-
-
Notifications
You must be signed in to change notification settings - Fork 0
Description
Vulnerable Library - @storm-stack/core-0.47.0.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Vulnerabilities
| Vulnerability | Severity | Dependency | Type | Fixed in (@storm-stack/core version) | Remediation Possible** | |
|---|---|---|---|---|---|---|
| CVE-2026-27606 | 9.1 | detected in multiple dependencies | Transitive | N/A* | ❌ | |
| CVE-2025-12816 | 8.6 | node-forge-1.3.1.tgz | Transitive | 0.48.0 | ❌ | |
| CVE-2026-33671 | 7.5 | detected in multiple dependencies | Transitive | N/A* | ❌ | |
| CVE-2026-22775 | 7.5 | devalue-5.3.2.tgz | Transitive | 0.48.0 | ❌ | |
| CVE-2026-22774 | 7.5 | devalue-5.3.2.tgz | Transitive | 0.48.0 | ❌ | |
| CVE-2025-66031 | 7.5 | node-forge-1.3.1.tgz | Transitive | 0.48.0 | ❌ | |
| CVE-2025-64756 | 7.5 | detected in multiple dependencies | Transitive | 0.48.0 | ❌ | |
| CVE-2025-13465 | 7.2 | lodash-4.17.21.tgz | Transitive | N/A* | ❌ | |
| CVE-2025-64764 | 7.1 | astro-5.14.1.tgz | Transitive | N/A* | ❌ | |
| CVE-2025-69874 | 6.5 | nanotar-0.2.0.tgz | Transitive | N/A* | ❌ | |
| CVE-2025-66202 | 6.5 | astro-5.14.1.tgz | Transitive | N/A* | ❌ | |
| CVE-2025-64525 | 6.5 | astro-5.14.1.tgz | Transitive | 0.48.0 | ❌ | |
| CVE-2025-62522 | 6.5 | detected in multiple dependencies | Transitive | N/A* | ❌ | |
| CVE-2025-61925 | 6.5 | astro-5.14.1.tgz | Transitive | 0.48.0 | ❌ | |
| CVE-2025-65019 | 5.4 | detected in multiple dependencies | Transitive | 0.48.0 | ❌ | |
| CVE-2026-33769 | 5.3 | astro-5.14.1.tgz | Transitive | 0.48.0 | ❌ | |
| CVE-2026-33672 | 5.3 | detected in multiple dependencies | Transitive | N/A* | ❌ | |
| CVE-2026-24001 | 5.3 | diff-5.2.0.tgz | Transitive | N/A* | ❌ | |
| CVE-2025-66400 | 5.3 | mdast-util-to-hast-13.2.0.tgz | Transitive | N/A* | ❌ | |
| CVE-2025-66030 | 5.3 | node-forge-1.3.1.tgz | Transitive | 0.48.0 | ❌ | |
| CVE-2025-64765 | 5.3 | astro-5.14.1.tgz | Transitive | N/A* | ❌ | |
| CVE-2025-64718 | 5.3 | js-yaml-4.1.0.tgz | Transitive | N/A* | ❌ | |
| CVE-2026-33532 | 4.3 | yaml-1.10.2.tgz | Transitive | N/A* | ❌ | |
| CVE-2026-30226 | 3.7 | devalue-5.3.2.tgz | Transitive | 0.48.0 | ❌ | |
| CVE-2026-2391 | 3.7 | qs-6.13.0.tgz | Transitive | 0.48.0 | ❌ | |
| CVE-2025-68458 | 3.7 | webpack-5.102.0.tgz | Transitive | 0.48.0 | ❌ | |
| CVE-2025-68157 | 3.7 | webpack-5.102.0.tgz | Transitive | 0.48.0 | ❌ | |
| CVE-2025-15284 | 3.7 | qs-6.13.0.tgz | Transitive | 0.48.0 | ❌ | |
| CVE-2025-64757 | 3.5 | astro-5.14.1.tgz | Transitive | N/A* | ❌ | |
| CVE-2025-69873 | 2.9 | detected in multiple dependencies | Transitive | N/A* | ❌ | |
| CVE-2025-64745 | 2.7 | astro-5.14.1.tgz | Transitive | 0.48.0 | ❌ |
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Partial details (20 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.
CVE-2026-27606
Vulnerable Libraries - rollup-4.52.3.tgz, rollup-4.52.2.tgz
rollup-4.52.3.tgz
Next-generation ES module bundler
Library home page: https://registry.npmjs.org/rollup/-/rollup-4.52.3.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- ❌ rollup-4.52.3.tgz (Vulnerable Library)
rollup-4.52.2.tgz
Next-generation ES module bundler
Library home page: https://registry.npmjs.org/rollup/-/rollup-4.52.2.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- rollup-plugin-typescript2-0.36.0.tgz
- ❌ rollup-4.52.2.tgz (Vulnerable Library)
- rollup-plugin-typescript2-0.36.0.tgz
Found in base branch: main
Vulnerability Details
Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure file name sanitization in the core engine allows an attacker to control output filenames (e.g., via CLI named inputs, manual chunk aliases, or malicious plugins) and use traversal sequences ("../") to overwrite files anywhere on the host filesystem that the build process has permissions for. This can lead to persistent Remote Code Execution (RCE) by overwriting critical system or user configuration files. Versions 2.80.0, 3.30.0, and 4.59.0 contain a patch for the issue.
Publish Date: 2026-02-25
URL: CVE-2026-27606
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Release Date: 2026-02-25
Fix Resolution: https://github.com/rollup/rollup.git - v2.80.0,https://github.com/rollup/rollup.git - v3.30.0,https://github.com/rollup/rollup.git - v4.59.0
Step up your Open Source Security Game with Mend here
CVE-2025-12816
Vulnerable Library - node-forge-1.3.1.tgz
JavaScript implementations of network transports, cryptography, ciphers, PKI, message digests, and various utilities.
Library home page: https://registry.npmjs.org/node-forge/-/node-forge-1.3.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- cli-1.5.8.tgz
- dev-server-1.1.4.tgz
- webpack-dev-server-5.2.2.tgz
- selfsigned-2.4.1.tgz
- ❌ node-forge-1.3.1.tgz (Vulnerable Library)
- selfsigned-2.4.1.tgz
- webpack-dev-server-5.2.2.tgz
- dev-server-1.1.4.tgz
- cli-1.5.8.tgz
Found in base branch: main
Vulnerability Details
An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.
Publish Date: 2025-11-25
URL: CVE-2025-12816
CVSS 3 Score Details (8.6)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: GHSA-5gfm-wpxj-wjgq
Release Date: 2025-11-25
Fix Resolution (node-forge): 1.3.2
Direct dependency fix Resolution (@storm-stack/core): 0.48.0
Step up your Open Source Security Game with Mend here
CVE-2026-33671
Vulnerable Libraries - picomatch-2.3.1.tgz, picomatch-4.0.2.tgz, picomatch-4.0.3.tgz
picomatch-2.3.1.tgz
Blazing fast and accurate glob matcher written in JavaScript, with no dependencies and full support for standard and extended Bash glob features, including braces, extglobs, POSIX brackets, and regular expressions.
Library home page: https://registry.npmjs.org/picomatch/-/picomatch-2.3.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- rollup-plugin-typescript2-0.36.0.tgz
- pluginutils-4.2.1.tgz
- ❌ picomatch-2.3.1.tgz (Vulnerable Library)
- pluginutils-4.2.1.tgz
- rollup-plugin-typescript2-0.36.0.tgz
picomatch-4.0.2.tgz
Library home page: https://registry.npmjs.org/picomatch/-/picomatch-4.0.2.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- build-tools-0.157.2.tgz
- js-21.5.3.tgz
- ❌ picomatch-4.0.2.tgz (Vulnerable Library)
- js-21.5.3.tgz
- build-tools-0.157.2.tgz
picomatch-4.0.3.tgz
Blazing fast and accurate glob matcher written in JavaScript, with no dependencies and full support for standard and extended Bash glob features, including braces, extglobs, POSIX brackets, and regular expressions.
Library home page: https://registry.npmjs.org/picomatch/-/picomatch-4.0.3.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- astro-5.14.1.tgz
- ❌ picomatch-4.0.3.tgz (Vulnerable Library)
- astro-5.14.1.tgz
Found in base branch: main
Vulnerability Details
Impact "picomatch" is vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as "+()" and "()", especially when combined with overlapping alternatives or nested extglobs, are compiled into regular expressions that can exhibit catastrophic backtracking on non-matching input. Examples of problematic patterns include "+(a|aa)", "+(|?)", "+(+(a))", "(+(a))", and "+(+(+(a)))". In local reproduction, these patterns caused multi-second event-loop blocking with relatively short inputs. For example, "+(a|aa)" compiled to "^(?:(?=.)(?:a|aa)+)$" and took about 2 seconds to reject a 41-character non-matching input, while nested patterns such as "+(+(a))" and "(+(a))" took around 29 seconds to reject a 33-character input on a modern M1 MacBook. Applications are impacted when they allow untrusted users to supply glob patterns that are passed to "picomatch" for compilation or matching. In those cases, an attacker can cause excessive CPU consumption and block the Node.js event loop, resulting in a denial of service. Applications that only use trusted, developer-controlled glob patterns are much less likely to be exposed in a security-relevant way. Patches This issue is fixed in picomatch 4.0.4, 3.0.2 and 2.3.2. Users should upgrade to one of these versions or later, depending on their supported release line. Workarounds If upgrading is not immediately possible, avoid passing untrusted glob patterns to "picomatch". Possible mitigations include: - disable extglob support for untrusted patterns by using "noextglob: true" - reject or sanitize patterns containing nested extglobs or extglob quantifiers such as "+()" and "*()" - enforce strict allowlists for accepted pattern syntax - run matching in an isolated worker or separate process with time and resource limits - apply application-level request throttling and input validation for any endpoint that accepts glob patterns Resources - Picomatch repository: https://github.com/micromatch/picomatch - "lib/parse.js" and "lib/constants.js" are involved in generating the vulnerable regex forms - Comparable ReDoS precedent: CVE-2024-4067 ("micromatch") - Comparable generated-regex precedent: CVE-2024-45296 ("path-to-regexp")
Publish Date: 2026-03-25
URL: CVE-2026-33671
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Release Date: 2026-03-25
Fix Resolution: https://github.com/micromatch/picomatch.git - 3.0.2,https://github.com/micromatch/picomatch.git - 4.0.4,https://github.com/micromatch/picomatch.git - 2.3.2
Step up your Open Source Security Game with Mend here
CVE-2026-22775
Vulnerable Library - devalue-5.3.2.tgz
Gets the job done when JSON.stringify can't
Library home page: https://registry.npmjs.org/devalue/-/devalue-5.3.2.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- astro-5.14.1.tgz
- ❌ devalue-5.3.2.tgz (Vulnerable Library)
- astro-5.14.1.tgz
Found in base branch: main
Vulnerability Details
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.1.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input from untrusted sources. This affects applications using devalue.parse on externally-supplied data. The root cause is the ArrayBuffer hydration expecting base64 encoded strings as input, but not checking the assumption before decoding the input. This vulnerability is fixed in 5.6.2.
Publish Date: 2026-01-15
URL: CVE-2026-22775
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Origin: GHSA-g2pg-6438-jwpf
Release Date: 2026-01-15
Fix Resolution (devalue): 5.6.2
Direct dependency fix Resolution (@storm-stack/core): 0.48.0
Step up your Open Source Security Game with Mend here
CVE-2026-22774
Vulnerable Library - devalue-5.3.2.tgz
Gets the job done when JSON.stringify can't
Library home page: https://registry.npmjs.org/devalue/-/devalue-5.3.2.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- astro-5.14.1.tgz
- ❌ devalue-5.3.2.tgz (Vulnerable Library)
- astro-5.14.1.tgz
Found in base branch: main
Vulnerability Details
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.3.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input from untrusted sources. This affects applications using devalue.parse on externally-supplied data. The root cause is the typed array hydration expecting an ArrayBuffer as input, but not checking the assumption before creating the typed array. This vulnerability is fixed in 5.6.2.
Publish Date: 2026-01-15
URL: CVE-2026-22774
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Origin: GHSA-vw5p-8cq8-m7mv
Release Date: 2026-01-15
Fix Resolution (devalue): 5.6.2
Direct dependency fix Resolution (@storm-stack/core): 0.48.0
Step up your Open Source Security Game with Mend here
CVE-2025-66031
Vulnerable Library - node-forge-1.3.1.tgz
JavaScript implementations of network transports, cryptography, ciphers, PKI, message digests, and various utilities.
Library home page: https://registry.npmjs.org/node-forge/-/node-forge-1.3.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- cli-1.5.8.tgz
- dev-server-1.1.4.tgz
- webpack-dev-server-5.2.2.tgz
- selfsigned-2.4.1.tgz
- ❌ node-forge-1.3.1.tgz (Vulnerable Library)
- selfsigned-2.4.1.tgz
- webpack-dev-server-5.2.2.tgz
- dev-server-1.1.4.tgz
- cli-1.5.8.tgz
Found in base branch: main
Vulnerability Details
Forge (also called "node-forge") is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.
Publish Date: 2025-11-26
URL: CVE-2025-66031
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Origin: GHSA-554w-wpv2-vw27
Release Date: 2025-11-26
Fix Resolution (node-forge): 1.3.2
Direct dependency fix Resolution (@storm-stack/core): 0.48.0
Step up your Open Source Security Game with Mend here
CVE-2025-64756
Vulnerable Libraries - glob-10.4.5.tgz, glob-11.0.3.tgz
glob-10.4.5.tgz
Library home page: https://registry.npmjs.org/glob/-/glob-10.4.5.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- esbuild-0.52.14.tgz
- tsup-8.4.0.tgz
- sucrase-3.35.0.tgz
- ❌ glob-10.4.5.tgz (Vulnerable Library)
- sucrase-3.35.0.tgz
- tsup-8.4.0.tgz
- esbuild-0.52.14.tgz
glob-11.0.3.tgz
the most correct and second fastest glob implementation in JavaScript
Library home page: https://registry.npmjs.org/glob/-/glob-11.0.3.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- build-tools-0.157.2.tgz
- ❌ glob-11.0.3.tgz (Vulnerable Library)
- build-tools-0.157.2.tgz
Found in base branch: main
Vulnerability Details
Glob matches files using patterns the shell uses. Starting in version 10.2.0 and prior to versions 10.5.0 and 11.1.0, the glob CLI contains a command injection vulnerability in its -c/--cmd option that allows arbitrary command execution when processing files with malicious names. When glob -c are used, matched filenames are passed to a shell with shell: true, enabling shell metacharacters in filenames to trigger command injection and achieve arbitrary code execution under the user or CI account privileges. This issue has been patched in versions 10.5.0 and 11.1.0.
Mend Note: The description of this vulnerability differs from MITRE.
Publish Date: 2025-11-17
URL: CVE-2025-64756
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Origin: GHSA-5j98-mcp5-4vw2
Release Date: 2025-11-17
Fix Resolution (glob): 10.5.0
Direct dependency fix Resolution (@storm-stack/core): 0.48.0
Fix Resolution (glob): 10.5.0
Direct dependency fix Resolution (@storm-stack/core): 0.48.0
Step up your Open Source Security Game with Mend here
CVE-2025-13465
Vulnerable Library - lodash-4.17.21.tgz
Lodash modular utilities.
Library home page: https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- api-extractor-7.52.11.tgz
- ❌ lodash-4.17.21.tgz (Vulnerable Library)
- api-extractor-7.52.11.tgz
Found in base branch: main
Vulnerability Details
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.
The issue permits deletion of properties but does not allow overwriting their original behavior.
This issue is patched on 4.17.23
Publish Date: 2026-01-21
URL: CVE-2025-13465
CVSS 3 Score Details (7.2)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: Low
Suggested Fix
Type: Upgrade version
Origin: GHSA-xxjr-mmjv-4gpg
Release Date: 2026-01-21
Fix Resolution: lodash-amd - 4.17.23,lodash - 4.17.23,lodash-es - 4.17.23
Step up your Open Source Security Game with Mend here
CVE-2025-64764
Vulnerable Library - astro-5.14.1.tgz
Astro is a modern site builder with web best practices, performance, and DX front-of-mind.
Library home page: https://registry.npmjs.org/astro/-/astro-5.14.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- ❌ astro-5.14.1.tgz (Vulnerable Library)
Found in base branch: main
Vulnerability Details
Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feature is used in the targeted application, regardless of what was intended by the component template(s). This issue has been patched in version 5.15.8.
Publish Date: 2025-11-19
URL: CVE-2025-64764
CVSS 3 Score Details (7.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: High
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Release Date: 2025-11-19
Fix Resolution: https://github.com/withastro/astro.git - astro@5.15.8
Step up your Open Source Security Game with Mend here
CVE-2025-69874
Vulnerable Library - nanotar-0.2.0.tgz
Tiny and fast Tar utils for any JavaScript runtime!
Library home page: https://registry.npmjs.org/nanotar/-/nanotar-0.2.0.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- ❌ nanotar-0.2.0.tgz (Vulnerable Library)
Found in base branch: main
Vulnerability Details
nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containing path traversal sequence.
Publish Date: 2026-02-11
URL: CVE-2025-69874
CVSS 3 Score Details (6.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: Low
Suggested Fix
Type: Upgrade version
Release Date: 2026-02-11
Fix Resolution: nanotar - 0.3.0,https://github.com/unjs/nanotar.git - v0.3.0
Step up your Open Source Security Game with Mend here
CVE-2025-66202
Vulnerable Library - astro-5.14.1.tgz
Astro is a modern site builder with web best practices, performance, and DX front-of-mind.
Library home page: https://registry.npmjs.org/astro/-/astro-5.14.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- ❌ astro-5.14.1.tgz (Vulnerable Library)
Found in base branch: main
Vulnerability Details
Astro is a web framework. Versions 5.15.7 and below have a double URL encoding bypass which allows any unauthenticated attacker to bypass path-based authentication checks in Astro middleware, granting unauthorized access to protected routes. While the original CVE-2025-64765 was fixed in v5.15.8, the fix is insufficient as it only decodes once. By using double-encoded URLs, attackers can still bypass authentication and access any route protected by middleware pathname checks. This issue is fixed in version 5.15.8.
Publish Date: 2025-12-08
URL: CVE-2025-66202
CVSS 3 Score Details (6.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Release Date: 2025-12-09
Fix Resolution: https://github.com/withastro/astro.git - astro@5.15.8
Step up your Open Source Security Game with Mend here
CVE-2025-64525
Vulnerable Library - astro-5.14.1.tgz
Astro is a modern site builder with web best practices, performance, and DX front-of-mind.
Library home page: https://registry.npmjs.org/astro/-/astro-5.14.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- ❌ astro-5.14.1.tgz (Vulnerable Library)
Found in base branch: main
Vulnerability Details
Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers "x-forwarded-proto" and "x-forwarded-port" are insecurely used, without sanitization, to build the URL. This has several consequences, the most important of which are: middleware-based protected route bypass (only via "x-forwarded-proto"), DoS via cache poisoning (if a CDN is present), SSRF (only via "x-forwarded-proto"), URL pollution (potential SXSS, if a CDN is present), and WAF bypass. Version 5.15.5 contains a patch.
Publish Date: 2025-11-13
URL: CVE-2025-64525
CVSS 3 Score Details (6.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: Low
Suggested Fix
Type: Upgrade version
Origin: GHSA-hr2q-hp5q-x767
Release Date: 2025-11-13
Fix Resolution (astro): 5.15.5
Direct dependency fix Resolution (@storm-stack/core): 0.48.0
Step up your Open Source Security Game with Mend here
CVE-2025-62522
Vulnerable Libraries - vite-6.3.6.tgz, vite-7.1.5.tgz
vite-6.3.6.tgz
Native-ESM powered web dev build tool
Library home page: https://registry.npmjs.org/vite/-/vite-6.3.6.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- astro-5.14.1.tgz
- ❌ vite-6.3.6.tgz (Vulnerable Library)
- astro-5.14.1.tgz
vite-7.1.5.tgz
Native-ESM powered web dev build tool
Library home page: https://registry.npmjs.org/vite/-/vite-7.1.5.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- ❌ vite-7.1.5.tgz (Vulnerable Library)
Found in base branch: main
Vulnerability Details
Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0 to before 7.1.11, files denied by server.fs.deny were sent if the URL ended with \ when the dev server is running on Windows. Only apps explicitly exposing the Vite dev server to the network and running the dev server on Windows were affected. This issue has been patched in versions 5.4.21, 6.4.1, 7.0.8, and 7.1.11.
Publish Date: 2025-10-20
URL: CVE-2025-62522
CVSS 3 Score Details (6.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: GHSA-93m4-6634-74q7
Release Date: 2025-10-20
Fix Resolution: vite - 7.0.8,vite - 5.4.21,vite - 7.1.11,vite - 6.4.1
Step up your Open Source Security Game with Mend here
CVE-2025-61925
Vulnerable Library - astro-5.14.1.tgz
Astro is a modern site builder with web best practices, performance, and DX front-of-mind.
Library home page: https://registry.npmjs.org/astro/-/astro-5.14.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- ❌ astro-5.14.1.tgz (Vulnerable Library)
Found in base branch: main
Vulnerability Details
Astro is a web framework. Prior to version 5.14.2, Astro reflects the value in "X-Forwarded-Host" in output when using "Astro.url" without any validation. It is common for web servers such as nginx to route requests via the "Host" header, and forward on other request headers. As such as malicious request can be sent with both a "Host" header and an "X-Forwarded-Host" header where the values do not match and the "X-Forwarded-Host" header is malicious. Astro will then return the malicious value. This could result in any usages of the "Astro.url" value in code being manipulated by a request. For example if a user follows guidance and uses "Astro.url" for a canonical link the canonical link can be manipulated to another site. It is theoretically possible that the value could also be used as a login/registration or other form URL as well, resulting in potential redirecting of login credentials to a malicious party. As this is a per-request attack vector the surface area would only be to the malicious user until one considers that having a caching proxy is a common setup, in which case any page which is cached could persist the malicious value for subsequent users. Many other frameworks have an allowlist of domains to validate against, or do not have a case where the headers are reflected to avoid such issues. This could affect anyone using Astro in an on-demand/dynamic rendering mode behind a caching proxy. Version 5.14.2 contains a fix for the issue.
Publish Date: 2025-10-10
URL: CVE-2025-61925
CVSS 3 Score Details (6.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: Low
Suggested Fix
Type: Upgrade version
Origin: GHSA-5ff5-9fcw-vg88
Release Date: 2025-10-10
Fix Resolution (astro): 5.14.3
Direct dependency fix Resolution (@storm-stack/core): 0.48.0
Step up your Open Source Security Game with Mend here
CVE-2025-65019
Vulnerable Libraries - internal-helpers-0.7.3.tgz, astro-5.14.1.tgz
internal-helpers-0.7.3.tgz
Internal helpers used by core Astro packages.
Library home page: https://registry.npmjs.org/@astrojs/internal-helpers/-/internal-helpers-0.7.3.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- astro-5.14.1.tgz
- ❌ internal-helpers-0.7.3.tgz (Vulnerable Library)
- astro-5.14.1.tgz
astro-5.14.1.tgz
Astro is a modern site builder with web best practices, performance, and DX front-of-mind.
Library home page: https://registry.npmjs.org/astro/-/astro-5.14.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- ❌ astro-5.14.1.tgz (Vulnerable Library)
Found in base branch: main
Vulnerability Details
Astro is a web framework. Prior to version 5.15.9, when using Astro's Cloudflare adapter (@astrojs/cloudflare) with output: 'server', the image optimization endpoint (/_image) contains a critical vulnerability in the isRemoteAllowed() function that unconditionally allows data: protocol URLs. This enables Cross-Site Scripting (XSS) attacks through malicious SVG payloads, bypassing domain restrictions and Content Security Policy protections. This issue has been patched in version 5.15.9.
Publish Date: 2025-11-19
URL: CVE-2025-65019
CVSS 3 Score Details (5.4)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Release Date: 2025-11-19
Fix Resolution (@astrojs/internal-helpers): 0.7.5
Direct dependency fix Resolution (@storm-stack/core): 0.48.0
Fix Resolution (astro): 0.7.5
Direct dependency fix Resolution (@storm-stack/core): 0.48.0
Step up your Open Source Security Game with Mend here
CVE-2026-33769
Vulnerable Library - astro-5.14.1.tgz
Astro is a modern site builder with web best practices, performance, and DX front-of-mind.
Library home page: https://registry.npmjs.org/astro/-/astro-5.14.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- ❌ astro-5.14.1.tgz (Vulnerable Library)
Found in base branch: main
Vulnerability Details
Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path enforcement for remote URLs used by server-side fetchers such as the image optimization endpoint. The path matching logic for /* wildcards is unanchored, so a pathname that contains the allowed prefix later in the path can still match. As a result, an attacker can fetch paths outside the intended allowlisted prefix on an otherwise allowed host. This issue has been patched in version 5.18.1.
Publish Date: 2026-03-24
URL: CVE-2026-33769
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: None
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: GHSA-g735-7g2w-hh3f
Release Date: 2026-03-24
Fix Resolution (astro): 5.18.1
Direct dependency fix Resolution (@storm-stack/core): 0.48.0
Step up your Open Source Security Game with Mend here
CVE-2026-33672
Vulnerable Libraries - picomatch-4.0.3.tgz, picomatch-4.0.2.tgz, picomatch-2.3.1.tgz
picomatch-4.0.3.tgz
Blazing fast and accurate glob matcher written in JavaScript, with no dependencies and full support for standard and extended Bash glob features, including braces, extglobs, POSIX brackets, and regular expressions.
Library home page: https://registry.npmjs.org/picomatch/-/picomatch-4.0.3.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- astro-5.14.1.tgz
- ❌ picomatch-4.0.3.tgz (Vulnerable Library)
- astro-5.14.1.tgz
picomatch-4.0.2.tgz
Library home page: https://registry.npmjs.org/picomatch/-/picomatch-4.0.2.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- build-tools-0.157.2.tgz
- js-21.5.3.tgz
- ❌ picomatch-4.0.2.tgz (Vulnerable Library)
- js-21.5.3.tgz
- build-tools-0.157.2.tgz
picomatch-2.3.1.tgz
Blazing fast and accurate glob matcher written in JavaScript, with no dependencies and full support for standard and extended Bash glob features, including braces, extglobs, POSIX brackets, and regular expressions.
Library home page: https://registry.npmjs.org/picomatch/-/picomatch-2.3.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- rollup-plugin-typescript2-0.36.0.tgz
- pluginutils-4.2.1.tgz
- ❌ picomatch-2.3.1.tgz (Vulnerable Library)
- pluginutils-4.2.1.tgz
- rollup-plugin-typescript2-0.36.0.tgz
Found in base branch: main
Vulnerability Details
Impact picomatch is vulnerable to a method injection vulnerability (CWE-1321) affecting the "POSIX_REGEX_SOURCE" object. Because the object inherits from "Object.prototype", specially crafted POSIX bracket expressions (e.g., "[[:constructor:]]") can reference inherited method names. These methods are implicitly converted to strings and injected into the generated regular expression. This leads to incorrect glob matching behavior (integrity impact), where patterns may match unintended filenames. The issue does not enable remote code execution, but it can cause security-relevant logic errors in applications that rely on glob matching for filtering, validation, or access control. All users of affected "picomatch" versions that process untrusted or user-controlled glob patterns are potentially impacted. Patches This issue is fixed in picomatch 4.0.4, 3.0.2 and 2.3.2. Users should upgrade to one of these versions or later, depending on their supported release line. Workarounds If upgrading is not immediately possible, avoid passing untrusted glob patterns to picomatch. Possible mitigations include: - Sanitizing or rejecting untrusted glob patterns, especially those containing POSIX character classes like "[[:...:]]". - Avoiding the use of POSIX bracket expressions if user input is involved. - Manually patching the library by modifying "POSIX_REGEX_SOURCE" to use a null prototype: const POSIX_REGEX_SOURCE = { proto: null, alnum: 'a-zA-Z0-9', alpha: 'a-zA-Z', // ... rest unchanged }; Resources - fix for similar issue: micromatch/picomatch#144 - picomatch repository https://github.com/micromatch/picomatch
Publish Date: 2026-03-25
URL: CVE-2026-33672
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Release Date: 2026-03-25
Fix Resolution: https://github.com/micromatch/picomatch.git - 2.3.2,https://github.com/micromatch/picomatch.git - 3.0.2,https://github.com/micromatch/picomatch.git - 4.0.4
Step up your Open Source Security Game with Mend here
CVE-2026-24001
Vulnerable Library - diff-5.2.0.tgz
Library home page: https://registry.npmjs.org/diff/-/diff-5.2.0.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- astro-5.14.1.tgz
- ❌ diff-5.2.0.tgz (Vulnerable Library)
- astro-5.14.1.tgz
Found in base branch: main
Vulnerability Details
jsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, 4.0.4, and 3.5.1, attempting to parse a patch whose filename headers contain the line break characters "\r", "\u2028", or "\u2029" can cause the "parsePatch" method to enter an infinite loop. It then consumes memory without limit until the process crashes due to running out of memory. Applications are therefore likely to be vulnerable to a denial-of-service attack if they call "parsePatch" with a user-provided patch as input. A large payload is not needed to trigger the vulnerability, so size limits on user input do not provide any protection. Furthermore, some applications may be vulnerable even when calling "parsePatch" on a patch generated by the application itself if the user is nonetheless able to control the filename headers (e.g. by directly providing the filenames of the files to be diffed). The "applyPatch" method is similarly affected if (and only if) called with a string representation of a patch as an argument, since under the hood it parses that string using "parsePatch". Other methods of the library are unaffected. Finally, a second and lesser interdependent bug - a ReDOS - also exhibits when those same line break characters are present in a patch's patch header (also known as its "leading garbage"). A maliciously-crafted patch header of length n can take "parsePatch" O(n³) time to parse. Versions 8.0.3, 5.2.2, 4.0.4, and 3.5.1 contain a fix. As a workaround, do not attempt to parse patches that contain any of these characters: "\r", "\u2028", or "\u2029".
Mend Note: The description of this vulnerability differs from MITRE.
Publish Date: 2026-01-22
URL: CVE-2026-24001
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
Suggested Fix
Type: Upgrade version
Release Date: 2026-01-22
Fix Resolution: https://github.com/kpdecker/jsdiff.git - v4.0.4,https://github.com/kpdecker/jsdiff.git - v5.2.2,https://github.com/kpdecker/jsdiff.git - v8.0.3
Step up your Open Source Security Game with Mend here
CVE-2025-66400
Vulnerable Library - mdast-util-to-hast-13.2.0.tgz
Library home page: https://registry.npmjs.org/mdast-util-to-hast/-/mdast-util-to-hast-13.2.0.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- astro-5.14.1.tgz
- @astrojs/markdown-remark-6.3.7.tgz
- remark-rehype-11.1.2.tgz
- ❌ mdast-util-to-hast-13.2.0.tgz (Vulnerable Library)
- remark-rehype-11.1.2.tgz
- @astrojs/markdown-remark-6.3.7.tgz
- astro-5.14.1.tgz
Found in base branch: main
Vulnerability Details
mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdown source by using character references. This could make rendered user supplied markdown code elements appear like the rest of the page. This vulnerability is fixed in 13.2.1.
Publish Date: 2025-12-01
URL: CVE-2025-66400
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Release Date: 2025-12-01
Fix Resolution: https://github.com/syntax-tree/mdast-util-to-hast.git - 13.2.1
Step up your Open Source Security Game with Mend here
CVE-2025-66030
Vulnerable Library - node-forge-1.3.1.tgz
JavaScript implementations of network transports, cryptography, ciphers, PKI, message digests, and various utilities.
Library home page: https://registry.npmjs.org/node-forge/-/node-forge-1.3.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- @storm-stack/core-0.47.0.tgz (Root Library)
- cli-1.5.8.tgz
- dev-server-1.1.4.tgz
- webpack-dev-server-5.2.2.tgz
- selfsigned-2.4.1.tgz
- ❌ node-forge-1.3.1.tgz (Vulnerable Library)
- selfsigned-2.4.1.tgz
- webpack-dev-server-5.2.2.tgz
- dev-server-1.1.4.tgz
- cli-1.5.8.tgz
Found in base branch: main
Vulnerability Details
Forge (also called "node-forge") is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.
Publish Date: 2025-11-26
URL: CVE-2025-66030
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: GHSA-65ch-62r8-g69g
Release Date: 2025-11-26
Fix Resolution (node-forge): 1.3.2
Direct dependency fix Resolution (@storm-stack/core): 0.48.0
Step up your Open Source Security Game with Mend here