Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @soketi/soketi
  4. ›
  5. GMS-2022-63

GMS-2022-63: Zalgo-like output that crashes the server

January 12, 2022

Impact

What kind of vulnerability is it? Who is impacted?

colors package caused zalgo-like output (see https://github.com/soketi/soketi/issues/276, https://github.com/Marak/colors.js/issues/289), breaking the servers.

Only NPM users that recently upgraded or installed the NPM package are affected.

Docker users seem to not be affected as the dependencies were bundled at the time of the build, which were tested.

Patches

Has the problem been patched? What versions should users upgrade to?

Latest patch. 0.26.1 to be exact at the time of writing.

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

You cannot get around this as it’s related to dependencies.

References

Are there any links users can visit to find out more?

  • https://github.com/Marak/colors.js/issues/289

For more information

If you have any questions or comments about this advisory:

  • Open an issue in the issues board
  • Email us at alex@renoki.org

References

  • github.com/advisories/GHSA-2w8g-m5j8-7m87
  • github.com/soketi/soketi/security/advisories/GHSA-2w8g-m5j8-7m87

Code Behaviors & Features

Detect and mitigate GMS-2022-63 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.26.1

Fixed versions

  • 0.26.1

Solution

Upgrade to version 0.26.1 or above.

Source file

npm/@soketi/soketi/GMS-2022-63.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:38 +0000.