CVE-2026-27699: Update get-uri's dependency basic-ftp to 5.2.0
envgap__TooTallNate__proxy-agents-396
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
ca1214831e101db331c974f1006592de97f5a59c- Manifest
packages/get-uri/package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
TooTallNate/proxy-agents #396 · read the original issue
get-uri is using basic-ftp 5.0.2 [here](https://github.com/TooTallNate/proxy-agents/blob/get-uri%406.0.5/packages/get-uri/package.json#L51), which is vulnerable to [CVE-2026-27699](https://www.cve.org/CVERecord?id=CVE-2026-27699).
Please update it to basic-ftp 5.2.0.
```json
"dependencies": {
"basic-ftp": "^5.0.2",
"data-uri-to-buffer": "^6.0.2",
"debug": "^4.3.4"
},
```
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]