Skip to content

fix(deps): vuln minor upgrades — 13 packages (minor: 8 · patch: 5) [rum-react-navigation] - #111

Open
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/npm/rum-react-navigation/1-1785767742
Open

fix(deps): vuln minor upgrades — 13 packages (minor: 8 · patch: 5) [rum-react-navigation]#111
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/npm/rum-react-navigation/1-1785767742

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: Critical-severity security update — 15 packages upgraded (MINOR changes included)

Manifests changed:

  • rum-react-navigation (yarn)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
vm2 3.9.14 3.11.5 minor Transitive 48 CRITICAL, 10 HIGH, 11 MEDIUM, 1 LOW
fast-xml-parser 4.1.3 4.5.7 minor Transitive 2 CRITICAL, 6 HIGH, 4 MEDIUM, 2 LOW
simple-git 3.16.0 3.36.0 minor Transitive 2 CRITICAL, 4 HIGH
shell-quote 1.8.0 1.10.0 minor Transitive 2 CRITICAL, 2 HIGH
form-data 3.0.0 3.0.5 patch Transitive 2 CRITICAL, 2 HIGH
@babel/traverse 7.20.13 7.29.8 minor Transitive 2 CRITICAL
minimatch 3.1.2 3.1.5 patch Transitive 6 HIGH
lodash 4.17.21 4.18.1 minor Transitive 4 HIGH, 4 MEDIUM
brace-expansion 1.1.11 1.1.18 patch Transitive 4 HIGH, 2 MEDIUM, 2 LOW
flatted 3.2.7 3.4.4 minor Transitive 4 HIGH
ws 7.4.6 7.5.13 minor Transitive 4 HIGH
ws 6.2.2 6.2.6 patch Transitive 4 HIGH
js-yaml 4.1.0 4.3.1 minor Transitive 2 HIGH, 4 MEDIUM
js-yaml 3.13.1 3.15.1 minor Transitive 2 HIGH, 4 MEDIUM
picomatch 2.3.1 2.3.2 patch Transitive 2 HIGH, 2 MEDIUM

Security Details

🚨 Critical & High Severity (114 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
@babel/traverse CVE-2023-45133 CRITICAL Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code 7.20.13 - -
@babel/traverse GHSA-67hx-6x53-jw92 CRITICAL Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code 7.20.13 7.23.2 -
fast-xml-parser GHSA-m7jm-9gc2-mpf2 CRITICAL fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names 4.1.3 5.3.5 -
fast-xml-parser CVE-2026-25896 CRITICAL fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names 4.1.3 - -
form-data CVE-2025-7783 CRITICAL Usage of unsafe random function in form-data for choosing boundary 3.0.0 - -
form-data GHSA-fjxv-7rqg-78g4 CRITICAL form-data uses unsafe random function in form-data for choosing boundary 3.0.0 2.5.4 -
shell-quote CVE-2026-9277 CRITICAL shell-quote quote() does not validate object-token shapes, allowing command injection via line terminators in .op 1.8.0 - -
shell-quote GHSA-w7jw-789q-3m8p CRITICAL shell-quote quote() does not escape newlines in object .op values 1.8.0 1.8.4 -
simple-git CVE-2026-28292 CRITICAL simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key that enables RCE 3.16.0 - -
simple-git GHSA-r275-fr43-pm7q CRITICAL simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE 3.16.0 3.32.3 -
vm2 CVE-2026-47137 CRITICAL vm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allows full RCE 3.9.14 - -
vm2 CVE-2023-37466 CRITICAL vm2 Sandbox Escape vulnerability 3.9.14 - -
vm2 CVE-2026-44006 CRITICAL vm2: Sandbox Escape 3.9.14 - -
vm2 GHSA-qcp4-v2jj-fjx8 CRITICAL vm2 has a Sandbox Escape Vulnerability 3.9.14 3.11.0 -
vm2 GHSA-whpj-8f3w-67p5 CRITICAL vm2 Sandbox Escape vulnerability 3.9.14 3.9.18 -
vm2 GHSA-m4wx-m65x-ghrr CRITICAL vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE 3.9.14 3.11.4 -
vm2 GHSA-99p7-6v5w-7xg8 CRITICAL vm2 has a Sandbox Escape 3.9.14 3.10.2 -
vm2 CVE-2026-22709 CRITICAL vm2 has a Sandbox Escape 3.9.14 - -
vm2 GHSA-v37h-5mfm-c47c CRITICAL VM2 Has Sandbox Breakout Through Inspect Function 3.9.14 3.11.0 -
vm2 CVE-2026-24781 CRITICAL vm2: Sandbox Breakout Through Inspect 3.9.14 - -
vm2 CVE-2023-29199 CRITICAL vm2 Sandbox escape vulnerability 3.9.14 - -
vm2 GHSA-qvjj-29qf-hp7p CRITICAL VM2 Has Sandbox Breakout Through Promise Species 3.9.14 3.10.5 -
vm2 CVE-2026-47140 CRITICAL vm2: NodeVM builtin denylist bypass via process and inspector/promises allows host code execution 3.9.14 - -
vm2 GHSA-xj72-wvfv-8985 CRITICAL vm2 Sandbox Escape vulnerability 3.9.14 3.9.16 -
vm2 GHSA-v6mx-mf47-r5wg CRITICAL vm2 has a Sandbox Escape issue 3.9.14 3.11.4 -
vm2 CVE-2026-47208 CRITICAL vm2: Sandbox Breakout Using Promise Species 3.9.14 - -
vm2 CVE-2026-24118 CRITICAL VM2 Sandbox Breakout Through lookupGetter 3.9.14 - -
vm2 GHSA-grj5-jjm8-h35p CRITICAL VM2 Sandbox Breakout Through lookupGetter 3.9.14 3.11.0 -
vm2 GHSA-76w7-j9cq-rx2j CRITICAL vm2 is Vulnerable to Sandbox Breakout Through Promise Species 3.9.14 3.11.4 -
vm2 CVE-2023-30547 CRITICAL Sandbox Escape in vm2 3.9.14 - -
vm2 CVE-2026-26332 CRITICAL vm2: Sandbox Escape 3.9.14 - -
vm2 GHSA-55hx-c926-fr95 CRITICAL VM2 Has a Sandbox Escape Issue via SuppressedError 3.9.14 3.11.0 -
vm2 GHSA-ch3r-j5x3-6q2m CRITICAL vm2 Sandbox Escape vulnerability 3.9.14 3.9.17 -
vm2 GHSA-rp36-8xq3-r6c4 CRITICAL NodeVM builtin denylist bypass via process and inspector/promises allows host code execution 3.9.14 3.11.4 -
vm2 GHSA-cchq-frgv-rjh5 CRITICAL vm2 Sandbox Escape vulnerability 3.9.14 3.10.0 -
vm2 CVE-2026-44008 CRITICAL vm2: Snabox breakout via neutralizeArraySpeciesBatch 3.9.14 - -
vm2 CVE-2026-47131 CRITICAL vm2: Sandbox Escape 3.9.14 - -
vm2 CVE-2023-32314 CRITICAL Sandbox Escape 3.9.14 - -
vm2 CVE-2026-44007 CRITICAL vm2: nesting: true bypasses require: false, allowing sandbox escape to arbitrary OS command execution 3.9.14 - -
vm2 GHSA-8hg8-63c5-gwmx CRITICAL vm2 NodeVM nesting: true bypasses require: false allowing sandbox escape and arbitrary OS command execution 3.9.14 3.11.1 -
vm2 GHSA-9qj6-qjgg-37qq CRITICAL vm2 has sandbox breakout via neutralizeArraySpeciesBatch 3.9.14 3.11.2 -
vm2 CVE-2026-24120 CRITICAL vm2: Sandbox Breakout Through Promise Species 3.9.14 - -
vm2 GHSA-47x8-96vw-5wg6 CRITICAL vm2 Access to Host Object Enables Sandbox Escape 3.9.14 3.11.0 -
vm2 CVE-2026-43997 CRITICAL vm2: Sandbox Escape 3.9.14 - -
vm2 GHSA-248r-7h7q-cr24 CRITICAL vm2 Has a Sandbox Breakout Using Async Generator 3.9.14 3.11.3 -
vm2 CVE-2026-45411 CRITICAL vm2: Sandbox Breakout Using Async Generator 3.9.14 - -
vm2 GHSA-6j2x-vhqr-qr7q CRITICAL vm2 sandbox escape via JSPI-backed Promise .finally() species bypass 3.9.14 3.11.4 -
vm2 CVE-2026-44009 CRITICAL vm2: Sandbox Breakout Through Null Proto Exception 3.9.14 - -
vm2 GHSA-9vg3-4rfj-wgcm CRITICAL vm2 has Sandbox Breakout Through Null Proto Exception 3.9.14 3.11.2 -
vm2 CVE-2026-47210 CRITICAL vm2 sandbox escape via JSPI-backed Promise .finally() species bypass 3.9.14 - -
vm2 GHSA-7jxr-cg7f-gpgv CRITICAL vm2 vulnerable to sandbox escape 3.9.14 3.9.15 -
vm2 CVE-2023-29017 CRITICAL vm2 Sandbox Escape vulnerability 3.9.14 - -
vm2 GHSA-g644-9gfx-q4q4 CRITICAL vm2 Sandbox Escape vulnerability 3.9.14 - -
vm2 CVE-2023-37903 CRITICAL Sandbox Escape in vm2 3.9.14 - -
vm2 GHSA-vwrp-x96c-mhwq CRITICAL vm2: Mutable Proxies for Host Intrinsic Prototypes Allows Sandbox Escape 3.9.14 3.11.0 -
vm2 CVE-2026-44005 CRITICAL vm2: Sandbox escape 3.9.14 - -
vm2 CVE-2026-26956 CRITICAL vm2: WASM Sandbox Escape (Node 25 only) 3.9.14 - -
vm2 GHSA-ffh4-j6h5-pg66 CRITICAL VM2 Has a WASM Sandbox Escape 3.9.14 3.10.5 -
brace-expansion CVE-2026-14257 HIGH brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash 1.1.11 - -
brace-expansion GHSA-3jxr-9vmj-r5cp HIGH brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups 1.1.11 5.0.7 -
brace-expansion CVE-2026-13149 HIGH - 1.1.11 - -
brace-expansion GHSA-mh99-v99m-4gvg HIGH brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash 1.1.11 5.0.8 -
fast-xml-parser CVE-2026-33036 HIGH fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278) 4.1.3 - -
fast-xml-parser GHSA-jmr7-xgp7-cmfj HIGH fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit) 4.1.3 4.5.4 -
fast-xml-parser CVE-2026-26278 HIGH fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit) 4.1.3 - -
fast-xml-parser GHSA-6w63-h3fj-q4vw HIGH fast-xml-parser vulnerable to Regex Injection via Doctype Entities 4.1.3 4.2.4 -
fast-xml-parser CVE-2023-34104 HIGH Regex Injection via Doctype Entities 4.1.3 - -
fast-xml-parser GHSA-8gc5-j5rx-235r HIGH fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278) 4.1.3 5.5.6 -
flatted GHSA-rf6f-7fwh-wjgh HIGH Prototype Pollution via parse() in NodeJS flatted 3.2.7 3.4.2 -
flatted GHSA-25h7-pfq9-p65f HIGH flatted vulnerable to unbounded recursion DoS in parse() revive phase 3.2.7 3.4.0 -
flatted CVE-2026-32141 HIGH flatted: Unbounded recursion DoS in parse() revive phase 3.2.7 - -
flatted CVE-2026-33228 HIGH flatted: Prototype Pollution via parse() 3.2.7 - -
form-data CVE-2026-12143 HIGH form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection) 3.0.0 - -
form-data GHSA-hmw2-7cc7-3qxx HIGH form-data: CRLF injection in form-data via unescaped multipart field names and filenames 3.0.0 2.5.6 -
js-yaml GHSA-52cp-r559-cp3m HIGH js-yaml: YAML merge-key chains can force quadratic CPU consumption 3.13.1 3.15.0 -
js-yaml CVE-2026-59869 HIGH js-yaml: YAML merge-key chains can force quadratic CPU consumption 3.13.1 - -
js-yaml GHSA-52cp-r559-cp3m HIGH js-yaml: YAML merge-key chains can force quadratic CPU consumption 4.1.0 3.15.0 -
js-yaml CVE-2026-59869 HIGH js-yaml: YAML merge-key chains can force quadratic CPU consumption 4.1.0 - -
lodash CVE-2026-4800 HIGH lodash vulnerable to Code Injection via _.template imports key names 4.17.21 - -
lodash GHSA-r5fr-rjxr-66jc HIGH lodash vulnerable to Code Injection via _.template imports key names 4.17.21 4.18.0 -
lodash CVE-2021-23337 HIGH - 4.17.21 - -
lodash GHSA-35jh-r3h4-6jhm HIGH Command Injection in lodash 4.17.21 4.17.21 -
minimatch GHSA-7r86-cg39-jmmj HIGH minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments 3.1.2 10.2.3 -
minimatch GHSA-23c5-xmqv-rm74 HIGH minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions 3.1.2 10.2.3 -
minimatch CVE-2026-27904 HIGH minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions 3.1.2 - -
minimatch CVE-2026-27903 HIGH minimatch has a ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments 3.1.2 - -
minimatch CVE-2026-26996 HIGH minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern 3.1.2 - -
minimatch GHSA-3ppc-4f35-3m26 HIGH minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern 3.1.2 10.2.1 -
picomatch GHSA-c2c7-rcm5-vvqj HIGH Picomatch has a ReDoS vulnerability via extglob quantifiers 2.3.1 4.0.4 -
picomatch CVE-2026-33671 HIGH Picomatch has a ReDoS vulnerability via extglob quantifiers 2.3.1 - -
shell-quote GHSA-395f-4hp3-45gv HIGH shell-quote: Quadratic-complexity Denial of Service in parse() (CWE-407) 1.8.0 1.9.0 -
shell-quote CVE-2026-13311 HIGH shell-quote parse() is quadratic in token count, enabling denial of service 1.8.0 - -
simple-git GHSA-jcxm-m3jx-f287 HIGH simple-git Affected by Command Execution via Option-Parsing Bypass 3.16.0 3.32.0 -
simple-git CVE-2026-6951 HIGH - 3.16.0 - -
simple-git CVE-2026-28291 HIGH simple-git has Command Execution via Option-Parsing Bypass 3.16.0 - -
simple-git GHSA-hffm-xvc3-vprc HIGH simple-git is vulnerable to Remote Code Execution 3.16.0 3.36.0 -
vm2 GHSA-m5q2-4fm3-vfqp HIGH vm2 has a sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks 3.9.14 3.11.4 -
vm2 CVE-2026-44004 HIGH vm2: Host Process OOM DoS via Buffer.alloc (Timeout Bypass) 3.9.14 - -
vm2 GHSA-hw58-p9xv-2mjh HIGH vm2 has a Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS) 3.9.14 3.11.0 -
vm2 CVE-2026-44001 HIGH vm2: Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS) 3.9.14 - -
vm2 GHSA-c4cf-2hgv-2qv6 HIGH vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain 3.9.14 3.11.4 -
vm2 CVE-2026-47209 HIGH vm2: Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain 3.9.14 - -
vm2 GHSA-r9pm-gxmw-wv6p HIGH NodeVM network builtin exclusions bypass via internal _http_client and _http_server 3.9.14 3.11.4 -
vm2 CVE-2026-47139 HIGH vm2: NodeVM network builtin exclusions bypass via internal _http_client and _http_server 3.9.14 - -
vm2 CVE-2026-47135 HIGH vm2: Sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks 3.9.14 - -
vm2 GHSA-6785-pvv7-mvg7 HIGH vm2 Sandbox Access to Host Buffer.alloc Allows timeout Bypass Resulting in Memory Exhaustion 3.9.14 3.11.0 -
ws CVE-2024-37890 HIGH Denial of service when handling a request with many HTTP headers in ws 7.4.6 - -
ws GHSA-96hv-2xvq-fx4p HIGH ws: Memory exhaustion DoS from tiny fragments and data chunks 7.4.6 5.2.5 -
ws CVE-2024-37890 HIGH Denial of service when handling a request with many HTTP headers in ws 6.2.2 - -
ws GHSA-3h5v-q93c-6h6q HIGH ws affected by a DoS when handling a request with many HTTP headers 6.2.2 5.2.4 -
ws CVE-2026-48779 HIGH ws: Memory exhaustion DoS from tiny fragments and data chunks 6.2.2 - -
ws GHSA-96hv-2xvq-fx4p HIGH ws: Memory exhaustion DoS from tiny fragments and data chunks 6.2.2 5.2.5 -
ws CVE-2026-48779 HIGH ws: Memory exhaustion DoS from tiny fragments and data chunks 7.4.6 - -
ws GHSA-3h5v-q93c-6h6q HIGH ws affected by a DoS when handling a request with many HTTP headers 7.4.6 5.2.4 -
ℹ️ Other Vulnerabilities (36)
Package CVE Severity Summary Unsafe Version Fixed In Case
brace-expansion CVE-2026-33750 MODERATE brace-expansion: Zero-step sequence causes process hang and memory exhaustion 1.1.11 - -
brace-expansion GHSA-f886-m6hf-6m8v MODERATE brace-expansion: Zero-step sequence causes process hang and memory exhaustion 1.1.11 5.0.5 -
fast-xml-parser CVE-2026-41650 MODERATE fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters 4.1.3 - -
fast-xml-parser GHSA-gh4j-gqv2-49f6 MODERATE fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters 4.1.3 5.7.0 -
fast-xml-parser CVE-2026-33349 MODERATE fast-xml-parser: Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation 4.1.3 - -
fast-xml-parser GHSA-jp2q-39xq-3w4g MODERATE Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser 4.1.3 4.5.5 -
js-yaml GHSA-mh29-5h37-fv8m MODERATE js-yaml has prototype pollution in merge (<<) 3.13.1 4.1.1 -
js-yaml CVE-2025-64718 MODERATE js-yaml has prototype pollution in merge (<<) 3.13.1 - -
js-yaml GHSA-h67p-54hq-rp68 MODERATE JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases 4.1.0 4.2.0 -
js-yaml CVE-2026-53550 MODERATE js-yaml: Quadratic-complexity DoS in merge key handling via repeated aliases 4.1.0 - -
js-yaml CVE-2026-53550 MODERATE js-yaml: Quadratic-complexity DoS in merge key handling via repeated aliases 3.13.1 - -
js-yaml GHSA-mh29-5h37-fv8m MODERATE js-yaml has prototype pollution in merge (<<) 4.1.0 4.1.1 -
js-yaml CVE-2025-64718 MODERATE js-yaml has prototype pollution in merge (<<) 4.1.0 - -
js-yaml GHSA-h67p-54hq-rp68 MODERATE JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases 3.13.1 4.2.0 -
lodash CVE-2025-13465 MODERATE Prototype Pollution Vulnerability in Lodash _.unset and _.omit functions 4.17.21 - -
lodash CVE-2026-2950 MODERATE lodash vulnerable to Prototype Pollution via array path bypass in _.unset and _.omit 4.17.21 - -
lodash GHSA-xxjr-mmjv-4gpg MODERATE Lodash has Prototype Pollution Vulnerability in _.unset and _.omit functions 4.17.21 4.17.23 -
lodash GHSA-f23m-r3pf-42rh MODERATE lodash vulnerable to Prototype Pollution via array path bypass in _.unset and _.omit 4.17.21 4.18.0 -
picomatch GHSA-3v7f-55p6-f55p MODERATE Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching 2.3.1 4.0.4 -
picomatch CVE-2026-33672 MODERATE Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching 2.3.1 - -
vm2 GHSA-mpf8-4hx2-7cjg MODERATE vm2 Host Promise Resolution Preserves Object Identity Across Sandbox Boundary 3.9.14 3.11.0 -
vm2 GHSA-v27g-jcqj-v8rw MODERATE vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak 3.9.14 3.11.0 -
vm2 GHSA-2cm2-m3w5-gp2f MODERATE vm2 has access to VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL 3.9.14 3.11.2 -
vm2 GHSA-9g8x-92q2-p28f MODERATE NodeVM observability builtins leak host process and HTTP request data 3.9.14 3.11.4 -
vm2 CVE-2026-44003 MODERATE vm2: Transformer Fast-Path Bypass Exposes Internal State Variable 3.9.14 - -
vm2 GHSA-wp5r-2gw5-m7q7 MODERATE vm2's Transformer Fast-Path Bypass Exposes Internal State Variable 3.9.14 3.11.0 -
vm2 GHSA-p5gc-c584-jj6v MODERATE vm2 vulnerable to Inspect Manipulation 3.9.14 3.9.18 -
vm2 CVE-2026-44000 MODERATE vm2: sandbox boundary bypass via host Promise resolution preserving host object identity 3.9.14 - -
vm2 CVE-2026-47141 MODERATE vm2: NodeVM observability builtins leak host process and HTTP request data 3.9.14 - -
vm2 CVE-2023-32313 MODERATE Inspect method manipulation in vm2 3.9.14 - -
vm2 CVE-2026-44002 MODERATE vm2: Host File Path Disclosure via Stack Trace Information Leak 3.9.14 - -
brace-expansion GHSA-v6h2-p8h4-qcjw LOW brace-expansion Regular Expression Denial of Service vulnerability 1.1.11 2.0.2 -
brace-expansion CVE-2025-5889 LOW juliangruber brace-expansion index.js expand redos 1.1.11 - -
fast-xml-parser CVE-2026-27942 LOW fast-xml-parser has stack overflow in XMLBuilder with preserveOrder 4.1.3 - -
fast-xml-parser GHSA-fj3w-jwp8-x2g3 LOW fast-xml-parser has stack overflow in XMLBuilder with preserveOrder 4.1.3 5.3.8 -
vm2 GHSA-q3fm-4wcw-g57x LOW vm2 setup-sandbox.js violates Defense Invariant #11 in stack-trace formatter 3.9.14 3.11.4 -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants