Skip to content

Bump @nuxt/ui to 4.11.1 to clear the Tiptap advisories - #4

Merged
sadeqabuhattem merged 1 commit into
mainfrom
bump-tiptap-security
Sep 10, 2026
Merged

sadeqabuhattem merged 1 commit into
mainfrom
bump-tiptap-security

Conversation

@sadeqabuhattem

Copy link
Copy Markdown
Member

The advisories

@tiptap/core 3.30.3 carries two:

severity advisory fixed in
High Quadratic ReDoS in block and inline Markdown attribute parsing 3.30.5
Moderate mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes 3.30.4

Nothing in clients/dashboard depends on Tiptap directly — the whole family arrives through @nuxt/ui.

Why not npm audit fix

I tried it first. It is not the fix: it upgrades @tiptap/starter-kit and nests a private @tiptap/core 3.31.3 beneath it, while the hoisted copy @nuxt/ui actually resolves stays on 3.30.3.

node_modules/@tiptap/core                            3.30.3   ← still vulnerable, still reachable
node_modules/@tiptap/starter-kit/.../@tiptap/core    3.31.3

Two copies in the bundle and the vulnerable one still in the graph. Reverted.

What this does instead

@nuxt/ui 4.11.0 asks for ^3.29.2 across seventeen @tiptap/* packages, and the extensions peer-depend on an exact core version — so the family only moves as a unit. 4.11.1 asks for ^3.31.3 throughout, which lifts all of them together:

node_modules/@tiptap/core    3.31.3    (single copy)
@nuxt/ui                     4.11.1

Both advisories clear.

Verified

  • nuxt build — succeeds, 1.84 MB total (454 kB gzip)
  • eslint . — clean
  • nuxt typecheck — clean
  • Rendered against the running API: the settings page loads, reads values and displays identically to before, with no console errors

Not addressed here

Two unrelated advisories remain in this lockfile: js-yaml 4.3.1 (high — maxTotalMergeKeys does not limit CPU on empty merge sources) and esbuild 0.27.7 (low — arbitrary file read via the dev server on Windows). Both are present on main at identical versions and neither was introduced by this change. Worth a follow-up; kept out to keep this diff to the Tiptap fix.

🤖 Generated with Claude Code

@tiptap/core 3.30.3 carries two advisories — a quadratic ReDoS in Markdown
attribute parsing (high, fixed in 3.30.5) and mergeAttributes() turning an own
__proto__ key into inherited executable DOM attributes (moderate, fixed in
3.30.4). Nothing here depends on Tiptap directly; the whole family arrives
through @nuxt/ui.

`npm audit fix` is not the fix. It upgrades @tiptap/starter-kit and nests a
private @tiptap/core 3.31.3 underneath it, while the hoisted copy @nuxt/ui
actually resolves stays on 3.30.3 — two copies in the bundle, the vulnerable
one still reachable.

@nuxt/ui 4.11.0 asks for ^3.29.2 across seventeen @tiptap packages, and the
extensions peer-depend on an exact core version, so the family only moves as a
unit. 4.11.1 asks for ^3.31.3 throughout, which lifts all of them together and
leaves a single @tiptap/core 3.31.3 in the tree.

Verified: nuxt build, eslint and nuxt typecheck all pass, and the dashboard
renders and reads settings unchanged against the running API, with no console
errors.

Two advisories remain in this lockfile and are untouched here: js-yaml 4.3.1
(high) and esbuild 0.27.7 (low). Both are present on main at the same versions
and are unrelated to Tiptap.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@sadeqabuhattem
sadeqabuhattem merged commit c8640b3 into main Sep 10, 2026
10 checks passed
@sadeqabuhattem
sadeqabuhattem deleted the bump-tiptap-security branch September 10, 2026 17:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant