{
  "stage": "stage2a-vulns",
  "generated_at": "2026-04-01T03:32:38.296Z",
  "scanners": {
    "grype": {
      "findingCount": 14,
      "durationMs": 4853
    },
    "osv_scanner": {
      "findingCount": 14,
      "durationMs": 1200
    },
    "npm_audit": {
      "findingCount": 46,
      "durationMs": 6832
    }
  },
  "total_raw_findings": 74,
  "deduplicated_count": 40,
  "findings": [
    {
      "cve_id": "CVE-2026-33672",
      "ghsa_id": "GHSA-3v7f-55p6-f55p",
      "osv_id": "GHSA-3v7f-55p6-f55p",
      "severity": "medium",
      "cvss_score": 5.3,
      "epss_score": null,
      "is_kev": false,
      "package_name": "picomatch",
      "installed_version": "4.0.2",
      "fixed_version": "4.0.4",
      "dependency_scope": "development",
      "title": "Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
      "description": "Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
      "url": "https://github.com/micromatch/picomatch/security/advisories/GHSA-3v7f-55p6-f55p",
      "sources": [
        "grype",
        "osv-scanner"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": "CVE-2026-33750",
      "ghsa_id": "GHSA-f886-m6hf-6m8v",
      "osv_id": "GHSA-f886-m6hf-6m8v",
      "severity": "medium",
      "cvss_score": 6.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "brace-expansion",
      "installed_version": "1.1.12",
      "fixed_version": "1.1.13",
      "dependency_scope": "development",
      "title": "brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
      "description": "brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
      "url": "https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-f886-m6hf-6m8v",
      "sources": [
        "grype",
        "osv-scanner"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": "CVE-2026-33671",
      "ghsa_id": "GHSA-c2c7-rcm5-vvqj",
      "osv_id": "GHSA-c2c7-rcm5-vvqj",
      "severity": "high",
      "cvss_score": 7.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "picomatch",
      "installed_version": "4.0.2",
      "fixed_version": "4.0.4",
      "dependency_scope": "development",
      "title": "Picomatch has a ReDoS vulnerability via extglob quantifiers",
      "description": "Picomatch has a ReDoS vulnerability via extglob quantifiers",
      "url": "https://github.com/micromatch/picomatch/security/advisories/GHSA-c2c7-rcm5-vvqj",
      "sources": [
        "grype",
        "osv-scanner"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": "CVE-2025-54798",
      "ghsa_id": "GHSA-52f5-9888-hmc6",
      "osv_id": "GHSA-52f5-9888-hmc6",
      "severity": "low",
      "cvss_score": 2.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "tmp",
      "installed_version": "0.0.33",
      "fixed_version": "0.2.4",
      "dependency_scope": "runtime",
      "title": "tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter",
      "description": "tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter",
      "url": "https://github.com/raszi/node-tmp/security/advisories/GHSA-52f5-9888-hmc6",
      "sources": [
        "grype",
        "osv-scanner"
      ],
      "has_fix": true,
      "is_runtime": true
    },
    {
      "cve_id": "CVE-2026-27903",
      "ghsa_id": "GHSA-7r86-cg39-jmmj",
      "osv_id": "GHSA-7r86-cg39-jmmj",
      "severity": "high",
      "cvss_score": 7.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "minimatch",
      "installed_version": "3.1.2",
      "fixed_version": "3.1.3",
      "dependency_scope": "development",
      "title": "minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments",
      "description": "minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments",
      "url": "https://github.com/isaacs/minimatch/security/advisories/GHSA-7r86-cg39-jmmj",
      "sources": [
        "grype",
        "osv-scanner"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": "CVE-2026-26996",
      "ghsa_id": "GHSA-3ppc-4f35-3m26",
      "osv_id": "GHSA-3ppc-4f35-3m26",
      "severity": "high",
      "cvss_score": 8.7,
      "epss_score": null,
      "is_kev": false,
      "package_name": "minimatch",
      "installed_version": "3.1.2",
      "fixed_version": "3.1.3",
      "dependency_scope": "development",
      "title": "minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
      "description": "minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
      "url": "https://github.com/isaacs/minimatch/security/advisories/GHSA-3ppc-4f35-3m26",
      "sources": [
        "grype",
        "osv-scanner"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": "CVE-2026-27904",
      "ghsa_id": "GHSA-23c5-xmqv-rm74",
      "osv_id": "GHSA-23c5-xmqv-rm74",
      "severity": "high",
      "cvss_score": 7.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "minimatch",
      "installed_version": "3.1.2",
      "fixed_version": "3.1.4",
      "dependency_scope": "development",
      "title": "minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions",
      "description": "minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions",
      "url": "https://github.com/isaacs/minimatch/security/advisories/GHSA-23c5-xmqv-rm74",
      "sources": [
        "grype",
        "osv-scanner"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-6475-r3vj-m8vf",
      "osv_id": null,
      "severity": "low",
      "cvss_score": 3.7,
      "epss_score": null,
      "is_kev": false,
      "package_name": "@smithy/config-resolver",
      "installed_version": "<4.4.0",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "AWS SDK for JavaScript v3 adopted defense in depth enhancement for region parameter value",
      "description": "AWS SDK for JavaScript v3 adopted defense in depth enhancement for region parameter value",
      "url": "https://github.com/advisories/GHSA-6475-r3vj-m8vf",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-f886-m6hf-6m8v",
      "osv_id": null,
      "severity": "moderate",
      "cvss_score": 6.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "brace-expansion",
      "installed_version": "<1.1.13 || >=2.0.0 <2.0.3",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
      "description": "brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
      "url": "https://github.com/advisories/GHSA-f886-m6hf-6m8v",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-73rr-hh4g-fpgx",
      "osv_id": null,
      "severity": "low",
      "cvss_score": 0,
      "epss_score": null,
      "is_kev": false,
      "package_name": "diff",
      "installed_version": "4.0.0 - 4.0.3 || 5.0.0 - 5.2.1 || 6.0.0 - 8.0.2",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch",
      "description": "jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch",
      "url": "https://github.com/advisories/GHSA-73rr-hh4g-fpgx",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-m7jm-9gc2-mpf2",
      "osv_id": null,
      "severity": "critical",
      "cvss_score": 9.3,
      "epss_score": null,
      "is_kev": false,
      "package_name": "fast-xml-parser",
      "installed_version": "4.0.0-beta.0 - 5.5.6",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names",
      "description": "fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names",
      "url": "https://github.com/advisories/GHSA-m7jm-9gc2-mpf2",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-jmr7-xgp7-cmfj",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 7.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "fast-xml-parser",
      "installed_version": "4.0.0-beta.0 - 5.5.6",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)",
      "description": "fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)",
      "url": "https://github.com/advisories/GHSA-jmr7-xgp7-cmfj",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-fj3w-jwp8-x2g3",
      "osv_id": null,
      "severity": "low",
      "cvss_score": 0,
      "epss_score": null,
      "is_kev": false,
      "package_name": "fast-xml-parser",
      "installed_version": "4.0.0-beta.0 - 5.5.6",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "fast-xml-parser has stack overflow in XMLBuilder with preserveOrder",
      "description": "fast-xml-parser has stack overflow in XMLBuilder with preserveOrder",
      "url": "https://github.com/advisories/GHSA-fj3w-jwp8-x2g3",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-8gc5-j5rx-235r",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 7.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "fast-xml-parser",
      "installed_version": "4.0.0-beta.0 - 5.5.6",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)",
      "description": "fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)",
      "url": "https://github.com/advisories/GHSA-8gc5-j5rx-235r",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-jp2q-39xq-3w4g",
      "osv_id": null,
      "severity": "moderate",
      "cvss_score": 5.9,
      "epss_score": null,
      "is_kev": false,
      "package_name": "fast-xml-parser",
      "installed_version": "4.0.0-beta.0 - 5.5.6",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser",
      "description": "Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser",
      "url": "https://github.com/advisories/GHSA-jp2q-39xq-3w4g",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-5j98-mcp5-4vw2",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 7.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "glob",
      "installed_version": "10.2.0 - 10.4.5",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "glob CLI: Command injection via -c/--cmd executes matches with shell:true",
      "description": "glob CLI: Command injection via -c/--cmd executes matches with shell:true",
      "url": "https://github.com/advisories/GHSA-5j98-mcp5-4vw2",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-3mfm-83xf-c92r",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 8.1,
      "epss_score": null,
      "is_kev": false,
      "package_name": "handlebars",
      "installed_version": "4.0.0 - 4.7.8",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block",
      "description": "Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block",
      "url": "https://github.com/advisories/GHSA-3mfm-83xf-c92r",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-2w6w-674q-4c4q",
      "osv_id": null,
      "severity": "critical",
      "cvss_score": 9.8,
      "epss_score": null,
      "is_kev": false,
      "package_name": "handlebars",
      "installed_version": "4.0.0 - 4.7.8",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "Handlebars.js has JavaScript Injection via AST Type Confusion",
      "description": "Handlebars.js has JavaScript Injection via AST Type Confusion",
      "url": "https://github.com/advisories/GHSA-2w6w-674q-4c4q",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-2qvq-rjwj-gvw9",
      "osv_id": null,
      "severity": "moderate",
      "cvss_score": 4.7,
      "epss_score": null,
      "is_kev": false,
      "package_name": "handlebars",
      "installed_version": "4.0.0 - 4.7.8",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection",
      "description": "Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection",
      "url": "https://github.com/advisories/GHSA-2qvq-rjwj-gvw9",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-7rx3-28cr-v5wh",
      "osv_id": null,
      "severity": "moderate",
      "cvss_score": 4.8,
      "epss_score": null,
      "is_kev": false,
      "package_name": "handlebars",
      "installed_version": "4.0.0 - 4.7.8",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist Entry",
      "description": "Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist Entry",
      "url": "https://github.com/advisories/GHSA-7rx3-28cr-v5wh",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-442j-39wm-28r2",
      "osv_id": null,
      "severity": "low",
      "cvss_score": 3.7,
      "epss_score": null,
      "is_kev": false,
      "package_name": "handlebars",
      "installed_version": "4.0.0 - 4.7.8",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "Handlebars.js has a Property Access Validation Bypass in container.lookup",
      "description": "Handlebars.js has a Property Access Validation Bypass in container.lookup",
      "url": "https://github.com/advisories/GHSA-442j-39wm-28r2",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-xjpj-3mr7-gcpf",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 8.3,
      "epss_score": null,
      "is_kev": false,
      "package_name": "handlebars",
      "installed_version": "4.0.0 - 4.7.8",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options",
      "description": "Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options",
      "url": "https://github.com/advisories/GHSA-xjpj-3mr7-gcpf",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-xhpv-hc6g-r9c6",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 8.1,
      "epss_score": null,
      "is_kev": false,
      "package_name": "handlebars",
      "installed_version": "4.0.0 - 4.7.8",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial",
      "description": "Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial",
      "url": "https://github.com/advisories/GHSA-xhpv-hc6g-r9c6",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-9cx6-37pm-9jff",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 7.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "handlebars",
      "installed_version": "4.0.0 - 4.7.8",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation",
      "description": "Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation",
      "url": "https://github.com/advisories/GHSA-9cx6-37pm-9jff",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-mh29-5h37-fv8m",
      "osv_id": null,
      "severity": "moderate",
      "cvss_score": 5.3,
      "epss_score": null,
      "is_kev": false,
      "package_name": "js-yaml",
      "installed_version": "<3.14.2 || >=4.0.0 <4.1.1",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "js-yaml has prototype pollution in merge (<<)",
      "description": "js-yaml has prototype pollution in merge (<<)",
      "url": "https://github.com/advisories/GHSA-mh29-5h37-fv8m",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-xxjr-mmjv-4gpg",
      "osv_id": null,
      "severity": "moderate",
      "cvss_score": 6.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "lodash",
      "installed_version": "4.0.0 - 4.17.21",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions",
      "description": "Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions",
      "url": "https://github.com/advisories/GHSA-xxjr-mmjv-4gpg",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-3ppc-4f35-3m26",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 0,
      "epss_score": null,
      "is_kev": false,
      "package_name": "minimatch",
      "installed_version": "<=3.1.3 || 5.0.0 - 5.1.7 || 9.0.0 - 9.0.6",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
      "description": "minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
      "url": "https://github.com/advisories/GHSA-3ppc-4f35-3m26",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-7r86-cg39-jmmj",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 7.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "minimatch",
      "installed_version": "<=3.1.3 || 5.0.0 - 5.1.7 || 9.0.0 - 9.0.6",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments",
      "description": "minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments",
      "url": "https://github.com/advisories/GHSA-7r86-cg39-jmmj",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-23c5-xmqv-rm74",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 7.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "minimatch",
      "installed_version": "<=3.1.3 || 5.0.0 - 5.1.7 || 9.0.0 - 9.0.6",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions",
      "description": "minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions",
      "url": "https://github.com/advisories/GHSA-23c5-xmqv-rm74",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-3v7f-55p6-f55p",
      "osv_id": null,
      "severity": "moderate",
      "cvss_score": 5.3,
      "epss_score": null,
      "is_kev": false,
      "package_name": "picomatch",
      "installed_version": "<=2.3.1 || 4.0.0 - 4.0.3",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
      "description": "Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
      "url": "https://github.com/advisories/GHSA-3v7f-55p6-f55p",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-c2c7-rcm5-vvqj",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 7.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "picomatch",
      "installed_version": "<=2.3.1 || 4.0.0 - 4.0.3",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "Picomatch has a ReDoS vulnerability via extglob quantifiers",
      "description": "Picomatch has a ReDoS vulnerability via extglob quantifiers",
      "url": "https://github.com/advisories/GHSA-c2c7-rcm5-vvqj",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-5c6j-r48x-rmvq",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 8.1,
      "epss_score": null,
      "is_kev": false,
      "package_name": "serialize-javascript",
      "installed_version": "<=7.0.4",
      "fixed_version": "7.2.0",
      "dependency_scope": "development",
      "title": "Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()",
      "description": "Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()",
      "url": "https://github.com/advisories/GHSA-5c6j-r48x-rmvq",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-qj8w-gfj5-8c6v",
      "osv_id": null,
      "severity": "moderate",
      "cvss_score": 5.9,
      "epss_score": null,
      "is_kev": false,
      "package_name": "serialize-javascript",
      "installed_version": "<=7.0.4",
      "fixed_version": "7.2.0",
      "dependency_scope": "development",
      "title": "Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects",
      "description": "Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects",
      "url": "https://github.com/advisories/GHSA-qj8w-gfj5-8c6v",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-34x7-hfp2-rc4v",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 8.2,
      "epss_score": null,
      "is_kev": false,
      "package_name": "tar",
      "installed_version": "<=7.5.10",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal",
      "description": "node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal",
      "url": "https://github.com/advisories/GHSA-34x7-hfp2-rc4v",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-8qq5-rm4j-mr97",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 0,
      "epss_score": null,
      "is_kev": false,
      "package_name": "tar",
      "installed_version": "<=7.5.10",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization",
      "description": "node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization",
      "url": "https://github.com/advisories/GHSA-8qq5-rm4j-mr97",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-83g3-92jg-28cx",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 7.1,
      "epss_score": null,
      "is_kev": false,
      "package_name": "tar",
      "installed_version": "<=7.5.10",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction",
      "description": "Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction",
      "url": "https://github.com/advisories/GHSA-83g3-92jg-28cx",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-qffp-2rhf-9h96",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 0,
      "epss_score": null,
      "is_kev": false,
      "package_name": "tar",
      "installed_version": "<=7.5.10",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "tar has Hardlink Path Traversal via Drive-Relative Linkpath",
      "description": "tar has Hardlink Path Traversal via Drive-Relative Linkpath",
      "url": "https://github.com/advisories/GHSA-qffp-2rhf-9h96",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-9ppj-qmqm-q256",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 0,
      "epss_score": null,
      "is_kev": false,
      "package_name": "tar",
      "installed_version": "<=7.5.10",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "node-tar Symlink Path Traversal via Drive-Relative Linkpath",
      "description": "node-tar Symlink Path Traversal via Drive-Relative Linkpath",
      "url": "https://github.com/advisories/GHSA-9ppj-qmqm-q256",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-r6q2-hw4h-h46w",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 8.8,
      "epss_score": null,
      "is_kev": false,
      "package_name": "tar",
      "installed_version": "<=7.5.10",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS",
      "description": "Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS",
      "url": "https://github.com/advisories/GHSA-r6q2-hw4h-h46w",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-52f5-9888-hmc6",
      "osv_id": null,
      "severity": "low",
      "cvss_score": 2.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "tmp",
      "installed_version": "<=0.2.3",
      "fixed_version": "available",
      "dependency_scope": "runtime",
      "title": "tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter",
      "description": "tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter",
      "url": "https://github.com/advisories/GHSA-52f5-9888-hmc6",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": true
    }
  ],
  "risk_score": {
    "runtimeCount": 2,
    "devCount": 38,
    "weightedScore": 208
  }
}