Packages you depend on that have known security holes (CVEs).
-
Serious CVE-2025-7783 form-data: Unsafe random function in form-data
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2025-7783). Fix: Update that package to its patched version.
-
Serious CVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bomb
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2026-59873). Fix: Update that package to its patched version.
-
Serious CVE-2026-54466 websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2026-54466). Fix: Update that package to its patched version.
-
Worth fixing CVE-2025-69873 ajv: ReDoS via $data reference
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2025-69873). Fix: Update that package to its patched version.
-
Worth fixing CVE-2025-69873 ajv: ReDoS via $data reference
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2025-69873). Fix: Update that package to its patched version.
-
Worth fixing CVE-2026-13149 brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2026-13149). Fix: Update that package to its patched version.
-
Worth fixing CVE-2026-14257 brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2026-14257). Fix: Update that package to its patched version.
-
Worth fixing CVE-2026-69152 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2026-69152). Fix: Update that package to its patched version.
-
Worth fixing CVE-2026-33750 brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2026-33750). Fix: Update that package to its patched version.
-
Worth fixing CVE-2024-4068 braces: fails to limit the number of characters it can handle
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2024-4068). Fix: Update that package to its patched version.
-
Worth fixing CVE-2024-4068 braces: fails to limit the number of characters it can handle
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2024-4068). Fix: Update that package to its patched version.
-
Worth fixing CVE-2024-21538 cross-spawn: regular expression denial of service
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2024-21538). Fix: Update that package to its patched version.
-
Worth fixing CVE-2026-32141 flatted: flatted: Unbounded recursion DoS in parse() revive phase
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2026-32141). Fix: Update that package to its patched version.
-
Worth fixing CVE-2026-33228 flatted: Flatted: Prototype pollution vulnerability allows arbitrary code execution via crafted JSON.
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2026-33228). Fix: Update that package to its patched version.
-
Worth fixing CVE-2026-12143 form-data: form-data: Form field override via CRLF injection
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2026-12143). Fix: Update that package to its patched version.
-
Worth fixing CVE-2026-59869 js-yaml: js-yaml: Denial of Service via crafted YAML documents
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2026-59869). Fix: Update that package to its patched version.
-
Worth fixing GHSA-5p4m-2wfm-xmqj JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (GHSA-5p4m-2wfm-xmqj). Fix: Update that package to its patched version.
-
Worth fixing CVE-2025-64718 js-yaml: js-yaml prototype pollution in merge
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2025-64718). Fix: Update that package to its patched version.
-
Worth fixing CVE-2026-53550 js-yaml: js-yaml: Denial of Service via crafted YAML merge keys
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2026-53550). Fix: Update that package to its patched version.
-
Worth fixing CVE-2026-4800 lodash: lodash: Arbitrary code execution via untrusted input in template imports
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2026-4800). Fix: Update that package to its patched version.
-
Worth fixing CVE-2025-13465 lodash: prototype pollution in _.unset and _.omit functions
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2025-13465). Fix: Update that package to its patched version.
-
Worth fixing CVE-2026-2950 lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2026-2950). Fix: Update that package to its patched version.
-
Worth fixing CVE-2024-4067 micromatch: vulnerable to Regular Expression Denial of Service
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2024-4067). Fix: Update that package to its patched version.
-
Worth fixing CVE-2024-4067 micromatch: vulnerable to Regular Expression Denial of Service
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2024-4067). Fix: Update that package to its patched version.
-
Worth fixing CVE-2022-3517 nodejs-minimatch: ReDoS via the braceExpand function
cirq-web/cirq_ts/package-lock.json
A package you depend on has a known security hole (CVE-2022-3517). Fix: Update that package to its patched version.