> [!IMPORTANT] > CLOSE THE ISSUE ONLY IF YOU PLAN TO DEPLOY THE FIX BEFORE THE DEADLINE IN THE TITLE. > > DO NOT MANUALLY MODIFY THE ISSUE TITLE OR TEXT BODY. `npm-brace-expansion >= 4.0.0, < 5.0.8` CODE_REPOSITORY/commercelayer-cli <ins>CVE-2026-14257</ins> **HIGH** remediate by: 2026-08-31T19:47:04.660Z - https://github.com/commercelayer/commercelayer-cli/security/dependabot/149 > <details><summary>Related URLs</summary> > > - https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-mh99-v99m-4gvg > - https://nvd.nist.gov/vuln/detail/CVE-2026-14257 > - https://github.com/juliangruber/brace-expansion/commit/a1bd33999ea75262c4749fff3bbb0d1372bd07b5 > - https://github.com/juliangruber/brace-expansion > - https://www.npmjs.com/package/brace-expansion > - https://github.com/juliangruber/brace-expansion/pull/129 > - https://github.com/juliangruber/brace-expansion/pull/130 > - https://github.com/juliangruber/brace-expansion/pull/136 > - https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d > - https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031 > - https://github.com/juliangruber/brace-expansion/commit/d13ff455a58b0d56704f0111e3c2a0b16ceb06eb > - https://github.com/advisories/GHSA-mh99-v99m-4gvg > > </details> `npm-brace-expansion >= 2.0.0, < 2.1.3` CODE_REPOSITORY/commercelayer-cli <ins>CVE-2026-14257</ins> **HIGH** remediate by: 2026-09-02T03:51:53.093Z - https://github.com/commercelayer/commercelayer-cli/security/dependabot/150 > <details><summary>Related URLs</summary> > > - https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-mh99-v99m-4gvg > - https://nvd.nist.gov/vuln/detail/CVE-2026-14257 > - https://github.com/juliangruber/brace-expansion/commit/a1bd33999ea75262c4749fff3bbb0d1372bd07b5 > - https://github.com/juliangruber/brace-expansion > - https://www.npmjs.com/package/brace-expansion > - https://github.com/juliangruber/brace-expansion/pull/129 > - https://github.com/juliangruber/brace-expansion/pull/130 > - https://github.com/juliangruber/brace-expansion/pull/136 > - https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d > - https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031 > - https://github.com/juliangruber/brace-expansion/commit/d13ff455a58b0d56704f0111e3c2a0b16ceb06eb > - https://github.com/advisories/GHSA-mh99-v99m-4gvg > > </details> `npm-brace-expansion >= 4.0.0, < 5.0.9` CODE_REPOSITORY/commercelayer-cli <ins>CVE-2026-69152</ins> **HIGH** remediate by: 2026-09-03T19:43:37.470Z - https://github.com/commercelayer/commercelayer-cli/security/dependabot/156 > <details><summary>Related URLs</summary> > > - https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-rgw5-rvv9-x895 > - https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d > - https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac > - https://github.com/juliangruber/brace-expansion/commit/688a99eeaab02627c2b89ba8ba4821fecfa659cf > - https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031 > - https://nvd.nist.gov/vuln/detail/CVE-2026-69152 > - https://github.com/advisories/GHSA-rgw5-rvv9-x895 > > </details> `npm-js-yaml >= 3.0.0, < 3.15.1` CODE_REPOSITORY/commercelayer-cli <ins>GHSA-5p4m-2wfm-xmqj</ins> **HIGH** remediate by: 2026-09-10T19:49:37.685Z - https://github.com/commercelayer/commercelayer-cli/security/dependabot/165 > <details><summary>Related URLs</summary> > > - https://github.com/nodeca/js-yaml/security/advisories/GHSA-5p4m-2wfm-xmqj > - https://github.com/advisories/GHSA-5p4m-2wfm-xmqj > > </details>
Important
CLOSE THE ISSUE ONLY IF YOU PLAN TO DEPLOY THE FIX BEFORE THE DEADLINE IN THE TITLE.
DO NOT MANUALLY MODIFY THE ISSUE TITLE OR TEXT BODY.
npm-brace-expansion >= 4.0.0, < 5.0.8CODE_REPOSITORY/commercelayer-cli CVE-2026-14257 HIGH remediate by: 2026-08-31T19:47:04.660Znpm-brace-expansion >= 2.0.0, < 2.1.3CODE_REPOSITORY/commercelayer-cli CVE-2026-14257 HIGH remediate by: 2026-09-02T03:51:53.093Znpm-brace-expansion >= 4.0.0, < 5.0.9CODE_REPOSITORY/commercelayer-cli CVE-2026-69152 HIGH remediate by: 2026-09-03T19:43:37.470Znpm-js-yaml >= 3.0.0, < 3.15.1CODE_REPOSITORY/commercelayer-cli GHSA-5p4m-2wfm-xmqj HIGH remediate by: 2026-09-10T19:49:37.685Z