Public advisories list karma-mojo 1.0.1 and earlier as affected by CVE-2020-7626 / GHSA-pf8j-vhg8-xmc3. The package is test-runner tooling, so the useful security question is whether a repository still installs the affected dependency in CI, developer, or test-runner environments where untrusted configuration could matter.
Impact
Affected karma-mojo versions can expose OS command-injection risk when attacker-controlled Karma/Mojo configuration reaches the vulnerable test-runner plugin. A dependency match is important patch-triage evidence for CI and developer hosts, but it is not the same as proving that a production web app is exploitable.
Covered by FixVibe
FixVibe's GitHub repo scans flag npm manifests or lockfiles that resolve karma-mojo to 1.0.1 or earlier, showing the package, file, line, version and advisory IDs so you can prioritize cleanup.
Remediation
Public advisories do not list a patched karma-mojo release. Remove karma-mojo or replace the Karma/Mojo integration with maintained test tooling, regenerate the active npm, pnpm, or Yarn lockfile, and rebuild CI images, devcontainers, package-manager caches, and test-runner artifacts that install dependencies.
Review untrusted pull-request and CI workflows so untrusted code cannot control Karma/Mojo configuration while repository secrets or trusted host access are available. After cleanup, rerun the FixVibe GitHub repo scan to confirm the affected dependency evidence is gone.
