{
 "arch": "amd64",
 "findings": [
  {
   "affects": [
    "thenify"
   ],
   "cvss": 9.8,
   "distro_severity": "critical",
   "fix_state": "fixed",
   "fixed_in": [
    "3.3.1"
   ],
   "id": "GHSA-29xr-v42j-r956",
   "severity": "critical",
   "title": "thenify before 3.3.1 made use of unsafe calls to `eval`.",
   "url": "https://github.com/advisories/GHSA-29xr-v42j-r956"
  },
  {
   "affects": [
    "loader-utils"
   ],
   "cvss": 9.8,
   "distro_severity": "critical",
   "fix_state": "fixed",
   "fixed_in": [
    "1.4.1"
   ],
   "id": "GHSA-76p3-8jx3-jpfq",
   "severity": "critical",
   "title": "Prototype pollution in webpack loader-utils",
   "url": "https://github.com/advisories/GHSA-76p3-8jx3-jpfq"
  },
  {
   "affects": [
    "json-schema"
   ],
   "cvss": 9.8,
   "distro_severity": "critical",
   "fix_state": "fixed",
   "fixed_in": [
    "0.4.0"
   ],
   "id": "GHSA-896r-f27r-55mw",
   "severity": "critical",
   "title": "json-schema is vulnerable to Prototype Pollution",
   "url": "https://github.com/advisories/GHSA-896r-f27r-55mw"
  },
  {
   "affects": [
    "minimist"
   ],
   "cvss": 9.8,
   "distro_severity": "critical",
   "fix_state": "fixed",
   "fixed_in": [
    "0.2.4"
   ],
   "id": "GHSA-xvch-5gv4-984h",
   "severity": "critical",
   "title": "Prototype Pollution in minimist",
   "url": "https://github.com/advisories/GHSA-xvch-5gv4-984h"
  },
  {
   "affects": [
    "form-data"
   ],
   "cvss": 9.4,
   "distro_severity": "critical",
   "fix_state": "fixed",
   "fixed_in": [
    "2.5.4"
   ],
   "id": "GHSA-fjxv-7rqg-78g4",
   "severity": "critical",
   "title": "form-data uses unsafe random function in form-data for choosing boundary",
   "url": "https://github.com/advisories/GHSA-fjxv-7rqg-78g4"
  },
  {
   "affects": [
    "lodash"
   ],
   "cvss": 9.1,
   "distro_severity": "critical",
   "fix_state": "fixed",
   "fixed_in": [
    "4.17.12"
   ],
   "id": "GHSA-jf85-cpcp-j695",
   "severity": "critical",
   "title": "Prototype Pollution in lodash",
   "url": "https://github.com/advisories/GHSA-jf85-cpcp-j695"
  },
  {
   "affects": [
    "minimatch"
   ],
   "cvss": 8.7,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "3.1.3"
   ],
   "id": "GHSA-3ppc-4f35-3m26",
   "severity": "high",
   "title": "minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
   "url": "https://github.com/advisories/GHSA-3ppc-4f35-3m26"
  },
  {
   "affects": [
    "tar-fs"
   ],
   "cvss": 8.7,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.16.5"
   ],
   "id": "GHSA-8cj5-5rvv-wf4v",
   "severity": "high",
   "title": "tar-fs can extract outside the specified dir with a specific tarball",
   "url": "https://github.com/advisories/GHSA-8cj5-5rvv-wf4v"
  },
  {
   "affects": [
    "tar-fs"
   ],
   "cvss": 8.7,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.16.6"
   ],
   "id": "GHSA-vj76-c3g6-qr5v",
   "severity": "high",
   "title": "tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball",
   "url": "https://github.com/advisories/GHSA-vj76-c3g6-qr5v"
  },
  {
   "affects": [
    "lodash"
   ],
   "cvss": 8.1,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "4.18.0"
   ],
   "id": "GHSA-r5fr-rjxr-66jc",
   "severity": "high",
   "title": "lodash vulnerable to Code Injection via `_.template` imports key names",
   "url": "https://github.com/advisories/GHSA-r5fr-rjxr-66jc"
  },
  {
   "affects": [
    "object-path"
   ],
   "cvss": 7.7,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.11.5"
   ],
   "id": "GHSA-cwx2-736x-mf6w",
   "severity": "high",
   "title": "Prototype pollution in object-path",
   "url": "https://github.com/advisories/GHSA-cwx2-736x-mf6w"
  },
  {
   "affects": [
    "tmp"
   ],
   "cvss": 7.7,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.2.6"
   ],
   "id": "GHSA-ph9p-34f9-6g65",
   "severity": "high",
   "title": "tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape",
   "url": "https://github.com/advisories/GHSA-ph9p-34f9-6g65"
  },
  {
   "affects": [
    "minimatch"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "3.1.4"
   ],
   "id": "GHSA-23c5-xmqv-rm74",
   "severity": "high",
   "title": "minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions",
   "url": "https://github.com/advisories/GHSA-23c5-xmqv-rm74"
  },
  {
   "affects": [
    "loader-utils"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.4.2"
   ],
   "id": "GHSA-3rfm-jhwj-7488",
   "severity": "high",
   "title": "loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS) via url variable",
   "url": "https://github.com/advisories/GHSA-3rfm-jhwj-7488"
  },
  {
   "affects": [
    "js-yaml"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "3.15.0"
   ],
   "id": "GHSA-52cp-r559-cp3m",
   "severity": "high",
   "title": "js-yaml: YAML merge-key chains can force quadratic CPU consumption",
   "url": "https://github.com/advisories/GHSA-52cp-r559-cp3m"
  },
  {
   "affects": [
    "js-yaml"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "3.15.1"
   ],
   "id": "GHSA-5p4m-2wfm-xmqj",
   "severity": "high",
   "title": "JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) \u2014 CVE-2026-59870 fix not backported",
   "url": "https://github.com/advisories/GHSA-5p4m-2wfm-xmqj"
  },
  {
   "affects": [
    "kind-of"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "6.0.3"
   ],
   "id": "GHSA-6c8f-qphg-qjgp",
   "severity": "high",
   "title": "Validation Bypass in kind-of",
   "url": "https://github.com/advisories/GHSA-6c8f-qphg-qjgp"
  },
  {
   "affects": [
    "minimatch"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "3.1.3"
   ],
   "id": "GHSA-7r86-cg39-jmmj",
   "severity": "high",
   "title": "minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments",
   "url": "https://github.com/advisories/GHSA-7r86-cg39-jmmj"
  },
  {
   "affects": [
    "object-path"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.11.8"
   ],
   "id": "GHSA-8v63-cqqc-6r2c",
   "severity": "high",
   "title": "Prototype Pollution in object-path",
   "url": "https://github.com/advisories/GHSA-8v63-cqqc-6r2c"
  },
  {
   "affects": [
    "ansi-regex"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "3.0.1"
   ],
   "id": "GHSA-93q8-gq69-wqmw",
   "severity": "high",
   "title": "Inefficient Regular Expression Complexity in chalk/ansi-regex",
   "url": "https://github.com/advisories/GHSA-93q8-gq69-wqmw"
  },
  {
   "affects": [
    "semver"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "5.7.2"
   ],
   "id": "GHSA-c2qf-rxjj-qqgw",
   "severity": "high",
   "title": "semver vulnerable to Regular Expression Denial of Service",
   "url": "https://github.com/advisories/GHSA-c2qf-rxjj-qqgw"
  },
  {
   "affects": [
    "minimatch"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "3.0.5"
   ],
   "id": "GHSA-f8q6-p94x-37v3",
   "severity": "high",
   "title": "minimatch ReDoS vulnerability",
   "url": "https://github.com/advisories/GHSA-f8q6-p94x-37v3"
  },
  {
   "affects": [
    "braces"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "3.0.3"
   ],
   "id": "GHSA-grv7-fg5c-xmjg",
   "severity": "high",
   "title": "Uncontrolled resource consumption in braces",
   "url": "https://github.com/advisories/GHSA-grv7-fg5c-xmjg"
  },
  {
   "affects": [
    "loader-utils"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.4.2"
   ],
   "id": "GHSA-hhq3-ff78-jv3g",
   "severity": "high",
   "title": "loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS)",
   "url": "https://github.com/advisories/GHSA-hhq3-ff78-jv3g"
  },
  {
   "affects": [
    "form-data"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "2.5.6"
   ],
   "id": "GHSA-hmw2-7cc7-3qxx",
   "severity": "high",
   "title": "form-data: CRLF injection in form-data via unescaped multipart field names and filenames",
   "url": "https://github.com/advisories/GHSA-hmw2-7cc7-3qxx"
  },
  {
   "affects": [
    "qs"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "6.5.3"
   ],
   "id": "GHSA-hrpp-h998-j3pp",
   "severity": "high",
   "title": "qs vulnerable to Prototype Pollution",
   "url": "https://github.com/advisories/GHSA-hrpp-h998-j3pp"
  },
  {
   "affects": [
    "brace-expansion"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.1.17"
   ],
   "id": "GHSA-mh99-v99m-4gvg",
   "severity": "high",
   "title": "brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash",
   "url": "https://github.com/advisories/GHSA-mh99-v99m-4gvg"
  },
  {
   "affects": [
    "tar-fs"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.16.4"
   ],
   "id": "GHSA-pq67-2wwv-3xjx",
   "severity": "high",
   "title": "tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File",
   "url": "https://github.com/advisories/GHSA-pq67-2wwv-3xjx"
  },
  {
   "affects": [
    "brace-expansion"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.1.18"
   ],
   "id": "GHSA-rgw5-rvv9-x895",
   "severity": "high",
   "title": "brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation",
   "url": "https://github.com/advisories/GHSA-rgw5-rvv9-x895"
  },
  {
   "affects": [
    "ssri"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "6.0.2"
   ],
   "id": "GHSA-vx3p-948g-6vhq",
   "severity": "high",
   "title": "Regular Expression Denial of Service (ReDoS)",
   "url": "https://github.com/advisories/GHSA-vx3p-948g-6vhq"
  },
  {
   "affects": [
    "decode-uri-component"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.2.1"
   ],
   "id": "GHSA-w573-4hg7-7wgq",
   "severity": "high",
   "title": "decode-uri-component vulnerable to Denial of Service (DoS)",
   "url": "https://github.com/advisories/GHSA-w573-4hg7-7wgq"
  },
  {
   "affects": [
    "uuid"
   ],
   "cvss": 7.5,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "11.1.1"
   ],
   "id": "GHSA-w5hq-g745-h8pq",
   "severity": "high",
   "title": "uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided",
   "url": "https://github.com/advisories/GHSA-w5hq-g745-h8pq"
  },
  {
   "affects": [
    "lodash"
   ],
   "cvss": 7.4,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "4.17.19"
   ],
   "id": "GHSA-p6mc-m468-83gw",
   "severity": "high",
   "title": "Prototype Pollution in lodash",
   "url": "https://github.com/advisories/GHSA-p6mc-m468-83gw"
  },
  {
   "affects": [
    "ini"
   ],
   "cvss": 7.3,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.3.6"
   ],
   "id": "GHSA-qqgx-2p2h-9c37",
   "severity": "high",
   "title": "ini before 1.3.6 vulnerable to Prototype Pollution via ini.parse",
   "url": "https://github.com/advisories/GHSA-qqgx-2p2h-9c37"
  },
  {
   "affects": [
    "lodash"
   ],
   "cvss": 7.2,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "4.17.21"
   ],
   "id": "GHSA-35jh-r3h4-6jhm",
   "severity": "high",
   "title": "Command Injection in lodash",
   "url": "https://github.com/advisories/GHSA-35jh-r3h4-6jhm"
  },
  {
   "affects": [
    "json5"
   ],
   "cvss": 7.1,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.0.2"
   ],
   "id": "GHSA-9c47-m6qq-7p4h",
   "severity": "high",
   "title": "Prototype Pollution in JSON5 via Parse Method",
   "url": "https://github.com/advisories/GHSA-9c47-m6qq-7p4h"
  },
  {
   "affects": [
    "tough-cookie"
   ],
   "cvss": 6.5,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "4.1.3"
   ],
   "id": "GHSA-72xf-g2v4-qvf3",
   "severity": "medium",
   "title": "tough-cookie Prototype Pollution vulnerability",
   "url": "https://github.com/advisories/GHSA-72xf-g2v4-qvf3"
  },
  {
   "affects": [
    "lodash"
   ],
   "cvss": 6.5,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "4.18.0"
   ],
   "id": "GHSA-f23m-r3pf-42rh",
   "severity": "medium",
   "title": "lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`",
   "url": "https://github.com/advisories/GHSA-f23m-r3pf-42rh"
  },
  {
   "affects": [
    "brace-expansion"
   ],
   "cvss": 6.5,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "1.1.13"
   ],
   "id": "GHSA-f886-m6hf-6m8v",
   "severity": "medium",
   "title": "brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
   "url": "https://github.com/advisories/GHSA-f886-m6hf-6m8v"
  },
  {
   "affects": [
    "bl"
   ],
   "cvss": 6.5,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "1.2.3"
   ],
   "id": "GHSA-pp7h-53gx-mx7r",
   "severity": "medium",
   "title": "Remote Memory Exposure in bl",
   "url": "https://github.com/advisories/GHSA-pp7h-53gx-mx7r"
  },
  {
   "affects": [
    "lodash"
   ],
   "cvss": 6.5,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "4.17.11"
   ],
   "id": "GHSA-x5rq-j2xg-h7qm",
   "severity": "medium",
   "title": "Regular Expression Denial of Service (ReDoS) in lodash",
   "url": "https://github.com/advisories/GHSA-x5rq-j2xg-h7qm"
  },
  {
   "affects": [
    "lodash"
   ],
   "cvss": 6.5,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "4.17.23"
   ],
   "id": "GHSA-xxjr-mmjv-4gpg",
   "severity": "medium",
   "title": "Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions",
   "url": "https://github.com/advisories/GHSA-xxjr-mmjv-4gpg"
  },
  {
   "affects": [
    "request"
   ],
   "cvss": 6.1,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "GHSA-p8p7-x288-28g6",
   "severity": "medium",
   "title": "Server-Side Request Forgery in Request",
   "url": "https://github.com/advisories/GHSA-p8p7-x288-28g6"
  },
  {
   "affects": [
    "lodash"
   ],
   "cvss": 5.6,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "4.17.11"
   ],
   "id": "GHSA-4xc9-xhrj-v574",
   "severity": "medium",
   "title": "Prototype Pollution in lodash",
   "url": "https://github.com/advisories/GHSA-4xc9-xhrj-v574"
  },
  {
   "affects": [
    "object-path"
   ],
   "cvss": 5.6,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "0.11.6"
   ],
   "id": "GHSA-v39p-96qg-c8rf",
   "severity": "medium",
   "title": "Prototype Pollution in object-path",
   "url": "https://github.com/advisories/GHSA-v39p-96qg-c8rf"
  },
  {
   "affects": [
    "ajv"
   ],
   "cvss": 5.6,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "6.12.3"
   ],
   "id": "GHSA-v88g-cgmw-v5xw",
   "severity": "medium",
   "title": "Prototype Pollution in Ajv",
   "url": "https://github.com/advisories/GHSA-v88g-cgmw-v5xw"
  },
  {
   "affects": [
    "minimist"
   ],
   "cvss": 5.6,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "0.2.1"
   ],
   "id": "GHSA-vh95-rmgr-6w4m",
   "severity": "medium",
   "title": "Prototype Pollution in minimist",
   "url": "https://github.com/advisories/GHSA-vh95-rmgr-6w4m"
  },
  {
   "affects": [
    "ajv"
   ],
   "cvss": 5.5,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "6.14.0"
   ],
   "id": "GHSA-2g4f-4pwh-qvx6",
   "severity": "medium",
   "title": "ajv has ReDoS when using `$data` option",
   "url": "https://github.com/advisories/GHSA-2g4f-4pwh-qvx6"
  },
  {
   "affects": [
    "lodash"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "4.17.21"
   ],
   "id": "GHSA-29mw-wpgm-hmr9",
   "severity": "medium",
   "title": "Regular Expression Denial of Service (ReDoS) in lodash",
   "url": "https://github.com/advisories/GHSA-29mw-wpgm-hmr9"
  },
  {
   "affects": [
    "brace-expansion"
   ],
   "cvss": 5.3,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.1.16"
   ],
   "id": "GHSA-3jxr-9vmj-r5cp",
   "severity": "medium",
   "title": "brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups",
   "url": "https://github.com/advisories/GHSA-3jxr-9vmj-r5cp"
  },
  {
   "affects": [
    "micromatch"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "4.0.8"
   ],
   "id": "GHSA-952p-6rrq-rcjv",
   "severity": "medium",
   "title": "Regular Expression Denial of Service (ReDoS) in micromatch",
   "url": "https://github.com/advisories/GHSA-952p-6rrq-rcjv"
  },
  {
   "affects": [
    "js-yaml"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.15.0"
   ],
   "id": "GHSA-h67p-54hq-rp68",
   "severity": "medium",
   "title": "JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases",
   "url": "https://github.com/advisories/GHSA-h67p-54hq-rp68"
  },
  {
   "affects": [
    "path-parse"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "1.0.7"
   ],
   "id": "GHSA-hj48-42vr-x3v9",
   "severity": "medium",
   "title": "Regular Expression Denial of Service in path-parse",
   "url": "https://github.com/advisories/GHSA-hj48-42vr-x3v9"
  },
  {
   "affects": [
    "js-yaml"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.14.2"
   ],
   "id": "GHSA-mh29-5h37-fv8m",
   "severity": "medium",
   "title": "js-yaml has prototype pollution in merge (<<)",
   "url": "https://github.com/advisories/GHSA-mh29-5h37-fv8m"
  },
  {
   "affects": [
    "qs"
   ],
   "cvss": 3.7,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "6.14.1"
   ],
   "id": "GHSA-6rw7-vpxm-498p",
   "severity": "low",
   "title": "qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion",
   "url": "https://github.com/advisories/GHSA-6rw7-vpxm-498p"
  },
  {
   "affects": [
    "brace-expansion"
   ],
   "cvss": 3.1,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "1.1.12"
   ],
   "id": "GHSA-v6h2-p8h4-qcjw",
   "severity": "low",
   "title": "brace-expansion Regular Expression Denial of Service vulnerability",
   "url": "https://github.com/advisories/GHSA-v6h2-p8h4-qcjw"
  },
  {
   "affects": [
    "tmp"
   ],
   "cvss": 2.5,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "0.2.4"
   ],
   "id": "GHSA-52f5-9888-hmc6",
   "severity": "low",
   "title": "tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter",
   "url": "https://github.com/advisories/GHSA-52f5-9888-hmc6"
  },
  {
   "affects": [
    "chownr"
   ],
   "cvss": 2.5,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "1.1.0"
   ],
   "id": "GHSA-c6rq-rjc2-86v2",
   "severity": "low",
   "title": "Time-of-check Time-of-use (TOCTOU) Race Condition in chownr",
   "url": "https://github.com/advisories/GHSA-c6rq-rjc2-86v2"
  }
 ],
 "findings_changed_at": "2026-08-26T19:59:54Z",
 "image": "yarn",
 "inputs": {
  "sbom_sha256": "419697fe2abf08ad0f70e8f5a316e3c53ecb6c751bcca659e386d02ccfa5e21e"
 },
 "platform_digest": "sha256:100251ca798e5efa583c0c2332c04b1045cee9bdc4eef0e446a279beb3035362",
 "project": "yarn",
 "receipt_sha256": "6aa84c7ded7e024c3f8ceb647466fcb1cd21749db5060b0d0f1af154db69b048",
 "scanner": "grype",
 "severity_counts": {
  "critical": 6,
  "high": 30,
  "low": 4,
  "medium": 18,
  "unknown": 0
 },
 "suppressed": [],
 "version": "1.22.22",
 "vex_applied": [
  "yarn-1.22.22-amd64.vex.json",
  "yarn-1.22.22-amd64.ubuntu-vex.json"
 ]
}
