Skip to content

[VANTA] [VULNERABILITY] <HIGH> CVE-2026-24842, CVE-2026-23950, CVE-2025-13465 and others, fix before 2026-02-15 #704

@commercelayer-ci

Description

@commercelayer-ci

Important

DO NOT MODIFY THE TEXT BELOW AND CLOSE THE ISSUE ONLY IF YOU PLAN TO DEPLOY THE FIX BEFORE 2026-02-15.

npm-tar <= 7.5.2 CODE_REPOSITORY/commercelayer-react-components CVE-2026-23745 HIGH remediate by: 2026-02-16T06:15:39.198Z

npm-tar <= 7.5.3 CODE_REPOSITORY/commercelayer-react-components CVE-2026-23950 HIGH remediate by: 2026-02-20T06:15:54.560Z

npm-tar < 7.5.7 CODE_REPOSITORY/commercelayer-react-components CVE-2026-24842 HIGH remediate by: 2026-02-27T22:15:53.692Z

npm-lodash >= 4.0.0, <= 4.17.22 CODE_REPOSITORY/commercelayer-react-components CVE-2025-13465 MEDIUM remediate by: 2026-03-23T06:15:19.249Z

npm-diff >= 5.0.0, < 5.2.2 CODE_REPOSITORY/commercelayer-react-components CVE-2026-24001 LOW remediate by: 2026-04-21T22:15:39.536Z

Metadata

Metadata

Labels

p1Security priority: Highp2Security priority: Mediump3Security priority: Lowsecurityvulnerability

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions