Skip to content

[VANTA] [VULNERABILITY] <CRITICAL> CVE-2026-2950, CVE-2026-33750, CVE-2026-33916 and others, fix before 2026-04-26 #124

@commercelayer-ci

Description

@commercelayer-ci

Important

CLOSE THE ISSUE ONLY IF YOU PLAN TO DEPLOY THE FIX BEFORE THE DEADLINE IN THE TITLE.

DO NOT MANUALLY MODIFY THE ISSUE TITLE OR TEXT BODY.

FIXED npm-handlebars >= 4.0.0, <= 4.7.8 CVE-2026-33937 CRITICAL

npm-handlebars >= 4.0.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-cli-plugin-resources CVE-2026-33937 CRITICAL remediate by: 2026-04-26T22:19:27.887Z

Related URLs
FIXED npm-handlebars >= 4.0.0, <= 4.7.8 CVE-2026-33941 HIGH

npm-handlebars >= 4.0.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-cli-plugin-resources CVE-2026-33941 HIGH remediate by: 2026-04-26T22:19:28.149Z

Related URLs
FIXED npm-handlebars >= 4.0.0, <= 4.7.8 CVE-2026-33938 HIGH

npm-handlebars >= 4.0.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-cli-plugin-resources CVE-2026-33938 HIGH remediate by: 2026-04-26T22:19:28.149Z

Related URLs
FIXED npm-handlebars >= 4.0.0, <= 4.7.8 CVE-2026-33940 HIGH

npm-handlebars >= 4.0.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-cli-plugin-resources CVE-2026-33940 HIGH remediate by: 2026-04-26T22:19:28.149Z

Related URLs
FIXED npm-handlebars >= 4.0.0, <= 4.7.8 CVE-2026-33939 HIGH

npm-handlebars >= 4.0.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-cli-plugin-resources CVE-2026-33939 HIGH remediate by: 2026-04-26T22:19:28.149Z

Related URLs
FIXED npm-handlebars >= 4.0.0, <= 4.7.8 GHSA-442j-39wm-28r2 LOW

npm-handlebars >= 4.0.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-cli-plugin-resources GHSA-442j-39wm-28r2 LOW remediate by: 2026-06-27T22:22:40.282Z

Related URLs
FIXED npm-lodash-es >= 4.0.0, <= 4.17.23 CVE-2026-4800 HIGH

npm-lodash-es >= 4.0.0, <= 4.17.23 CODE_REPOSITORY/commercelayer-cli-plugin-resources CVE-2026-4800 HIGH remediate by: 2026-05-02T14:38:24.409Z

Related URLs
FIXED npm-lodash >= 4.0.0, <= 4.17.23 CVE-2026-4800 HIGH

npm-lodash >= 4.0.0, <= 4.17.23 CODE_REPOSITORY/commercelayer-cli-plugin-resources CVE-2026-4800 HIGH remediate by: 2026-05-10T06:21:04.459Z

Related URLs
FIXED npm-handlebars >= 4.0.0, < 4.7.9 CVE-2026-33916 MEDIUM

npm-handlebars >= 4.0.0, < 4.7.9 CODE_REPOSITORY/commercelayer-cli-plugin-resources CVE-2026-33916 MEDIUM remediate by: 2026-05-26T06:15:32.686Z

Related URLs
FIXED npm-brace-expansion >= 4.0.0, < 5.0.5 CVE-2026-33750 MEDIUM

npm-brace-expansion >= 4.0.0, < 5.0.5 CODE_REPOSITORY/commercelayer-cli-plugin-resources CVE-2026-33750 MEDIUM remediate by: 2026-05-26T22:19:28.497Z

Related URLs
FIXED npm-serialize-javascript < 7.0.5 CVE-2026-34043 MEDIUM

npm-serialize-javascript < 7.0.5 CODE_REPOSITORY/commercelayer-cli-plugin-resources CVE-2026-34043 MEDIUM remediate by: 2026-05-28T14:18:26.573Z

Related URLs
FIXED npm-brace-expansion >= 2.0.0, < 2.0.3 CVE-2026-33750 MEDIUM

npm-brace-expansion >= 2.0.0, < 2.0.3 CODE_REPOSITORY/commercelayer-cli-plugin-resources CVE-2026-33750 MEDIUM remediate by: 2026-05-28T22:22:39.992Z

Related URLs
FIXED npm-handlebars >= 4.6.0, <= 4.7.8 GHSA-7rx3-28cr-v5wh MEDIUM

npm-handlebars >= 4.6.0, <= 4.7.8 CODE_REPOSITORY/commercelayer-cli-plugin-resources GHSA-7rx3-28cr-v5wh MEDIUM remediate by: 2026-05-28T22:22:39.992Z

Related URLs
FIXED npm-lodash-es <= 4.17.23 CVE-2026-2950 MEDIUM

npm-lodash-es <= 4.17.23 CODE_REPOSITORY/commercelayer-cli-plugin-resources CVE-2026-2950 MEDIUM remediate by: 2026-06-01T14:38:24.736Z

Related URLs
FIXED npm-lodash <= 4.17.23 CVE-2026-2950 MEDIUM

npm-lodash <= 4.17.23 CODE_REPOSITORY/commercelayer-cli-plugin-resources CVE-2026-2950 MEDIUM remediate by: 2026-06-09T14:23:14.879Z

Related URLs

Metadata

Metadata

Labels

compliancedependenciesPull requests that update a dependency filep0Security priority: Criticalp1Security priority: Highp2Security priority: Mediump3Security priority: Lowvulnerability

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions