π Security Alerts β IBM/template-node-typescript
Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.
SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only β
they will never trigger warnings or archiving.
π‘ Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings β Advanced Security β Dependabot security updates β Enable.
π New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.
Attention: (no direct admin collaborators assigned to this repo β please add an admin to receive security notifications)
Dependabot Alerts
| Severity |
CVE/GHSA |
Package |
Affected |
Patched |
Fix PR |
| π΄ critical |
CVE-2023-45133 |
@babel/traverse |
< 7.23.2 |
7.23.2 |
β |
| π‘ medium |
CVE-2023-26159 |
follow-redirects |
< 1.15.4 |
1.15.4 |
β |
| π‘ medium |
CVE-2023-45857 |
axios |
>= 0.8.1, < 0.28.0 |
0.28.0 |
β |
| π΅ low |
CVE-2024-27088 |
es5-ext |
>= 0.10.0, < 0.10.63 |
0.10.63 |
β |
| π‘ medium |
CVE-2024-28849 |
follow-redirects |
<= 1.15.5 |
1.15.6 |
β |
| π‘ medium |
CVE-2024-29041 |
express |
< 4.19.2 |
4.19.2 |
β |
| π‘ medium |
CVE-2024-43788 |
webpack |
>= 5.0.0-alpha.0, < 5.94.0 |
5.94.0 |
β |
| π high |
CVE-2024-45296 |
path-to-regexp |
< 0.1.10 |
0.1.10 |
β |
| π high |
CVE-2024-45590 |
body-parser |
< 1.20.3 |
1.20.3 |
β |
| π΅ low |
CVE-2024-43796 |
express |
< 4.20.0 |
4.20.0 |
β |
| π΅ low |
CVE-2024-43800 |
serve-static |
< 1.16.0 |
1.16.0 |
β |
| π΅ low |
CVE-2024-43799 |
send |
< 0.19.0 |
0.19.0 |
β |
| π΅ low |
CVE-2024-47764 |
cookie |
< 0.7.0 |
0.7.0 |
β |
| π high |
CVE-2024-21538 |
cross-spawn |
>= 7.0.0, < 7.0.5 |
7.0.5 |
β |
| π high |
CVE-2024-52798 |
path-to-regexp |
< 0.1.12 |
0.1.12 |
β |
| π‘ medium |
CVE-2024-11831 |
serialize-javascript |
>= 6.0.0, < 6.0.2 |
6.0.2 |
β |
| π΅ low |
CVE-2025-46653 |
formidable |
>= 2.1.0, < 2.1.3 |
2.1.3 |
β |
| π high |
CVE-2025-48997 |
multer |
>= 1.4.4-lts.1, < 2.0.1 |
2.0.1 |
β |
| π΅ low |
CVE-2025-5889 |
brace-expansion |
>= 2.0.0, <= 2.0.1 |
2.0.2 |
β |
| π high |
CVE-2025-7338 |
multer |
>= 1.4.4-lts.1, < 2.0.2 |
2.0.2 |
β |
| π΄ critical |
CVE-2025-7783 |
form-data |
>= 4.0.0, < 4.0.4 |
4.0.4 |
β |
| π΅ low |
CVE-2025-54798 |
tmp |
<= 0.2.3 |
0.2.4 |
β |
| π‘ medium |
CVE-2025-64718 |
js-yaml |
>= 4.0.0, < 4.1.1 |
4.1.1 |
β |
| π‘ medium |
CVE-2025-15284 |
qs |
< 6.14.1 |
6.14.1 |
β |
| π‘ medium |
CVE-2025-13465 |
lodash |
>= 4.0.0, <= 4.17.22 |
4.17.23 |
β |
| π΅ low |
CVE-2025-68458 |
webpack |
>= 5.49.0, <= 5.104.0 |
5.104.1 |
β |
| π΅ low |
CVE-2025-68157 |
webpack |
>= 5.49.0, < 5.104.0 |
5.104.0 |
β |
| π΅ low |
CVE-2026-2391 |
qs |
>= 6.7.0, <= 6.14.1 |
6.14.2 |
β |
| π high |
CVE-2026-25639 |
axios |
<= 0.30.2 |
0.30.3 |
β |
| π high |
CVE-2026-26996 |
minimatch |
>= 5.0.0, < 5.1.7 |
5.1.7 |
β |
| π high |
CVE-2026-27903 |
minimatch |
>= 8.0.0, < 8.0.6 |
8.0.6 |
β |
| π high |
CVE-2026-27904 |
minimatch |
>= 5.0.0, < 5.1.8 |
5.1.8 |
β |
| π high |
GHSA-5c6j-r48x-rmvq |
serialize-javascript |
<= 7.0.2 |
7.0.3 |
β |
| π high |
CVE-2026-2359 |
multer |
< 2.1.0 |
2.1.0 |
β |
| π high |
CVE-2026-3304 |
multer |
< 2.1.0 |
2.1.0 |
β |
| π high |
CVE-2026-27601 |
underscore |
<= 1.13.7 |
1.13.8 |
β |
| π high |
CVE-2026-3520 |
multer |
< 2.1.1 |
2.1.1 |
β |
| π high |
CVE-2026-33228 |
flatted |
<= 3.4.1 |
3.4.2 |
β |
| π‘ medium |
CVE-2026-33672 |
picomatch |
< 2.3.2 |
2.3.2 |
β |
| π‘ medium |
CVE-2026-33750 |
brace-expansion |
>= 2.0.0, < 2.0.3 |
2.0.3 |
β |
| π high |
CVE-2026-4867 |
path-to-regexp |
< 0.1.13 |
0.1.13 |
β |
| π‘ medium |
CVE-2026-2950 |
lodash |
<= 4.17.23 |
4.18.0 |
β |
| π high |
CVE-2026-4800 |
lodash |
>= 4.0.0, <= 4.17.23 |
4.18.0 |
β |
| π‘ medium |
CVE-2026-35515 |
@nestjs/core |
<= 11.1.17 |
11.1.18 |
β |
| π‘ medium |
GHSA-r4q5-vmmm-2653 |
follow-redirects |
<= 1.15.11 |
1.16.0 |
β |
| π‘ medium |
CVE-2026-40175 |
axios |
< 0.31.0 |
0.31.0 |
β |
| π‘ medium |
CVE-2025-62718 |
axios |
< 0.31.0 |
0.31.0 |
β |
| π high |
CVE-2026-42043 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π΅ low |
CVE-2026-42040 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π‘ medium |
CVE-2026-42041 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π‘ medium |
CVE-2026-42042 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π‘ medium |
CVE-2026-42036 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π high |
CVE-2026-42033 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π high |
CVE-2026-42035 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π‘ medium |
CVE-2026-42039 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π‘ medium |
CVE-2026-42034 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π‘ medium |
CVE-2026-42038 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π‘ medium |
CVE-2026-34043 |
serialize-javascript |
>= 5.0.0, < 7.0.5 |
7.0.5 |
β |
| π high |
CVE-2026-44705 |
tmp |
< 0.2.6 |
0.2.6 |
β |
| π‘ medium |
CVE-2026-44490 |
axios |
<= 0.31.1 |
0.32.0 |
β |
| π high |
CVE-2026-44492 |
axios |
<= 0.31.1 |
0.32.0 |
β |
| π high |
CVE-2026-44495 |
axios |
>= 0.19.0, < 0.31.1 |
0.31.1 |
β |
| π high |
CVE-2026-44487 |
axios |
<= 0.31.1 |
0.32.0 |
β |
| π high |
CVE-2026-44486 |
axios |
<= 0.31.1 |
0.32.0 |
β |
| π high |
CVE-2026-44496 |
axios |
<= 0.31.1 |
0.32.0 |
β |
| π high |
CVE-2026-12143 |
form-data |
>= 4.0.0, < 4.0.6 |
4.0.6 |
β |
| π΅ low |
CVE-2026-49356 |
@babel/core |
<= 7.29.0 |
7.29.6 |
β |
| π high |
CVE-2026-5079 |
multer |
>= 1.0.0, < 2.2.0 |
2.2.0 |
β |
| π‘ medium |
CVE-2026-53550 |
js-yaml |
>= 4.0.0, <= 4.1.1 |
4.2.0 |
β |
| π high |
CVE-2026-13149 |
brace-expansion |
>= 2.0.0, < 2.1.2 |
2.1.2 |
β |
| π high |
CVE-2026-59869 |
js-yaml |
>= 4.0.0, < 4.3.0 |
4.3.0 |
β |
| π΅ low |
CVE-2026-12590 |
body-parser |
< 1.20.6 |
1.20.6 |
β |
| π‘ medium |
CVE-2026-67316 |
axios |
< 0.33.0 |
0.33.0 |
β |
| π‘ medium |
CVE-2026-67319 |
axios |
>= 0.8.0, < 0.33.0 |
0.33.0 |
β |
| π high |
CVE-2026-14257 |
brace-expansion |
>= 2.0.0, < 2.1.3 |
2.1.3 |
β |
| π high |
CVE-2026-69152 |
brace-expansion |
>= 2.0.0, < 2.1.4 |
2.1.4 |
β |
| π high |
GHSA-5p4m-2wfm-xmqj |
js-yaml |
>= 3.0.0, < 3.15.1 |
3.15.1 |
β |
| π high |
CVE-2026-73088 |
browserslist |
<= 4.28.6 |
4.28.7 |
β |
| π‘ medium |
CVE-2026-82417 |
qs |
>= 2.2.5, < 6.16.0 |
6.16.0 |
β |
| π high |
CVE-2026-84375 |
js-yaml |
>= 4.0.0, < 4.3.2 |
4.3.2 |
β |
| π high |
CVE-2026-77078 |
multer |
< 2.3.0 |
2.3.0 |
β |
| π΅ low |
CVE-2026-77063 |
multer |
< 2.3.0 |
2.3.0 |
β |
| π high |
CVE-2026-82333 |
multer |
< 2.3.0 |
2.3.0 |
β |
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.
π Security Alerts β IBM/template-node-typescript
Attention: (no direct admin collaborators assigned to this repo β please add an admin to receive security notifications)
Dependabot Alerts
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.