Skip to content

[VANTA] [VULNERABILITY] <HIGH> GHSA-5c6j-r48x-rmvq, fix before 2026-04-01 #23

@commercelayer-ci

Description

@commercelayer-ci

Important

CLOSE THE ISSUE ONLY IF YOU PLAN TO DEPLOY THE FIX BEFORE THE DEADLINE IN THE TITLE.

DO NOT MANUALLY MODIFY THE ISSUE TITLE OR TEXT BODY.

FIXED npm-serialize-javascript <= 7.0.2 GHSA-5c6j-r48x-rmvq HIGH

npm-serialize-javascript <= 7.0.2 CODE_REPOSITORY/commercelayer-cli-plugin-exports GHSA-5c6j-r48x-rmvq HIGH remediate by: 2026-04-01T14:19:30.006Z

Related URLs
npm-fast-xml-parser >= 4.0.0-beta.3, <= 5.5.5 CODE_REPOSITORY/commercelayer-cli-plugin-exports CVE-2026-33036 HIGH remediate by: 2026-04-17T06:15:42.032Z
Related URLs
FIXED npm-minimatch >= 9.0.0, < 9.0.7 CVE-2026-27903 HIGH

npm-minimatch >= 9.0.0, < 9.0.7 CODE_REPOSITORY/commercelayer-cli-plugin-exports CVE-2026-27903 HIGH remediate by: 2026-04-01T14:19:30.006Z

Related URLs
FIXED npm-minimatch >= 9.0.0, < 9.0.7 CVE-2026-27904 HIGH

npm-minimatch >= 9.0.0, < 9.0.7 CODE_REPOSITORY/commercelayer-cli-plugin-exports CVE-2026-27904 HIGH remediate by: 2026-04-01T14:19:30.006Z

Related URLs
FIXED npm-minimatch >= 9.0.0, < 9.0.6 CVE-2026-26996 HIGH

npm-minimatch >= 9.0.0, < 9.0.6 CODE_REPOSITORY/commercelayer-cli-plugin-exports CVE-2026-26996 HIGH remediate by: 2026-04-01T14:19:30.006Z

Related URLs
npm-flatted < 3.4.0 CODE_REPOSITORY/commercelayer-cli-plugin-exports CVE-2026-32141 HIGH remediate by: 2026-04-14T06:14:58.215Z
Related URLs

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions