You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

npm install出现多种漏洞如何解决?附firebase漏洞详情

解决npm audit检测到的firebase资源消耗漏洞

你遇到的是Uncontrolled Resource Consumption类型的firebase相关漏洞,根源是项目中fcm-node(>=1.4.0)或fcm-notification依赖的旧版firebase-admin(4.0.0-11.4.0),这些旧版admin包又嵌套依赖了存在问题的@firebase/util、@firebase/app等子包。

漏洞检测日志:

Uncontrolled Resource Consumption in firebase
fix available via `npm audit fix --force`
Will install fcm-node@1.3.0, which is a breaking change
node_modules/fcm-notification/node_modules/@firebase/util
  @firebase/app  <=0.6.13-longpoll.66863f547 || 0.6.14-2021026232412 - 0.6.14-canary.fd16bb26d || 0.6.15-2021119233939 - 0.6.15-eap-storage-emulator.ed256f582
  Depends on vulnerable versions of @firebase/util
  node_modules/fcm-notification/node_modules/@firebase/app
    firebase-admin  4.0.0 - 11.4.0
    Depends on vulnerable versions of @firebase/app
    Depends on vulnerable versions of @firebase/database
    Depends on vulnerable versions of @google-cloud/firestore
    Depends on vulnerable versions of dicer
    Depends on vulnerable versions of jsonwebtoken
    Depends on vulnerable versions of node-forge
    node_modules/fcm-node/node_modules/firebase-admin
    node_modules/fcm-notification/node_modules/firebase-admin
      fcm-node  >=1.4.0
      Depends on vulnerable versions of firebase-admin
      node_modules/fcm-node
      fcm-notification  *
      Depends on vulnerable versions of firebase-admin
      node_modules/fcm-notification
  @firebase/database  <=0.7.1-canary.fc9de467b || 0.8.0-202010180421 - 0.8.0-canary.bab4e1935 || 0.8.1-1.0.0-eap-firestore-debug.9c6096f43 - 0.8.1-canary.ff9dc3460 || 0.8.2-20210721223 - 0.8.2-longpoll.66863f547 || 0.8.3-2021012224526 - 0.8.3-canary.fb90580e5 || 0.9.0-2021019222814 - 0.9.0-canary.d9b945fed || 0.9.1-2021026232412 - 0.9.1-canary.fd16bb26d || 0.9.2-202112213818 - 0.9.2-canary.f5139220e || 0.9.3-202119234540 - 0.9.3-canary.ee6980dee || 0.9.4-2021119233939 - 0.9.4-eap-storage-emulator.ed256f582
  Depends on vulnerable versions of @firebase/util
  node_modules/fcm-notification/node_modules/@firebase/database

可行解决方案

1. 尝试官方强制修复(注意破坏性变更)

运行官方提示的命令,这会将fcm-node降级到1.3.0以修复漏洞,但可能破坏现有代码逻辑:

npm audit fix --force

重点提醒:执行前务必核对fcm-node 1.3.0的API文档,确认项目中的推送逻辑兼容旧版本。

2. 手动升级依赖(推荐,避免降级)

如果不想降级fcm-node,可以直接升级相关依赖:

  • 若项目package.json直接声明了fcm-node或fcm-notification,将版本号改为最新稳定版,然后执行:
npm install
  • 若为间接依赖(项目未直接声明),使用npm的overrides功能(需npm 8.3+)强制指定安全版本的firebase-admin:
    在package.json中添加:
"overrides": {
  "firebase-admin": "^11.5.0"
}

随后清理旧依赖并重装:

rm -rf node_modules package-lock.json
npm install

3. 清理缓存重新验证

若以上步骤无效,清理npm缓存并重装依赖:

npm cache clean --force
rm -rf node_modules package-lock.json
npm install

4. 验证修复

执行以下命令确认漏洞已解决:

npm audit

内容的提问来源于stack exchange,提问作者Robert Melente

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 09:37:20