Skip to content

[VANTA] [VULNERABILITY] <HIGH> CVE-2026-41305, CVE-2026-41907, CVE-2026-44728 and others, fix before 2026-06-08 #775

@commercelayer-ci

Description

@commercelayer-ci

Important

CLOSE THE ISSUE ONLY IF YOU PLAN TO DEPLOY THE FIX BEFORE THE DEADLINE IN THE TITLE.

DO NOT MANUALLY MODIFY THE ISSUE TITLE OR TEXT BODY.

npm-fast-uri <= 3.1.0 CODE_REPOSITORY/commercelayer-react-components CVE-2026-6321 HIGH remediate by: 2026-06-08T03:55:38.092Z

Related URLs

npm-fast-uri <= 3.1.1 CODE_REPOSITORY/commercelayer-react-components CVE-2026-6322 HIGH remediate by: 2026-06-08T03:55:38.092Z

Related URLs

npm-@babel/plugin-transform-modules-systemjs >= 7.12.0, <= 7.29.3 CODE_REPOSITORY/commercelayer-react-components CVE-2026-44728 HIGH remediate by: 2026-06-08T19:53:06.785Z

Related URLs

npm-js-cookie <= 3.0.5 CODE_REPOSITORY/commercelayer-react-components CVE-2026-46625 HIGH remediate by: 2026-06-21T05:28:39.074Z

Related URLs

npm-postcss < 8.5.10 CODE_REPOSITORY/commercelayer-react-components CVE-2026-41305 MEDIUM remediate by: 2026-06-26T11:09:35.270Z

Related URLs

npm-qs >= 6.11.1, <= 6.15.1 CODE_REPOSITORY/commercelayer-react-components CVE-2026-8723 MEDIUM remediate by: 2026-07-22T19:40:43.361Z

Related URLs

npm-uuid < 11.1.1 CODE_REPOSITORY/commercelayer-react-components CVE-2026-41907 MEDIUM remediate by: 2026-07-23T03:44:40.917Z

Related URLs

Metadata

Metadata

Labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions