package-lock.json - Trivy Report - 2026-07-13 07:59:23.81845825 +0000 UTC m=+1.918403505
npm
Package
Vulnerability ID
Severity
Installed Version
Fixed Version
Links
dompurify
CVE-2025-15599
MEDIUM
2.5.4
3.2.7
https://access.redhat.com/security/cve/CVE-2025-15599
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/commit/c861f5a83fb8d90800f1680f855fee551161ac2b
https://nvd.nist.gov/vuln/detail/CVE-2025-15599
https://www.cve.org/CVERecord?id=CVE-2025-15599
https://www.vulncheck.com/advisories/dompurify-xss-via-textarea-rawtext-bypass-in-safe-for-xml
https://www.vulncheck.com/advisories/dompurify-xss-via-textarea-rawtext-bypass-in-safeforxml
dompurify
CVE-2025-26791
MEDIUM
2.5.4
3.2.4
https://access.redhat.com/security/cve/CVE-2025-26791
https://ensy.zip/posts/dompurify-323-bypass
https://ensy.zip/posts/dompurify-323-bypass/
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/commit/d18ffcb554e0001748865da03ac75dd7829f0f02
https://github.com/cure53/DOMPurify/releases/tag/3.2.4
https://nsysean.github.io/posts/dompurify-323-bypass
https://nsysean.github.io/posts/dompurify-323-bypass/
https://nvd.nist.gov/vuln/detail/CVE-2025-26791
https://www.cve.org/CVERecord?id=CVE-2025-26791
dompurify
CVE-2026-0540
MEDIUM
2.5.4
3.3.2, 2.5.9
https://access.redhat.com/security/cve/CVE-2026-0540
https://fluidattacks.com/advisories/daft
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/commit/302b51de22535cc90235472c52e3401bedd46f80
https://github.com/cure53/DOMPurify/commit/fca0a938b4261ddc9c0293a289935a9029c049f5
https://github.com/cure53/DOMPurify/releases/tag/3.3.2
https://nvd.nist.gov/vuln/detail/CVE-2026-0540
https://www.cve.org/CVERecord?id=CVE-2026-0540
https://www.vulncheck.com/advisories/dompurify-xss-via-missing-rawtext-elements-in-safe-for-xml
https://www.vulncheck.com/advisories/dompurify-xss-via-missing-rawtext-elements-in-safeforxml
dompurify
CVE-2026-41239
MEDIUM
2.5.4
3.4.0
https://access.redhat.com/security/cve/CVE-2026-41239
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/releases/tag/3.4.0
https://github.com/cure53/DOMPurify/security/advisories/GHSA-crv5-9vww-q3g8
https://nvd.nist.gov/vuln/detail/CVE-2026-41239
https://www.cve.org/CVERecord?id=CVE-2026-41239
dompurify
CVE-2026-41240
MEDIUM
2.5.4
3.4.0
https://access.redhat.com/security/cve/CVE-2026-41240
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/commit/c361baa18dbdcb3344a41110f4c48ad85bf48f80
https://github.com/cure53/DOMPurify/releases/tag/3.4.0
https://github.com/cure53/DOMPurify/security/advisories/GHSA-h7mw-gpvr-xq4m
https://nvd.nist.gov/vuln/detail/CVE-2026-41240
https://www.cve.org/CVERecord?id=CVE-2026-41240
dompurify
CVE-2026-49458
MEDIUM
2.5.4
3.4.6
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/security/advisories/GHSA-hpcv-96wg-7vj8
dompurify
CVE-2026-49459
MEDIUM
2.5.4
3.4.6
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/security/advisories/GHSA-r47g-fvhr-h676
dompurify
CVE-2026-49978
MEDIUM
2.5.4
3.4.7
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/security/advisories/GHSA-rp9w-3fw7-7cwq
dompurify
GHSA-39q2-94rc-95cp
MEDIUM
2.5.4
3.4.0
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/security/advisories/GHSA-39q2-94rc-95cp
dompurify
GHSA-76mc-f452-cxcm
MEDIUM
2.5.4
3.4.7
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/security/advisories/GHSA-76mc-f452-cxcm
dompurify
GHSA-cj63-jhhr-wcxv
MEDIUM
2.5.4
3.3.2
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/releases/tag/3.3.2
https://github.com/cure53/DOMPurify/security/advisories/GHSA-cj63-jhhr-wcxv
dompurify
GHSA-cjmm-f4jc-qw8r
MEDIUM
2.5.4
3.3.2
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/releases/tag/3.3.2
https://github.com/cure53/DOMPurify/security/advisories/GHSA-cjmm-f4jc-qw8r
dompurify
GHSA-cmwh-pvxp-8882
MEDIUM
2.5.4
3.4.11
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/security/advisories/GHSA-cmwh-pvxp-8882
dompurify
GHSA-h8r8-wccr-v5f2
MEDIUM
2.5.4
3.3.2
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/releases/tag/3.3.2
https://github.com/cure53/DOMPurify/security/advisories/GHSA-h8r8-wccr-v5f2
dompurify
GHSA-vxr8-fq34-vvx9
LOW
2.5.4
3.4.9
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/security/advisories/GHSA-vxr8-fq34-vvx9
dompurify
GHSA-x4vx-rjvf-j5p4
LOW
2.5.4
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/security/advisories/GHSA-x4vx-rjvf-j5p4
echarts
CVE-2026-45249
MEDIUM
5.6.0
6.1.0
http://www.openwall.com/lists/oss-security/2026/05/23/4
https://echarts.apache.org/en/option.html#series-lines
https://echarts.apache.org/handbook/en/best-practices/security/#passing_raw_html_safely
https://github.com/apache/echarts
https://github.com/apache/echarts/commit/1e39b00eedda0e4a0b048e099c0e13ce7149d90f
https://github.com/apache/echarts/pull/21608
https://lists.apache.org/thread/1g6xk7gd9vg1c6zyqqt2lnko10zomc3o
https://nvd.nist.gov/vuln/detail/CVE-2026-45249
follow-redirects
CVE-2022-0536
MEDIUM
1.14.7
1.14.8
https://access.redhat.com/security/cve/CVE-2022-0536
https://github.com/follow-redirects/follow-redirects
https://github.com/follow-redirects/follow-redirects/commit/62e546a99c07c3ee5e4e0718c84a6ca127c5c445
https://huntr.dev/bounties/7cf2bf90-52da-4d59-8028-a73b132de0db
https://nvd.nist.gov/vuln/detail/CVE-2022-0536
https://ubuntu.com/security/notices/USN-8217-1
https://www.cve.org/CVERecord?id=CVE-2022-0536
follow-redirects
CVE-2023-26159
MEDIUM
1.14.7
1.15.4
https://access.redhat.com/security/cve/CVE-2023-26159
https://github.com/follow-redirects/follow-redirects
https://github.com/follow-redirects/follow-redirects/commit/7a6567e16dfa9ad18a70bfe91784c28653fbf19d
https://github.com/follow-redirects/follow-redirects/issues/235
https://github.com/follow-redirects/follow-redirects/pull/236
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZZ425BFKNBQ6AK7I5SAM56TWON5OF2XM
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZZ425BFKNBQ6AK7I5SAM56TWON5OF2XM/
https://nvd.nist.gov/vuln/detail/CVE-2023-26159
https://security.netapp.com/advisory/ntap-20241108-0002
https://security.netapp.com/advisory/ntap-20241108-0002/
https://security.snyk.io/vuln/SNYK-JS-FOLLOWREDIRECTS-6141137
https://ubuntu.com/security/notices/USN-8217-1
https://www.cve.org/CVERecord?id=CVE-2023-26159
follow-redirects
CVE-2024-28849
MEDIUM
1.14.7
1.15.6
https://access.redhat.com/security/cve/CVE-2024-28849
https://fetch.spec.whatwg.org/#authentication-entries
https://github.com/follow-redirects/follow-redirects
https://github.com/follow-redirects/follow-redirects/commit/c4f847f85176991f95ab9c88af63b1294de8649b
https://github.com/follow-redirects/follow-redirects/commit/c4f847f85176991f95ab9c88af63b1294de8649b%20%28v1.15.6%29
https://github.com/follow-redirects/follow-redirects/security/advisories/GHSA-cxjh-pqwp-8mfp
https://github.com/psf/requests/issues/1885
https://hackerone.com/reports/2390009
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOIF4EPQUCKDBEVTGRQDZ3CGTYQHPO7Z
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOIF4EPQUCKDBEVTGRQDZ3CGTYQHPO7Z/
https://nvd.nist.gov/vuln/detail/CVE-2024-28849
https://ubuntu.com/security/notices/USN-8217-1
https://www.cve.org/CVERecord?id=CVE-2024-28849
follow-redirects
GHSA-r4q5-vmmm-2653
MEDIUM
1.14.7
1.16.0
https://github.com/follow-redirects/follow-redirects
https://github.com/follow-redirects/follow-redirects/commit/844c4d302ac963d29bdb5dc1754ec7df3d70d7f9
https://github.com/follow-redirects/follow-redirects/security/advisories/GHSA-r4q5-vmmm-2653
katex
CVE-2024-28243
MEDIUM
0.12.0
0.16.10
https://github.com/KaTeX/KaTeX
https://github.com/KaTeX/KaTeX/commit/e88b4c357f978b1bca8edfe3297f0aa309bcbe34
https://github.com/KaTeX/KaTeX/commit/e88b4c357f978b1bca8edfe3297f0aa309bcbe34%20%28v0.16.10%29
https://github.com/KaTeX/KaTeX/security/advisories/GHSA-64fm-8hw2-v72w
https://github.com/github/advisory-database/pull/6777
https://nvd.nist.gov/vuln/detail/CVE-2024-28243
https://ubuntu.com/security/notices/USN-7572-1
https://www.cve.org/CVERecord?id=CVE-2024-28243
katex
CVE-2024-28245
MEDIUM
0.12.0
0.16.10
https://github.com/KaTeX/KaTeX
https://github.com/KaTeX/KaTeX/commit/c5897fcd1f73da9612a53e6b5544f1d776e17770
https://github.com/KaTeX/KaTeX/commit/c5897fcd1f73da9612a53e6b5544f1d776e17770%20%28v0.16.10%29
https://github.com/KaTeX/KaTeX/security/advisories/GHSA-f98w-7cxr-ff2h
https://nvd.nist.gov/vuln/detail/CVE-2024-28245
https://ubuntu.com/security/notices/USN-7572-1
https://www.cve.org/CVERecord?id=CVE-2024-28245
katex
CVE-2024-28246
MEDIUM
0.12.0
0.16.10
https://github.com/KaTeX/KaTeX
https://github.com/KaTeX/KaTeX/commit/fc5af64183a3ceb9be9d1c23a275999a728593de
https://github.com/KaTeX/KaTeX/commit/fc5af64183a3ceb9be9d1c23a275999a728593de%20%28v0.16.10%29
https://github.com/KaTeX/KaTeX/security/advisories/GHSA-3wc5-fcw2-2329
https://nvd.nist.gov/vuln/detail/CVE-2024-28246
https://ubuntu.com/security/notices/USN-7572-1
https://www.cve.org/CVERecord?id=CVE-2024-28246
katex
CVE-2025-23207
MEDIUM
0.12.0
0.16.21
https://access.redhat.com/security/cve/CVE-2025-23207
https://github.com/KaTeX/KaTeX
https://github.com/KaTeX/KaTeX/commit/ff289955e81aab89086eef09254cbf88573d415c
https://github.com/KaTeX/KaTeX/commit/ff289955e81aab89086eef09254cbf88573d415c%20%28v0.16.21%29
https://github.com/KaTeX/KaTeX/security/advisories/GHSA-cg87-wmx4-v546
https://nvd.nist.gov/vuln/detail/CVE-2025-23207
https://ubuntu.com/security/notices/USN-7572-1
https://www.cve.org/CVERecord?id=CVE-2025-23207
mermaid
CVE-2025-54881
MEDIUM
10.9.3
11.10.0, 10.9.4
https://github.com/mermaid-js/mermaid
https://github.com/mermaid-js/mermaid/commit/5c69e5fdb004a6d0a2abe97e23d26e223a059832
https://github.com/mermaid-js/mermaid/commit/685516a85ec1df64cefd4fd15f26533be87d458e
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-7rqq-prvp-x9jh
https://nvd.nist.gov/vuln/detail/CVE-2025-54881
mermaid
CVE-2026-41148
MEDIUM
10.9.3
11.15.0, 10.9.6
https://access.redhat.com/security/cve/CVE-2026-41148
https://github.com/mermaid-js/mermaid
https://github.com/mermaid-js/mermaid/commit/8fead23c59166b7bab6a39eac81acebee2859102
https://github.com/mermaid-js/mermaid/commit/e9b0f34d8d82a6260077764ee45e1d7d90957a0f
https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.15.0
https://github.com/mermaid-js/mermaid/releases/tag/v10.9.6
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-xcj9-5m2h-648r
https://mermaid.js.org/config/schema-docs/config.html#securitylevel
https://nvd.nist.gov/vuln/detail/CVE-2026-41148
https://www.cve.org/CVERecord?id=CVE-2026-41148
mermaid
CVE-2026-41149
MEDIUM
10.9.3
11.15.0, 10.9.6
https://access.redhat.com/security/cve/CVE-2026-41149
https://github.com/mermaid-js/mermaid
https://github.com/mermaid-js/mermaid/commit/37ff937f1da2e19f882fd1db01235db4d01f4056
https://github.com/mermaid-js/mermaid/commit/4e2d512bf5bf6f9de1a8f0a48da78dc4d09ac4f3
https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.15.0
https://github.com/mermaid-js/mermaid/releases/tag/v10.9.6
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-ghcm-xqfw-q4vr
https://mermaid.js.org/config/schema-docs/config.html#securitylevel
https://nvd.nist.gov/vuln/detail/CVE-2026-41149
https://www.cve.org/CVERecord?id=CVE-2026-41149
mermaid
CVE-2026-41150
MEDIUM
10.9.3
11.15.0, 10.9.6
https://access.redhat.com/security/cve/CVE-2026-41150
https://github.com/mermaid-js/mermaid
https://github.com/mermaid-js/mermaid/commit/a59ea56174712ee5430dfd5bc877cb5151f501a6
https://github.com/mermaid-js/mermaid/commit/faafb5d49106dd32c367f3882505f2dd625aa30e
https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.15.0
https://github.com/mermaid-js/mermaid/releases/tag/v10.9.6
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-6m6c-36f7-fhxh
https://nvd.nist.gov/vuln/detail/CVE-2026-41150
https://www.cve.org/CVERecord?id=CVE-2026-41150
mermaid
CVE-2026-41159
MEDIUM
10.9.3
11.15.0, 10.9.6
https://access.redhat.com/security/cve/CVE-2026-41159
https://github.com/mermaid-js/mermaid
https://github.com/mermaid-js/mermaid/commit/64769738d5b59211e1decb471ffbaca8afec51aa
https://github.com/mermaid-js/mermaid/commit/64769738d5b59211e1decb471ffbaca8afec51aahttps://github.com/mermaid-js/mermaid/commit/a9d9f0d8eb790349121508688cd338253fd80d76
https://github.com/mermaid-js/mermaid/commit/a9d9f0d8eb790349121508688cd338253fd80d76
https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.15.0
https://github.com/mermaid-js/mermaid/releases/tag/v10.9.6
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-87f9-hvmw-gh4p
https://nvd.nist.gov/vuln/detail/CVE-2026-41159
https://www.cve.org/CVERecord?id=CVE-2026-41159
uuid
CVE-2026-41907
MEDIUM
9.0.1
11.1.1, 12.0.1, 13.0.1
https://access.redhat.com/security/cve/CVE-2026-41907
https://github.com/uuidjs/uuid
https://github.com/uuidjs/uuid/commit/32389c887c9e75f90442ee4cc95bbab0c4e8346e
https://github.com/uuidjs/uuid/commit/3d2c5b0342f0fcb52a5ac681c3d47c13e7444b34
https://github.com/uuidjs/uuid/commit/3d61d6ac1f782cf6b1dd8661c60f11722cd49a0d
https://github.com/uuidjs/uuid/commit/9d27ddf7046ce496ef39569ff84d948eeff9cb2a
https://github.com/uuidjs/uuid/releases/tag/v11.1.1
https://github.com/uuidjs/uuid/releases/tag/v12.0.1
https://github.com/uuidjs/uuid/releases/tag/v13.0.1
https://github.com/uuidjs/uuid/releases/tag/v14.0.0
https://github.com/uuidjs/uuid/security/advisories/GHSA-w5hq-g745-h8pq
https://nvd.nist.gov/vuln/detail/CVE-2026-41907
https://www.cve.org/CVERecord?id=CVE-2026-41907
vue
CVE-2024-9506
LOW
2.7.16
3.0.0-alpha.0
https://access.redhat.com/security/cve/CVE-2024-9506
https://github.com/vuejs/core
https://nvd.nist.gov/vuln/detail/CVE-2024-9506
https://www.cve.org/CVERecord?id=CVE-2024-9506
https://www.herodevs.com/vulnerability-directory/cve-2024-9506
vue-template-compiler
CVE-2024-6783
MEDIUM
2.7.16
3.0.0
https://github.com/advisories/GHSA-g3ch-rx76-35fx
https://github.com/vuejs/vue
https://nvd.nist.gov/vuln/detail/CVE-2024-6783
https://www.herodevs.com/vulnerability-directory/cve-2024-6783
https://www.herodevs.com/vulnerability-directory/cve-2024-6783---vue-client-side-xss
No Misconfigurations found
dockerfile
No Vulnerabilities found
No Misconfigurations found