Skip to content

chore(deps): update dependency @nestjs/common to v11.0.16 [security]#1073

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-nestjs-common-vulnerability
Open

chore(deps): update dependency @nestjs/common to v11.0.16 [security]#1073
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-nestjs-common-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 11, 2025

This PR contains the following updates:

Package Change Age Confidence
@nestjs/common (source) 11.0.1111.0.16 age confidence

nest allows a remote attacker to execute arbitrary code via the Content-Type header

CVE-2024-29409 / GHSA-cj7v-w2c7-cp7c

More information

Details

File Upload vulnerability in nestjs nest prior to v.11.0.16 allows a remote attacker to execute arbitrary code via the Content-Type header.

Severity

  • CVSS Score: 5.5 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

nestjs/nest (@​nestjs/common)

v11.0.16

Compare Source

v11.0.16 (2025-04-11)

v11.0.15

Compare Source

v11.0.15 (2025-04-10)
Bug fixes
Committers: 1

v11.0.14

Compare Source

v11.0.14 (2025-04-09)
Bug fixes
  • platform-fastify
Committers: 1

v11.0.13

Compare Source

v11.0.13 (2025-04-03)
Bug fixes
  • platform-fastify
  • microservices
    • #​14869 fix(microservices): do not re-create client connection once get client by service name (@​mingo023)
Dependencies
Committers: 2

v11.0.12

Compare Source

v11.0.12 (2025-03-19)
Bug fixes
Enhancements

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot force-pushed the renovate/npm-nestjs-common-vulnerability branch 2 times, most recently from dea5404 to 7dc09e4 Compare April 14, 2025 07:38
@renovate renovate Bot force-pushed the renovate/npm-nestjs-common-vulnerability branch 2 times, most recently from f8c5f43 to 22ab459 Compare May 5, 2025 08:37
@renovate renovate Bot force-pushed the renovate/npm-nestjs-common-vulnerability branch from 22ab459 to 7f4040f Compare May 12, 2025 13:12
@renovate renovate Bot force-pushed the renovate/npm-nestjs-common-vulnerability branch from 7f4040f to d4acca3 Compare June 22, 2025 13:34
@renovate renovate Bot force-pushed the renovate/npm-nestjs-common-vulnerability branch 3 times, most recently from 3cf6f6a to 0e6c624 Compare July 8, 2025 14:57
@renovate renovate Bot force-pushed the renovate/npm-nestjs-common-vulnerability branch 2 times, most recently from f8d3909 to fa2dcdb Compare August 13, 2025 17:29
@renovate renovate Bot force-pushed the renovate/npm-nestjs-common-vulnerability branch 7 times, most recently from 683726b to 1d4db0f Compare August 26, 2025 11:38
@renovate renovate Bot force-pushed the renovate/npm-nestjs-common-vulnerability branch from 1d4db0f to b91bea8 Compare August 29, 2025 10:21
@renovate renovate Bot force-pushed the renovate/npm-nestjs-common-vulnerability branch 2 times, most recently from 7b8bd45 to 61d2380 Compare September 25, 2025 18:49
@renovate renovate Bot force-pushed the renovate/npm-nestjs-common-vulnerability branch from 61d2380 to 761a1a9 Compare November 18, 2025 14:06
@renovate renovate Bot force-pushed the renovate/npm-nestjs-common-vulnerability branch from 761a1a9 to 9bc2a38 Compare January 8, 2026 18:52
@renovate renovate Bot force-pushed the renovate/npm-nestjs-common-vulnerability branch 2 times, most recently from 60fa2b4 to 72f5e3f Compare March 6, 2026 08:46
@renovate renovate Bot force-pushed the renovate/npm-nestjs-common-vulnerability branch from 72f5e3f to 5e8015d Compare March 13, 2026 13:34
@renovate renovate Bot changed the title chore(deps): update dependency @nestjs/common to v11.0.16 [security] chore(deps): update dependency @nestjs/common to v11.0.16 [security] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate renovate Bot deleted the renovate/npm-nestjs-common-vulnerability branch March 27, 2026 02:10
@renovate renovate Bot changed the title chore(deps): update dependency @nestjs/common to v11.0.16 [security] - autoclosed chore(deps): update dependency @nestjs/common to v11.0.16 [security] Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate renovate Bot force-pushed the renovate/npm-nestjs-common-vulnerability branch 2 times, most recently from 5e8015d to 7b29e64 Compare March 30, 2026 22:28
@renovate renovate Bot force-pushed the renovate/npm-nestjs-common-vulnerability branch 3 times, most recently from 58dc04f to ccafae6 Compare April 13, 2026 07:20
@renovate renovate Bot force-pushed the renovate/npm-nestjs-common-vulnerability branch 3 times, most recently from 0560d08 to 5390b7b Compare April 24, 2026 08:00
@renovate renovate Bot changed the title chore(deps): update dependency @nestjs/common to v11.0.16 [security] chore(deps): update dependency @nestjs/common to v11.0.16 [security] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
@renovate renovate Bot changed the title chore(deps): update dependency @nestjs/common to v11.0.16 [security] - autoclosed chore(deps): update dependency @nestjs/common to v11.0.16 [security] Apr 27, 2026
@renovate renovate Bot reopened this Apr 27, 2026
@renovate renovate Bot force-pushed the renovate/npm-nestjs-common-vulnerability branch 2 times, most recently from 5390b7b to fed9241 Compare April 27, 2026 23:14
@renovate renovate Bot force-pushed the renovate/npm-nestjs-common-vulnerability branch from fed9241 to 06c61eb Compare April 28, 2026 10:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants