Skip to content

Navigation Menu

Sign in
Sign up

core-3.9.2.tgz: 79 vulnerabilities (highest severity is: 9.8) #303

Open

Description

Vulnerable Library - core-3.9.2.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/fast-uri-npm-3.1.0-57fa0b3f3c-10c0.zip

Vulnerabilities

Vulnerability Severity CVSS Dependency Type Fixed in (core version) Remediation Possible**
CVE-2026-41907 Critical 9.8 uuid-8.3.2.tgz Transitive N/A*
CVE-2026-59873 High 8.6 tar-7.5.6.tgz Transitive 3.10.0
CVE-2026-54466 High 8.6 websocket-driver-0.7.4.tgz Transitive N/A*
CVE-2026-25547 High 8.6 brace-expansion-5.0.0.tgz Transitive N/A*
CVE-2026-53632 High 8.3 launch-editor-2.12.0.tgz Transitive N/A*
CVE-2026-84370 High 8.2 svgo-3.3.2.tgz Transitive N/A*
CVE-2026-73650 High 8.2 svgo-3.3.2.tgz Transitive N/A*
CVE-2026-44728 High 8.2 plugin-transform-modules-systemjs-7.28.5.tgz Transitive 3.10.0
CVE-2026-24842 High 8.2 tar-7.5.6.tgz Transitive 3.10.0
CVE-2026-9277 High 8.1 shell-quote-1.8.3.tgz Transitive 3.10.0
CVE-2026-4800 High 8.1 lodash-4.17.23.tgz Transitive N/A*
CVE-2026-84375 High 7.5 detected in multiple dependencies Transitive N/A*
CVE-2026-84292 High 7.5 fast-uri-3.1.0.tgz Transitive N/A*
CVE-2026-76172 High 7.5 fast-uri-3.1.0.tgz Transitive N/A*
CVE-2026-75975 High 7.5 fast-uri-3.1.0.tgz Transitive N/A*
CVE-2026-73646 High 7.5 postcss-8.5.6.tgz Transitive N/A*
CVE-2026-73566 High 7.5 tar-7.5.6.tgz Transitive 3.10.0
CVE-2026-73089 High 7.5 browserslist-4.28.1.tgz Transitive N/A*
CVE-2026-73088 High 7.5 browserslist-4.28.1.tgz Transitive N/A*
CVE-2026-69152 High 7.5 brace-expansion-1.1.12.tgz Transitive N/A*
CVE-2026-6322 High 7.5 fast-uri-3.1.0.tgz Transitive N/A*
CVE-2026-6321 High 7.5 fast-uri-3.1.0.tgz Transitive 3.10.0
CVE-2026-59874 High 7.5 tar-7.5.6.tgz Transitive 3.10.0
CVE-2026-59869 High 7.5 detected in multiple dependencies Transitive 3.10.0
CVE-2026-48779 High 7.5 detected in multiple dependencies Transitive N/A*
CVE-2026-4867 High 7.5 path-to-regexp-0.1.12.tgz Transitive N/A*
CVE-2026-45819 High 7.5 baseline-browser-mapping-2.9.17.tgz Transitive N/A*
CVE-2026-45623 High 7.5 postcss-8.5.6.tgz Transitive 3.10.0
CVE-2026-33671 High 7.5 detected in multiple dependencies Transitive N/A*
CVE-2026-29074 High 7.5 svgo-3.3.2.tgz Transitive N/A*
CVE-2026-27904 High 7.5 detected in multiple dependencies Transitive 3.10.0
CVE-2026-27903 High 7.5 detected in multiple dependencies Transitive N/A*
CVE-2026-26996 High 7.5 detected in multiple dependencies Transitive N/A*
CVE-2026-18446 High 7.5 fast-uri-3.1.0.tgz Transitive N/A*
CVE-2026-16221 High 7.5 fast-uri-3.1.0.tgz Transitive N/A*
CVE-2026-14257 High 7.5 brace-expansion-1.1.12.tgz Transitive N/A*
CVE-2026-13676 High 7.5 fast-uri-3.1.0.tgz Transitive 3.10.0
CVE-2026-13311 High 7.5 shell-quote-1.8.3.tgz Transitive 3.10.0
CVE-2026-13149 High 7.5 brace-expansion-1.1.12.tgz Transitive N/A*
CVE-2025-71330 High 7.5 image-size-2.0.2.tgz Transitive N/A*
CVE-2025-71329 High 7.5 image-size-2.0.2.tgz Transitive N/A*
CVE-2026-73086 High 7.4 nanoid-3.3.11.tgz Transitive 3.10.0
CVE-2026-31802 High 7.1 tar-7.5.6.tgz Transitive N/A*
CVE-2026-29786 High 7.1 tar-7.5.6.tgz Transitive N/A*
CVE-2026-26960 High 7.1 tar-7.5.6.tgz Transitive 3.10.0
CVE-2026-33750 Medium 6.5 brace-expansion-1.1.12.tgz Transitive N/A*
CVE-2026-2950 Medium 6.5 lodash-4.17.23.tgz Transitive N/A*
CVE-2026-53655 Medium 6.2 tar-7.5.6.tgz Transitive N/A*
CVE-2026-84369 Medium 6.1 svgo-3.3.2.tgz Transitive N/A*
CVE-2026-41305 Medium 6.1 postcss-8.5.6.tgz Transitive 3.10.0
CVE-2026-67214 Medium 5.9 nanoid-3.3.11.tgz Transitive N/A*
CVE-2026-67213 Medium 5.9 nanoid-3.3.11.tgz Transitive N/A*
CVE-2026-34043 Medium 5.9 serialize-javascript-6.0.2.tgz Transitive N/A*
CVE-2026-69192 Medium 5.8 ip-address-10.1.0.tgz Transitive N/A*
CVE-2026-54490 Medium 5.8 websocket-driver-0.7.4.tgz Transitive N/A*
CVE-2026-42338 Medium 5.4 ip-address-10.1.0.tgz Transitive 3.10.0
CVE-2026-9595 Medium 5.3 webpack-dev-server-5.2.3.tgz Transitive N/A*
CVE-2026-8723 Medium 5.3 qs-6.14.1.tgz Transitive 3.10.0
CVE-2026-85062 Medium 5.3 colord-2.9.3.tgz Transitive N/A*
CVE-2026-82417 Medium 5.3 qs-6.14.1.tgz Transitive N/A*
CVE-2026-69153 Medium 5.3 postcss-8.5.6.tgz Transitive N/A*
CVE-2026-6402 Medium 5.3 webpack-dev-server-5.2.3.tgz Transitive 3.10.0
CVE-2026-59875 Medium 5.3 tar-7.5.6.tgz Transitive 3.10.0
CVE-2026-59871 Medium 5.3 tar-7.5.6.tgz Transitive 3.10.0
CVE-2026-55602 Medium 5.3 http-proxy-middleware-2.0.9.tgz Transitive N/A*
CVE-2026-53550 Medium 5.3 detected in multiple dependencies Transitive N/A*
CVE-2026-48038 Medium 5.3 joi-17.13.3.tgz Transitive N/A*
CVE-2026-40895 Medium 5.3 follow-redirects-1.15.11.tgz Transitive 3.10.0
CVE-2026-33672 Medium 5.3 detected in multiple dependencies Transitive N/A*
CVE-2026-14631 Medium 5.3 webpack-dev-server-5.2.3.tgz Transitive N/A*
CVE-2026-14620 Medium 4.7 webpack-dev-server-5.2.3.tgz Transitive N/A*
CVE-2026-45736 Medium 4.4 ws-8.19.0.tgz Transitive 3.10.0
CVE-2026-9358 Medium 4.3 detected in multiple dependencies Transitive N/A*
CVE-2026-84368 Low 3.7 joi-17.13.3.tgz Transitive N/A*
CVE-2026-84367 Low 3.7 joi-17.13.3.tgz Transitive N/A*
CVE-2026-2391 Low 3.7 qs-6.14.1.tgz Transitive 3.10.0
CVE-2026-12590 Low 3.7 body-parser-1.20.4.tgz Transitive N/A*
CVE-2026-49356 Low 3.2 core-7.28.6.tgz Transitive N/A*
CVE-2025-69873 Low 2.9 detected in multiple dependencies Transitive N/A*

*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

Partial details (16 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.

CVE-2026-41907

Vulnerable Library - uuid-8.3.2.tgz

RFC4122 (v1, v4, and v5) UUIDs

Library home page: https://registry.npmjs.org/uuid/-/uuid-8.3.2.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/uuid-npm-8.3.2-eca0baba53-10c0.zip

Dependency Hierarchy:

  • core-3.9.2.tgz (Root Library)
    • webpack-dev-server-5.2.3.tgz
      • sockjs-0.3.24.tgz
        • uuid-8.3.2.tgz (Vulnerable Library)

Found in base branch: main

Vulnerability Details

uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.

Publish Date: 2026年04月24日

URL: CVE-2026-41907

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-w5hq-g745-h8pq

Release Date: 2026年04月24日

Fix Resolution: https://github.com/uuidjs/uuid.git - v11.1.1,https://github.com/uuidjs/uuid.git - v13.0.1,https://github.com/uuidjs/uuid.git - v12.0.1

Step up your Open Source Security Game with Mend here

CVE-2026-59873

Vulnerable Library - tar-7.5.6.tgz

tar for node

Library home page: https://registry.npmjs.org/tar/-/tar-7.5.6.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/tar-npm-7.5.6-955ec951c2-10c0.zip

Dependency Hierarchy:

  • core-3.9.2.tgz (Root Library)
    • chokidar-3.6.0.tgz
      • fsevents-2.3.3.tgz
        • node-gyp-12.1.0.tgz
          • tar-7.5.6.tgz (Vulnerable Library)

Found in base branch: main

Vulnerability Details

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.

Publish Date: 2026年07月08日

URL: CVE-2026-59873

CVSS 3 Score Details (8.6)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-23hp-3jrh-7fpw

Release Date: 2026年07月08日

Fix Resolution (tar): 7.5.19

Direct dependency fix Resolution (@⁠docusaurus/core): 3.10.0

Step up your Open Source Security Game with Mend here

CVE-2026-54466

Vulnerable Library - websocket-driver-0.7.4.tgz

WebSocket protocol handler with pluggable I/O

Library home page: https://registry.npmjs.org/websocket-driver/-/websocket-driver-0.7.4.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/websocket-driver-npm-0.7.4-a72739da70-10c0.zip

Dependency Hierarchy:

  • core-3.9.2.tgz (Root Library)
    • webpack-dev-server-5.2.3.tgz
      • sockjs-0.3.24.tgz
        • websocket-driver-0.7.4.tgz (Vulnerable Library)

Found in base branch: main

Vulnerability Details

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values 0x80 or above, a client can make the server parse these bytes into an ever-growing integer in lib/websocket/driver/draft75.js; because JavaScript numbers are 64-bit floating point values, this number will eventually lose precision and lead to the subsequent payload being parsed incorrectly. This issue is fixed in version 0.7.5.

Publish Date: 2026年07月17日

URL: CVE-2026-54466

CVSS 3 Score Details (8.6)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-xv26-6w52-cph6

Release Date: 2026年07月15日

Fix Resolution: websocket-driver - 0.7.5

Step up your Open Source Security Game with Mend here

CVE-2026-25547

Vulnerable Library - brace-expansion-5.0.0.tgz

Brace expansion as known from sh/bash

Library home page: https://registry.npmjs.org/@⁠isaacs/brace-expansion/-/brace-expansion-5.0.0.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/@⁠isaacs-brace-expansion-npm-5.0.0-754d3cb3f5-10c0.zip

Dependency Hierarchy:

  • core-3.9.2.tgz (Root Library)
    • chokidar-3.6.0.tgz
      • fsevents-2.3.3.tgz
        • node-gyp-12.1.0.tgz
          • make-fetch-happen-15.0.3.tgz
            • cacache-20.0.3.tgz
              • glob-13.0.0.tgz
                • minimatch-10.1.1.tgz
                  • brace-expansion-5.0.0.tgz (Vulnerable Library)

Found in base branch: main

Vulnerability Details

@⁠isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @⁠isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1.

Publish Date: 2026年02月04日

URL: CVE-2026-25547

CVSS 3 Score Details (8.6)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026年02月04日

Fix Resolution: https://github.com/isaacs/brace-expansion.git - v5.0.1

Step up your Open Source Security Game with Mend here

CVE-2026-53632

Vulnerable Library - launch-editor-2.12.0.tgz

launch editor from node.js

Library home page: https://registry.npmjs.org/launch-editor/-/launch-editor-2.12.0.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/launch-editor-npm-2.12.0-7298d11419-10c0.zip

Dependency Hierarchy:

  • core-3.9.2.tgz (Root Library)
    • webpack-dev-server-5.2.3.tgz
      • launch-editor-2.12.0.tgz (Vulnerable Library)

Found in base branch: main

Vulnerability Details

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user’s NTLMv2 password hash to be leaked to an attacker-controlled SMB server. This can result in credential compromise through offline hash cracking. This vulnerability is fixed in 2.14.1.

Publish Date: 2026年06月22日

URL: CVE-2026-53632

CVSS 3 Score Details (8.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026年06月15日

Fix Resolution: https://github.com/vitejs/vite.git - v8.0.16,https://github.com/vitejs/vite.git - v6.4.3,https://github.com/vitejs/launch-editor.git - v2.14.1,https://github.com/vitejs/vite.git - v7.3.5

Step up your Open Source Security Game with Mend here

CVE-2026-84370

Vulnerable Library - svgo-3.3.2.tgz

Library home page: https://registry.npmjs.org/svgo/-/svgo-3.3.2.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/svgo-npm-3.3.2-69e1d32944-10c0.zip

Dependency Hierarchy:

  • core-3.9.2.tgz (Root Library)
    • bundler-3.9.2.tgz
      • cssnano-6.1.2.tgz
        • cssnano-preset-default-6.1.2.tgz
          • postcss-svgo-6.0.3.tgz
            • svgo-3.3.2.tgz (Vulnerable Library)

Found in base branch: main

Vulnerability Details

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions 2 and 3, incompletely filters executable links in plugins/removeScripts.js and lib/svgo/tools.js. The plugin does not recognize namespace-prefixed SVG anchor elements such as svg:a with href or namespaced *:href values, and it does not remove ASCII tab, line-feed, or carriage-return characters before checking URL schemes. Browsers remove those characters before parsing a scheme, allowing an executable link to pass the plugin's check. When an application processes attacker-controlled SVG input and serves the result in an active browser context, a victim who activates the surviving link can execute script in the SVG's origin, expose data, modify content, or perform actions as the victim. This issue is fixed in versions 2.8.4, 3.3.5, and 4.1.0.

Publish Date: 2026年09月01日

URL: CVE-2026-84370

CVSS 3 Score Details (8.2)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: Low
    • Availability Impact: None
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-w27v-7q3p-w38r

Release Date: 2026年09月01日

Fix Resolution: svgo - 4.1.0,svgo - 3.3.5,svgo - 2.8.4,https://github.com/svg/svgo.git - v3.3.5,https://github.com/svg/svgo.git - v2.8.4,https://github.com/svg/svgo.git - v4.1.0

Step up your Open Source Security Game with Mend here

CVE-2026-73650

Vulnerable Library - svgo-3.3.2.tgz

Library home page: https://registry.npmjs.org/svgo/-/svgo-3.3.2.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/svgo-npm-3.3.2-69e1d32944-10c0.zip

Dependency Hierarchy:

  • core-3.9.2.tgz (Root Library)
    • bundler-3.9.2.tgz
      • cssnano-6.1.2.tgz
        • cssnano-preset-default-6.1.2.tgz
          • postcss-svgo-6.0.3.tgz
            • svgo-3.3.2.tgz (Vulnerable Library)

Found in base branch: main

Vulnerability Details

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can leave executable content in optimized SVGs because it does not remove namespaced or prefixed script elements such as "svg:script" (svg:script) and, in versions 3 and 4, matches JavaScript URIs case sensitively. Applications that process untrusted SVG input with this plugin enabled and serve the result can allow scripts to execute when another user opens the SVG, exposing local storage or cookies. This issue is fixed in versions 2.8.3, 3.3.4, and 4.0.2.
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2026年08月13日

URL: CVE-2026-73650

CVSS 3 Score Details (8.2)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: Low
    • Availability Impact: None
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026年08月13日

Fix Resolution: https://github.com/svg/svgo.git - v3.3.4,https://github.com/svg/svgo.git - v4.0.2

Step up your Open Source Security Game with Mend here

CVE-2026-44728

Vulnerable Library - plugin-transform-modules-systemjs-7.28.5.tgz

This plugin transforms ES2015 modules to SystemJS

Library home page: https://registry.npmjs.org/@⁠babel/plugin-transform-modules-systemjs/-/plugin-transform-modules-systemjs-7.28.5.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/@⁠babel-plugin-transform-modules-systemjs-npm-7.28.5-1fe3e218f1-10c0.zip

Dependency Hierarchy:

  • core-3.9.2.tgz (Root Library)
    • babel-3.9.2.tgz
      • preset-env-7.28.6.tgz
        • plugin-transform-modules-systemjs-7.28.5.tgz (Vulnerable Library)

Found in base branch: main

Vulnerability Details

Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13.

Publish Date: 2026年05月26日

URL: CVE-2026-44728

CVSS 3 Score Details (8.2)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-fv7c-fp4j-7gwp

Release Date: 2026年05月09日

Fix Resolution (@⁠babel/plugin-transform-modules-systemjs): 7.29.4

Direct dependency fix Resolution (@⁠docusaurus/core): 3.10.0

Step up your Open Source Security Game with Mend here

CVE-2026-24842

Vulnerable Library - tar-7.5.6.tgz

tar for node

Library home page: https://registry.npmjs.org/tar/-/tar-7.5.6.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/tar-npm-7.5.6-955ec951c2-10c0.zip

Dependency Hierarchy:

  • core-3.9.2.tgz (Root Library)
    • chokidar-3.6.0.tgz
      • fsevents-2.3.3.tgz
        • node-gyp-12.1.0.tgz
          • tar-7.5.6.tgz (Vulnerable Library)

Found in base branch: main

Vulnerability Details

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.

Publish Date: 2026年01月28日

URL: CVE-2026-24842

CVSS 3 Score Details (8.2)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: Low
    • Availability Impact: None
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026年01月28日

Fix Resolution (tar): 7.5.7

Direct dependency fix Resolution (@⁠docusaurus/core): 3.10.0

Step up your Open Source Security Game with Mend here

CVE-2026-9277

Vulnerable Library - shell-quote-1.8.3.tgz

quote and parse shell commands

Library home page: https://registry.npmjs.org/shell-quote/-/shell-quote-1.8.3.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/shell-quote-npm-1.8.3-b29f851134-10c0.zip

Dependency Hierarchy:

  • core-3.9.2.tgz (Root Library)
    • webpack-dev-server-5.2.3.tgz
      • launch-editor-2.12.0.tgz
        • shell-quote-1.8.3.tgz (Vulnerable Library)

Found in base branch: main

Vulnerability Details

shell-quote's "quote()" function did not validate object-token inputs against the operator model used by "parse()". The ".op" field was backslash-escaped character by character using "/(.)/g", which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line terminator in ".op" therefore passed through unescaped into the output; POSIX shells treat a literal newline as a command separator, so any content after it would execute as a second command. The vulnerable code path is reachable in two ways: (1) direct construction of "{ op: '...\n...' }" from external input, and (2) via "parse(cmd, envFn)" when "envFn" returns object tokens whose ".op" is attacker-influenced. Both are documented API surface. Fixed by replacing the per-character escape with strict shape validation: ".op" must match the parser's control-operator allowlist; "{ op: 'glob', pattern }" validates "pattern" and forbids line terminators; "{ comment }" validates "comment" and forbids line terminators; any other object shape throws "TypeError".

Publish Date: 2026年05月22日

URL: CVE-2026-9277

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026年05月22日

Fix Resolution (shell-quote): 1.8.4

Direct dependency fix Resolution (@⁠docusaurus/core): 3.10.0

Step up your Open Source Security Game with Mend here

CVE-2026-4800

Vulnerable Library - lodash-4.17.23.tgz

Lodash modular utilities.

Library home page: https://registry.npmjs.org/lodash/-/lodash-4.17.23.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/lodash-npm-4.17.23-50bdb1c01a-10c0.zip

Dependency Hierarchy:

  • core-3.9.2.tgz (Root Library)
    • lodash-4.17.23.tgz (Vulnerable Library)

Found in base branch: main

Vulnerability Details

Impact:
The fix for CVE-2021-23337 (GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.
When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.
Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function().
Patches:
Users should upgrade to version 4.18.0.
Workarounds:
Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

Publish Date: 2026年03月31日

URL: CVE-2026-4800

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-r5fr-rjxr-66jc

Release Date: 2026年03月31日

Fix Resolution: lodash-amd - 4.18.0,lodash.template - 4.18.0,lodash-es - 4.18.0,lodash - 4.18.0

Step up your Open Source Security Game with Mend here

CVE-2026-84375

Vulnerable Libraries - js-yaml-3.14.2.tgz, js-yaml-4.1.1.tgz

js-yaml-3.14.2.tgz

YAML 1.2 parser and serializer

Library home page: https://registry.npmjs.org/js-yaml/-/js-yaml-3.14.2.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/js-yaml-npm-3.14.2-debd9d20c3-10c0.zip

Dependency Hierarchy:

  • core-3.9.2.tgz (Root Library)
    • utils-3.9.2.tgz
      • gray-matter-4.0.3.tgz
        • js-yaml-3.14.2.tgz (Vulnerable Library)

js-yaml-4.1.1.tgz

YAML 1.2 parser and serializer

Library home page: https://registry.npmjs.org/js-yaml/-/js-yaml-4.1.1.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/js-yaml-npm-4.1.1-86ec786790-10c0.zip

Dependency Hierarchy:

  • core-3.9.2.tgz (Root Library)
    • bundler-3.9.2.tgz
      • postcss-loader-7.3.4.tgz
        • cosmiconfig-8.3.6.tgz
          • js-yaml-4.1.1.tgz (Vulnerable Library)

Found in base branch: main

Vulnerability Details

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias a large sequence of empty mappings into many merge targets, causing O(N * K) processing while totalMergeKeys remains unchanged and the configured resource limit is never reached. A relatively small YAML document can therefore cause prolonged CPU consumption in applications that parse untrusted YAML, and merge processing is enabled by default on these release lines. This issue is fixed in versions 3.15.2 and 4.3.2.

Publish Date: 2026年09月01日

URL: CVE-2026-84375

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-2883-xcg3-v3hh

Release Date: 2026年09月01日

Fix Resolution: js-yaml - 3.15.2,js-yaml - 4.3.2,js-yaml - 4.3.2,js-yaml - 3.15.2,https://github.com/nodeca/js-yaml.git - 4.3.2,https://github.com/nodeca/js-yaml.git - 3.15.2

Step up your Open Source Security Game with Mend here

CVE-2026-84292

Vulnerable Library - fast-uri-3.1.0.tgz

Dependency-free RFC 3986 URI toolbox

Library home page: https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.0.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/fast-uri-npm-3.1.0-57fa0b3f3c-10c0.zip

Dependency Hierarchy:

  • core-3.9.2.tgz (Root Library)
    • webpack-dev-server-5.2.3.tgz
      • schema-utils-4.3.3.tgz
        • ajv-formats-2.1.1.tgz
          • ajv-8.17.1.tgz
            • fast-uri-3.1.0.tgz (Vulnerable Library)

Found in base branch: main

Vulnerability Details

fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node's URL read the result back as the attacker's host with no error, so re-validating the built URI does not catch it. This affects applications that build URIs from parts and assign untrusted data to the port component through the serialize, normalize, or equal functions in their object forms. The issue affects fast-uri versions before 2.4.6, from 3.0.0 before 3.1.7, and from 4.0.0 before 4.1.4. It is fixed in 2.4.6, 3.1.7, and 4.1.4, where recomposeAuthority rejects any port that is not a digit sequence per RFC 3986.

Publish Date: 2026年09月02日

URL: CVE-2026-84292

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-qw65-cvwx-89v3

Release Date: 2026年09月02日

Fix Resolution: fast-uri - 3.1.7,fast-uri - 2.4.6,fast-uri - 4.1.4

Step up your Open Source Security Game with Mend here

CVE-2026-76172

Vulnerable Library - fast-uri-3.1.0.tgz

Dependency-free RFC 3986 URI toolbox

Library home page: https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.0.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/fast-uri-npm-3.1.0-57fa0b3f3c-10c0.zip

Dependency Hierarchy:

  • core-3.9.2.tgz (Root Library)
    • webpack-dev-server-5.2.3.tgz
      • schema-utils-4.3.3.tgz
        • ajv-formats-2.1.1.tgz
          • ajv-8.17.1.tgz
            • fast-uri-3.1.0.tgz (Vulnerable Library)

Found in base branch: main

Vulnerability Details

fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host component which is re-escaped. As a result an input whose scheme carries percent-encoded slashes parses as a scheme with no authority, so the parsed host and error are both undefined, yet resolving or normalizing that same input emits a network-path reference whose authority is attacker-chosen and re-parses to that host. An application that allowlists on the parsed host, or treats a reference with no authority as safe to resolve against its base, gets the opposite of what it checked, giving an off-site redirect, server-side request forgery, or address-policy bypass. The legacy decoder also expands non-standard escape forms, widening the issue past upstream filters, and control characters in the scheme can reach the output as raw carriage return and line feed. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which reject a scheme that is not valid after decoding. Users should upgrade to a patched version.

Publish Date: 2026年08月24日

URL: CVE-2026-76172

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-jqff-g426-hqxp

Release Date: 2026年08月24日

Fix Resolution: fast-uri - 2.4.5,fast-uri - 3.1.6,fast-uri - 4.1.3

Step up your Open Source Security Game with Mend here

CVE-2026-75975

Vulnerable Library - fast-uri-3.1.0.tgz

Dependency-free RFC 3986 URI toolbox

Library home page: https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.0.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/fast-uri-npm-3.1.0-57fa0b3f3c-10c0.zip

Dependency Hierarchy:

  • core-3.9.2.tgz (Root Library)
    • webpack-dev-server-5.2.3.tgz
      • schema-utils-4.3.3.tgz
        • ajv-formats-2.1.1.tgz
          • ajv-8.17.1.tgz
            • fast-uri-3.1.0.tgz (Vulnerable Library)

Found in base branch: main

Vulnerability Details

fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 destination. For example, a bracketed literal with invalid trailing characters is normalized to the unspecified address, which a Node HTTP client then connects to a local service over loopback, and other malformed literals collapse to private-range addresses. No error is set on the parsed result, so an application checking the error field cannot detect the rewrite. An application that normalizes untrusted URLs before outbound requests, redirects, proxy routing, or address-policy enforcement can be redirected to a local or private IPv6 target, giving a server-side request forgery and address-policy bypass primitive. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which validate bracketed IP literals against the full grammar and mark malformed literals as authority errors. Users should upgrade to a patched version.

Publish Date: 2026年08月24日

URL: CVE-2026-75975

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-f65p-4m7j-42xc

Release Date: 2026年08月24日

Fix Resolution: fast-uri - 2.4.5,fast-uri - 4.1.3,fast-uri - 3.1.6

Step up your Open Source Security Game with Mend here

CVE-2026-73646

Vulnerable Library - postcss-8.5.6.tgz

Tool for transforming styles with JS plugins

Library home page: https://registry.npmjs.org/postcss/-/postcss-8.5.6.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/postcss-npm-8.5.6-e7f126c6f3-10c0.zip

Dependency Hierarchy:

  • core-3.9.2.tgz (Root Library)
    • bundler-3.9.2.tgz
      • postcss-8.5.6.tgz (Vulnerable Library)

Found in base branch: main

Vulnerability Details

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values to join(dirname(opts.from), annotation), and loadFile() permits traversed or absolute .map paths, allowing untrusted CSS processed without map: false to disclose sourcesContent from arbitrary reachable .map files through result.map. This issue is fixed in version 8.5.18.

Publish Date: 2026年08月17日

URL: CVE-2026-73646

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026年08月13日

Fix Resolution: https://github.com/postcss/postcss.git - 8.5.18

Step up your Open Source Security Game with Mend here

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      AltStyle によって変換されたページ (->オリジナル) /