Skip to content

[Snyk] Security upgrade forever from 2.0.0 to 3.0.4 - #78

Open
snyk-io[bot] wants to merge 1 commit into
masterfrom
snyk-fix-562a43d26e96ed26ddf25f6aa58d9894
Open

[Snyk] Security upgrade forever from 2.0.0 to 3.0.4#78
snyk-io[bot] wants to merge 1 commit into
masterfrom
snyk-fix-562a43d26e96ed26ddf25f6aa58d9894

Conversation

@snyk-io

@snyk-io snyk-io Bot commented Aug 4, 2026

Copy link
Copy Markdown

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • package.json
⚠️ Warning
Failed to update the package-lock.json, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-BRACEEXPANSION-18512280
  710  

Breaking Change Risk

Merge Risk: Low

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Allocation of Resources Without Limits or Throttling

@snyk-io

snyk-io Bot commented Aug 4, 2026

Copy link
Copy Markdown
Author

Merge Risk: Low

This is a major version upgrade, but the risk of breaking changes is low. The primary changes between version 2.0.0 and 3.0.4 are security-focused dependency updates.

  • The v3.0.0 release was marked as a major version bump out of caution due to an update to the forever-monitor dependency. The maintainers stated that no migration changes should be needed. [2, 3]
  • Versions 3.0.1 through 3.0.4 consist of further security updates to underlying dependencies. [3]
  • In version 3.0.2, a project deprecation warning was added to the documentation. The maintainers now encourage using alternatives like pm2 or nodemon for new projects. [3, 4]

Recommendation: No action is required for this upgrade as there are no documented API or functional breaking changes.

Source: GitHub Changelog

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@snyk-io

snyk-io Bot commented Aug 4, 2026

Copy link
Copy Markdown
Author

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@sonarqubecloud

sonarqubecloud Bot commented Aug 4, 2026

Copy link
Copy Markdown

@AC-KunalParmar

Copy link
Copy Markdown

Logo
Checkmarx One – Scan Summary & Details72aa1c8f-c8c1-40a1-aa75-5878ea4007bf


New Issues (94)

Critical: 10 · High: 53 · Medium: 30 · Low: 1

Checkmarx found the following issues in this Pull Request

# Severity Issue Source File / Package Checkmarx Insight
1 CRITICAL CVE-2026-33937 Npm-handlebars-4.0.5
detailsRecommended version: 4.7.9
Description: Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pr...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: RzCBGQ3wc%2Fsby2tBuIjMoGswPqm7Dxdj4ddTf20O%2Fc8%3D
Vulnerable Package
2 CRITICAL CVE-2026-42043 Npm-axios-1.12.2
detailsRecommended version: 1.15.1
Description: Axios is a promise based HTTP client for the browser and Node.js. In versions prior to 0.31.1 and 1.0.0 prior to 1.15.1 , an attacker who can influ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: X0HEIezjfd%2BxqOnWXnlHFU6V7wSkjEkpE0R2WYX4ms4%3D
Vulnerable Package
3 CRITICAL CVE-2026-42264 Npm-axios-1.12.2
detailsRecommended version: 1.15.2
Description: Axios is a promise-based HTTP client for the browser and Node.js. From version 1.0.0 prior to version 1.15.2, five config properties (auth, baseURL...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: HzMK2tczrRkFA3kD%2Be4ek8AOujwz1SGpqkWtHyvaUeQ%3D
Vulnerable Package
4 CRITICAL CVE-2026-4800 Npm-lodash-4.17.20
detailsRecommended version: 4.18.0
Description: The fix for CVE-2021-23337 added validation for the variable option in _.template but did not apply the same validation to "options.imports" key na...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: EugAJn3fUgsRRG0S7FGtL6EngeNTfFJUF9rIJyj1%2FrA%3D
Vulnerable Package
5 CRITICAL CVE-2026-4800 Npm-lodash-4.17.21
detailsRecommended version: 4.18.0
Description: The fix for CVE-2021-23337 added validation for the variable option in _.template but did not apply the same validation to "options.imports" key na...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: ODRumI99PNotLB6sk4N%2B%2FBxlMVzGjXvVL1XY5Bik0zo%3D
Vulnerable Package
6 CRITICAL CVE-2026-4800 Npm-lodash-4.17.11
detailsRecommended version: 4.18.0
Description: The fix for CVE-2021-23337 added validation for the variable option in _.template but did not apply the same validation to "options.imports" key na...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Y15XdXQUPZnzUr2j%2Bfs%2BDPkzBvUnzd2cf81iR019zsE%3D
Vulnerable Package
7 CRITICAL CVE-2026-4800 Npm-lodash-4.13.1
detailsRecommended version: 4.18.0
Description: The fix for CVE-2021-23337 added validation for the variable option in _.template but did not apply the same validation to "options.imports" key na...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: T%2F9ijBW0tYnlS2sjRXSfEiS%2BElb%2B4d7nGqMeQB%2FU0IU%3D
Vulnerable Package
8 CRITICAL CVE-2026-54466 Npm-websocket-driver-0.7.0
detailsRecommended version: 0.7.5
Description: The frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a s...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: qfMic6%2F5uiF4sEq7ycDLnf5o4rI1K3ZSZe5mLaZ43Yw%3D
Vulnerable Package
9 CRITICAL CVE-2026-59873 Npm-tar-2.2.1
detailsRecommended version: 7.5.19
Description: node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: iNSZWSs%2Bs7zQnDCgzOMkdrsKE0U0vTmikvfPtBk%2BmfA%3D
Vulnerable Package
10 CRITICAL CVE-2026-59873 Npm-tar-4.4.8
detailsRecommended version: 7.5.19
Description: node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: yGT%2FqCT7DZutCNfYLWc0a5dE4kFkbdvit5QpH%2Bt0Ebo%3D
Vulnerable Package
11 HIGH CVE-2026-12143 Npm-form-data-2.3.3
detailsRecommended version: 2.5.6
Description: form-data is a library for creating readable multipart/form-data streams. In versions through 2.5.5, 3.x through 3.0.4 and 4.x through 4.0.5, the `...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: jV8ym4uiqxXd1808A4Cmj75g32ZbvZF1ebL%2BfIrpDWk%3D
Vulnerable Package
12 HIGH CVE-2026-12143 Npm-form-data-2.0.0
detailsRecommended version: 2.5.6
Description: form-data is a library for creating readable multipart/form-data streams. In versions through 2.5.5, 3.x through 3.0.4 and 4.x through 4.0.5, the `...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 6qAb5ONbxDWqcp0bWqYfGQ%2FwiJggtnbelk3bfNCliqY%3D
Vulnerable Package
13 HIGH CVE-2026-12143 Npm-form-data-2.1.4
detailsRecommended version: 2.5.6
Description: form-data is a library for creating readable multipart/form-data streams. In versions through 2.5.5, 3.x through 3.0.4 and 4.x through 4.0.5, the `...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: cxEx0emJKMzJr2JwJVRHffOAaM6HvWlO2i9P9ZxCb5Y%3D
Vulnerable Package
14 HIGH CVE-2026-12143 Npm-form-data-4.0.4
detailsRecommended version: 4.0.6
Description: form-data is a library for creating readable multipart/form-data streams. In versions through 2.5.5, 3.x through 3.0.4 and 4.x through 4.0.5, the `...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: dGIvk5lQXfzBvEQwZasXg%2FN8BcfTUKylsqvIi71sPW8%3D
Vulnerable Package
15 HIGH CVE-2026-13149 Npm-brace-expansion-2.0.2
detailsRecommended version: 2.1.2
Description: brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of conse...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: UzX527umlZ9vegIxWYG05QuGqjcCcYxlvd%2FDebpDGuw%3D
Vulnerable Package
16 HIGH CVE-2026-13149 Npm-brace-expansion-1.1.12
detailsRecommended version: 1.1.16
Description: brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of conse...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: HwilziginvVMNK%2F%2FU6S3M2GPG5LpefyrlJpCdIVQGG4%3D
Vulnerable Package
17 HIGH CVE-2026-13149 Npm-brace-expansion-1.1.6
detailsRecommended version: 1.1.16
Description: brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of conse...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: I5pfm5v3H2qpY3CvN2P%2FZuHs26r6UC9hwArzhayFn2w%3D
Vulnerable Package
18 HIGH CVE-2026-13149 Npm-brace-expansion-1.1.11
detailsRecommended version: 1.1.16
Description: brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of conse...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: C0A7x57qgMcRp69FKAYsEa0x8xJyQdSsXzHlAOukGmU%3D
Vulnerable Package
19 HIGH CVE-2026-14257 Npm-brace-expansion-2.0.2
detailsRecommended version: 2.1.3
Description: brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a m...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 1vNzvd3P4v14IF8YBgo516x%2BT%2BJF06rpBUxft5BcY9A%3D
Vulnerable Package
20 HIGH CVE-2026-14257 Npm-brace-expansion-1.1.12
detailsRecommended version: 1.1.17
Description: brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a m...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: PKdLyJqwNpNIZ91ZJUtT1KXfsT3Fd5Ocy5TpeJDz6nQ%3D
Vulnerable Package
21 HIGH CVE-2026-14257 Npm-brace-expansion-1.1.6
detailsRecommended version: 1.1.17
Description: brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a m...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Tm2wo1qktlRc3kuPy3NkQ1xv7s2bjhXjuw%2FGJokXLkA%3D
Vulnerable Package
22 HIGH CVE-2026-14257 Npm-brace-expansion-1.1.11
detailsRecommended version: 1.1.17
Description: brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a m...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 8qmIF%2FQtikADlODEi0U6q%2FWPnpmg0jbm%2F3rpW7fiWRQ%3D
Vulnerable Package
23 HIGH CVE-2026-27601 Npm-underscore-1.13.7
detailsRecommended version: 1.13.8
Description: Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the "_.flatten" and "_.isEqual" functions use recursion without a depth li...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: kWhzQspw0mn9J4J5yC1p0bQBWKxOxXS45dDpC0iZ23Q%3D
Vulnerable Package
24 HIGH CVE-2026-33671 Npm-picomatch-2.3.1
detailsRecommended version: 2.3.2
Description: `picomatch` is vulnerable prior to 2.3.2, 3.x prior to 3.0.2 and 4.x prior to 4.0.4, to Regular Expression Denial of Service (ReDoS) when processi...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 4qlSxqt7M9WMeJSioER%2F5oPO9IB7uP8RbJDSEy%2Fxr38%3D
Vulnerable Package
25 HIGH CVE-2026-33750 Npm-brace-expansion-2.0.2
detailsRecommended version: 2.0.3
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. In versions prior to 1.1.13, 2.0.0 prior to 2.0.3, 3...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Wonj98KsU75laAke7jqJ8svtPSNJkxwQh04JkiJSTDU%3D
Vulnerable Package
26 HIGH CVE-2026-33750 Npm-brace-expansion-1.1.6
detailsRecommended version: 1.1.13
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. In versions prior to 1.1.13, 2.0.0 prior to 2.0.3, 3...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: a8ub0sG4QqQi4pyCIoP334HMSG1HsUaIJ66axwKFaKs%3D
Vulnerable Package
27 HIGH CVE-2026-33750 Npm-brace-expansion-1.1.12
detailsRecommended version: 1.1.13
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. In versions prior to 1.1.13, 2.0.0 prior to 2.0.3, 3...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: kWQJHrkkaMrfGGhay%2F7e4Orl%2B3Qtn%2FEvEv%2FJqYCN4ZE%3D
Vulnerable Package
28 HIGH CVE-2026-33750 Npm-brace-expansion-1.1.11
detailsRecommended version: 1.1.13
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. In versions prior to 1.1.13, 2.0.0 prior to 2.0.3, 3...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: j5ZjBbShOvMCvhvYfB7%2BZUAlR9l9WfySHhH3ooARzPc%3D
Vulnerable Package
29 HIGH CVE-2026-33938 Npm-handlebars-4.0.5
detailsRecommended version: 4.7.9
Description: Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variab...
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: Q0aoTgxkn2xADmRDmSCzSlO9OKMXrBsPUMxcgwu5SVI%3D
Vulnerable Package
30 HIGH CVE-2026-33939 Npm-handlebars-4.0.5
detailsRecommended version: 4.7.9
Description: Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: ZFJk4SzQ5PW8w6W6qyzKuBhocpDAWUWAy9w9nDPPoTQ%3D
Vulnerable Package
31 HIGH CVE-2026-33940 Npm-handlebars-4.0.5
detailsRecommended version: 4.7.9
Description: Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the temp...
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: ABxxquFQ8SVGS%2FAyc%2FDQBy0XEzwXEa%2FRPv54dS9Ux%2Fg%3D
Vulnerable Package
32 HIGH CVE-2026-33941 Npm-handlebars-4.0.5
detailsRecommended version: 4.7.9
Description: Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bi...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: e8dfBRj%2Bu0kilFToyLXCDxwm3yyakaFs03G1oPKLoi0%3D
Vulnerable Package
33 HIGH CVE-2026-34043 Npm-serialize-javascript-6.0.2
detailsRecommended version: 7.0.5
Description: Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial-of-Service (D...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 3VSE1t5h1emEOQgV0YuwlIYfFgtJGe7NOC4ch%2Fhj79c%3D
Vulnerable Package
34 HIGH CVE-2026-39244 Npm-adm-zip-0.4.4
detailsRecommended version: 0.5.18
Description: adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size header field. In zipEntry.js l...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: VXcNwkPI8WZzyTdATK6w190tc2E6Vq%2FwO14v2o3sx6c%3D
Vulnerable Package
35 HIGH CVE-2026-42033 Npm-axios-1.12.2
detailsRecommended version: 1.15.1
Description: Axios is a promise-based HTTP client for the browser and Node.js. In versions prior to 0.31.1 and 1.0.0 prior to 1.15.1, when Object.prototype has ...
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: t1xKhpLVoOE%2Bog1h9fuXFlp1J%2F9zCQRN%2Bvjxnxa3FlM%3D
Vulnerable Package
36 HIGH CVE-2026-42035 Npm-axios-1.12.2
detailsRecommended version: 1.15.1
Description: Axios is a promise-based HTTP client for the browser and Node.js. In versions prior to 0.31.1 and 1.0.0 prior to 1.15.1, a prototype pollution gadg...
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: hr%2BFi3mvbeDnLaf%2BQYWIECPXSeWElT%2BCW%2BcQ1him7%2Fs%3D
Vulnerable Package
37 HIGH CVE-2026-42038 Npm-axios-1.12.2
detailsRecommended version: 1.15.1
Description: Axios is a promise-based HTTP client for the browser and Node.js. Prior to 0.31.1 and 1.0.0 prior to 1.15.1, he fix for no_proxy hostname normalisa...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: DlI43448Tz9spTuYtbfk6dDIKx6HN%2FOrP%2B7DYhVIUHo%3D
Vulnerable Package
38 HIGH CVE-2026-44486 Npm-axios-1.12.2
detailsRecommended version: 1.16.0
Description: Axios versions prior to 0.32.0 in the 0.x release line and prior to 1.16.0 in the 1.x release line are affected by a vulnerability in the Node.js H...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: M7RBLVg%2FcjjefSGlNTzFSOoAgpnQhOGvQTA3AuXTNWk%3D
Vulnerable Package
39 HIGH CVE-2026-44487 Npm-axios-1.12.2
detailsRecommended version: 1.16.0
Description: Axios's Node.js versions prior to `0.32.0` on the `0.x` line and versions prior to `1.16.0` on the `1.x`, HTTP adapter may forward a `Proxy-Authori...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: gN629255Pf%2FjhlzLJsZ3hgP57SDYwoZHTt2VvQ56rAs%3D
Vulnerable Package
40 HIGH CVE-2026-44488 Npm-axios-1.12.2
detailsRecommended version: 1.16.0
Description: Axios versions `1.7.0` through `1.15.x` did not enforce configured request and response size limits when requests were sent with the `fetch` adapte...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: laOQuZ%2BTKGFwD67sVOSG1QbtmkSBsF35XxmrZEiQqCQ%3D
Vulnerable Package
41 HIGH CVE-2026-44490 Npm-axios-1.12.2
detailsRecommended version: 1.16.0
Description: Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.0.0 prior to 1.16.0, axios exposes two read-side prototype-...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 9arOqxnM%2B%2FBGT%2Br98NMcZd9SnmLmwfcsKTlidu4%2BcLs%3D
Vulnerable Package
42 HIGH CVE-2026-44492 Npm-axios-1.12.2
detailsRecommended version: 1.16.0
Description: shouldBypassProxy, introduced in v1.15.0 to fix CVE-2025-62718, does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: YVAABwtAXNwoTPqfEvsrrV9NyGuZ7KkM6RZY5KNfUPo%3D
Vulnerable Package
43 HIGH CVE-2026-44494 Npm-axios-1.12.2
detailsRecommended version: 1.16.0
Description: The Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency...
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: WKCkd7T5t6O0BYsjgRXz%2FRhI0Rkwoi85hzHbJ5tYKfk%3D
Vulnerable Package
44 HIGH CVE-2026-44495 Npm-axios-1.12.2
detailsRecommended version: 1.15.2
Description: Axios versions before the fixed releases contain prototype-pollution gadgets in request config processing. If another vulnerability in the same Jav...
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: BGNW2UcSFOE3qPqc5j9buQMPXv00plaSks3TXVrr7oE%3D
Vulnerable Package
45 HIGH CVE-2026-44496 Npm-axios-1.12.2
detailsRecommended version: 1.16.0
Description: Axios versions prior to `0.32.0` on the `0.x` line and versions prior to `1.16.0` on the `1.x` line build a regular expression from the configured ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: HR0a7h9h%2BfqoRWElzyHozc9ydypfdBApuaKpG0vDA2E%3D
Vulnerable Package
46 HIGH CVE-2026-44705 Npm-tmp-0.1.0
detailsRecommended version: 0.2.6
Description: The tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into th...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 0gj5cl79DVQNTu5m0CkxEtCzyNIcCEnQFGS1WI4HbyI%3D
Vulnerable Package
47 HIGH CVE-2026-44705 Npm-tmp-0.0.24
detailsRecommended version: 0.2.6
Description: The tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into th...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: L%2FmLMr3AxFF%2FoH6MHRfYUh7VW%2BDfJPyWjQg5jEH7hjA%3D
Vulnerable Package
48 HIGH CVE-2026-4867 Npm-path-to-regexp-0.1.12
detailsRecommended version: 0.1.13
Description: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a peri...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: ZfmT3MfXNxCjlOx84arWhdAjqmsm02rkajSFGJJBsls%3D
Vulnerable Package
49 HIGH CVE-2026-48779 Npm-ws-1.1.5
detailsRecommended version: 5.2.5
Description: A high volume of exceptionally small fragments and data chunks can be sent by a peer, with modest network traffic, to force the remote peer into al...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 7K32o1DVCqKpDJngD%2FMrXNWhecZTZ1gU50RWE3gNkCo%3D
Vulnerable Package
50 HIGH CVE-2026-49982 Npm-tmp-0.0.24
detailsRecommended version: 0.2.7
Description: tmp is a temporary file and directory creator for node.js. In version through 0.2.6, the "_assertPath" guard added to tmp rejects only string value...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Ufl8%2BTgu%2BeUbG8lZf57W4wzatvz%2BjTcTfs2sEJJcXvU%3D
Vulnerable Package
51 HIGH CVE-2026-49982 Npm-tmp-0.1.0
detailsRecommended version: 0.2.7
Description: tmp is a temporary file and directory creator for node.js. In version through 0.2.6, the "_assertPath" guard added to tmp rejects only string value...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 3ggSFYusN0Sn0j0Ti6AUPkqWgO03b%2Be%2FFTYHYvlvzPE%3D
Vulnerable Package
52 HIGH CVE-2026-59869 Npm-js-yaml-4.1.0
detailsRecommended version: 4.3.0
Description: js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 prior to 3.15.0 and from 4.0.0 prior to 4.3.0, from 5.0.0 prior to 5.1.0, js-yaml can sp...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: UIBLC53BKwun6A0tUNOTUBF0a%2FXct8y0DDH%2FB%2FuanzI%3D
Vulnerable Package
53 HIGH CVE-2026-59869 Npm-js-yaml-3.14.1
detailsRecommended version: 3.15.0
Description: js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 prior to 3.15.0 and from 4.0.0 prior to 4.3.0, from 5.0.0 prior to 5.1.0, js-yaml can sp...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: D7PFzpPzF205g6iFPLt6r1cZ0ID88L%2B1fv6zhouc8fs%3D
Vulnerable Package
54 HIGH CVE-2026-59869 Npm-js-yaml-3.6.1
detailsRecommended version: 3.15.0
Description: js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 prior to 3.15.0 and from 4.0.0 prior to 4.3.0, from 5.0.0 prior to 5.1.0, js-yaml can sp...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 99ZcSjWcMfHtpJDvTo8OcN%2FBl8VJpqLAWck2tHWHGh0%3D
Vulnerable Package
55 HIGH CVE-2026-59871 Npm-tar-4.4.8
detailsRecommended version: 7.5.18
Description: node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: JMXqbS6DH0j%2BRmjzNPyOMQsKj7mPbJyMa6CW9QI4%2F6k%3D
Vulnerable Package
56 HIGH CVE-2026-59871 Npm-tar-2.2.1
detailsRecommended version: 7.5.18
Description: node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: wntrT1Dabd7s1Q7f4fjLCAR28bBQieFqt%2BSUGxUe5KI%3D
Vulnerable Package
57 HIGH CVE-2026-59874 Npm-tar-4.4.8
detailsRecommended version: 7.5.18
Description: node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-2...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Pj1KN2ei5BeIYq9YG21aOKrDwgn6PYHUdweqPT4FAls%3D
Vulnerable Package
58 HIGH CVE-2026-59874 Npm-tar-2.2.1
detailsRecommended version: 7.5.18
Description: node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-2...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: szEaIh6kIKrnDDAcVdKRVLQvcSIDvLC5hp6cYLxtnPg%3D
Vulnerable Package
59 HIGH CVE-2026-62389 Npm-ws-1.1.5
detailsRecommended version: 5.2.7
Description: ws prior to 8.21.1 contains a memory exhaustion vulnerability in lib/receiver.js where the fragment guard only triggers when fragment count reaches...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: OeMUXTt6hkuBsgXn3nZ76zXSwONHCxpTisszO4fsnl4%3D
Vulnerable Package
60 HIGH CVE-2026-69152 Npm-brace-expansion-1.1.6
detailsRecommended version: 1.1.18
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() d...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Jd%2BSkWFQpD2ujTGklcTZeDzP9%2BLvZLbbypJ2u7wW1%2Fc%3D
Vulnerable Package
61 HIGH CVE-2026-69152 Npm-brace-expansion-2.0.2
detailsRecommended version: 2.1.4
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() d...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: EVJq26TuM8hXtS8dzPPA0OCjjVywidWHtoo6%2FkQEM%2Fc%3D
Vulnerable Package
62 HIGH CVE-2026-69152 Npm-brace-expansion-1.1.11
detailsRecommended version: 1.1.18
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() d...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 1c%2BFrcUEjDN7cBLEPaXVZtQOAJjnKYXoy0c2AlEFjoE%3D
Vulnerable Package
63 HIGH CVE-2026-69152 Npm-brace-expansion-1.1.12
detailsRecommended version: 1.1.18
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() d...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: KelX%2Bizw3ZkECnGDehV1CZATflwxbZIHhHxg2k%2BoKqs%3D
Vulnerable Package
64 MEDIUM CVE-2025-62718 Npm-axios-1.12.2
detailsRecommended version: 1.15.0
Description: Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, Axios does not correctly handle hostname normalization when chec...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: zPaglGPw0RyG76mFBXsfCmMZ0TIeNbIbjPBayCBgG2s%3D
Vulnerable Package
65 MEDIUM CVE-2026-12590 Npm-body-parser-1.20.3
detailsRecommended version: 1.20.6
Description: Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.0.0-beta.1 prior to 2.3.0 , when the parser is configured with an invalid limit op...
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: S4PgSXGbfViiw4H%2B6H2DUQ1s78snLXP7WkLLZ0EwQ8k%3D
Vulnerable Package
66 MEDIUM CVE-2026-2950 Npm-lodash-4.17.21
detailsRecommended version: 4.18.0
Description: Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: T6PZ8dM79x7lplJXVfe6u%2FkUda%2FRcZtXu3AQcsAgWi4%3D
Vulnerable Package
67 MEDIUM CVE-2026-2950 Npm-lodash-4.17.20
detailsRecommended version: 4.18.0
Description: Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: HZMOfvdWTFyt9kpC5wiZ9fW7A8yJ1bzJPUtFXfr2Ck0%3D
Vulnerable Package
68 MEDIUM CVE-2026-2950 Npm-lodash-4.17.11
detailsRecommended version: 4.18.0
Description: Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: kvymmFVBHi8irIrFAthr7ZVUDQv%2FUMd05FfMCoTnIrA%3D
Vulnerable Package
69 MEDIUM CVE-2026-2950 Npm-lodash-4.13.1
detailsRecommended version: 4.18.0
Description: Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: iWHwHTV3u0GZGlJuPSuyZO9I2yO6Oo9hMdQQklAaS9c%3D
Vulnerable Package
70 MEDIUM CVE-2026-33672 Npm-picomatch-2.3.1
detailsRecommended version: 2.3.2
Description: Picomatch is a glob matcher written JavaScript. Versions prior to 2.3.2, 3.0.0 prior to 3.0.2 and 4.0.0 prior to 4.0.4, are vulnerable to a method ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: UETZ02ZS0YvDP6g616uS4AB7p4zZvz8Z4%2F2sjEOtiKY%3D
Vulnerable Package
71 MEDIUM CVE-2026-33916 Npm-handlebars-4.0.5
detailsRecommended version: 4.7.9
Description: Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebar...
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: MyIMNOAI5XnVPAz2JAhwEzyL4krYWn6ipZGY7WsAbFY%3D
Vulnerable Package
72 MEDIUM CVE-2026-40175 Npm-axios-1.12.2
detailsRecommended version: 1.15.0
Description: Axios is a promise-based HTTP client for the browser and Node.js. Prior to 0.31.0 and 1.x prior to 1.15.0, the Axios library is vulnerable to a spe...
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: FEElb%2F9%2FlyH4jnuaGLA62j0Ru%2FfUV0F67nlwEUuCaUc%3D
Vulnerable Package
73 MEDIUM CVE-2026-40895 Npm-follow-redirects-1.15.11
detailsRecommended version: 1.16.0
Description: follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to versio...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: m0gP4iaHqXdsnTnBvrwJpmp6b3SVutUVCLF3cdaMpIA%3D
Vulnerable Package
74 MEDIUM CVE-2026-42034 Npm-axios-1.12.2
detailsRecommended version: 1.15.1
Description: Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 2k3YdxmYh3HgO3ncim7FBCxJzqUX63BWkLmHYaaBExQ%3D
Vulnerable Package
75 MEDIUM CVE-2026-42036 Npm-axios-1.12.2
detailsRecommended version: 1.15.1
Description: Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns th...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: WyzvtDU37SckSzVMVZGTfjaAKkjIVfEEuHOl64RidaE%3D
Vulnerable Package
76 MEDIUM CVE-2026-42037 Npm-axios-1.12.2
detailsRecommended version: 1.15.1
Description: Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formData...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 5pFpWA1XaSFj8DvuAFPZF2XnlmtnJGOcM%2BWtrf%2F4dCc%3D
Vulnerable Package
77 MEDIUM CVE-2026-42039 Npm-axios-1.12.2
detailsRecommended version: 1.15.1
Description: Axios is a promise-based HTTP client for the browser and Node.js. Prior to 0.31.1 and 1.0.0 prior to 1.15.1, FormData recursively walks nested obje...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Tebg5TjRHSwXpiJvzot5J1nvbqBbocdjP2OMD%2B%2Fe9iw%3D
Vulnerable Package
78 MEDIUM CVE-2026-42041 Npm-axios-1.12.2
detailsRecommended version: 1.15.1
Description: Axios is a promise-based HTTP client for the browser and Node.js. From 1.x prior to 1.15.1 and from 0.x prior to 0.31.1, the Axios library is vulne...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: fX6If1rxowPea1AR2MEHYVR3jlYSJuJYR59KFpcGYew%3D
Vulnerable Package
79 MEDIUM CVE-2026-42042 Npm-axios-1.12.2
detailsRecommended version: 1.15.1
Description: Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: aaccQP8JaazoMG6KTdH5u1iU%2BlfqYVoOYWXCfpmYCcE%3D
Vulnerable Package
80 MEDIUM CVE-2026-45822 Npm-decode-uri-component-0.2.0
detailsRecommended version: 0.5.0
Description: decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decod...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: muLRWLcDi8HwoQNGptbxg%2F7E7Rn41Nr5HKUGwTvj1iI%3D
Vulnerable Package
81 MEDIUM CVE-2026-53550 Npm-js-yaml-3.6.1
detailsRecommended version: 3.15.0
Description: js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: eHq0ptjypFZkxgH2m12tg1cKjSArDPC64JtmYrUPuJA%3D
Vulnerable Package
82 MEDIUM CVE-2026-53550 Npm-js-yaml-4.1.0
detailsRecommended version: 4.2.0
Description: js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: xeDHbR0o2JEC2x5%2BYqZKjz3eAmJhQBQmIOazbPdxFls%3D
Vulnerable Package

More results are available on the CxOne platform


Communicate with Checkmarx by submitting a PR comment with @Checkmarx followed by one of the supported commands. Learn about the supported commands here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant