Skip to content

[VANTA] [VULNERABILITY] <HIGH> CVE-2026-26996, fix before 2026-03-27 #51

@commercelayer-ci

Description

@commercelayer-ci

Important

CLOSE THE ISSUE ONLY IF YOU PLAN TO DEPLOY THE FIX BEFORE THE DEADLINE IN THE TITLE.

DO NOT MANUALLY MODIFY THE ISSUE TITLE OR TEXT BODY.

npm-fast-xml-parser >= 5.0.9, <= 5.3.3 CODE_REPOSITORY/commercelayer-cli-plugin-microstore CVE-2026-25128 HIGH remediate by: 2026-03-13T22:15:20.604Z
Related URLs
npm-lodash-es >= 4.0.0, <= 4.17.22 CODE_REPOSITORY/commercelayer-cli-plugin-microstore CVE-2025-13465 MEDIUM remediate by: 2026-03-23T06:15:19.249Z
Related URLs
npm-lodash >= 4.0.0, <= 4.17.22 CODE_REPOSITORY/commercelayer-cli-plugin-microstore CVE-2025-13465 MEDIUM remediate by: 2026-03-23T06:15:19.249Z
Related URLs
npm-undici < 6.23.0 CODE_REPOSITORY/commercelayer-cli-plugin-microstore CVE-2026-22036 MEDIUM remediate by: 2026-03-23T23:28:22.790Z
Related URLs
npm-undici >= 7.0.0, < 7.18.2 CODE_REPOSITORY/commercelayer-cli-plugin-microstore CVE-2026-22036 MEDIUM remediate by: 2026-03-23T23:28:22.790Z
Related URLs
npm-minimatch >= 5.0.0, < 5.1.7 CODE_REPOSITORY/commercelayer-cli-plugin-microstore CVE-2026-26996 HIGH remediate by: 2026-03-27T08:50:05.811Z
Related URLs
npm-minimatch < 3.1.3 CODE_REPOSITORY/commercelayer-cli-plugin-microstore CVE-2026-26996 HIGH remediate by: 2026-03-27T08:50:05.811Z
Related URLs
FIXED npm-minimatch >= 9.0.0, < 9.0.6 CVE-2026-26996 HIGH

npm-minimatch >= 9.0.0, < 9.0.6 CODE_REPOSITORY/commercelayer-cli-plugin-microstore CVE-2026-26996 HIGH remediate by: 2026-03-27T08:50:05.811Z

Related URLs
npm-minimatch >= 5.0.0, < 5.1.8 CODE_REPOSITORY/commercelayer-cli-plugin-microstore CVE-2026-27904 HIGH remediate by: 2026-03-30T06:15:08.603Z
Related URLs
npm-minimatch >= 5.0.0, < 5.1.8 CODE_REPOSITORY/commercelayer-cli-plugin-microstore CVE-2026-27903 HIGH remediate by: 2026-03-30T06:15:08.603Z
Related URLs
npm-diff >= 5.0.0, < 5.2.2 CODE_REPOSITORY/commercelayer-cli-plugin-microstore CVE-2026-24001 LOW remediate by: 2026-04-21T22:15:39.536Z
Related URLs
npm-ajv < 6.14.0 CODE_REPOSITORY/commercelayer-cli-plugin-microstore CVE-2025-69873 MEDIUM remediate by: 2026-04-23T06:15:03.493Z
Related URLs

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions