Skip to content

[get-uri] Bump basic-ftp from 5.3.1 to 6.2.1 (CVE-2026-102990) - #500

Open
rhanneken wants to merge 1 commit into
TooTallNate:mainfrom
rhanneken:get-uri-basic-ftp-6.2.1
Open

rhanneken wants to merge 1 commit into
TooTallNate:mainfrom
rhanneken:get-uri-basic-ftp-6.2.1

Conversation

@rhanneken

Copy link
Copy Markdown

Bumps basic-ftp in get-uri from ^5.3.1 to ^6.2.1 to pick up the fix for GHSA-c475-qrg2-pj4r / CVE-2026-102990 (high severity): quadratic-time CPU denial of service in the Client.list() Unix directory-listing parser.

Why a major bump

The advisory affects basic-ftp <= 6.2.0 and the only patched release is 6.2.1. There is no fixed release in the 5.x line, so the current ^5.3.1 range can't resolve to a patched version. npm audit now flags everything downstream of get-uri (pac-proxy-agent, proxy-agent), and its only suggested fix is downgrading to proxy-agent@5.

get-uri reaches the affected code: ftp.ts falls back to client.list() when the server doesn't support MDTM.

Compatibility

The only breaking change between 5.3.1 and 6.2.1 is in 6.0.0:

This library no longer allows separate transfer hosts by default. [...] Preventing it by default protects users from FTP bounce attacks. You can still allow separate transfer hosts by using allowSeparateTransferHost: true when instantiating a Client.

Two things worth knowing about that:

  • The Client methods get-uri uses (access, lastMod, list, downloadTo, close) are unchanged, so no source changes are needed.
  • get-uri calls new Client() with no arguments and passes its options to client.access(), so there is currently no way for a get-uri caller to opt back in to separate transfer hosts. An ftp: URI served by a server that sends PASV responses pointing at a different host would stop working. I've left that as is, since the new default is the safer one, but I'm happy to add a pass-through option if you'd prefer.

I've marked the changeset as patch, in line with the earlier basic-ftp security bumps (#401, #413, #425). Let me know if you'd rather treat the behavior change above as minor or major.

basic-ftp@6.2.1 declares engines.node >= 10, so it fits within get-uri's node >= 20.

Testing

With the bump applied, on Node 24.21.0:

  • pnpm --filter get-uri... build succeeds
  • vitest run in packages/get-uri passes: 7 test files, 22 tests, including ftp.test.ts

Release request

Once this lands, could you cut releases of get-uri, pac-proxy-agent, and proxy-agent? pac-proxy-agent depends on an exact get-uri version, so consumers of proxy-agent won't get the fix until all three are published.

🤖 Generated with Claude Code

Addresses CVE-2026-102990 (GHSA-c475-qrg2-pj4r), a quadratic-time CPU
denial of service in the Client.list() directory-listing parser. The
advisory affects basic-ftp <= 6.2.0 and there is no patched 5.x release.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@changeset-bot

changeset-bot Bot commented Oct 2, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5d954f5

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
Name Type
get-uri Patch
pac-proxy-agent Patch
proxy-agent Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

martinfrancois added a commit to martinfrancois/testing-toolbox that referenced this pull request Oct 5, 2026
basic-ftp 5.3.1 is affected by GHSA-c475-qrg2-pj4r (high, fixed in 6.2.1)
and GHSA-5rfr-xx34-2xxv (moderate, fixed in 6.2.2), and no 5.x release
carries either fix. @wdio/utils reaches it through @puppeteer/browsers,
proxy-agent, pac-proxy-agent and get-uri 6.0.5, and get-uri asks for
^5.3.1 even in its newest release, 8.0.1, so no parent update gets out of
the 5.x line. An override scoped to basic-ftp@5 is the only way to the fix.
TooTallNate/proxy-agents#500 makes the same bump upstream.

basic-ftp 6.0 has one break: a passive data connection to a host other
than the control host now needs allowSeparateTransferHost. get-uri calls
access, lastMod, list and downloadTo, which did not change, and get-uri
6.0.5 with 6.2.2 fetched a PAC file from a local FTP server.

6.2.2 was published on 2026-10-04 and is younger than pnpm's built-in
one-day minimumReleaseAge. That default is not strict, so pnpm wrote
basic-ftp@6.2.2 into minimumReleaseAgeExclude on its own. The entry is
kept with a comment that says when it can go.

A plain pnpm install --lockfile-only also deduplicated @types/node 22.7.8
onto 24.13.4. The lockfile here changes only basic-ftp; pnpm 12.4.1 leaves
it byte-identical on install --lockfile-only and installs it with
--frozen-lockfile.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant