Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
Root's @rootio/pug Package Security Patch
ROOT-APP-NPM-AIKIDO-2024-10105
Summary
A security patch has been released for the @rootio/pug package used in Root's npm repository. This patch fixes a vulnerability that has been addressed by the developers. To ensure security, update to the latest version of the package.
What to do
- Update rootio @rootio/pug to version 2.0.4-root.io.1.
- Update pug to version 2.0.4-aikido.1.
- Update rootio @rootio/pug to version 2.0.4-root.io.2.
- Update pug to version 2.0.4-aikido.2.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Root:npm | rootio | @rootio/pug |
< 2.0.4-root.io.1 < 2.0.4-root.io.2 Fix: upgrade to 2.0.4-root.io.1
|
| Root:npm | – | pug |
< 2.0.4-aikido.1 < 2.0.4-aikido.2 Fix: upgrade to 2.0.4-aikido.1
|
Original title
AIKIDO-2024-10105 in @rootio/pug - Patched by Root
Original description
Root has patched AIKIDO-2024-10105 in the @rootio/pug package for Root:npm. Multiple fixed versions available.
Published: 16 Jul 2026 · Updated: 16 Jul 2026 · First seen: 13 Jul 2026