --force`
Will install node-red-node-email@0.1.12, which is a breaking change
node_modules/node-red-node-email/node_modules/semver
  utf7 >=1.0.2
  Depends on vulnerable versions of semver
  node_modules/node-red-node-email/node_modules/utf7
    imap >=0.8.18
    Depends on vulnerable versions of utf7
    node_modules/node-red-node-email/node_modules/imap
      node-red-node-email >=0.1.13
      Depends on vulnerable versions of imap
      node_modules/node-red-node-email

4 high severity vulnerabilities

To address all issues (including breaking changes), run:
  npm audit fix --force

```

Question is how do I know if these fixes would be breaking changes?  
My system is not visible outside of my local subnet, and "breaking changes" would be a showstopper unless there is a proven solution for the breakage.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [30 November 2024 18:48 UTC](https://discourse.nodered.org/t/npm-high-security-vulnerabilities/90624/2 "2024-11-30T18:48:36Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
