mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 03:01:21 +02:00
chore(deps): bump python-multipart 0.0.22→0.0.26 and dompurify 3.3.3→3.4.0
python-multipart 0.0.26 closes CVE-2026-40347 (GHSA-mj87-hwqh-73pj), a DoS triggered by large preamble/epilogue data around a multipart boundary. Bambuddy consumes python-multipart transitively through FastAPI/Starlette for form and file-upload parsing, so multipart routes (backup restore, project thumbnail upload, etc.) were exposed. dompurify 3.4.0 picks up the fix for GHSA-39q2-94rc-95cp (function-form ADD_TAGS could bypass FORBID_TAGS). Bambuddy's two call sites use only array-form ALLOWED_TAGS/ALLOWED_ATTR, so the specific bypass was not reachable, but the bump still hardens the sanitizer and clears the audit warning. requirements.txt floor raised to python-multipart>=0.0.26; frontend/package.json caret pinned to ^3.4.0; npm audit and pip audit both report zero outstanding advisories after the bumps.
This commit is contained in:
@@ -28,7 +28,7 @@
|
||||
"@tiptap/react": "^3.11.1",
|
||||
"@tiptap/starter-kit": "^3.11.1",
|
||||
"@types/three": "^0.181.0",
|
||||
"dompurify": "^3.3.3",
|
||||
"dompurify": "^3.4.0",
|
||||
"gcode-preview": "^2.18.0",
|
||||
"i18next": "25.6.3",
|
||||
"i18next-browser-languagedetector": "^8.2.0",
|
||||
|
||||
Reference in New Issue
Block a user