Skip to content

[VANTA] [VULNERABILITY] <HIGH> CVE-2026-2950, CVE-2026-33671, CVE-2026-33672 and others, fix before 2026-04-29 #746

@commercelayer-ci

Description

@commercelayer-ci

Important

CLOSE THE ISSUE ONLY IF YOU PLAN TO DEPLOY THE FIX BEFORE THE DEADLINE IN THE TITLE.

DO NOT MANUALLY MODIFY THE ISSUE TITLE OR TEXT BODY.

npm-path-to-regexp < 0.1.13 CODE_REPOSITORY/commercelayer-react-components CVE-2026-4867 HIGH remediate by: 2026-04-29T14:24:03.258Z

Related URLs

npm-picomatch < 2.3.2 CODE_REPOSITORY/commercelayer-react-components CVE-2026-33671 HIGH remediate by: 2026-04-29T22:15:21.750Z

Related URLs

npm-picomatch < 2.3.2 CODE_REPOSITORY/commercelayer-react-components CVE-2026-33672 MEDIUM remediate by: 2026-05-29T22:15:22.072Z

Related URLs

npm-vite >= 7.0.0, <= 7.3.1 CODE_REPOSITORY/commercelayer-react-components CVE-2026-39363 HIGH remediate by: 2026-05-07T06:20:48.749Z

Related URLs

npm-vite >= 7.0.0, <= 7.3.1 CODE_REPOSITORY/commercelayer-react-components CVE-2026-39365 MEDIUM remediate by: 2026-06-06T14:36:41.686Z

Related URLs

npm-vite >= 6.0.0, <= 6.4.1 CODE_REPOSITORY/commercelayer-react-components CVE-2026-39363 HIGH remediate by: 2026-05-07T06:20:48.749Z

Related URLs

npm-vite >= 7.1.0, <= 7.3.1 CODE_REPOSITORY/commercelayer-react-components CVE-2026-39364 HIGH remediate by: 2026-05-07T14:36:41.372Z

Related URLs

npm-lodash >= 4.0.0, <= 4.17.23 CODE_REPOSITORY/commercelayer-react-components CVE-2026-4800 HIGH remediate by: 2026-05-10T06:21:04.459Z

Related URLs

npm-vite <= 6.4.1 CODE_REPOSITORY/commercelayer-react-components CVE-2026-39365 MEDIUM remediate by: 2026-06-09T06:21:04.770Z

Related URLs

npm-lodash <= 4.17.23 CODE_REPOSITORY/commercelayer-react-components CVE-2026-2950 MEDIUM remediate by: 2026-06-09T14:23:14.879Z

Related URLs
FIXED npm-picomatch >= 4.0.0, < 4.0.4 CVE-2026-33671 HIGH

npm-picomatch >= 4.0.0, < 4.0.4 CODE_REPOSITORY/commercelayer-react-components CVE-2026-33671 HIGH remediate by: 2026-04-25T14:19:30.796Z

Related URLs
FIXED npm-picomatch >= 4.0.0, < 4.0.4 CVE-2026-33672 MEDIUM

npm-picomatch >= 4.0.0, < 4.0.4 CODE_REPOSITORY/commercelayer-react-components CVE-2026-33672 MEDIUM remediate by: 2026-05-25T14:19:31.055Z

Related URLs
FIXED npm-handlebars >= 4.0.0, <= 4.7.8 CVE-2026-33937 CRITICAL

npm-handlebars >= 4.0.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-react-components CVE-2026-33937 CRITICAL remediate by: 2026-04-26T22:19:27.887Z

Related URLs
FIXED npm-handlebars >= 4.0.0, <= 4.7.8 CVE-2026-33941 HIGH

npm-handlebars >= 4.0.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-react-components CVE-2026-33941 HIGH remediate by: 2026-04-26T22:19:28.149Z

Related URLs
FIXED npm-handlebars >= 4.0.0, <= 4.7.8 CVE-2026-33938 HIGH

npm-handlebars >= 4.0.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-react-components CVE-2026-33938 HIGH remediate by: 2026-04-26T22:19:28.149Z

Related URLs
FIXED npm-handlebars >= 4.0.0, <= 4.7.8 CVE-2026-33940 HIGH

npm-handlebars >= 4.0.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-react-components CVE-2026-33940 HIGH remediate by: 2026-04-26T22:19:28.149Z

Related URLs
FIXED npm-handlebars >= 4.0.0, <= 4.7.8 CVE-2026-33939 HIGH

npm-handlebars >= 4.0.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-react-components CVE-2026-33939 HIGH remediate by: 2026-04-26T22:19:28.149Z

Related URLs
FIXED npm-handlebars >= 4.0.0, <= 4.7.8 GHSA-442j-39wm-28r2 LOW

npm-handlebars >= 4.0.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-react-components GHSA-442j-39wm-28r2 LOW remediate by: 2026-06-27T22:22:40.282Z

Related URLs
FIXED npm-handlebars >= 4.0.0, < 4.7.9 CVE-2026-33916 MEDIUM

npm-handlebars >= 4.0.0, < 4.7.9 CODE_REPOSITORY/commercelayer-react-components CVE-2026-33916 MEDIUM remediate by: 2026-05-26T06:15:32.686Z

Related URLs
FIXED npm-yaml >= 2.0.0, < 2.8.3 CVE-2026-33532 MEDIUM

npm-yaml >= 2.0.0, < 2.8.3 CODE_REPOSITORY/commercelayer-react-components CVE-2026-33532 MEDIUM remediate by: 2026-05-26T06:15:32.686Z

Related URLs
FIXED npm-brace-expansion >= 4.0.0, < 5.0.5 CVE-2026-33750 MEDIUM

npm-brace-expansion >= 4.0.0, < 5.0.5 CODE_REPOSITORY/commercelayer-react-components CVE-2026-33750 MEDIUM remediate by: 2026-05-26T22:19:28.497Z

Related URLs
FIXED npm-brace-expansion >= 2.0.0, < 2.0.3 CVE-2026-33750 MEDIUM

npm-brace-expansion >= 2.0.0, < 2.0.3 CODE_REPOSITORY/commercelayer-react-components CVE-2026-33750 MEDIUM remediate by: 2026-05-28T22:22:39.992Z

Related URLs
FIXED npm-handlebars >= 4.6.0, <= 4.7.8 GHSA-7rx3-28cr-v5wh MEDIUM

npm-handlebars >= 4.6.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-react-components GHSA-7rx3-28cr-v5wh MEDIUM remediate by: 2026-05-28T22:22:39.992Z

Related URLs

Metadata

Metadata

Labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions