-
Notifications
You must be signed in to change notification settings - Fork 2
core-3.9.2.tgz: 79 vulnerabilities (highest severity is: 9.8) #303
Description
Vulnerable Library - core-3.9.2.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/fast-uri-npm-3.1.0-57fa0b3f3c-10c0.zip
Vulnerabilities
| Vulnerability | Severity | CVSS | Dependency | Type | Fixed in (core version) | Remediation Possible** |
|---|---|---|---|---|---|---|
| CVE-2026-41907 | Critical | 9.8 | uuid-8.3.2.tgz | Transitive | N/A* | ❌ |
| CVE-2026-59873 | High | 8.6 | tar-7.5.6.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-54466 | High | 8.6 | websocket-driver-0.7.4.tgz | Transitive | N/A* | ❌ |
| CVE-2026-25547 | High | 8.6 | brace-expansion-5.0.0.tgz | Transitive | N/A* | ❌ |
| CVE-2026-53632 | High | 8.3 | launch-editor-2.12.0.tgz | Transitive | N/A* | ❌ |
| CVE-2026-84370 | High | 8.2 | svgo-3.3.2.tgz | Transitive | N/A* | ❌ |
| CVE-2026-73650 | High | 8.2 | svgo-3.3.2.tgz | Transitive | N/A* | ❌ |
| CVE-2026-44728 | High | 8.2 | plugin-transform-modules-systemjs-7.28.5.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-24842 | High | 8.2 | tar-7.5.6.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-9277 | High | 8.1 | shell-quote-1.8.3.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-4800 | High | 8.1 | lodash-4.17.23.tgz | Transitive | N/A* | ❌ |
| CVE-2026-84375 | High | 7.5 | detected in multiple dependencies | Transitive | N/A* | ❌ |
| CVE-2026-84292 | High | 7.5 | fast-uri-3.1.0.tgz | Transitive | N/A* | ❌ |
| CVE-2026-76172 | High | 7.5 | fast-uri-3.1.0.tgz | Transitive | N/A* | ❌ |
| CVE-2026-75975 | High | 7.5 | fast-uri-3.1.0.tgz | Transitive | N/A* | ❌ |
| CVE-2026-73646 | High | 7.5 | postcss-8.5.6.tgz | Transitive | N/A* | ❌ |
| CVE-2026-73566 | High | 7.5 | tar-7.5.6.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-73089 | High | 7.5 | browserslist-4.28.1.tgz | Transitive | N/A* | ❌ |
| CVE-2026-73088 | High | 7.5 | browserslist-4.28.1.tgz | Transitive | N/A* | ❌ |
| CVE-2026-69152 | High | 7.5 | brace-expansion-1.1.12.tgz | Transitive | N/A* | ❌ |
| CVE-2026-6322 | High | 7.5 | fast-uri-3.1.0.tgz | Transitive | N/A* | ❌ |
| CVE-2026-6321 | High | 7.5 | fast-uri-3.1.0.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-59874 | High | 7.5 | tar-7.5.6.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-59869 | High | 7.5 | detected in multiple dependencies | Transitive | 3.10.0 | ❌ |
| CVE-2026-48779 | High | 7.5 | detected in multiple dependencies | Transitive | N/A* | ❌ |
| CVE-2026-4867 | High | 7.5 | path-to-regexp-0.1.12.tgz | Transitive | N/A* | ❌ |
| CVE-2026-45819 | High | 7.5 | baseline-browser-mapping-2.9.17.tgz | Transitive | N/A* | ❌ |
| CVE-2026-45623 | High | 7.5 | postcss-8.5.6.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-33671 | High | 7.5 | detected in multiple dependencies | Transitive | N/A* | ❌ |
| CVE-2026-29074 | High | 7.5 | svgo-3.3.2.tgz | Transitive | N/A* | ❌ |
| CVE-2026-27904 | High | 7.5 | detected in multiple dependencies | Transitive | 3.10.0 | ❌ |
| CVE-2026-27903 | High | 7.5 | detected in multiple dependencies | Transitive | N/A* | ❌ |
| CVE-2026-26996 | High | 7.5 | detected in multiple dependencies | Transitive | N/A* | ❌ |
| CVE-2026-18446 | High | 7.5 | fast-uri-3.1.0.tgz | Transitive | N/A* | ❌ |
| CVE-2026-16221 | High | 7.5 | fast-uri-3.1.0.tgz | Transitive | N/A* | ❌ |
| CVE-2026-14257 | High | 7.5 | brace-expansion-1.1.12.tgz | Transitive | N/A* | ❌ |
| CVE-2026-13676 | High | 7.5 | fast-uri-3.1.0.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-13311 | High | 7.5 | shell-quote-1.8.3.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-13149 | High | 7.5 | brace-expansion-1.1.12.tgz | Transitive | N/A* | ❌ |
| CVE-2025-71330 | High | 7.5 | image-size-2.0.2.tgz | Transitive | N/A* | ❌ |
| CVE-2025-71329 | High | 7.5 | image-size-2.0.2.tgz | Transitive | N/A* | ❌ |
| CVE-2026-73086 | High | 7.4 | nanoid-3.3.11.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-31802 | High | 7.1 | tar-7.5.6.tgz | Transitive | N/A* | ❌ |
| CVE-2026-29786 | High | 7.1 | tar-7.5.6.tgz | Transitive | N/A* | ❌ |
| CVE-2026-26960 | High | 7.1 | tar-7.5.6.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-33750 | Medium | 6.5 | brace-expansion-1.1.12.tgz | Transitive | N/A* | ❌ |
| CVE-2026-2950 | Medium | 6.5 | lodash-4.17.23.tgz | Transitive | N/A* | ❌ |
| CVE-2026-53655 | Medium | 6.2 | tar-7.5.6.tgz | Transitive | N/A* | ❌ |
| CVE-2026-84369 | Medium | 6.1 | svgo-3.3.2.tgz | Transitive | N/A* | ❌ |
| CVE-2026-41305 | Medium | 6.1 | postcss-8.5.6.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-67214 | Medium | 5.9 | nanoid-3.3.11.tgz | Transitive | N/A* | ❌ |
| CVE-2026-67213 | Medium | 5.9 | nanoid-3.3.11.tgz | Transitive | N/A* | ❌ |
| CVE-2026-34043 | Medium | 5.9 | serialize-javascript-6.0.2.tgz | Transitive | N/A* | ❌ |
| CVE-2026-69192 | Medium | 5.8 | ip-address-10.1.0.tgz | Transitive | N/A* | ❌ |
| CVE-2026-54490 | Medium | 5.8 | websocket-driver-0.7.4.tgz | Transitive | N/A* | ❌ |
| CVE-2026-42338 | Medium | 5.4 | ip-address-10.1.0.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-9595 | Medium | 5.3 | webpack-dev-server-5.2.3.tgz | Transitive | N/A* | ❌ |
| CVE-2026-8723 | Medium | 5.3 | qs-6.14.1.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-85062 | Medium | 5.3 | colord-2.9.3.tgz | Transitive | N/A* | ❌ |
| CVE-2026-82417 | Medium | 5.3 | qs-6.14.1.tgz | Transitive | N/A* | ❌ |
| CVE-2026-69153 | Medium | 5.3 | postcss-8.5.6.tgz | Transitive | N/A* | ❌ |
| CVE-2026-6402 | Medium | 5.3 | webpack-dev-server-5.2.3.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-59875 | Medium | 5.3 | tar-7.5.6.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-59871 | Medium | 5.3 | tar-7.5.6.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-55602 | Medium | 5.3 | http-proxy-middleware-2.0.9.tgz | Transitive | N/A* | ❌ |
| CVE-2026-53550 | Medium | 5.3 | detected in multiple dependencies | Transitive | N/A* | ❌ |
| CVE-2026-48038 | Medium | 5.3 | joi-17.13.3.tgz | Transitive | N/A* | ❌ |
| CVE-2026-40895 | Medium | 5.3 | follow-redirects-1.15.11.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-33672 | Medium | 5.3 | detected in multiple dependencies | Transitive | N/A* | ❌ |
| CVE-2026-14631 | Medium | 5.3 | webpack-dev-server-5.2.3.tgz | Transitive | N/A* | ❌ |
| CVE-2026-14620 | Medium | 4.7 | webpack-dev-server-5.2.3.tgz | Transitive | N/A* | ❌ |
| CVE-2026-45736 | Medium | 4.4 | ws-8.19.0.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-9358 | Medium | 4.3 | detected in multiple dependencies | Transitive | N/A* | ❌ |
| CVE-2026-84368 | Low | 3.7 | joi-17.13.3.tgz | Transitive | N/A* | ❌ |
| CVE-2026-84367 | Low | 3.7 | joi-17.13.3.tgz | Transitive | N/A* | ❌ |
| CVE-2026-2391 | Low | 3.7 | qs-6.14.1.tgz | Transitive | 3.10.0 | ❌ |
| CVE-2026-12590 | Low | 3.7 | body-parser-1.20.4.tgz | Transitive | N/A* | ❌ |
| CVE-2026-49356 | Low | 3.2 | core-7.28.6.tgz | Transitive | N/A* | ❌ |
| CVE-2025-69873 | Low | 2.9 | detected in multiple dependencies | Transitive | N/A* | ❌ |
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Partial details (16 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.
CVE-2026-41907
Vulnerable Library - uuid-8.3.2.tgz
RFC4122 (v1, v4, and v5) UUIDs
Library home page: https://registry.npmjs.org/uuid/-/uuid-8.3.2.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/uuid-npm-8.3.2-eca0baba53-10c0.zip
Dependency Hierarchy:
- core-3.9.2.tgz (Root Library)
- webpack-dev-server-5.2.3.tgz
- sockjs-0.3.24.tgz
- ❌ uuid-8.3.2.tgz (Vulnerable Library)
- sockjs-0.3.24.tgz
- webpack-dev-server-5.2.3.tgz
Found in base branch: main
Vulnerability Details
uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.
Publish Date: 2026年04月24日
URL: CVE-2026-41907
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Origin: GHSA-w5hq-g745-h8pq
Release Date: 2026年04月24日
Fix Resolution: https://github.com/uuidjs/uuid.git - v11.1.1,https://github.com/uuidjs/uuid.git - v13.0.1,https://github.com/uuidjs/uuid.git - v12.0.1
Step up your Open Source Security Game with Mend here
CVE-2026-59873
Vulnerable Library - tar-7.5.6.tgz
tar for node
Library home page: https://registry.npmjs.org/tar/-/tar-7.5.6.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/tar-npm-7.5.6-955ec951c2-10c0.zip
Dependency Hierarchy:
- core-3.9.2.tgz (Root Library)
- chokidar-3.6.0.tgz
- fsevents-2.3.3.tgz
- node-gyp-12.1.0.tgz
- ❌ tar-7.5.6.tgz (Vulnerable Library)
- node-gyp-12.1.0.tgz
- fsevents-2.3.3.tgz
- chokidar-3.6.0.tgz
Found in base branch: main
Vulnerability Details
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Publish Date: 2026年07月08日
URL: CVE-2026-59873
CVSS 3 Score Details (8.6)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Origin: GHSA-23hp-3jrh-7fpw
Release Date: 2026年07月08日
Fix Resolution (tar): 7.5.19
Direct dependency fix Resolution (@docusaurus/core): 3.10.0
Step up your Open Source Security Game with Mend here
CVE-2026-54466
Vulnerable Library - websocket-driver-0.7.4.tgz
WebSocket protocol handler with pluggable I/O
Library home page: https://registry.npmjs.org/websocket-driver/-/websocket-driver-0.7.4.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/websocket-driver-npm-0.7.4-a72739da70-10c0.zip
Dependency Hierarchy:
- core-3.9.2.tgz (Root Library)
- webpack-dev-server-5.2.3.tgz
- sockjs-0.3.24.tgz
- ❌ websocket-driver-0.7.4.tgz (Vulnerable Library)
- sockjs-0.3.24.tgz
- webpack-dev-server-5.2.3.tgz
Found in base branch: main
Vulnerability Details
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values 0x80 or above, a client can make the server parse these bytes into an ever-growing integer in lib/websocket/driver/draft75.js; because JavaScript numbers are 64-bit floating point values, this number will eventually lose precision and lead to the subsequent payload being parsed incorrectly. This issue is fixed in version 0.7.5.
Publish Date: 2026年07月17日
URL: CVE-2026-54466
CVSS 3 Score Details (8.6)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: GHSA-xv26-6w52-cph6
Release Date: 2026年07月15日
Fix Resolution: websocket-driver - 0.7.5
Step up your Open Source Security Game with Mend here
CVE-2026-25547
Vulnerable Library - brace-expansion-5.0.0.tgz
Brace expansion as known from sh/bash
Library home page: https://registry.npmjs.org/@isaacs/brace-expansion/-/brace-expansion-5.0.0.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/@isaacs-brace-expansion-npm-5.0.0-754d3cb3f5-10c0.zip
Dependency Hierarchy:
- core-3.9.2.tgz (Root Library)
- chokidar-3.6.0.tgz
- fsevents-2.3.3.tgz
- node-gyp-12.1.0.tgz
- make-fetch-happen-15.0.3.tgz
- cacache-20.0.3.tgz
- glob-13.0.0.tgz
- minimatch-10.1.1.tgz
- ❌ brace-expansion-5.0.0.tgz (Vulnerable Library)
- minimatch-10.1.1.tgz
- glob-13.0.0.tgz
- cacache-20.0.3.tgz
- make-fetch-happen-15.0.3.tgz
- node-gyp-12.1.0.tgz
- fsevents-2.3.3.tgz
- chokidar-3.6.0.tgz
Found in base branch: main
Vulnerability Details
@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1.
Publish Date: 2026年02月04日
URL: CVE-2026-25547
CVSS 3 Score Details (8.6)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Release Date: 2026年02月04日
Fix Resolution: https://github.com/isaacs/brace-expansion.git - v5.0.1
Step up your Open Source Security Game with Mend here
CVE-2026-53632
Vulnerable Library - launch-editor-2.12.0.tgz
launch editor from node.js
Library home page: https://registry.npmjs.org/launch-editor/-/launch-editor-2.12.0.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/launch-editor-npm-2.12.0-7298d11419-10c0.zip
Dependency Hierarchy:
- core-3.9.2.tgz (Root Library)
- webpack-dev-server-5.2.3.tgz
- ❌ launch-editor-2.12.0.tgz (Vulnerable Library)
- webpack-dev-server-5.2.3.tgz
Found in base branch: main
Vulnerability Details
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user’s NTLMv2 password hash to be leaked to an attacker-controlled SMB server. This can result in credential compromise through offline hash cracking. This vulnerability is fixed in 2.14.1.
Publish Date: 2026年06月22日
URL: CVE-2026-53632
CVSS 3 Score Details (8.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: Required
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Release Date: 2026年06月15日
Fix Resolution: https://github.com/vitejs/vite.git - v8.0.16,https://github.com/vitejs/vite.git - v6.4.3,https://github.com/vitejs/launch-editor.git - v2.14.1,https://github.com/vitejs/vite.git - v7.3.5
Step up your Open Source Security Game with Mend here
CVE-2026-84370
Vulnerable Library - svgo-3.3.2.tgz
Library home page: https://registry.npmjs.org/svgo/-/svgo-3.3.2.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/svgo-npm-3.3.2-69e1d32944-10c0.zip
Dependency Hierarchy:
- core-3.9.2.tgz (Root Library)
- bundler-3.9.2.tgz
- cssnano-6.1.2.tgz
- cssnano-preset-default-6.1.2.tgz
- postcss-svgo-6.0.3.tgz
- ❌ svgo-3.3.2.tgz (Vulnerable Library)
- postcss-svgo-6.0.3.tgz
- cssnano-preset-default-6.1.2.tgz
- cssnano-6.1.2.tgz
- bundler-3.9.2.tgz
Found in base branch: main
Vulnerability Details
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions 2 and 3, incompletely filters executable links in plugins/removeScripts.js and lib/svgo/tools.js. The plugin does not recognize namespace-prefixed SVG anchor elements such as svg:a with href or namespaced *:href values, and it does not remove ASCII tab, line-feed, or carriage-return characters before checking URL schemes. Browsers remove those characters before parsing a scheme, allowing an executable link to pass the plugin's check. When an application processes attacker-controlled SVG input and serves the result in an active browser context, a victim who activates the surviving link can execute script in the SVG's origin, expose data, modify content, or perform actions as the victim. This issue is fixed in versions 2.8.4, 3.3.5, and 4.1.0.
Publish Date: 2026年09月01日
URL: CVE-2026-84370
CVSS 3 Score Details (8.2)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: Low
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: GHSA-w27v-7q3p-w38r
Release Date: 2026年09月01日
Fix Resolution: svgo - 4.1.0,svgo - 3.3.5,svgo - 2.8.4,https://github.com/svg/svgo.git - v3.3.5,https://github.com/svg/svgo.git - v2.8.4,https://github.com/svg/svgo.git - v4.1.0
Step up your Open Source Security Game with Mend here
CVE-2026-73650
Vulnerable Library - svgo-3.3.2.tgz
Library home page: https://registry.npmjs.org/svgo/-/svgo-3.3.2.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/svgo-npm-3.3.2-69e1d32944-10c0.zip
Dependency Hierarchy:
- core-3.9.2.tgz (Root Library)
- bundler-3.9.2.tgz
- cssnano-6.1.2.tgz
- cssnano-preset-default-6.1.2.tgz
- postcss-svgo-6.0.3.tgz
- ❌ svgo-3.3.2.tgz (Vulnerable Library)
- postcss-svgo-6.0.3.tgz
- cssnano-preset-default-6.1.2.tgz
- cssnano-6.1.2.tgz
- bundler-3.9.2.tgz
Found in base branch: main
Vulnerability Details
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can leave executable content in optimized SVGs because it does not remove namespaced or prefixed script elements such as "svg:script" (svg:script) and, in versions 3 and 4, matches JavaScript URIs case sensitively. Applications that process untrusted SVG input with this plugin enabled and serve the result can allow scripts to execute when another user opens the SVG, exposing local storage or cookies. This issue is fixed in versions 2.8.3, 3.3.4, and 4.0.2.
Mend Note: The description of this vulnerability differs from MITRE.
Publish Date: 2026年08月13日
URL: CVE-2026-73650
CVSS 3 Score Details (8.2)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: Low
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Release Date: 2026年08月13日
Fix Resolution: https://github.com/svg/svgo.git - v3.3.4,https://github.com/svg/svgo.git - v4.0.2
Step up your Open Source Security Game with Mend here
CVE-2026-44728
Vulnerable Library - plugin-transform-modules-systemjs-7.28.5.tgz
This plugin transforms ES2015 modules to SystemJS
Library home page: https://registry.npmjs.org/@babel/plugin-transform-modules-systemjs/-/plugin-transform-modules-systemjs-7.28.5.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/@babel-plugin-transform-modules-systemjs-npm-7.28.5-1fe3e218f1-10c0.zip
Dependency Hierarchy:
- core-3.9.2.tgz (Root Library)
- babel-3.9.2.tgz
- preset-env-7.28.6.tgz
- ❌ plugin-transform-modules-systemjs-7.28.5.tgz (Vulnerable Library)
- preset-env-7.28.6.tgz
- babel-3.9.2.tgz
Found in base branch: main
Vulnerability Details
Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13.
Publish Date: 2026年05月26日
URL: CVE-2026-44728
CVSS 3 Score Details (8.2)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: Required
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Origin: GHSA-fv7c-fp4j-7gwp
Release Date: 2026年05月09日
Fix Resolution (@babel/plugin-transform-modules-systemjs): 7.29.4
Direct dependency fix Resolution (@docusaurus/core): 3.10.0
Step up your Open Source Security Game with Mend here
CVE-2026-24842
Vulnerable Library - tar-7.5.6.tgz
tar for node
Library home page: https://registry.npmjs.org/tar/-/tar-7.5.6.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/tar-npm-7.5.6-955ec951c2-10c0.zip
Dependency Hierarchy:
- core-3.9.2.tgz (Root Library)
- chokidar-3.6.0.tgz
- fsevents-2.3.3.tgz
- node-gyp-12.1.0.tgz
- ❌ tar-7.5.6.tgz (Vulnerable Library)
- node-gyp-12.1.0.tgz
- fsevents-2.3.3.tgz
- chokidar-3.6.0.tgz
Found in base branch: main
Vulnerability Details
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.
Publish Date: 2026年01月28日
URL: CVE-2026-24842
CVSS 3 Score Details (8.2)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: Low
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Release Date: 2026年01月28日
Fix Resolution (tar): 7.5.7
Direct dependency fix Resolution (@docusaurus/core): 3.10.0
Step up your Open Source Security Game with Mend here
CVE-2026-9277
Vulnerable Library - shell-quote-1.8.3.tgz
quote and parse shell commands
Library home page: https://registry.npmjs.org/shell-quote/-/shell-quote-1.8.3.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/shell-quote-npm-1.8.3-b29f851134-10c0.zip
Dependency Hierarchy:
- core-3.9.2.tgz (Root Library)
- webpack-dev-server-5.2.3.tgz
- launch-editor-2.12.0.tgz
- ❌ shell-quote-1.8.3.tgz (Vulnerable Library)
- launch-editor-2.12.0.tgz
- webpack-dev-server-5.2.3.tgz
Found in base branch: main
Vulnerability Details
shell-quote's "quote()" function did not validate object-token inputs against the operator model used by "parse()". The ".op" field was backslash-escaped character by character using "/(.)/g", which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line terminator in ".op" therefore passed through unescaped into the output; POSIX shells treat a literal newline as a command separator, so any content after it would execute as a second command. The vulnerable code path is reachable in two ways: (1) direct construction of "{ op: '...\n...' }" from external input, and (2) via "parse(cmd, envFn)" when "envFn" returns object tokens whose ".op" is attacker-influenced. Both are documented API surface. Fixed by replacing the per-character escape with strict shape validation: ".op" must match the parser's control-operator allowlist; "{ op: 'glob', pattern }" validates "pattern" and forbids line terminators; "{ comment }" validates "comment" and forbids line terminators; any other object shape throws "TypeError".
Publish Date: 2026年05月22日
URL: CVE-2026-9277
CVSS 3 Score Details (8.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Release Date: 2026年05月22日
Fix Resolution (shell-quote): 1.8.4
Direct dependency fix Resolution (@docusaurus/core): 3.10.0
Step up your Open Source Security Game with Mend here
CVE-2026-4800
Vulnerable Library - lodash-4.17.23.tgz
Lodash modular utilities.
Library home page: https://registry.npmjs.org/lodash/-/lodash-4.17.23.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/lodash-npm-4.17.23-50bdb1c01a-10c0.zip
Dependency Hierarchy:
- core-3.9.2.tgz (Root Library)
- ❌ lodash-4.17.23.tgz (Vulnerable Library)
Found in base branch: main
Vulnerability Details
Impact:
The fix for CVE-2021-23337 (GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.
When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.
Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function().
Patches:
Users should upgrade to version 4.18.0.
Workarounds:
Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.
Publish Date: 2026年03月31日
URL: CVE-2026-4800
CVSS 3 Score Details (8.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Origin: GHSA-r5fr-rjxr-66jc
Release Date: 2026年03月31日
Fix Resolution: lodash-amd - 4.18.0,lodash.template - 4.18.0,lodash-es - 4.18.0,lodash - 4.18.0
Step up your Open Source Security Game with Mend here
CVE-2026-84375
Vulnerable Libraries - js-yaml-3.14.2.tgz, js-yaml-4.1.1.tgz
js-yaml-3.14.2.tgz
YAML 1.2 parser and serializer
Library home page: https://registry.npmjs.org/js-yaml/-/js-yaml-3.14.2.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/js-yaml-npm-3.14.2-debd9d20c3-10c0.zip
Dependency Hierarchy:
- core-3.9.2.tgz (Root Library)
- utils-3.9.2.tgz
- gray-matter-4.0.3.tgz
- ❌ js-yaml-3.14.2.tgz (Vulnerable Library)
- gray-matter-4.0.3.tgz
- utils-3.9.2.tgz
js-yaml-4.1.1.tgz
YAML 1.2 parser and serializer
Library home page: https://registry.npmjs.org/js-yaml/-/js-yaml-4.1.1.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/js-yaml-npm-4.1.1-86ec786790-10c0.zip
Dependency Hierarchy:
- core-3.9.2.tgz (Root Library)
- bundler-3.9.2.tgz
- postcss-loader-7.3.4.tgz
- cosmiconfig-8.3.6.tgz
- ❌ js-yaml-4.1.1.tgz (Vulnerable Library)
- cosmiconfig-8.3.6.tgz
- postcss-loader-7.3.4.tgz
- bundler-3.9.2.tgz
Found in base branch: main
Vulnerability Details
js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias a large sequence of empty mappings into many merge targets, causing O(N * K) processing while totalMergeKeys remains unchanged and the configured resource limit is never reached. A relatively small YAML document can therefore cause prolonged CPU consumption in applications that parse untrusted YAML, and merge processing is enabled by default on these release lines. This issue is fixed in versions 3.15.2 and 4.3.2.
Publish Date: 2026年09月01日
URL: CVE-2026-84375
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Origin: GHSA-2883-xcg3-v3hh
Release Date: 2026年09月01日
Fix Resolution: js-yaml - 3.15.2,js-yaml - 4.3.2,js-yaml - 4.3.2,js-yaml - 3.15.2,https://github.com/nodeca/js-yaml.git - 4.3.2,https://github.com/nodeca/js-yaml.git - 3.15.2
Step up your Open Source Security Game with Mend here
CVE-2026-84292
Vulnerable Library - fast-uri-3.1.0.tgz
Dependency-free RFC 3986 URI toolbox
Library home page: https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.0.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/fast-uri-npm-3.1.0-57fa0b3f3c-10c0.zip
Dependency Hierarchy:
- core-3.9.2.tgz (Root Library)
- webpack-dev-server-5.2.3.tgz
- schema-utils-4.3.3.tgz
- ajv-formats-2.1.1.tgz
- ajv-8.17.1.tgz
- ❌ fast-uri-3.1.0.tgz (Vulnerable Library)
- ajv-8.17.1.tgz
- ajv-formats-2.1.1.tgz
- schema-utils-4.3.3.tgz
- webpack-dev-server-5.2.3.tgz
Found in base branch: main
Vulnerability Details
fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node's URL read the result back as the attacker's host with no error, so re-validating the built URI does not catch it. This affects applications that build URIs from parts and assign untrusted data to the port component through the serialize, normalize, or equal functions in their object forms. The issue affects fast-uri versions before 2.4.6, from 3.0.0 before 3.1.7, and from 4.0.0 before 4.1.4. It is fixed in 2.4.6, 3.1.7, and 4.1.4, where recomposeAuthority rejects any port that is not a digit sequence per RFC 3986.
Publish Date: 2026年09月02日
URL: CVE-2026-84292
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: GHSA-qw65-cvwx-89v3
Release Date: 2026年09月02日
Fix Resolution: fast-uri - 3.1.7,fast-uri - 2.4.6,fast-uri - 4.1.4
Step up your Open Source Security Game with Mend here
CVE-2026-76172
Vulnerable Library - fast-uri-3.1.0.tgz
Dependency-free RFC 3986 URI toolbox
Library home page: https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.0.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/fast-uri-npm-3.1.0-57fa0b3f3c-10c0.zip
Dependency Hierarchy:
- core-3.9.2.tgz (Root Library)
- webpack-dev-server-5.2.3.tgz
- schema-utils-4.3.3.tgz
- ajv-formats-2.1.1.tgz
- ajv-8.17.1.tgz
- ❌ fast-uri-3.1.0.tgz (Vulnerable Library)
- ajv-8.17.1.tgz
- ajv-formats-2.1.1.tgz
- schema-utils-4.3.3.tgz
- webpack-dev-server-5.2.3.tgz
Found in base branch: main
Vulnerability Details
fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host component which is re-escaped. As a result an input whose scheme carries percent-encoded slashes parses as a scheme with no authority, so the parsed host and error are both undefined, yet resolving or normalizing that same input emits a network-path reference whose authority is attacker-chosen and re-parses to that host. An application that allowlists on the parsed host, or treats a reference with no authority as safe to resolve against its base, gets the opposite of what it checked, giving an off-site redirect, server-side request forgery, or address-policy bypass. The legacy decoder also expands non-standard escape forms, widening the issue past upstream filters, and control characters in the scheme can reach the output as raw carriage return and line feed. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which reject a scheme that is not valid after decoding. Users should upgrade to a patched version.
Publish Date: 2026年08月24日
URL: CVE-2026-76172
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: GHSA-jqff-g426-hqxp
Release Date: 2026年08月24日
Fix Resolution: fast-uri - 2.4.5,fast-uri - 3.1.6,fast-uri - 4.1.3
Step up your Open Source Security Game with Mend here
CVE-2026-75975
Vulnerable Library - fast-uri-3.1.0.tgz
Dependency-free RFC 3986 URI toolbox
Library home page: https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.0.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/fast-uri-npm-3.1.0-57fa0b3f3c-10c0.zip
Dependency Hierarchy:
- core-3.9.2.tgz (Root Library)
- webpack-dev-server-5.2.3.tgz
- schema-utils-4.3.3.tgz
- ajv-formats-2.1.1.tgz
- ajv-8.17.1.tgz
- ❌ fast-uri-3.1.0.tgz (Vulnerable Library)
- ajv-8.17.1.tgz
- ajv-formats-2.1.1.tgz
- schema-utils-4.3.3.tgz
- webpack-dev-server-5.2.3.tgz
Found in base branch: main
Vulnerability Details
fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 destination. For example, a bracketed literal with invalid trailing characters is normalized to the unspecified address, which a Node HTTP client then connects to a local service over loopback, and other malformed literals collapse to private-range addresses. No error is set on the parsed result, so an application checking the error field cannot detect the rewrite. An application that normalizes untrusted URLs before outbound requests, redirects, proxy routing, or address-policy enforcement can be redirected to a local or private IPv6 target, giving a server-side request forgery and address-policy bypass primitive. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which validate bracketed IP literals against the full grammar and mark malformed literals as authority errors. Users should upgrade to a patched version.
Publish Date: 2026年08月24日
URL: CVE-2026-75975
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: GHSA-f65p-4m7j-42xc
Release Date: 2026年08月24日
Fix Resolution: fast-uri - 2.4.5,fast-uri - 4.1.3,fast-uri - 3.1.6
Step up your Open Source Security Game with Mend here
CVE-2026-73646
Vulnerable Library - postcss-8.5.6.tgz
Tool for transforming styles with JS plugins
Library home page: https://registry.npmjs.org/postcss/-/postcss-8.5.6.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/postcss-npm-8.5.6-e7f126c6f3-10c0.zip
Dependency Hierarchy:
- core-3.9.2.tgz (Root Library)
- bundler-3.9.2.tgz
- ❌ postcss-8.5.6.tgz (Vulnerable Library)
- bundler-3.9.2.tgz
Found in base branch: main
Vulnerability Details
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values to join(dirname(opts.from), annotation), and loadFile() permits traversed or absolute .map paths, allowing untrusted CSS processed without map: false to disclose sourcesContent from arbitrary reachable .map files through result.map. This issue is fixed in version 8.5.18.
Publish Date: 2026年08月17日
URL: CVE-2026-73646
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Release Date: 2026年08月13日
Fix Resolution: https://github.com/postcss/postcss.git - 8.5.18
Step up your Open Source Security Game with Mend here