danny-avila / LibreChat

Enhanced ChatGPT Clone: Features Anthropic, AWS, OpenAI, Assistants API, Azure, Groq, o1, GPT-4o, Mistral, OpenRouter, Vertex AI, Gemini, Artifacts, AI model switching, message search, langchain, DALL-E-3, ChatGPT Plugins, OpenAI Functions, Secure Multi-User System, Presets, completely open-source for self-hosting. Actively in public development.
https://librechat.ai/
MIT License
19.15k stars 3.19k forks source link

Enhancement: Outdated Packages with Vulnerabilities #4123

Closed hanna-daoud closed 1 month ago

hanna-daoud commented 2 months ago

API Dependencies

  1. axios: ^1.3.4

    • Newer Version: 1.7.7
    • Security Advisory:
      • Severity: MODERATE (6.5)
      • Action: Please upgrade to version 1.7.4 or higher.
  2. express: ^4.18.2

    • Newer Version: 4.21.0
    • Security Advisory:
      • Severity: MODERATE (5.0)
      • Action: Please upgrade to version 4.20.0 or higher.
  3. mongoose: ^7.1.1

    • Newer Version: 7.8.1
    • Security Advisory:
      • Severity: CRITICAL (10.0)
      • Action: Please upgrade to version 7.3.3 or higher.
  4. nodemailer: ^6.9.4

    • Newer Version: 6.9.15
    • Security Advisory:
      • Severity: MODERATE (5.3)
      • Action: Please upgrade to version 6.9.9 or higher.
  5. ws: ^8.17.0

    • Newer Version: 8.18.0
    • Security Advisory:
      • Severity: HIGH (7.5)
      • Action: Please upgrade to version 8.17.1 or higher.

Client Dependencies

  1. axios: ^1.3.4

    • Newer Version: 1.7.7
    • Security Advisory:
      • Severity: MODERATE (6.5)
      • Action: Please upgrade to version 1.7.4 or higher.
  2. vite: ^5.1.1

    • Newer Version: 5.4.6
    • Security Advisory:
      • Severity: MODERATE (6.4)
      • Action: Please upgrade to version 5.2.14 or higher.