Important
CLOSE THE ISSUE ONLY IF YOU PLAN TO DEPLOY THE FIX BEFORE THE DEADLINE IN THE TITLE.
DO NOT MANUALLY MODIFY THE ISSUE TITLE OR TEXT BODY.
FIXED npm-handlebars >= 4.0.0, <= 4.7.8 CVE-2026-33937 CRITICAL
npm-handlebars >= 4.0.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-33937 CRITICAL remediate by: 2026-04-26T22:19:27.887Z
Related URLs
FIXED npm-handlebars >= 4.0.0, <= 4.7.8 CVE-2026-33941 HIGH
npm-handlebars >= 4.0.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-33941 HIGH remediate by: 2026-04-26T22:19:28.149Z
Related URLs
FIXED npm-handlebars >= 4.0.0, <= 4.7.8 CVE-2026-33940 HIGH
npm-handlebars >= 4.0.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-33940 HIGH remediate by: 2026-04-26T22:19:28.149Z
Related URLs
FIXED npm-handlebars >= 4.0.0, <= 4.7.8 CVE-2026-33938 HIGH
npm-handlebars >= 4.0.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-33938 HIGH remediate by: 2026-04-26T22:19:28.149Z
Related URLs
FIXED npm-handlebars >= 4.0.0, <= 4.7.8 CVE-2026-33939 HIGH
npm-handlebars >= 4.0.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-33939 HIGH remediate by: 2026-04-26T22:19:28.149Z
Related URLs
FIXED npm-handlebars >= 4.0.0, <= 4.7.8 GHSA-442j-39wm-28r2 LOW
npm-handlebars >= 4.0.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-cli-plugin-links GHSA-442j-39wm-28r2 LOW remediate by: 2026-06-27T22:22:40.282Z
Related URLs
FIXED npm-serialize-javascript <= 7.0.2 GHSA-5c6j-r48x-rmvq HIGH
npm-serialize-javascript <= 7.0.2 CODE_REPOSITORY/commercelayer-cli-plugin-links GHSA-5c6j-r48x-rmvq HIGH remediate by: 2026-04-29T22:15:21.750Z
Related URLs
FIXED npm-lodash-es >= 4.0.0, <= 4.17.23 CVE-2026-4800 HIGH
npm-lodash-es >= 4.0.0, <= 4.17.23 CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-4800 HIGH remediate by: 2026-05-02T14:38:24.409Z
Related URLs
FIXED npm-lodash >= 4.0.0, <= 4.17.23 CVE-2026-4800 HIGH
npm-lodash >= 4.0.0, <= 4.17.23 CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-4800 HIGH remediate by: 2026-05-10T06:21:04.459Z
Related URLs
FIXED npm-handlebars >= 4.0.0, < 4.7.9 CVE-2026-33916 MEDIUM
npm-handlebars >= 4.0.0, < 4.7.9 CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-33916 MEDIUM remediate by: 2026-05-26T06:15:32.686Z
Related URLs
FIXED npm-brace-expansion >= 4.0.0, < 5.0.5 CVE-2026-33750 MEDIUM
npm-brace-expansion >= 4.0.0, < 5.0.5 CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-33750 MEDIUM remediate by: 2026-05-26T22:19:28.497Z
Related URLs
FIXED npm-serialize-javascript < 7.0.5 CVE-2026-34043 MEDIUM
npm-serialize-javascript < 7.0.5 CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-34043 MEDIUM remediate by: 2026-05-28T14:18:26.573Z
Related URLs
FIXED npm-brace-expansion >= 2.0.0, < 2.0.3 CVE-2026-33750 MEDIUM
npm-brace-expansion >= 2.0.0, < 2.0.3 CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-33750 MEDIUM remediate by: 2026-05-28T22:22:39.992Z
Related URLs
FIXED npm-handlebars >= 4.6.0, <= 4.7.8 GHSA-7rx3-28cr-v5wh MEDIUM
npm-handlebars >= 4.6.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-cli-plugin-links GHSA-7rx3-28cr-v5wh MEDIUM remediate by: 2026-05-28T22:22:39.992Z
Related URLs
FIXED npm-lodash-es <= 4.17.23 CVE-2026-2950 MEDIUM
npm-lodash-es <= 4.17.23 CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-2950 MEDIUM remediate by: 2026-06-01T14:38:24.736Z
Related URLs
FIXED npm-lodash <= 4.17.23 CVE-2026-2950 MEDIUM
npm-lodash <= 4.17.23 CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-2950 MEDIUM remediate by: 2026-06-09T14:23:14.879Z
Related URLs
FIXED npm-diff >= 6.0.0, < 8.0.3 CVE-2026-24001 LOW
npm-diff >= 6.0.0, < 8.0.3 CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-24001 LOW remediate by: 2026-06-28T22:15:22.360Z
Related URLs
Important
CLOSE THE ISSUE ONLY IF YOU PLAN TO DEPLOY THE FIX BEFORE THE DEADLINE IN THE TITLE.
DO NOT MANUALLY MODIFY THE ISSUE TITLE OR TEXT BODY.
FIXED
npm-handlebars >= 4.0.0, <= 4.7.8CVE-2026-33937 CRITICALnpm-handlebars >= 4.0.0, <= 4.7.8CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-33937 CRITICAL remediate by: 2026-04-26T22:19:27.887ZFIXED
npm-handlebars >= 4.0.0, <= 4.7.8CVE-2026-33941 HIGHnpm-handlebars >= 4.0.0, <= 4.7.8CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-33941 HIGH remediate by: 2026-04-26T22:19:28.149ZFIXED
npm-handlebars >= 4.0.0, <= 4.7.8CVE-2026-33940 HIGHnpm-handlebars >= 4.0.0, <= 4.7.8CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-33940 HIGH remediate by: 2026-04-26T22:19:28.149ZFIXED
npm-handlebars >= 4.0.0, <= 4.7.8CVE-2026-33938 HIGHnpm-handlebars >= 4.0.0, <= 4.7.8CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-33938 HIGH remediate by: 2026-04-26T22:19:28.149ZFIXED
npm-handlebars >= 4.0.0, <= 4.7.8CVE-2026-33939 HIGHnpm-handlebars >= 4.0.0, <= 4.7.8CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-33939 HIGH remediate by: 2026-04-26T22:19:28.149ZFIXED
npm-handlebars >= 4.0.0, <= 4.7.8GHSA-442j-39wm-28r2 LOWnpm-handlebars >= 4.0.0, <= 4.7.8CODE_REPOSITORY/commercelayer-cli-plugin-links GHSA-442j-39wm-28r2 LOW remediate by: 2026-06-27T22:22:40.282ZFIXED
npm-serialize-javascript <= 7.0.2GHSA-5c6j-r48x-rmvq HIGHnpm-serialize-javascript <= 7.0.2CODE_REPOSITORY/commercelayer-cli-plugin-links GHSA-5c6j-r48x-rmvq HIGH remediate by: 2026-04-29T22:15:21.750ZFIXED
npm-lodash-es >= 4.0.0, <= 4.17.23CVE-2026-4800 HIGHnpm-lodash-es >= 4.0.0, <= 4.17.23CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-4800 HIGH remediate by: 2026-05-02T14:38:24.409ZFIXED
npm-lodash >= 4.0.0, <= 4.17.23CVE-2026-4800 HIGHnpm-lodash >= 4.0.0, <= 4.17.23CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-4800 HIGH remediate by: 2026-05-10T06:21:04.459ZFIXED
npm-handlebars >= 4.0.0, < 4.7.9CVE-2026-33916 MEDIUMnpm-handlebars >= 4.0.0, < 4.7.9CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-33916 MEDIUM remediate by: 2026-05-26T06:15:32.686ZFIXED
npm-brace-expansion >= 4.0.0, < 5.0.5CVE-2026-33750 MEDIUMnpm-brace-expansion >= 4.0.0, < 5.0.5CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-33750 MEDIUM remediate by: 2026-05-26T22:19:28.497ZFIXED
npm-serialize-javascript < 7.0.5CVE-2026-34043 MEDIUMnpm-serialize-javascript < 7.0.5CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-34043 MEDIUM remediate by: 2026-05-28T14:18:26.573ZFIXED
npm-brace-expansion >= 2.0.0, < 2.0.3CVE-2026-33750 MEDIUMnpm-brace-expansion >= 2.0.0, < 2.0.3CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-33750 MEDIUM remediate by: 2026-05-28T22:22:39.992ZFIXED
npm-handlebars >= 4.6.0, <= 4.7.8GHSA-7rx3-28cr-v5wh MEDIUMnpm-handlebars >= 4.6.0, <= 4.7.8CODE_REPOSITORY/commercelayer-cli-plugin-links GHSA-7rx3-28cr-v5wh MEDIUM remediate by: 2026-05-28T22:22:39.992ZFIXED
npm-lodash-es <= 4.17.23CVE-2026-2950 MEDIUMnpm-lodash-es <= 4.17.23CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-2950 MEDIUM remediate by: 2026-06-01T14:38:24.736ZFIXED
npm-lodash <= 4.17.23CVE-2026-2950 MEDIUMnpm-lodash <= 4.17.23CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-2950 MEDIUM remediate by: 2026-06-09T14:23:14.879ZFIXED
npm-diff >= 6.0.0, < 8.0.3CVE-2026-24001 LOWnpm-diff >= 6.0.0, < 8.0.3CODE_REPOSITORY/commercelayer-cli-plugin-links CVE-2026-24001 LOW remediate by: 2026-06-28T22:15:22.360Z