Skip to content

[VANTA] [VULNERABILITY] <HIGH> CVE-2026-14257, CVE-2026-69152, GHSA-5p4m-2wfm-xmqj, fix before 2026-08-31 #207

Description

@commercelayer-ci

Important

CLOSE THE ISSUE ONLY IF YOU PLAN TO DEPLOY THE FIX BEFORE THE DEADLINE IN THE TITLE.

DO NOT MANUALLY MODIFY THE ISSUE TITLE OR TEXT BODY.

npm-brace-expansion >= 4.0.0, < 5.0.8 CODE_REPOSITORY/commercelayer-cli CVE-2026-14257 HIGH remediate by: 2026-08-31T19:47:04.660Z

Related URLs

npm-brace-expansion >= 2.0.0, < 2.1.3 CODE_REPOSITORY/commercelayer-cli CVE-2026-14257 HIGH remediate by: 2026-09-02T03:51:53.093Z

Related URLs

npm-brace-expansion >= 4.0.0, < 5.0.9 CODE_REPOSITORY/commercelayer-cli CVE-2026-69152 HIGH remediate by: 2026-09-03T19:43:37.470Z

Related URLs

npm-js-yaml >= 3.0.0, < 3.15.1 CODE_REPOSITORY/commercelayer-cli GHSA-5p4m-2wfm-xmqj HIGH remediate by: 2026-09-10T19:49:37.685Z

Related URLs

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions