### Impact Morgan's `:remote-user` token extracts the Basic auth username from the `Authorization` header and writes it to the log stream without neutralizing control characters. An attacker can send a crafted `Authorization: Basic` header containing CR/LF characters to inject forged log lines, corrupting the one-request-per-line structure of access logs. The built-in `combined`, `common`, `default`, and `short` formats are affected, as well as any custom format that includes `:remote-user`. ### Patches Users should upgrade to version 1.11.0. ### Workarounds Use a custom format string that does not include `:remote-user`.
Update morgan to 1.11.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanmorgan vulnerable to Log Forging via unneutralized control characters in :remote-user affects morgan (npm). Severity is medium. ### Impact Morgan's `:remote-user` token extracts the Basic auth username from the `Authorization` header and writes it to the log stream without neutralizing control characters. An attacker can send a crafted `Authorization: Basic` header containing CR/LF characters to inject forged log lines, corrupting the one-request-per-line structure of access logs. The built-in `combined`, `common`, `default`, and `short` formats are affected, as well as any custom format that includes `:remote-user`. ### Patches Users should upgrade to version 1.11.0. ### Workarounds Use a custom format string that does not include `:remote-user`.
AI coding agents often install or upgrade packages automatically in npm. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| morgannpm |
### Impact Morgan's `:remote-user` token extracts the Basic auth username from the `Authorization` header and writes it to the log stream without neutralizing control characters. An attacker can send a crafted `Authorization: Basic` header containing CR/LF characters to inject forged log lines, corrupting the one-request-per-line structure of access logs. The built-in `combined`, `common`, `default`, and `short` formats are affected, as well as any custom format that includes `:remote-user`. ### Patches Users should upgrade to version 1.11.0. ### Workarounds Use a custom format string that does not include `:remote-user`.
Update morgan to 1.11.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanmorgan vulnerable to Log Forging via unneutralized control characters in :remote-user affects morgan (npm). Severity is medium. ### Impact Morgan's `:remote-user` token extracts the Basic auth username from the `Authorization` header and writes it to the log stream without neutralizing control characters. An attacker can send a crafted `Authorization: Basic` header containing CR/LF characters to inject forged log lines, corrupting the one-request-per-line structure of access logs. The built-in `combined`, `common`, `default`, and `short` formats are affected, as well as any custom format that includes `:remote-user`. ### Patches Users should upgrade to version 1.11.0. ### Workarounds Use a custom format string that does not include `:remote-user`.
AI coding agents often install or upgrade packages automatically in npm. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| morgannpm |
| >=1.2.0,<=1.10.1 |
| 1.11.0 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| >=1.2.0,<=1.10.1 |
| 1.11.0 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard