Skip to content

[VANTA] [VULNERABILITY] <HIGH> CVE-2026-14257, CVE-2026-69152, GHSA-5p4m-2wfm-xmqj, fix before 2026-08-31 #207

Description

@commercelayer-ci

Important

CLOSE THE ISSUE ONLY IF YOU PLAN TO DEPLOY THE FIX BEFORE THE DEADLINE IN THE TITLE.

DO NOT MANUALLY MODIFY THE ISSUE TITLE OR TEXT BODY.

npm-brace-expansion >= 4.0.0, < 5.0.8 CODE_REPOSITORY/commercelayer-cli CVE-2026-14257 HIGH remediate by: 2026-08-31T19:47:04.660Z

Related URLs

npm-brace-expansion >= 2.0.0, < 2.1.3 CODE_REPOSITORY/commercelayer-cli CVE-2026-14257 HIGH remediate by: 2026-09-02T03:51:53.093Z

Related URLs

npm-brace-expansion >= 4.0.0, < 5.0.9 CODE_REPOSITORY/commercelayer-cli CVE-2026-69152 HIGH remediate by: 2026-09-03T19:43:37.470Z

Related URLs

npm-js-yaml >= 3.0.0, < 3.15.1 CODE_REPOSITORY/commercelayer-cli GHSA-5p4m-2wfm-xmqj HIGH remediate by: 2026-09-10T19:49:37.685Z

Related URLs

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions