Urgent.News

What's breaking now, across thousands of outlets.

Tech

Security Notice: @bananacool467/ui-tools — Use 0.1.9-beta or Newer

Published : August 27, 2026 Package : @bananacool467/ui-tools I want to clarify a security issue affecting earlier versions of @bananacool467/ui-tools . Versions 0.1.0-beta through 0.1.7-beta contained an unauthenticated WebSocket terminal endpoint. This allowed a client connecting to the endpoint to interact with a PTY running on the server. The issue has since been addressed. Affected versions…

On August 27, 2026, it was announced that an earlier version of the @bananacool467/ui-tools package, specifically versions 0.1.0-beta through 0.1.7-beta, contained a security vulnerability. This issue involved an unauthenticated WebSocket terminal endpoint that allowed clients to interact with a PTY running on the server. The OSV advisory MAL-2026-13416 identifies these versions as affected, with the malicious-packages record also available for reference.

The developers addressed the issue in version 0.1.9-beta, which added authentication before the WebSocket upgrade was accepted. This means that unauthenticated connections are now rejected before the WebSocket is upgraded, preventing unauthorized access to the terminal functionality. To resolve the vulnerability, users are advised to update to version 0.1.9-beta or newer.

This can be done using the command `npm install @bananacool467/ui-tools@latest` or explicitly specifying the version with `npm install @bananacool467/ui-tools@0.1.9-beta`.

To check the installed version, users can run `npm ls @bananacool467/ui-tools`. The issue was not with the terminal functionality itself, which is intentional in the @bananacool467/ui-tools package, but rather with the lack of authentication in the earlier version of the WebSocket endpoint. The terminal functionality is useful for development and UI purposes, but the security flaw posed a risk to server security. The OSV record for this advisory is available at https://api.osv.dev/v1/vulns/MAL-2026-13416.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

The Growing Threat: Attackers Using GitHub Repositories as Malware Staging Mechanisms

This blog was originally published by Brian Tant on the Raxis blog January 21, 2026 GitHub has become the backbone of modern software development, hosting over 100 million repositories and serving…

  • Cybercriminals use GitHub repositories to stage malware, targeting over 100 million repositories
  • Storm-0409 campaign infected nearly one million devices worldwide using GitHub
  • GitHub's trust, accessibility, and technical features make it attractive for attackers

SK hynix’s Indiana Fab Opens New Horizon for S. Korea-U.S. AI Chip Alliance

SK hynix held a historic groundbreaking ceremony for its next-generation High Bandwidth Memory (HBM) advanced packaging production base in West Lafayette, Indiana, the United States on Aug.

  • SK hynix inaugurates Indiana fab on August 27 for AI chip alliance
  • $4 billion investment starts Oct 2028, full production begins 2029
  • Project creates >7,000 jobs and enhances national security

More from Friday 28 August →