Update dependency body-parser to v1.20.4 #38
Security Report
You have successfully remediated 1 vulnerabilities, but introduced 6 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|---|
CVE-941441-362681Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> forever-2.0.0.tgz (Root Library) -> forever-monitor-2.0.0.tgz -> chokidar-2.1.8.tgz -> fsevents-1.2.9.tgz -> node-pre-gyp-0.12.0.tgz -> rimraf-2.6.3.tgz -> glob-7.1.3.tgz -> ❌ once-1.4.0.tgz (Vulnerable Library) |
9.8 | Transitive once-1.4.0.tgz |
forever-2.0.0.tgz | #3 | ||
CVE-398484-724968Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> core-7.23.2.tgz (Root Library) -> traverse-7.29.0.tgz -> debug-4.4.3.tgz -> ❌ ms-2.1.3.tgz (Vulnerable Library) |
9.8 | Transitive ms-2.1.3.tgz |
core-7.23.2.tgz | None | ||
CVE-289561-266276Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> body-parser-1.20.4.tgz (Root Library) -> raw-body-2.5.3.tgz -> http-errors-2.0.1.tgz -> ❌ inherits-2.0.4.tgz (Vulnerable Library) |
9.8 | Transitive inherits-2.0.4.tgz |
body-parser-1.20.4.tgz | None | ||
CVE-214679-86261Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> forever-2.0.0.tgz (Root Library) -> forever-monitor-2.0.0.tgz -> chokidar-2.1.8.tgz -> fsevents-1.2.9.tgz -> node-pre-gyp-0.12.0.tgz -> nopt-4.0.1.tgz -> osenv-0.1.5.tgz -> ❌ os-tmpdir-1.0.2.tgz (Vulnerable Library) |
9.8 | Transitive os-tmpdir-1.0.2.tgz |
forever-2.0.0.tgz | #3 | ||
CVE-2026-41239Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> ❌ dompurify-2.5.9.tgz (Vulnerable Library) |
6.8 | Direct dompurify-2.5.9.tgz |
dompurify-2.5.9.tgz | Upgrade to version dompurify - 3.4.0 or greater | None | |
CVE-2026-41240Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> ❌ dompurify-2.5.9.tgz (Vulnerable Library) |
6.5 | Direct dompurify-2.5.9.tgz |
dompurify-2.5.9.tgz | Upgrade to version dompurify - 3.4.0 or greater | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-506311-612488 | content-type-1.0.4.tgz |
Base branch total remaining vulnerabilities: 80
Base branch commit: 716fe17b8d26ad794de274101da05107a712797c
Total libraries scanned: 446
Scan token: e4a921410ada48bca2c5f80f7d656e0d