> [!IMPORTANT] > CLOSE THE ISSUE ONLY IF YOU PLAN TO DEPLOY THE FIX BEFORE THE DEADLINE IN THE TITLE. > > DO NOT MANUALLY MODIFY THE ISSUE TITLE OR TEXT BODY. `npm-minimatch >= 9.0.0, < 9.0.6` CODE_REPOSITORY/commercelayer-cli-plugin-provisioning <ins>CVE-2026-26996</ins> **HIGH** remediate by: 2026-03-27T08:50:05.811Z - https://github.com/commercelayer/commercelayer-cli-plugin-provisioning/security/dependabot/35 > <details><summary>Related URLs</summary> > > - https://github.com/isaacs/minimatch/security/advisories/GHSA-3ppc-4f35-3m26 > - https://github.com/isaacs/minimatch/commit/2e111f3a79abc00fa73110195de2c0f2351904f5 > - https://nvd.nist.gov/vuln/detail/CVE-2026-26996 > - https://github.com/advisories/GHSA-3ppc-4f35-3m26 > > </details> `npm-minimatch >= 9.0.0, < 9.0.7` CODE_REPOSITORY/commercelayer-cli-plugin-provisioning <ins>CVE-2026-27903</ins> **HIGH** remediate by: 2026-03-30T22:15:05.999Z - https://github.com/commercelayer/commercelayer-cli-plugin-provisioning/security/dependabot/38 > <details><summary>Related URLs</summary> > > - https://github.com/isaacs/minimatch/security/advisories/GHSA-7r86-cg39-jmmj > - https://nvd.nist.gov/vuln/detail/CVE-2026-27903 > - https://github.com/isaacs/minimatch/commit/0bf499aa45f5059b56809cc3b75ff3eafeb8d748 > - https://github.com/advisories/GHSA-7r86-cg39-jmmj > > </details> `npm-minimatch >= 9.0.0, < 9.0.7` CODE_REPOSITORY/commercelayer-cli-plugin-provisioning <ins>CVE-2026-27904</ins> **HIGH** remediate by: 2026-03-30T22:15:05.999Z - https://github.com/commercelayer/commercelayer-cli-plugin-provisioning/security/dependabot/39 > <details><summary>Related URLs</summary> > > - https://github.com/isaacs/minimatch/security/advisories/GHSA-23c5-xmqv-rm74 > - https://nvd.nist.gov/vuln/detail/CVE-2026-27904 > - https://github.com/isaacs/minimatch/commit/11d0df6165d15a955462316b26d52e5efae06fce > - https://github.com/advisories/GHSA-23c5-xmqv-rm74 > > </details> `npm-serialize-javascript <= 7.0.2` CODE_REPOSITORY/commercelayer-cli-plugin-provisioning <ins>GHSA-5c6j-r48x-rmvq</ins> **HIGH** remediate by: 2026-04-01T14:19:30.006Z - https://github.com/commercelayer/commercelayer-cli-plugin-provisioning/security/dependabot/47 > <details><summary>Related URLs</summary> > > - https://github.com/yahoo/serialize-javascript/security/advisories/GHSA-5c6j-r48x-rmvq > - https://nvd.nist.gov/vuln/detail/CVE-2020-7660 > - https://github.com/yahoo/serialize-javascript/commit/2e609d0a9f4f5b097f0945af88bd45b9c7fb48d9 > - https://github.com/advisories/GHSA-hxcc-f52p-wc94 > - https://github.com/yahoo/serialize-javascript/releases/tag/v7.0.3 > - https://github.com/advisories/GHSA-5c6j-r48x-rmvq > > </details> <details><summary><sup><i><code>npm-fast-xml-parser >= 5.0.0, < 5.3.8</code> CODE_REPOSITORY/commercelayer-cli-plugin-provisioning <ins>CVE-2026-27942</ins> <b>LOW</b> remediate by: 2026-06-01T14:21:07.775Z</i></sup></summary> - https://github.com/commercelayer/commercelayer-cli-plugin-provisioning/security/dependabot/48 > <details><summary>Related URLs</summary> > > - https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-fj3w-jwp8-x2g3 > - https://nvd.nist.gov/vuln/detail/CVE-2026-27942 > - https://github.com/NaturalIntelligence/fast-xml-parser/pull/791 > - https://github.com/NaturalIntelligence/fast-xml-parser/commit/c13a961910f14986295dd28484eee830fa1a0e8a > - https://github.com/advisories/GHSA-fj3w-jwp8-x2g3 > > </details> </details>