Skip to content

[VANTA] [VULNERABILITY] <HIGH> CVE-2026-46625, fix before 2026-10-03 #38

Description

@marco-commercelayer

Important

CLOSE THE ISSUE ONLY IF YOU PLAN TO DEPLOY THE FIX BEFORE THE DEADLINE IN THE TITLE.

DO NOT MANUALLY MODIFY THE ISSUE TITLE OR TEXT BODY.

FIXED npm-js-cookie <= 3.0.5 CVE-2026-46625 HIGH

npm-js-cookie <= 3.0.5 CODE_REPOSITORY/examples CVE-2026-46625 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-axios >= 1.0.0, < 1.16.0 CVE-2026-44494 HIGH

npm-axios >= 1.0.0, < 1.16.0 CODE_REPOSITORY/examples CVE-2026-44494 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-axios >= 1.0.0, < 1.16.0 CVE-2026-44486 HIGH

npm-axios >= 1.0.0, < 1.16.0 CODE_REPOSITORY/examples CVE-2026-44486 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-axios >= 1.0.0, < 1.16.0 CVE-2026-44496 HIGH

npm-axios >= 1.0.0, < 1.16.0 CODE_REPOSITORY/examples CVE-2026-44496 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-axios >= 1.0.0, < 1.16.0 CVE-2026-44487 HIGH

npm-axios >= 1.0.0, < 1.16.0 CODE_REPOSITORY/examples CVE-2026-44487 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-axios >= 1.0.0, < 1.16.0 CVE-2026-44490 MEDIUM

npm-axios >= 1.0.0, < 1.16.0 CODE_REPOSITORY/examples CVE-2026-44490 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-axios >= 1.0.0, < 1.12.0 CVE-2025-58754 HIGH

npm-axios >= 1.0.0, < 1.12.0 CODE_REPOSITORY/examples CVE-2025-58754 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-axios >= 1.0.0, <= 1.13.4 CVE-2026-25639 HIGH

npm-axios >= 1.0.0, <= 1.13.4 CODE_REPOSITORY/examples CVE-2026-25639 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 15.3.0-canary.0, < 15.3.6 GHSA-9qr9-h5gf-34mp CRITICAL

npm-next >= 15.3.0-canary.0, < 15.3.6 CODE_REPOSITORY/examples GHSA-9qr9-h5gf-34mp CRITICAL remediate by: 2026-10-03T14:05:15.305Z

Related URLs
FIXED npm-next >= 15.5.0-canary.0, < 15.5.7 GHSA-9qr9-h5gf-34mp CRITICAL

npm-next >= 15.5.0-canary.0, < 15.5.7 CODE_REPOSITORY/examples GHSA-9qr9-h5gf-34mp CRITICAL remediate by: 2026-10-03T14:05:15.305Z

Related URLs
FIXED npm-next >= 13.0.0, < 13.5.9 CVE-2025-29927 CRITICAL

npm-next >= 13.0.0, < 13.5.9 CODE_REPOSITORY/examples CVE-2025-29927 CRITICAL remediate by: 2026-10-03T14:05:15.305Z

Related URLs
FIXED npm-next >= 14.0.0, < 14.2.25 CVE-2025-29927 CRITICAL

npm-next >= 14.0.0, < 14.2.25 CODE_REPOSITORY/examples CVE-2025-29927 CRITICAL remediate by: 2026-10-03T14:05:15.305Z

Related URLs
FIXED npm-shell-quote >= 1.1.0, <= 1.8.3 CVE-2026-9277 CRITICAL

npm-shell-quote >= 1.1.0, <= 1.8.3 CODE_REPOSITORY/examples CVE-2026-9277 CRITICAL remediate by: 2026-10-03T14:05:15.305Z

Related URLs
FIXED npm-form-data >= 4.0.0, < 4.0.4 CVE-2025-7783 CRITICAL

npm-form-data >= 4.0.0, < 4.0.4 CODE_REPOSITORY/examples CVE-2025-7783 CRITICAL remediate by: 2026-10-03T14:05:15.305Z

Related URLs
FIXED npm-form-data < 2.5.4 CVE-2025-7783 CRITICAL

npm-form-data < 2.5.4 CODE_REPOSITORY/examples CVE-2025-7783 CRITICAL remediate by: 2026-10-03T14:05:15.305Z

Related URLs
FIXED npm-h3 <= 1.15.4 CVE-2026-23527 HIGH

npm-h3 <= 1.15.4 CODE_REPOSITORY/examples CVE-2026-23527 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 13.4.13, < 15.5.16 CVE-2026-44578 HIGH

npm-next >= 13.4.13, < 15.5.16 CODE_REPOSITORY/examples CVE-2026-44578 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-axios <= 0.31.1 CVE-2026-44492 HIGH

npm-axios <= 0.31.1 CODE_REPOSITORY/examples CVE-2026-44492 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-axios <= 0.31.1 CVE-2026-44486 HIGH

npm-axios <= 0.31.1 CODE_REPOSITORY/examples CVE-2026-44486 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-axios <= 0.31.1 CVE-2026-44496 HIGH

npm-axios <= 0.31.1 CODE_REPOSITORY/examples CVE-2026-44496 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-axios <= 0.31.1 CVE-2026-44487 HIGH

npm-axios <= 0.31.1 CODE_REPOSITORY/examples CVE-2026-44487 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-axios <= 0.31.1 CVE-2026-44490 MEDIUM

npm-axios <= 0.31.1 CODE_REPOSITORY/examples CVE-2026-44490 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-lodash >= 4.0.0, <= 4.17.23 CVE-2026-4800 HIGH

npm-lodash >= 4.0.0, <= 4.17.23 CODE_REPOSITORY/examples CVE-2026-4800 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 15.4.0, < 15.5.16 CVE-2026-44574 HIGH

npm-next >= 15.4.0, < 15.5.16 CODE_REPOSITORY/examples CVE-2026-44574 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-ws >= 7.0.0, < 7.5.10 CVE-2024-37890 HIGH

npm-ws >= 7.0.0, < 7.5.10 CODE_REPOSITORY/examples CVE-2024-37890 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-path-to-regexp >= 4.0.0, < 6.3.0 CVE-2024-45296 HIGH

npm-path-to-regexp >= 4.0.0, < 6.3.0 CODE_REPOSITORY/examples CVE-2024-45296 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-body-parser < 1.20.3 CVE-2024-45590 HIGH

npm-body-parser < 1.20.3 CODE_REPOSITORY/examples CVE-2024-45590 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 9.5.5, < 14.2.15 CVE-2024-51479 HIGH

npm-next >= 9.5.5, < 14.2.15 CODE_REPOSITORY/examples CVE-2024-51479 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-cross-spawn >= 7.0.0, < 7.0.5 CVE-2024-21538 HIGH

npm-cross-spawn >= 7.0.0, < 7.0.5 CODE_REPOSITORY/examples CVE-2024-21538 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-path-to-regexp < 0.1.10 CVE-2024-45296 HIGH

npm-path-to-regexp < 0.1.10 CODE_REPOSITORY/examples CVE-2024-45296 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-path-to-regexp < 0.1.12 CVE-2024-52798 HIGH

npm-path-to-regexp < 0.1.12 CODE_REPOSITORY/examples CVE-2024-52798 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-braces < 3.0.3 CVE-2024-4068 HIGH

npm-braces < 3.0.3 CODE_REPOSITORY/examples CVE-2024-4068 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 14.0.0, < 14.2.10 CVE-2024-46982 HIGH

npm-next >= 14.0.0, < 14.2.10 CODE_REPOSITORY/examples CVE-2024-46982 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-glob >= 10.2.0, < 10.5.0 CVE-2025-64756 HIGH

npm-glob >= 10.2.0, < 10.5.0 CODE_REPOSITORY/examples CVE-2025-64756 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-jws < 3.2.3 CVE-2025-65945 HIGH

npm-jws < 3.2.3 CODE_REPOSITORY/examples CVE-2025-65945 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 15.5.1-canary.0, < 15.5.8 GHSA-mwv6-3258-q52c HIGH

npm-next >= 15.5.1-canary.0, < 15.5.8 CODE_REPOSITORY/examples GHSA-mwv6-3258-q52c HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 15.5.1-canary.0, < 15.5.8 GHSA-w37m-7fhw-fmv9 MEDIUM

npm-next >= 15.5.1-canary.0, < 15.5.8 CODE_REPOSITORY/examples GHSA-w37m-7fhw-fmv9 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-next >= 15.3.0-canary.0, < 15.3.7 GHSA-mwv6-3258-q52c HIGH

npm-next >= 15.3.0-canary.0, < 15.3.7 CODE_REPOSITORY/examples GHSA-mwv6-3258-q52c HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 15.3.0-canary.0, < 15.3.7 GHSA-w37m-7fhw-fmv9 MEDIUM

npm-next >= 15.3.0-canary.0, < 15.3.7 CODE_REPOSITORY/examples GHSA-w37m-7fhw-fmv9 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-next >= 13.3.0, < 14.2.34 GHSA-mwv6-3258-q52c HIGH

npm-next >= 13.3.0, < 14.2.34 CODE_REPOSITORY/examples GHSA-mwv6-3258-q52c HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 13.3.1-canary.0, < 14.2.35 GHSA-5j59-xgg2-r9c4 HIGH

npm-next >= 13.3.1-canary.0, < 14.2.35 CODE_REPOSITORY/examples GHSA-5j59-xgg2-r9c4 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 15.5.1-canary.0, < 15.5.10 GHSA-h25m-26qc-wcjf HIGH

npm-next >= 15.5.1-canary.0, < 15.5.10 CODE_REPOSITORY/examples GHSA-h25m-26qc-wcjf HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 15.3.0-canary.0, < 15.3.9 GHSA-h25m-26qc-wcjf HIGH

npm-next >= 15.3.0-canary.0, < 15.3.9 CODE_REPOSITORY/examples GHSA-h25m-26qc-wcjf HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 13.0.0, < 15.0.8 GHSA-h25m-26qc-wcjf HIGH

npm-next >= 13.0.0, < 15.0.8 CODE_REPOSITORY/examples GHSA-h25m-26qc-wcjf HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-axios <= 0.30.2 CVE-2026-25639 HIGH

npm-axios <= 0.30.2 CODE_REPOSITORY/examples CVE-2026-25639 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-minimatch < 3.1.3 CVE-2026-27903 HIGH

npm-minimatch < 3.1.3 CODE_REPOSITORY/examples CVE-2026-27903 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-minimatch < 3.1.3 CVE-2026-26996 HIGH

npm-minimatch < 3.1.3 CODE_REPOSITORY/examples CVE-2026-26996 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-minimatch < 3.1.4 CVE-2026-27904 HIGH

npm-minimatch < 3.1.4 CODE_REPOSITORY/examples CVE-2026-27904 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-minimatch >= 9.0.0, < 9.0.7 CVE-2026-27903 HIGH

npm-minimatch >= 9.0.0, < 9.0.7 CODE_REPOSITORY/examples CVE-2026-27903 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-minimatch >= 9.0.0, < 9.0.7 CVE-2026-27904 HIGH

npm-minimatch >= 9.0.0, < 9.0.7 CODE_REPOSITORY/examples CVE-2026-27904 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-h3 < 1.15.6 CVE-2026-33128 HIGH

npm-h3 < 1.15.6 CODE_REPOSITORY/examples CVE-2026-33128 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-h3 < 1.15.6 GHSA-wr4h-v87w-p3r7 MEDIUM

npm-h3 < 1.15.6 CODE_REPOSITORY/examples GHSA-wr4h-v87w-p3r7 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-picomatch < 2.3.2 CVE-2026-33671 HIGH

npm-picomatch < 2.3.2 CODE_REPOSITORY/examples CVE-2026-33671 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-picomatch < 2.3.2 CVE-2026-33672 MEDIUM

npm-picomatch < 2.3.2 CODE_REPOSITORY/examples CVE-2026-33672 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-path-to-regexp < 0.1.13 CVE-2026-4867 HIGH

npm-path-to-regexp < 0.1.13 CODE_REPOSITORY/examples CVE-2026-4867 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-defu <= 6.1.4 CVE-2026-35209 HIGH

npm-defu <= 6.1.4 CODE_REPOSITORY/examples CVE-2026-35209 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 13.0.0, < 15.5.15 GHSA-q4gf-8mx6-v5v3 HIGH

npm-next >= 13.0.0, < 15.5.15 CODE_REPOSITORY/examples GHSA-q4gf-8mx6-v5v3 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 15.2.0, < 15.5.18 CVE-2026-45109 HIGH

npm-next >= 15.2.0, < 15.5.18 CODE_REPOSITORY/examples CVE-2026-45109 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 15.2.0, < 15.5.16 CVE-2026-44575 HIGH

npm-next >= 15.2.0, < 15.5.16 CODE_REPOSITORY/examples CVE-2026-44575 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 15.0.0, < 15.5.16 CVE-2026-44579 HIGH

npm-next >= 15.0.0, < 15.5.16 CODE_REPOSITORY/examples CVE-2026-44579 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 13.0.0, < 15.5.16 GHSA-8h8q-6873-q5fj HIGH

npm-next >= 13.0.0, < 15.5.16 CODE_REPOSITORY/examples GHSA-8h8q-6873-q5fj HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 13.0.0, < 15.5.16 CVE-2026-44580 MEDIUM

npm-next >= 13.0.0, < 15.5.16 CODE_REPOSITORY/examples CVE-2026-44580 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-next >= 12.2.0, < 15.5.16 CVE-2026-44573 HIGH

npm-next >= 12.2.0, < 15.5.16 CODE_REPOSITORY/examples CVE-2026-44573 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-next >= 12.2.0, < 15.5.16 CVE-2026-44572 LOW

npm-next >= 12.2.0, < 15.5.16 CODE_REPOSITORY/examples CVE-2026-44572 LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-axios >= 1.7.0, < 1.16.0 CVE-2026-44488 HIGH

npm-axios >= 1.7.0, < 1.16.0 CODE_REPOSITORY/examples CVE-2026-44488 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-form-data >= 4.0.0, < 4.0.6 CVE-2026-12143 HIGH

npm-form-data >= 4.0.0, < 4.0.6 CODE_REPOSITORY/examples CVE-2026-12143 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-vite >= 8.0.0, <= 8.0.15 CVE-2026-53571 HIGH

npm-vite >= 8.0.0, <= 8.0.15 CODE_REPOSITORY/examples CVE-2026-53571 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-vite >= 8.0.0, <= 8.0.15 CVE-2026-53632 MEDIUM

npm-vite >= 8.0.0, <= 8.0.15 CODE_REPOSITORY/examples CVE-2026-53632 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-ws >= 7.0.0, < 7.5.11 CVE-2026-48779 HIGH

npm-ws >= 7.0.0, < 7.5.11 CODE_REPOSITORY/examples CVE-2026-48779 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-form-data < 2.5.6 CVE-2026-12143 HIGH

npm-form-data < 2.5.6 CODE_REPOSITORY/examples CVE-2026-12143 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-shell-quote <= 1.8.4 CVE-2026-13311 HIGH

npm-shell-quote <= 1.8.4 CODE_REPOSITORY/examples CVE-2026-13311 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-postcss <= 8.5.11 CVE-2026-45623 HIGH

npm-postcss <= 8.5.11 CODE_REPOSITORY/examples CVE-2026-45623 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-postcss <= 8.5.17 CVE-2026-73646 HIGH

npm-postcss <= 8.5.17 CODE_REPOSITORY/examples CVE-2026-73646 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs
FIXED npm-brace-expansion >= 2.0.0, < 2.1.3 CVE-2026-14257 HIGH

npm-brace-expansion >= 2.0.0, < 2.1.3 CODE_REPOSITORY/examples CVE-2026-14257 HIGH remediate by: 2026-10-03T14:05:19.404Z

Related URLs

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions