GHSA-vxq2-vhm7-7mhq: expand fetch-page-assets affected versions beyond = 1.2.9

Open Beginner friendly
#9,255 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
68/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
node.js
Domain
security

Research direction

Start by reviewing the linked GHSA and the existing fetch-page-assets advisory entry, then verify the npm versions and the public malware evidence cited in the issue. Update the affected-version data to include 1.2.10 through 1.2.14, and confirm that all five malicious versions are represented when the advisory is complete.

Written by the indexing model from the issue text.

Description

Advisory

https://github.com/advisories/GHSA-vxq2-vhm7-7mhq

Currently pinned to fetch-page-assets = 1.2.9.

Requested change

Add these still-malicious versions:

  • 1.2.10
  • 1.2.11
  • 1.2.12
  • 1.2.13
  • 1.2.14

1.2.13 and 1.2.14 are already in MAL-2026-6358 (Amazon Inspector, 2026-08-25). 1.2.101.2.12 remain listed on the npm registry and were omitted from both this GHSA and the later Inspector additions.

Public sources

These GHSA malware records do not appear in this git tree, so this is an issue rather than an advisory-file PR.

Dominant language
No language data
Stars
2.5k
Forks
772
Avg merge
3d 20h
Merged PRs (30d)
49

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/advisory-database

All issues in github/advisory-database

Similar issues

More Security issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.