You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

iOS端React Native项目安装react-native-config遇高严重级漏洞问题

React Native iOS项目安装react-native-config时的高危漏洞解决方法

问题现象

在iOS平台的React Native项目中安装react-native-config时,无论使用以下哪种命令:

  • npm install react-native-config
  • npm i react-native-config
  • npm install github:lugg/react-native-config

都会出现如下提示:

141 packages are looking for funding
  run `npm fund` for details

5 high severity vulnerabilities

To address all issues (including breaking changes), run:
  npm audit fix --force

Run `npm audit` for details.

执行npm audit后,报告显示漏洞源于ip包的Server-Side Request Forgery(SSRF)问题,依赖链为ip → @react-native-community/cli-doctor/cli-hermes → @react-native-community/cli → react-native。多次执行npm audit fix --force会陷入React Native版本反复重装的循环,最终漏洞提示依旧存在。

解决方案

1. 强制修复依赖版本(推荐)

在项目根目录的package.json中添加overrides字段,直接将ip包替换为已修复漏洞的版本:

{
  "overrides": {
    "ip": "1.1.9"
  }
}

添加完成后执行npm install,重新安装依赖后,npm audit将不再提示该高危漏洞。

2. 锁定React Native CLI相关版本

如果上述方法无效,可以手动锁定@react-native-community/cli及其子包的版本到已修复该漏洞的稳定版本,在package.json的devDependencies中添加:

{
  "devDependencies": {
    "@react-native-community/cli": "9.3.0",
    "@react-native-community/cli-doctor": "9.3.0",
    "@react-native-community/cli-hermes": "9.3.0"
  }
}

执行npm install后,这些包会使用不依赖有漏洞ip版本的分支。

3. 临时忽略漏洞(不推荐长期使用)

如果确认该漏洞不会影响项目运行(比如项目未使用CLI的doctor或hermes功能,或不存在SSRF风险场景),可以执行以下命令强制跳过依赖冲突:

npm audit fix --force --legacy-peer-deps

或者在package.json中添加脚本跳过npm audit检查:

{
  "scripts": {
    "preinstall": "npm set audit false"
  }
}

内容的提问来源于stack exchange,提问作者Lluís Rodríguez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 03:42:48