{
  "auditReportVersion": 2,
  "vulnerabilities": {
    "@babel/core": {
      "name": "@babel/core",
      "severity": "low",
      "isDirect": false,
      "via": [
        {
          "source": 1123528,
          "name": "@babel/core",
          "dependency": "@babel/core",
          "title": "@babel/core: Arbitrary File Read via sourceMappingURL Comment",
          "url": "https://github.com/advisories/GHSA-4x5r-pxfx-6jf8",
          "severity": "low",
          "cwe": [
            "CWE-22",
            "CWE-200"
          ],
          "cvss": {
            "score": 3.2,
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N"
          },
          "range": "<=7.29.0"
        }
      ],
      "effects": [],
      "range": "<=7.29.0",
      "nodes": [
        "node_modules/@babel/core"
      ],
      "fixAvailable": true
    },
    "@remix-run/router": {
      "name": "@remix-run/router",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1112052,
          "name": "@remix-run/router",
          "dependency": "@remix-run/router",
          "title": "React Router vulnerable to XSS via Open Redirects",
          "url": "https://github.com/advisories/GHSA-2w69-qvjg-hvjx",
          "severity": "high",
          "cwe": [
            "CWE-79"
          ],
          "cvss": {
            "score": 8,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N"
          },
          "range": "<=1.23.1"
        },
        {
          "source": 1136293,
          "name": "@remix-run/router",
          "dependency": "@remix-run/router",
          "title": "React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation",
          "url": "https://github.com/advisories/GHSA-2j2x-hqr9-3h42",
          "severity": "moderate",
          "cwe": [
            "CWE-601"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": ">=1.3.0 <1.23.3"
        }
      ],
      "effects": [
        "react-router",
        "react-router-dom"
      ],
      "range": "<=1.23.2",
      "nodes": [
        "node_modules/@remix-run/router"
      ],
      "fixAvailable": true
    },
    "@vitest/coverage-v8": {
      "name": "@vitest/coverage-v8",
      "severity": "critical",
      "isDirect": true,
      "via": [
        "vitest"
      ],
      "effects": [],
      "range": "<=3.2.5",
      "nodes": [
        "node_modules/@vitest/coverage-v8"
      ],
      "fixAvailable": {
        "name": "@vitest/coverage-v8",
        "version": "5.0.0",
        "isSemVerMajor": true
      }
    },
    "@vitest/ui": {
      "name": "@vitest/ui",
      "severity": "critical",
      "isDirect": true,
      "via": [
        "vitest"
      ],
      "effects": [
        "vitest"
      ],
      "range": "<=0.0.130 || 0.31.0 - 3.2.5",
      "nodes": [
        "node_modules/@vitest/ui"
      ],
      "fixAvailable": {
        "name": "@vitest/ui",
        "version": "5.0.0",
        "isSemVerMajor": true
      }
    },
    "ajv": {
      "name": "ajv",
      "severity": "moderate",
      "isDirect": false,
      "via": [
        {
          "source": 1113714,
          "name": "ajv",
          "dependency": "ajv",
          "title": "ajv has ReDoS when using `$data` option",
          "url": "https://github.com/advisories/GHSA-2g4f-4pwh-qvx6",
          "severity": "moderate",
          "cwe": [
            "CWE-400",
            "CWE-1333"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": "<6.14.0"
        }
      ],
      "effects": [],
      "range": "<6.14.0",
      "nodes": [
        "node_modules/ajv"
      ],
      "fixAvailable": true
    },
    "axios": {
      "name": "axios",
      "severity": "high",
      "isDirect": true,
      "via": [
        {
          "source": 1116673,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF",
          "url": "https://github.com/advisories/GHSA-3p68-rc4w-qgx5",
          "severity": "moderate",
          "cwe": [
            "CWE-441",
            "CWE-918"
          ],
          "cvss": {
            "score": 4.8,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
          },
          "range": ">=1.0.0 <1.15.0"
        },
        {
          "source": 1117574,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy",
          "url": "https://github.com/advisories/GHSA-w9j2-pvgh-6h63",
          "severity": "moderate",
          "cwe": [
            "CWE-287",
            "CWE-1321"
          ],
          "cvss": {
            "score": 4.8,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
          },
          "range": ">=1.0.0 <1.15.1"
        },
        {
          "source": 1117576,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: Incomplete Fix for CVE-2025-62718 \u2014 NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0",
          "url": "https://github.com/advisories/GHSA-pmwg-cvhr-8vh7",
          "severity": "high",
          "cwe": [
            "CWE-183",
            "CWE-441",
            "CWE-918"
          ],
          "cvss": {
            "score": 7.2,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
          },
          "range": ">=1.0.0 <1.15.1"
        },
        {
          "source": 1117577,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`",
          "url": "https://github.com/advisories/GHSA-3w6x-2g7m-8v23",
          "severity": "moderate",
          "cwe": [
            "CWE-915",
            "CWE-1321"
          ],
          "cvss": {
            "score": 6.5,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
          },
          "range": ">=1.0.0 <1.15.2"
        },
        {
          "source": 1117580,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams",
          "url": "https://github.com/advisories/GHSA-xhjh-pmcv-23jw",
          "severity": "low",
          "cwe": [
            "CWE-116",
            "CWE-626"
          ],
          "cvss": {
            "score": 3.7,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
          },
          "range": ">=1.0.0 <1.15.1"
        },
        {
          "source": 1117581,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream",
          "url": "https://github.com/advisories/GHSA-445q-vr5w-6q77",
          "severity": "moderate",
          "cwe": [
            "CWE-93"
          ],
          "cvss": {
            "score": 5.3,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
          },
          "range": ">=1.0.0 <1.15.1"
        },
        {
          "source": 1117583,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: no_proxy bypass via IP alias allows SSRF",
          "url": "https://github.com/advisories/GHSA-m7pr-hjqh-92cm",
          "severity": "moderate",
          "cwe": [
            "CWE-918"
          ],
          "cvss": {
            "score": 6.8,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"
          },
          "range": ">=1.0.0 <1.15.1"
        },
        {
          "source": 1117587,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0",
          "url": "https://github.com/advisories/GHSA-5c9x-8gcm-mpgx",
          "severity": "moderate",
          "cwe": [
            "CWE-770"
          ],
          "cvss": {
            "score": 5.3,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
          },
          "range": ">=1.0.0 <1.15.1"
        },
        {
          "source": 1117589,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: HTTP adapter streamed responses bypass maxContentLength",
          "url": "https://github.com/advisories/GHSA-vf2m-468p-8v99",
          "severity": "moderate",
          "cwe": [
            "CWE-770"
          ],
          "cvss": {
            "score": 5.3,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
          },
          "range": ">=1.0.0 <1.15.1"
        },
        {
          "source": 1117591,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking",
          "url": "https://github.com/advisories/GHSA-pf86-5x62-jrwf",
          "severity": "high",
          "cwe": [
            "CWE-1321"
          ],
          "cvss": {
            "score": 7.4,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
          },
          "range": ">=1.0.0 <1.15.1"
        },
        {
          "source": 1117593,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: Header Injection via Prototype Pollution",
          "url": "https://github.com/advisories/GHSA-6chq-wfr3-2hj9",
          "severity": "high",
          "cwe": [
            "CWE-113",
            "CWE-1321"
          ],
          "cvss": {
            "score": 7.4,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
          },
          "range": ">=1.0.0 <1.15.1"
        },
        {
          "source": 1117595,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion",
          "url": "https://github.com/advisories/GHSA-xx6v-rp6x-q39c",
          "severity": "moderate",
          "cwe": [
            "CWE-183",
            "CWE-201"
          ],
          "cvss": {
            "score": 5.4,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
          },
          "range": ">=1.0.0 <1.15.1"
        },
        {
          "source": 1117858,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig",
          "url": "https://github.com/advisories/GHSA-43fc-jf86-j433",
          "severity": "high",
          "cwe": [
            "CWE-754",
            "CWE-1321"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": ">=1.0.0 <=1.13.4"
        },
        {
          "source": 1118607,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking",
          "url": "https://github.com/advisories/GHSA-q8qp-cvcw-x6jj",
          "severity": "high",
          "cwe": [
            "CWE-1321"
          ],
          "cvss": {
            "score": 7.4,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
          },
          "range": ">=1.0.0 <1.15.2"
        },
        {
          "source": 1119404,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain",
          "url": "https://github.com/advisories/GHSA-fvcv-3m26-pcqx",
          "severity": "moderate",
          "cwe": [
            "CWE-113",
            "CWE-444",
            "CWE-918"
          ],
          "cvss": {
            "score": 4.8,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
          },
          "range": ">=1.0.0 <1.15.0"
        },
        {
          "source": 1120125,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: unbounded recursion in toFormData causes DoS via deeply nested request data",
          "url": "https://github.com/advisories/GHSA-62hf-57xw-28j9",
          "severity": "moderate",
          "cwe": [
            "CWE-674"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": ">=1.0.0 <1.15.1"
        },
        {
          "source": 1120547,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection",
          "url": "https://github.com/advisories/GHSA-hfxv-24rg-xrqf",
          "severity": "high",
          "cwe": [
            "CWE-400",
            "CWE-1333"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": ">=1.0.0 <1.16.0"
        },
        {
          "source": 1120643,
          "name": "axios",
          "dependency": "axios",
          "title": "Allocation of Resources Without Limits or Throttling in Axios",
          "url": "https://github.com/advisories/GHSA-777c-7fjr-54vf",
          "severity": "high",
          "cwe": [
            "CWE-770"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": ">=1.7.0 <1.16.0"
        },
        {
          "source": 1120645,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter",
          "url": "https://github.com/advisories/GHSA-p92q-9vqr-4j8v",
          "severity": "high",
          "cwe": [
            "CWE-201"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": ">=1.0.0 <1.16.0"
        },
        {
          "source": 1120647,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection",
          "url": "https://github.com/advisories/GHSA-j5f8-grm9-p9fc",
          "severity": "high",
          "cwe": [
            "CWE-200"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
          },
          "range": ">=1.0.0 <1.16.0"
        },
        {
          "source": 1120649,
          "name": "axios",
          "dependency": "axios",
          "title": "axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge",
          "url": "https://github.com/advisories/GHSA-3g43-6gmg-66jw",
          "severity": "high",
          "cwe": [
            "CWE-94",
            "CWE-1321"
          ],
          "cvss": {
            "score": 7,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L"
          },
          "range": ">=1.0.0 <1.15.2"
        },
        {
          "source": 1120650,
          "name": "axios",
          "dependency": "axios",
          "title": "axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`",
          "url": "https://github.com/advisories/GHSA-35jp-ww65-95wh",
          "severity": "high",
          "cwe": [
            "CWE-441",
            "CWE-1321"
          ],
          "cvss": {
            "score": 8.7,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
          },
          "range": ">=1.0.0 <1.16.0"
        },
        {
          "source": 1120652,
          "name": "axios",
          "dependency": "axios",
          "title": "axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions",
          "url": "https://github.com/advisories/GHSA-898c-q2cr-xwhg",
          "severity": "moderate",
          "cwe": [
            "CWE-1321"
          ],
          "cvss": {
            "score": 4.8,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
          },
          "range": ">=1.0.0 <1.16.0"
        },
        {
          "source": 1147949,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: Prototype pollution gadgets can alter axios request construction",
          "url": "https://github.com/advisories/GHSA-mmx7-hfxf-jppx",
          "severity": "moderate",
          "cwe": [
            "CWE-1321"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": ">=1.0.0 <1.18.0"
        },
        {
          "source": 1147950,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: Deep formToJSON Key Recursion Can Cause Denial of Service",
          "url": "https://github.com/advisories/GHSA-pmv8-rq9r-6j72",
          "severity": "moderate",
          "cwe": [
            "CWE-400",
            "CWE-770"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": ">=1.0.0 <1.18.0"
        },
        {
          "source": 1153175,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: HTTP/2 streamed uploads bypass `maxBodyLength`",
          "url": "https://github.com/advisories/GHSA-mwf2-3pr3-8698",
          "severity": "moderate",
          "cwe": [
            "CWE-400"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": ">=1.13.0 <1.18.0"
        },
        {
          "source": 1153180,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: Nested axios option objects can consume polluted prototype values",
          "url": "https://github.com/advisories/GHSA-7q8q-rj6j-mhjq",
          "severity": "moderate",
          "cwe": [
            "CWE-1321"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": ">=1.0.0 <1.18.0"
        },
        {
          "source": 1153182,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`",
          "url": "https://github.com/advisories/GHSA-jqh4-m9w3-8hp9",
          "severity": "moderate",
          "cwe": [
            "CWE-770"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": ">=1.7.0 <1.18.0"
        },
        {
          "source": 1153185,
          "name": "axios",
          "dependency": "axios",
          "title": "Axios: Excessive recursion in formDataToJSON can cause denial of service",
          "url": "https://github.com/advisories/GHSA-42h9-826w-cgv3",
          "severity": "moderate",
          "cwe": [
            "CWE-400",
            "CWE-674"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": ">=1.0.0 <1.18.0"
        }
      ],
      "effects": [],
      "range": "1.0.0 - 1.17.0",
      "nodes": [
        "node_modules/axios"
      ],
      "fixAvailable": true
    },
    "brace-expansion": {
      "name": "brace-expansion",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1115540,
          "name": "brace-expansion",
          "dependency": "brace-expansion",
          "title": "brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
          "url": "https://github.com/advisories/GHSA-f886-m6hf-6m8v",
          "severity": "moderate",
          "cwe": [
            "CWE-400"
          ],
          "cvss": {
            "score": 6.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
          },
          "range": "<1.1.13"
        },
        {
          "source": 1115541,
          "name": "brace-expansion",
          "dependency": "brace-expansion",
          "title": "brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
          "url": "https://github.com/advisories/GHSA-f886-m6hf-6m8v",
          "severity": "moderate",
          "cwe": [
            "CWE-400"
          ],
          "cvss": {
            "score": 6.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
          },
          "range": ">=2.0.0 <2.0.3"
        },
        {
          "source": 1123896,
          "name": "brace-expansion",
          "dependency": "brace-expansion",
          "title": "brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups",
          "url": "https://github.com/advisories/GHSA-3jxr-9vmj-r5cp",
          "severity": "high",
          "cwe": [
            "CWE-400",
            "CWE-407"
          ],
          "cvss": {
            "score": 5.3,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
          },
          "range": ">=2.0.0 <2.1.2"
        },
        {
          "source": 1123897,
          "name": "brace-expansion",
          "dependency": "brace-expansion",
          "title": "brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups",
          "url": "https://github.com/advisories/GHSA-3jxr-9vmj-r5cp",
          "severity": "high",
          "cwe": [
            "CWE-400",
            "CWE-407"
          ],
          "cvss": {
            "score": 5.3,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
          },
          "range": "<1.1.16"
        },
        {
          "source": 1130588,
          "name": "brace-expansion",
          "dependency": "brace-expansion",
          "title": "brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash",
          "url": "https://github.com/advisories/GHSA-mh99-v99m-4gvg",
          "severity": "high",
          "cwe": [
            "CWE-400",
            "CWE-770"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": "<1.1.17"
        },
        {
          "source": 1130589,
          "name": "brace-expansion",
          "dependency": "brace-expansion",
          "title": "brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash",
          "url": "https://github.com/advisories/GHSA-mh99-v99m-4gvg",
          "severity": "high",
          "cwe": [
            "CWE-400",
            "CWE-770"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": ">=2.0.0 <2.1.3"
        },
        {
          "source": 1130736,
          "name": "brace-expansion",
          "dependency": "brace-expansion",
          "title": "brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation",
          "url": "https://github.com/advisories/GHSA-rgw5-rvv9-x895",
          "severity": "high",
          "cwe": [
            "CWE-400",
            "CWE-770"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": ">=2.0.0 <2.1.4"
        },
        {
          "source": 1130737,
          "name": "brace-expansion",
          "dependency": "brace-expansion",
          "title": "brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation",
          "url": "https://github.com/advisories/GHSA-rgw5-rvv9-x895",
          "severity": "high",
          "cwe": [
            "CWE-400",
            "CWE-770"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": "<1.1.18"
        }
      ],
      "effects": [],
      "range": "<=1.1.17 || 2.0.0 - 2.1.3",
      "nodes": [
        "node_modules/@eslint/eslintrc/node_modules/brace-expansion",
        "node_modules/@humanwhocodes/config-array/node_modules/brace-expansion",
        "node_modules/brace-expansion",
        "node_modules/eslint/node_modules/brace-expansion",
        "node_modules/glob/node_modules/brace-expansion",
        "node_modules/test-exclude/node_modules/brace-expansion"
      ],
      "fixAvailable": true
    },
    "browserslist": {
      "name": "browserslist",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1153171,
          "name": "browserslist",
          "dependency": "browserslist",
          "title": "Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM",
          "url": "https://github.com/advisories/GHSA-c83g-rgw3-j3cx",
          "severity": "high",
          "cwe": [
            "CWE-770"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": "<=4.28.6"
        },
        {
          "source": 1153172,
          "name": "browserslist",
          "dependency": "browserslist",
          "title": "Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)",
          "url": "https://github.com/advisories/GHSA-73wf-gq98-2v4g",
          "severity": "high",
          "cwe": [
            "CWE-248",
            "CWE-1321"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": "<=4.28.6"
        }
      ],
      "effects": [],
      "range": "<=4.28.6",
      "nodes": [
        "node_modules/browserslist"
      ],
      "fixAvailable": true
    },
    "esbuild": {
      "name": "esbuild",
      "severity": "moderate",
      "isDirect": false,
      "via": [
        {
          "source": 1102341,
          "name": "esbuild",
          "dependency": "esbuild",
          "title": "esbuild enables any website to send any requests to the development server and read the response",
          "url": "https://github.com/advisories/GHSA-67mh-4wv8-2f99",
          "severity": "moderate",
          "cwe": [
            "CWE-346"
          ],
          "cvss": {
            "score": 5.3,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
          },
          "range": "<=0.24.2"
        }
      ],
      "effects": [
        "vite"
      ],
      "range": "<=0.24.2",
      "nodes": [
        "node_modules/esbuild"
      ],
      "fixAvailable": {
        "name": "vite",
        "version": "8.2.2",
        "isSemVerMajor": true
      }
    },
    "fflate": {
      "name": "fflate",
      "severity": "moderate",
      "isDirect": false,
      "via": [
        {
          "source": 1164782,
          "name": "fflate",
          "dependency": "fflate",
          "title": "fflate unzipSync can enter an infinite loop when parsing malformed ZIP64 archives",
          "url": "https://github.com/advisories/GHSA-px8p-9vwx-vf98",
          "severity": "moderate",
          "cwe": [
            "CWE-400"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": ">=0.8.0 <0.8.3"
        }
      ],
      "effects": [],
      "range": "0.8.0 - 0.8.2",
      "nodes": [
        "node_modules/fflate"
      ],
      "fixAvailable": true
    },
    "flatted": {
      "name": "flatted",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1114526,
          "name": "flatted",
          "dependency": "flatted",
          "title": "flatted vulnerable to unbounded recursion DoS in parse() revive phase",
          "url": "https://github.com/advisories/GHSA-25h7-pfq9-p65f",
          "severity": "high",
          "cwe": [
            "CWE-674"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": "<3.4.0"
        },
        {
          "source": 1115357,
          "name": "flatted",
          "dependency": "flatted",
          "title": "Prototype Pollution via parse() in NodeJS flatted",
          "url": "https://github.com/advisories/GHSA-rf6f-7fwh-wjgh",
          "severity": "high",
          "cwe": [
            "CWE-1321"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": "<=3.4.1"
        }
      ],
      "effects": [],
      "range": "<=3.4.1",
      "nodes": [
        "node_modules/flatted"
      ],
      "fixAvailable": true
    },
    "follow-redirects": {
      "name": "follow-redirects",
      "severity": "moderate",
      "isDirect": false,
      "via": [
        {
          "source": 1116560,
          "name": "follow-redirects",
          "dependency": "follow-redirects",
          "title": "follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets",
          "url": "https://github.com/advisories/GHSA-r4q5-vmmm-2653",
          "severity": "moderate",
          "cwe": [
            "CWE-200"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": "<=1.15.11"
        }
      ],
      "effects": [],
      "range": "<=1.15.11",
      "nodes": [
        "node_modules/follow-redirects"
      ],
      "fixAvailable": true
    },
    "form-data": {
      "name": "form-data",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1120743,
          "name": "form-data",
          "dependency": "form-data",
          "title": "form-data: CRLF injection in form-data via unescaped multipart field names and filenames",
          "url": "https://github.com/advisories/GHSA-hmw2-7cc7-3qxx",
          "severity": "high",
          "cwe": [
            "CWE-93"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
          },
          "range": ">=4.0.0 <4.0.6"
        }
      ],
      "effects": [],
      "range": "4.0.0 - 4.0.5",
      "nodes": [
        "node_modules/form-data"
      ],
      "fixAvailable": true
    },
    "glob": {
      "name": "glob",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1109842,
          "name": "glob",
          "dependency": "glob",
          "title": "glob CLI: Command injection via -c/--cmd executes matches with shell:true",
          "url": "https://github.com/advisories/GHSA-5j98-mcp5-4vw2",
          "severity": "high",
          "cwe": [
            "CWE-78"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
          },
          "range": ">=10.2.0 <10.5.0"
        }
      ],
      "effects": [],
      "range": "10.2.0 - 10.4.5",
      "nodes": [
        "node_modules/sucrase/node_modules/glob"
      ],
      "fixAvailable": true
    },
    "js-yaml": {
      "name": "js-yaml",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1121860,
          "name": "js-yaml",
          "dependency": "js-yaml",
          "title": "JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases",
          "url": "https://github.com/advisories/GHSA-h67p-54hq-rp68",
          "severity": "moderate",
          "cwe": [
            "CWE-407"
          ],
          "cvss": {
            "score": 5.3,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
          },
          "range": ">=4.0.0 <=4.1.1"
        },
        {
          "source": 1123911,
          "name": "js-yaml",
          "dependency": "js-yaml",
          "title": "js-yaml: YAML merge-key chains can force quadratic CPU consumption",
          "url": "https://github.com/advisories/GHSA-52cp-r559-cp3m",
          "severity": "high",
          "cwe": [
            "CWE-400",
            "CWE-407"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": ">=4.0.0 <4.3.0"
        },
        {
          "source": 1138115,
          "name": "js-yaml",
          "dependency": "js-yaml",
          "title": "JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) \u2014 CVE-2026-59870 fix not backported",
          "url": "https://github.com/advisories/GHSA-5p4m-2wfm-xmqj",
          "severity": "high",
          "cwe": [
            "CWE-407"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": ">=4.0.0 <4.3.1"
        }
      ],
      "effects": [],
      "range": "4.0.0 - 4.3.0",
      "nodes": [
        "node_modules/js-yaml"
      ],
      "fixAvailable": true
    },
    "minimatch": {
      "name": "minimatch",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1113459,
          "name": "minimatch",
          "dependency": "minimatch",
          "title": "minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
          "url": "https://github.com/advisories/GHSA-3ppc-4f35-3m26",
          "severity": "high",
          "cwe": [
            "CWE-1333"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": "<3.1.3"
        },
        {
          "source": 1113465,
          "name": "minimatch",
          "dependency": "minimatch",
          "title": "minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
          "url": "https://github.com/advisories/GHSA-3ppc-4f35-3m26",
          "severity": "high",
          "cwe": [
            "CWE-1333"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": ">=9.0.0 <9.0.6"
        },
        {
          "source": 1113538,
          "name": "minimatch",
          "dependency": "minimatch",
          "title": "minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments",
          "url": "https://github.com/advisories/GHSA-7r86-cg39-jmmj",
          "severity": "high",
          "cwe": [
            "CWE-407"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": "<3.1.3"
        },
        {
          "source": 1113544,
          "name": "minimatch",
          "dependency": "minimatch",
          "title": "minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments",
          "url": "https://github.com/advisories/GHSA-7r86-cg39-jmmj",
          "severity": "high",
          "cwe": [
            "CWE-407"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": ">=9.0.0 <9.0.7"
        },
        {
          "source": 1113546,
          "name": "minimatch",
          "dependency": "minimatch",
          "title": "minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions",
          "url": "https://github.com/advisories/GHSA-23c5-xmqv-rm74",
          "severity": "high",
          "cwe": [
            "CWE-1333"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": "<3.1.4"
        },
        {
          "source": 1113552,
          "name": "minimatch",
          "dependency": "minimatch",
          "title": "minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions",
          "url": "https://github.com/advisories/GHSA-23c5-xmqv-rm74",
          "severity": "high",
          "cwe": [
            "CWE-1333"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": ">=9.0.0 <9.0.7"
        }
      ],
      "effects": [],
      "range": "<=3.1.3 || 9.0.0 - 9.0.6",
      "nodes": [
        "node_modules/@eslint/eslintrc/node_modules/minimatch",
        "node_modules/@humanwhocodes/config-array/node_modules/minimatch",
        "node_modules/eslint/node_modules/minimatch",
        "node_modules/glob/node_modules/minimatch",
        "node_modules/minimatch",
        "node_modules/test-exclude/node_modules/minimatch"
      ],
      "fixAvailable": true
    },
    "nanoid": {
      "name": "nanoid",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1138811,
          "name": "nanoid",
          "dependency": "nanoid",
          "title": "nanoid: non-secure generators can loop indefinitely with negative size",
          "url": "https://github.com/advisories/GHSA-28wg-ghj8-5hjv",
          "severity": "high",
          "cwe": [
            "CWE-835"
          ],
          "cvss": {
            "score": 5.9,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": "<3.3.16"
        },
        {
          "source": 1139427,
          "name": "nanoid",
          "dependency": "nanoid",
          "title": "nanoid: custom generators can loop indefinitely when size is zero",
          "url": "https://github.com/advisories/GHSA-2v37-7h3g-55p8",
          "severity": "high",
          "cwe": [
            "CWE-835"
          ],
          "cvss": {
            "score": 5.9,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": "<3.3.18"
        },
        {
          "source": 1153189,
          "name": "nanoid",
          "dependency": "nanoid",
          "title": "nanoid: Integer Overflow or Wraparound",
          "url": "https://github.com/advisories/GHSA-xwg4-73v4-xw9w",
          "severity": "high",
          "cwe": [
            "CWE-190"
          ],
          "cvss": {
            "score": 7.4,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
          },
          "range": "<3.3.12"
        }
      ],
      "effects": [],
      "range": "<=3.3.17",
      "nodes": [
        "node_modules/nanoid"
      ],
      "fixAvailable": true
    },
    "picomatch": {
      "name": "picomatch",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1115549,
          "name": "picomatch",
          "dependency": "picomatch",
          "title": "Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
          "url": "https://github.com/advisories/GHSA-3v7f-55p6-f55p",
          "severity": "moderate",
          "cwe": [
            "CWE-1321"
          ],
          "cvss": {
            "score": 5.3,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
          },
          "range": "<2.3.2"
        },
        {
          "source": 1115552,
          "name": "picomatch",
          "dependency": "picomatch",
          "title": "Picomatch has a ReDoS vulnerability via extglob quantifiers",
          "url": "https://github.com/advisories/GHSA-c2c7-rcm5-vvqj",
          "severity": "high",
          "cwe": [
            "CWE-1333"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": "<2.3.2"
        }
      ],
      "effects": [],
      "range": "<=2.3.1",
      "nodes": [
        "node_modules/picomatch"
      ],
      "fixAvailable": true
    },
    "postcss": {
      "name": "postcss",
      "severity": "high",
      "isDirect": true,
      "via": [
        {
          "source": 1117015,
          "name": "postcss",
          "dependency": "postcss",
          "title": "PostCSS has XSS via Unescaped </style> in its CSS Stringify Output",
          "url": "https://github.com/advisories/GHSA-qx2v-qp2m-jg93",
          "severity": "moderate",
          "cwe": [
            "CWE-79"
          ],
          "cvss": {
            "score": 6.1,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
          },
          "range": "<8.5.10"
        },
        {
          "source": 1124252,
          "name": "postcss",
          "dependency": "postcss",
          "title": "PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments",
          "url": "https://github.com/advisories/GHSA-6g55-p6wh-862q",
          "severity": "high",
          "cwe": [
            "CWE-22",
            "CWE-200"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
          },
          "range": "<=8.5.11"
        },
        {
          "source": 1130709,
          "name": "postcss",
          "dependency": "postcss",
          "title": "PostCSS: incomplete fix of GHSA-6g55-p6wh-862q \u2014 attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset",
          "url": "https://github.com/advisories/GHSA-fxqj-rqcc-2cmp",
          "severity": "moderate",
          "cwe": [
            "CWE-22",
            "CWE-200"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": "<=8.5.22"
        },
        {
          "source": 1139510,
          "name": "postcss",
          "dependency": "postcss",
          "title": "PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure",
          "url": "https://github.com/advisories/GHSA-r28c-9q8g-f849",
          "severity": "high",
          "cwe": [
            "CWE-22"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
          },
          "range": "<=8.5.17"
        }
      ],
      "effects": [],
      "range": "<=8.5.22",
      "nodes": [
        "node_modules/postcss"
      ],
      "fixAvailable": true
    },
    "postcss-selector-parser": {
      "name": "postcss-selector-parser",
      "severity": "low",
      "isDirect": false,
      "via": [
        {
          "source": 1153170,
          "name": "postcss-selector-parser",
          "dependency": "postcss-selector-parser",
          "title": "postcss-selector-parser allows denial of service through uncontrolled AST recursion",
          "url": "https://github.com/advisories/GHSA-w9m9-85wc-3x92",
          "severity": "low",
          "cwe": [
            "CWE-404"
          ],
          "cvss": {
            "score": 4.3,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
          },
          "range": ">=6.1.0 <6.1.3"
        }
      ],
      "effects": [],
      "range": "6.1.0 - 6.1.2",
      "nodes": [
        "node_modules/postcss-selector-parser"
      ],
      "fixAvailable": true
    },
    "react-router": {
      "name": "react-router",
      "severity": "high",
      "isDirect": false,
      "via": [
        "@remix-run/router",
        {
          "source": 1124268,
          "name": "react-router",
          "dependency": "react-router",
          "title": "React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)",
          "url": "https://github.com/advisories/GHSA-wrjc-x8rr-h8h6",
          "severity": "moderate",
          "cwe": [
            "CWE-601"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": ">=6.0.0 <7.18.0"
        },
        {
          "source": 1124272,
          "name": "react-router",
          "dependency": "react-router",
          "title": "React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration",
          "url": "https://github.com/advisories/GHSA-337j-9hxr-rhxg",
          "severity": "moderate",
          "cwe": [
            "CWE-470"
          ],
          "cvss": {
            "score": 6.1,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
          },
          "range": ">=6.4.0 <7.18.0"
        },
        {
          "source": 1136303,
          "name": "react-router",
          "dependency": "react-router",
          "title": "React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation",
          "url": "https://github.com/advisories/GHSA-2j2x-hqr9-3h42",
          "severity": "moderate",
          "cwe": [
            "CWE-601"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": ">=6.7.0 <6.30.4"
        }
      ],
      "effects": [
        "react-router-dom"
      ],
      "range": "6.0.0 - 7.17.0",
      "nodes": [
        "node_modules/react-router"
      ],
      "fixAvailable": true
    },
    "react-router-dom": {
      "name": "react-router-dom",
      "severity": "high",
      "isDirect": true,
      "via": [
        "@remix-run/router",
        {
          "source": 1124270,
          "name": "react-router-dom",
          "dependency": "react-router-dom",
          "title": "React Router: Open redirect leading to XSS",
          "url": "https://github.com/advisories/GHSA-jjmj-jmhj-qwj2",
          "severity": "moderate",
          "cwe": [
            "CWE-601"
          ],
          "cvss": {
            "score": 6.9,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N"
          },
          "range": ">=6.30.2 <=6.30.4"
        },
        "react-router"
      ],
      "effects": [],
      "range": "6.0.0-alpha.0 - 7.17.0",
      "nodes": [
        "node_modules/react-router-dom"
      ],
      "fixAvailable": true
    },
    "rollup": {
      "name": "rollup",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1113515,
          "name": "rollup",
          "dependency": "rollup",
          "title": "Rollup 4 has Arbitrary File Write via Path Traversal",
          "url": "https://github.com/advisories/GHSA-mw96-cpmx-2vgc",
          "severity": "high",
          "cwe": [
            "CWE-22"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": ">=4.0.0 <4.59.0"
        }
      ],
      "effects": [],
      "range": "4.0.0 - 4.58.0",
      "nodes": [
        "node_modules/rollup"
      ],
      "fixAvailable": true
    },
    "vite": {
      "name": "vite",
      "severity": "high",
      "isDirect": true,
      "via": [
        {
          "source": 1116229,
          "name": "vite",
          "dependency": "vite",
          "title": "Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
          "url": "https://github.com/advisories/GHSA-4w7w-66w2-5vf9",
          "severity": "moderate",
          "cwe": [
            "CWE-22",
            "CWE-200"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": "<=6.4.1"
        },
        {
          "source": 1120784,
          "name": "vite",
          "dependency": "vite",
          "title": "launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows",
          "url": "https://github.com/advisories/GHSA-v6wh-96g9-6wx3",
          "severity": "moderate",
          "cwe": [
            "CWE-73",
            "CWE-522"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": "<=6.4.2"
        },
        {
          "source": 1123525,
          "name": "vite",
          "dependency": "vite",
          "title": "vite: `server.fs.deny` bypass on Windows alternate paths",
          "url": "https://github.com/advisories/GHSA-fx2h-pf6j-xcff",
          "severity": "high",
          "cwe": [
            "CWE-22",
            "CWE-200"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
          },
          "range": "<=6.4.2"
        },
        "esbuild"
      ],
      "effects": [
        "vite-node",
        "vitest"
      ],
      "range": "<=6.4.2",
      "nodes": [
        "node_modules/vite"
      ],
      "fixAvailable": {
        "name": "vite",
        "version": "8.2.2",
        "isSemVerMajor": true
      }
    },
    "vite-node": {
      "name": "vite-node",
      "severity": "moderate",
      "isDirect": false,
      "via": [
        "vite"
      ],
      "effects": [
        "vitest"
      ],
      "range": "<=2.2.0-beta.2",
      "nodes": [
        "node_modules/vite-node"
      ],
      "fixAvailable": {
        "name": "vitest",
        "version": "5.0.0",
        "isSemVerMajor": true
      }
    },
    "vitest": {
      "name": "vitest",
      "severity": "critical",
      "isDirect": true,
      "via": [
        "@vitest/ui",
        {
          "source": 1139528,
          "name": "vitest",
          "dependency": "vitest",
          "title": "When Vitest UI server is listening, arbitrary file can be read and executed",
          "url": "https://github.com/advisories/GHSA-5xrq-8626-4rwp",
          "severity": "critical",
          "cwe": [
            "CWE-22",
            "CWE-862"
          ],
          "cvss": {
            "score": 9.8,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
          },
          "range": "<3.2.6"
        },
        "vite",
        "vite-node"
      ],
      "effects": [
        "@vitest/coverage-v8",
        "@vitest/ui"
      ],
      "range": "<=3.2.5 || 4.0.0-beta.1 - 4.0.0-beta.14",
      "nodes": [
        "node_modules/vitest"
      ],
      "fixAvailable": {
        "name": "vitest",
        "version": "5.0.0",
        "isSemVerMajor": true
      }
    },
    "ws": {
      "name": "ws",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1119108,
          "name": "ws",
          "dependency": "ws",
          "title": "ws: Uninitialized memory disclosure",
          "url": "https://github.com/advisories/GHSA-58qx-3vcg-4xpx",
          "severity": "moderate",
          "cwe": [
            "CWE-908"
          ],
          "cvss": {
            "score": 4.4,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
          },
          "range": ">=8.0.0 <8.20.1"
        },
        {
          "source": 1123259,
          "name": "ws",
          "dependency": "ws",
          "title": "ws: Memory exhaustion DoS from tiny fragments and data chunks",
          "url": "https://github.com/advisories/GHSA-96hv-2xvq-fx4p",
          "severity": "high",
          "cwe": [
            "CWE-400",
            "CWE-770",
            "CWE-1050"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": ">=8.0.0 <8.21.0"
        }
      ],
      "effects": [],
      "range": "8.0.0 - 8.20.1",
      "nodes": [
        "node_modules/ws"
      ],
      "fixAvailable": true
    },
    "xlsx": {
      "name": "xlsx",
      "severity": "high",
      "isDirect": true,
      "via": [
        {
          "source": 1108110,
          "name": "xlsx",
          "dependency": "xlsx",
          "title": "Prototype Pollution in sheetJS",
          "url": "https://github.com/advisories/GHSA-4r6h-8v6p-xvw6",
          "severity": "high",
          "cwe": [
            "CWE-1321"
          ],
          "cvss": {
            "score": 7.8,
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
          },
          "range": "<0.19.3"
        },
        {
          "source": 1108111,
          "name": "xlsx",
          "dependency": "xlsx",
          "title": "SheetJS Regular Expression Denial of Service (ReDoS)",
          "url": "https://github.com/advisories/GHSA-5pgg-2g8v-p4x9",
          "severity": "high",
          "cwe": [
            "CWE-1333"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": "<0.20.2"
        }
      ],
      "effects": [],
      "range": "*",
      "nodes": [
        "node_modules/xlsx"
      ],
      "fixAvailable": false
    }
  },
  "metadata": {
    "vulnerabilities": {
      "info": 0,
      "low": 2,
      "moderate": 5,
      "high": 18,
      "critical": 3,
      "total": 28
    },
    "dependencies": {
      "prod": 205,
      "dev": 451,
      "optional": 47,
      "peer": 1,
      "peerOptional": 0,
      "total": 657
    }
  }
}