major
minor
defect
major
minor
Ein Security-Scan (Juli 2026) meldet mehrere verwundbare npm-Pakete in den package-lock.json der React-Module. Für alle existiert eine Fix-Version; das Update erfolgt durch Regenerieren der Lockfiles bzw. overrides-Einträge in der jeweiligen package.json.
Zu behebende Pakete
| = Paket = | = aktuell = | = CVE / GHSA = | = Fix-Version = | = Art = |
| vite | 6.4.1 / 6.4.2 | CVE-2026-39363, -39365, -53571, -53632; GHSA-4w7w-66w2-5vf9, -p9ff-h696-f583, -fx2h-pf6j-xcff, -v6wh-96g9-6wx3 | 6.4.3 (deckt alle ab) | Build/Dev |
| picomatch | 4.0.3 | CVE-2026-33671, -33672; GHSA-c2c7-rcm5-vvqj, -3v7f-55p6-f55p | 4.0.4 | Build (transitiv) |
| postcss | 8.5.6 / 8.5.8 | CVE-2026-41305; GHSA-qx2v-qp2m-jg93 | 8.5.10 | Build (transitiv) |
| @babel/core | 7.29.0 | GHSA-4x5r-pxfx-6jf8 (CVE-2026-49356) | 7.29.6 | Build (transitiv) |
| markdown-it | 14.1.1 | CVE-2026-48988; GHSA-6v5v-wf23-fmfq | 14.2.0 | Laufzeit (WYSIWYG, transitiv) |
| linkify-it | 5.0.0 | CVE-2026-48801 (Fix 5.0.1), CVE-2026-59887 + GHSA-22p9-wv53-3rq4 (Fix 5.0.2) | 5.0.2 | Laufzeit (WYSIWYG, transitiv) |
Betroffene Module
vite, picomatch, postcss, @babel/core liegen in den Lockfiles von:
- com.top_logic.layout.react
- com.top_logic.layout.react.codeedit
- com.top_logic.layout.react.chartjs
- com.top_logic.layout.react.wysiwyg
- com.top_logic.model.search.react
- com.top_logic.react.flow.server
- com.top_logic.demo
markdown-it/`linkify-it` nur in com.top_logic.layout.react.wysiwyg.
Risikoeinordnung
vite/`postcss`/`picomatch`/`@babel/core` sind reine Build-/Dev-Abhängigkeiten (wirken nur auf Build-Rechner bzw. Dev-Server, nicht in der ausgelieferten Anwendung) — geringes Risiko, aber sauber zu schließen. markdown-it/`linkify-it` sind laufzeitrelevant (WYSIWYG-Editor, verarbeiten ggf. Nutzereingaben; ReDoS/quadratische Komplexität) — höhere Priorität.
Vorgehen
vite ist als ^6.0.0 deklariert, daher genügt ein Regenerieren der Lockfiles für 6.4.3. Für die transitiven Pakete overrides in der jeweiligen package.json setzen. Der JS/TS-Build läuft über das frontend-maven-plugin während mvn compile.