Skip to content

korojscommands-1.2.20.tgz: 77 vulnerabilities (highest severity is: 9.8) #11

Description

@mend-bolt-for-github
Vulnerable Library - korojscommands-1.2.20.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Found in HEAD commit: d95b6caec2b8ac8d1ac6383ee1f7faee94f527c4

Vulnerabilities

Vulnerability Severity CVSS Dependency Type Fixed in (korojscommands version) Remediation Possible**
CVE-2026-6951 Critical 9.8 simple-git-1.132.0.tgz Transitive N/A*
CVE-2026-41907 Critical 9.8 detected in multiple dependencies Transitive N/A*
CVE-2026-33937 Critical 9.8 handlebars-4.7.7.tgz Transitive N/A*
CVE-2023-42282 Critical 9.8 ip-1.1.5.tgz Transitive N/A*
CVE-2026-23950 High 8.8 tar-4.4.19.tgz Transitive N/A*
CVE-2025-7783 High 8.7 form-data-2.3.3.tgz Transitive N/A*
CVE-2026-59873 High 8.6 tar-4.4.19.tgz Transitive N/A*
CVE-2026-33941 High 8.2 handlebars-4.7.7.tgz Transitive N/A*
CVE-2026-24842 High 8.2 tar-4.4.19.tgz Transitive N/A*
CVE-2026-9277 High 8.1 shell-quote-1.7.4.tgz Transitive 1.2.21
CVE-2026-56876 High 8.1 extract-zip-2.0.1.tgz Transitive N/A*
CVE-2026-4800 High 8.1 lodash-4.17.21.tgz Transitive N/A*
CVE-2026-33940 High 8.1 handlebars-4.7.7.tgz Transitive N/A*
CVE-2026-33938 High 8.1 handlebars-4.7.7.tgz Transitive N/A*
CVE-2026-28291 High 8.1 simple-git-1.132.0.tgz Transitive N/A*
CVE-2024-29415 High 8.1 ip-1.1.5.tgz Transitive N/A*
CVE-2022-25912 High 8.1 simple-git-1.132.0.tgz Transitive N/A*
CVE-2022-25860 High 8.1 simple-git-1.132.0.tgz Transitive N/A*
CVE-2022-24433 High 8.1 simple-git-1.132.0.tgz Transitive N/A*
CVE-2022-24066 High 8.1 simple-git-1.132.0.tgz Transitive N/A*
CVE-2026-59887 High 7.5 linkify-it-4.0.1.tgz Transitive N/A*
CVE-2026-59874 High 7.5 tar-4.4.19.tgz Transitive N/A*
CVE-2026-59869 High 7.5 js-yaml-4.1.0.tgz Transitive N/A*
CVE-2026-48801 High 7.5 linkify-it-4.0.1.tgz Transitive N/A*
CVE-2026-44705 High 7.5 detected in multiple dependencies Transitive N/A*
CVE-2026-33939 High 7.5 handlebars-4.7.7.tgz Transitive N/A*
CVE-2026-33671 High 7.5 picomatch-2.3.1.tgz Transitive N/A*
CVE-2026-27904 High 7.5 detected in multiple dependencies Transitive 1.2.21
CVE-2026-27903 High 7.5 detected in multiple dependencies Transitive N/A*
CVE-2026-26996 High 7.5 detected in multiple dependencies Transitive N/A*
CVE-2026-14257 High 7.5 detected in multiple dependencies Transitive N/A*
CVE-2026-13311 High 7.5 shell-quote-1.7.4.tgz Transitive N/A*
CVE-2026-13149 High 7.5 detected in multiple dependencies Transitive N/A*
CVE-2026-12143 High 7.5 form-data-2.3.3.tgz Transitive N/A*
CVE-2025-64756 High 7.5 glob-10.2.7.tgz Transitive N/A*
CVE-2025-59343 High 7.5 tar-fs-2.0.1.tgz Transitive N/A*
CVE-2025-48387 High 7.5 tar-fs-2.0.1.tgz Transitive N/A*
CVE-2025-25975 High 7.5 parse-git-config-3.0.0.tgz Transitive N/A*
CVE-2024-4068 High 7.5 braces-3.0.2.tgz Transitive N/A*
CVE-2024-21538 High 7.5 detected in multiple dependencies Transitive N/A*
CVE-2024-12905 High 7.5 tar-fs-2.0.1.tgz Transitive N/A*
CVE-2023-2251 High 7.5 yaml-2.2.1.tgz Transitive 1.2.21
CVE-2025-13465 High 7.2 lodash-4.17.21.tgz Transitive N/A*
CVE-2026-31802 High 7.1 tar-4.4.19.tgz Transitive N/A*
CVE-2026-29786 High 7.1 tar-4.4.19.tgz Transitive N/A*
CVE-2026-26960 High 7.1 tar-4.4.19.tgz Transitive N/A*
CVE-2026-23745 High 7.1 tar-4.4.19.tgz Transitive N/A*
CVE-2026-33750 Medium 6.5 detected in multiple dependencies Transitive N/A*
CVE-2026-2950 Medium 6.5 lodash-4.17.21.tgz Transitive N/A*
CVE-2024-28863 Medium 6.5 tar-4.4.19.tgz Transitive N/A*
CVE-2023-26143 Medium 6.5 blamer-1.0.3.tgz Transitive N/A*
CVE-2023-26136 Medium 6.5 tough-cookie-2.5.0.tgz Transitive N/A*
CVE-2026-53655 Medium 6.2 tar-4.4.19.tgz Transitive N/A*
CVE-2025-27789 Medium 6.2 runtime-7.20.7.tgz Transitive 1.2.21
CVE-2023-28155 Medium 6.1 detected in multiple dependencies Transitive 1.2.21
CVE-2026-59875 Medium 5.3 tar-4.4.19.tgz Transitive N/A*
CVE-2026-59871 Medium 5.3 tar-4.4.19.tgz Transitive N/A*
CVE-2026-53550 Medium 5.3 js-yaml-4.1.0.tgz Transitive N/A*
CVE-2026-48988 Medium 5.3 markdown-it-13.0.1.tgz Transitive N/A*
CVE-2026-33672 Medium 5.3 picomatch-2.3.1.tgz Transitive N/A*
CVE-2026-2327 Medium 5.3 markdown-it-13.0.1.tgz Transitive N/A*
CVE-2025-64718 Medium 5.3 js-yaml-4.1.0.tgz Transitive N/A*
CVE-2024-4067 Medium 5.3 micromatch-4.0.5.tgz Transitive 1.2.21
CVE-2023-0842 Medium 5.3 xml2js-0.4.23.tgz Transitive N/A*
CVE-2022-33987 Medium 5.3 got-6.7.1.tgz Transitive N/A*
CVE-2022-25883 Medium 5.3 detected in multiple dependencies Transitive N/A*
CVE-2026-33916 Medium 4.7 handlebars-4.7.7.tgz Transitive N/A*
CVE-2026-33532 Medium 4.3 detected in multiple dependencies Transitive N/A*
CVE-2026-15187 Medium 4.3 enquirer-2.3.6.tgz Transitive N/A*
CVE-2024-33883 Medium 4.0 ejs-3.1.8.tgz Transitive N/A*
CVE-2026-2391 Low 3.7 detected in multiple dependencies Transitive N/A*
CVE-2025-15284 Low 3.7 detected in multiple dependencies Transitive N/A*
CVE-2025-59437 Low 3.2 ip-1.1.5.tgz Transitive N/A*
CVE-2025-59436 Low 3.2 ip-1.1.5.tgz Transitive N/A*
CVE-2025-5889 Low 3.1 detected in multiple dependencies Transitive 1.2.21
CVE-2025-69873 Low 2.9 ajv-6.12.6.tgz Transitive N/A*
CVE-2025-54798 Low 2.5 detected in multiple dependencies Transitive N/A*

*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

Partial details (16 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.

CVE-2026-6951

Vulnerable Library - simple-git-1.132.0.tgz

Simple GIT interface for node.js

Library home page: https://registry.npmjs.org/simple-git/-/simple-git-1.132.0.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • korojscommands-1.2.20.tgz (Root Library)
    • gitmoji-changelog-2.3.0.tgz
      • simple-git-1.132.0.tgz (Vulnerable Library)

Found in HEAD commit: d95b6caec2b8ac8d1ac6383ee1f7faee94f527c4

Found in base branch: main

Vulnerability Details

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for "CVE-2022-25912" (https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2026-04-25

URL: CVE-2026-6951

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-04-25

Fix Resolution: simple-git - 3.36.0,https://github.com/steveukx/git-js.git - simple-git@3.36.0

Step up your Open Source Security Game with Mend here

CVE-2026-41907

Vulnerable Libraries - uuid-8.3.2.tgz, uuid-3.4.0.tgz

uuid-8.3.2.tgz

RFC4122 (v1, v4, and v5) UUIDs

Library home page: https://registry.npmjs.org/uuid/-/uuid-8.3.2.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • korojscommands-1.2.20.tgz (Root Library)
    • cypress-12.15.0.tgz
      • request-2.88.11.tgz
        • uuid-8.3.2.tgz (Vulnerable Library)

uuid-3.4.0.tgz

RFC4122 (v1, v4, and v5) UUIDs

Library home page: https://registry.npmjs.org/uuid/-/uuid-3.4.0.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • korojscommands-1.2.20.tgz (Root Library)
    • gitmoji-changelog-2.3.0.tgz
      • libnpm-3.0.1.tgz
        • npm-lifecycle-3.1.5.tgz
          • node-gyp-5.1.1.tgz
            • request-2.88.2.tgz
              • uuid-3.4.0.tgz (Vulnerable Library)

Found in HEAD commit: d95b6caec2b8ac8d1ac6383ee1f7faee94f527c4

Found in base branch: main

Vulnerability Details

uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.

Publish Date: 2026-04-24

URL: CVE-2026-41907

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-w5hq-g745-h8pq

Release Date: 2026-04-24

Fix Resolution: https://github.com/uuidjs/uuid.git - v11.1.1,https://github.com/uuidjs/uuid.git - v13.0.1,https://github.com/uuidjs/uuid.git - v12.0.1

Step up your Open Source Security Game with Mend here

CVE-2026-33937

Vulnerable Library - handlebars-4.7.7.tgz

Handlebars provides the power necessary to let you build semantic templates effectively with no frustration

Library home page: https://registry.npmjs.org/handlebars/-/handlebars-4.7.7.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • korojscommands-1.2.20.tgz (Root Library)
    • gitmoji-changelog-2.3.0.tgz
      • markdown-2.3.0.tgz
        • handlebars-4.7.7.tgz (Vulnerable Library)

Found in HEAD commit: d95b6caec2b8ac8d1ac6383ee1f7faee94f527c4

Found in base branch: main

Vulnerability Details

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, "Handlebars.compile()" accepts a pre-parsed AST object in addition to a template string. The "value" field of a "NumberLiteral" AST node is emitted directly into the generated JavaScript without quoting or sanitization. An attacker who can supply a crafted AST to "compile()" can therefore inject and execute arbitrary JavaScript, leading to Remote Code Execution on the server. Version 4.7.9 fixes the issue. Some workarounds are available. Validate input type before calling "Handlebars.compile()"; ensure the argument is always a "string", never a plain object or JSON-deserialized value. Use the Handlebars runtime-only build ("handlebars/runtime") on the server if templates are pre-compiled at build time; "compile()" will be unavailable.

Publish Date: 2026-03-27

URL: CVE-2026-33937

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-03-27

Fix Resolution: https://github.com/handlebars-lang/handlebars.js.git - v4.7.9

Step up your Open Source Security Game with Mend here

CVE-2023-42282

Vulnerable Library - ip-1.1.5.tgz

[![](https://badge.fury.io/js/ip.svg)](https://www.npmjs.com/package/ip)

Library home page: https://registry.npmjs.org/ip/-/ip-1.1.5.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • korojscommands-1.2.20.tgz (Root Library)
    • gitmoji-changelog-2.3.0.tgz
      • libnpm-3.0.1.tgz
        • npm-registry-fetch-4.0.7.tgz
          • make-fetch-happen-5.0.2.tgz
            • socks-proxy-agent-4.0.2.tgz
              • socks-2.3.3.tgz
                • ip-1.1.5.tgz (Vulnerable Library)

Found in HEAD commit: d95b6caec2b8ac8d1ac6383ee1f7faee94f527c4

Found in base branch: main

Vulnerability Details

The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.

Publish Date: 2024-02-08

URL: CVE-2023-42282

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-78xj-cgh5-2h22

Release Date: 2024-02-08

Fix Resolution: ip - 1.1.9,2.0.1

Step up your Open Source Security Game with Mend here

CVE-2026-23950

Vulnerable Library - tar-4.4.19.tgz

tar for node

Library home page: https://registry.npmjs.org/tar/-/tar-4.4.19.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • korojscommands-1.2.20.tgz (Root Library)
    • gitmoji-changelog-2.3.0.tgz
      • libnpm-3.0.1.tgz
        • pacote-9.5.12.tgz
          • tar-4.4.19.tgz (Vulnerable Library)

Found in HEAD commit: d95b6caec2b8ac8d1ac6383ee1f7faee94f527c4

Found in base branch: main

Vulnerability Details

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the "path-reservations" system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., "ß" and "ss"), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink Poisoning attacks via race conditions. The library uses a "PathReservations" system to ensure that metadata checks and file operations for the same path are serialized. This prevents race conditions where one entry might clobber another concurrently. This is a Race Condition which enables Arbitrary File Overwrite. This vulnerability affects users and systems using node-tar on macOS (APFS/HFS+). Because of using "NFD" Unicode normalization (in which "ß" and "ss" are different), conflicting paths do not have their order properly preserved under filesystems that ignore Unicode normalization (e.g., APFS (in which "ß" causes an inode collision with "ss")). This enables an attacker to circumvent internal parallelization locks ("PathReservations") using conflicting filenames within a malicious tar archive. The patch in version 7.5.4 updates "path-reservations.js" to use a normalization form that matches the target filesystem's behavior (e.g., "NFKD"), followed by first "toLocaleLowerCase('en')" and then "toLocaleUpperCase('en')". As a workaround, users who cannot upgrade promptly, and who are programmatically using "node-tar" to extract arbitrary tarball data should filter out all "SymbolicLink" entries (as npm does) to defend against arbitrary file writes via this file system entry name collision issue.

Publish Date: 2026-01-20

URL: CVE-2026-23950

CVSS 3 Score Details (8.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: High
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-r6q2-hw4h-h46w

Release Date: 2026-01-20

Fix Resolution: https://github.com/isaacs/node-tar.git - v7.5.4,tar - 7.5.4

Step up your Open Source Security Game with Mend here

CVE-2025-7783

Vulnerable Library - form-data-2.3.3.tgz

A library to create readable "multipart/form-data" streams. Can be used to submit forms and file uploads to other web applications.

Library home page: https://registry.npmjs.org/form-data/-/form-data-2.3.3.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • korojscommands-1.2.20.tgz (Root Library)
    • cypress-12.15.0.tgz
      • request-2.88.11.tgz
        • form-data-2.3.3.tgz (Vulnerable Library)

Found in HEAD commit: d95b6caec2b8ac8d1ac6383ee1f7faee94f527c4

Found in base branch: main

Vulnerability Details

Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js.
This issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2025-07-18

URL: CVE-2025-7783

CVSS 3 Score Details (8.7)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-fjxv-7rqg-78g4

Release Date: 2025-07-18

Fix Resolution: form-data - 3.0.4,https://github.com/form-data/form-data.git - v2.5.4,form-data - 4.0.4,https://github.com/form-data/form-data.git - v4.0.4,https://github.com/form-data/form-data.git - v3.0.4,form-data - 2.5.4

Step up your Open Source Security Game with Mend here

CVE-2026-59873

Vulnerable Library - tar-4.4.19.tgz

tar for node

Library home page: https://registry.npmjs.org/tar/-/tar-4.4.19.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • korojscommands-1.2.20.tgz (Root Library)
    • gitmoji-changelog-2.3.0.tgz
      • libnpm-3.0.1.tgz
        • pacote-9.5.12.tgz
          • tar-4.4.19.tgz (Vulnerable Library)

Found in HEAD commit: d95b6caec2b8ac8d1ac6383ee1f7faee94f527c4

Found in base branch: main

Vulnerability Details

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.

Publish Date: 2026-07-08

URL: CVE-2026-59873

CVSS 3 Score Details (8.6)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-23hp-3jrh-7fpw

Release Date: 2026-07-08

Fix Resolution: tar - 7.5.19,https://github.com/isaacs/node-tar.git - 7.5.19

Step up your Open Source Security Game with Mend here

CVE-2026-33941

Vulnerable Library - handlebars-4.7.7.tgz

Handlebars provides the power necessary to let you build semantic templates effectively with no frustration

Library home page: https://registry.npmjs.org/handlebars/-/handlebars-4.7.7.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • korojscommands-1.2.20.tgz (Root Library)
    • gitmoji-changelog-2.3.0.tgz
      • markdown-2.3.0.tgz
        • handlebars-4.7.7.tgz (Vulnerable Library)

Found in HEAD commit: d95b6caec2b8ac8d1ac6383ee1f7faee94f527c4

Found in base branch: main

Vulnerability Details

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler ("bin/handlebars" / "lib/precompiler.js") concatenates user-controlled strings — template file names and several CLI options — directly into the JavaScript it emits, without any escaping or sanitization. An attacker who can influence template filenames or CLI arguments can inject arbitrary JavaScript that executes when the generated bundle is loaded in Node.js or a browser. Version 4.7.9 fixes the issue. Some workarounds are available. First, validate all CLI inputs before invoking the precompiler. Reject filenames and option values that contain characters with JavaScript string-escaping significance (""", "'", ";", etc.). Second, use a fixed, trusted namespace string passed via a configuration file rather than command-line arguments in automated pipelines. Third, run the precompiler in a sandboxed environment (container with no write access to sensitive paths) to limit the impact of successful exploitation. Fourth, audit template filenames in any repository or package that is consumed by an automated build pipeline.

Publish Date: 2026-03-27

URL: CVE-2026-33941

CVSS 3 Score Details (8.2)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-03-27

Fix Resolution: https://github.com/handlebars-lang/handlebars.js.git - v4.7.9

Step up your Open Source Security Game with Mend here

CVE-2026-24842

Vulnerable Library - tar-4.4.19.tgz

tar for node

Library home page: https://registry.npmjs.org/tar/-/tar-4.4.19.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • korojscommands-1.2.20.tgz (Root Library)
    • gitmoji-changelog-2.3.0.tgz
      • libnpm-3.0.1.tgz
        • pacote-9.5.12.tgz
          • tar-4.4.19.tgz (Vulnerable Library)

Found in HEAD commit: d95b6caec2b8ac8d1ac6383ee1f7faee94f527c4

Found in base branch: main

Vulnerability Details

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.

Publish Date: 2026-01-28

URL: CVE-2026-24842

CVSS 3 Score Details (8.2)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-01-28

Fix Resolution: tar - 7.5.7,https://github.com/isaacs/node-tar.git - v7.5.7

Step up your Open Source Security Game with Mend here

CVE-2026-9277

Vulnerable Library - shell-quote-1.7.4.tgz

quote and parse shell commands

Library home page: https://registry.npmjs.org/shell-quote/-/shell-quote-1.7.4.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • korojscommands-1.2.20.tgz (Root Library)
    • npm-run-all-4.1.5.tgz
      • shell-quote-1.7.4.tgz (Vulnerable Library)

Found in HEAD commit: d95b6caec2b8ac8d1ac6383ee1f7faee94f527c4

Found in base branch: main

Vulnerability Details

shell-quote's "quote()" function did not validate object-token inputs against the operator model used by "parse()". The ".op" field was backslash-escaped character by character using "/(.)/g", which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line terminator in ".op" therefore passed through unescaped into the output; POSIX shells treat a literal newline as a command separator, so any content after it would execute as a second command. The vulnerable code path is reachable in two ways: (1) direct construction of "{ op: '...\n...' }" from external input, and (2) via "parse(cmd, envFn)" when "envFn" returns object tokens whose ".op" is attacker-influenced. Both are documented API surface. Fixed by replacing the per-character escape with strict shape validation: ".op" must match the parser's control-operator allowlist; "{ op: 'glob', pattern }" validates "pattern" and forbids line terminators; "{ comment }" validates "comment" and forbids line terminators; any other object shape throws "TypeError".

Publish Date: 2026-05-22

URL: CVE-2026-9277

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-05-22

Fix Resolution (shell-quote): 1.8.4

Direct dependency fix Resolution (korojscommands): 1.2.21

Step up your Open Source Security Game with Mend here

CVE-2026-56876

Vulnerable Library - extract-zip-2.0.1.tgz

unzip a zip file into a directory using 100% javascript

Library home page: https://registry.npmjs.org/extract-zip/-/extract-zip-2.0.1.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • korojscommands-1.2.20.tgz (Root Library)
    • cypress-12.15.0.tgz
      • extract-zip-2.0.1.tgz (Vulnerable Library)

Found in HEAD commit: d95b6caec2b8ac8d1ac6383ee1f7faee94f527c4

Found in base branch: main

Vulnerability Details

extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how extract-zip is used, an attacker could read or write to arbitrary files.

Publish Date: 2026-06-26

URL: CVE-2026-56876

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Step up your Open Source Security Game with Mend here

CVE-2026-4800

Vulnerable Library - lodash-4.17.21.tgz

Lodash modular utilities.

Library home page: https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • korojscommands-1.2.20.tgz (Root Library)
    • all-contributors-cli-6.26.0.tgz
      • lodash-4.17.21.tgz (Vulnerable Library)

Found in HEAD commit: d95b6caec2b8ac8d1ac6383ee1f7faee94f527c4

Found in base branch: main

Vulnerability Details

Impact:
The fix for CVE-2021-23337 (GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.
When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.
Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function().
Patches:
Users should upgrade to version 4.18.0.
Workarounds:
Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

Publish Date: 2026-03-31

URL: CVE-2026-4800

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-r5fr-rjxr-66jc

Release Date: 2026-03-31

Fix Resolution: lodash-amd - 4.18.0,lodash.template - 4.18.0,lodash-es - 4.18.0,lodash - 4.18.0

Step up your Open Source Security Game with Mend here

CVE-2026-33940

Vulnerable Library - handlebars-4.7.7.tgz

Handlebars provides the power necessary to let you build semantic templates effectively with no frustration

Library home page: https://registry.npmjs.org/handlebars/-/handlebars-4.7.7.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • korojscommands-1.2.20.tgz (Root Library)
    • gitmoji-changelog-2.3.0.tgz
      • markdown-2.3.0.tgz
        • handlebars-4.7.7.tgz (Vulnerable Library)

Found in HEAD commit: d95b6caec2b8ac8d1ac6383ee1f7faee94f527c4

Found in base branch: main

Vulnerability Details

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the template context can bypass all conditional guards in "resolvePartial()" and cause "invokePartial()" to return "undefined". The Handlebars runtime then treats the unresolved partial as a source that needs to be compiled, passing the crafted object to "env.compile()". Because the object is a valid Handlebars AST containing injected code, the generated JavaScript executes arbitrary commands on the server. The attack requires the adversary to control a value that can be returned by a dynamic partial lookup. Version 4.7.9 fixes the issue. Some workarounds are available. First, use the runtime-only build ("require('handlebars/runtime')"). Without "compile()", the fallback compilation path in "invokePartial" is unreachable. Second, sanitize context data before rendering: Ensure no value in the context is a non-primitive object that could be passed to a dynamic partial. Third, avoid dynamic partial lookups ("{{> (lookup ...)}}") when context data is user-controlled.

Publish Date: 2026-03-27

URL: CVE-2026-33940

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-03-27

Fix Resolution: https://github.com/handlebars-lang/handlebars.js.git - v4.7.9

Step up your Open Source Security Game with Mend here

CVE-2026-33938

Vulnerable Library - handlebars-4.7.7.tgz

Handlebars provides the power necessary to let you build semantic templates effectively with no frustration

Library home page: https://registry.npmjs.org/handlebars/-/handlebars-4.7.7.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • korojscommands-1.2.20.tgz (Root Library)
    • gitmoji-changelog-2.3.0.tgz
      • markdown-2.3.0.tgz
        • handlebars-4.7.7.tgz (Vulnerable Library)

Found in HEAD commit: d95b6caec2b8ac8d1ac6383ee1f7faee94f527c4

Found in base branch: main

Vulnerability Details

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the "@⁠partial-block" special variable is stored in the template data context and is reachable and mutable from within a template via helpers that accept arbitrary objects. When a helper overwrites "@⁠partial-block" with a crafted Handlebars AST, a subsequent invocation of "{{> @⁠partial-block}}" compiles and executes that AST, enabling arbitrary JavaScript execution on the server. Version 4.7.9 fixes the issue. Some workarounds are available. First, use the runtime-only build ("require('handlebars/runtime')"). The "compile()" method is absent, eliminating the vulnerable fallback path. Second, audit registered helpers for any that write arbitrary values to context objects. Helpers should treat context data as read-only. Third, avoid registering helpers from third-party packages (such as "handlebars-helpers") in contexts where templates or context data can be influenced by untrusted input.

Publish Date: 2026-03-27

URL: CVE-2026-33938

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-03-27

Fix Resolution: https://github.com/handlebars-lang/handlebars.js.git - v4.7.9

Step up your Open Source Security Game with Mend here

CVE-2026-28291

Vulnerable Library - simple-git-1.132.0.tgz

Simple GIT interface for node.js

Library home page: https://registry.npmjs.org/simple-git/-/simple-git-1.132.0.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • korojscommands-1.2.20.tgz (Root Library)
    • gitmoji-changelog-2.3.0.tgz
      • simple-git-1.132.0.tgz (Vulnerable Library)

Found in HEAD commit: d95b6caec2b8ac8d1ac6383ee1f7faee94f527c4

Found in base branch: main

Vulnerability Details

simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option manipulation, bypassing safety checks meant to block dangerous options like -u and --upload-pack. The flaw stems from an incomplete fix for CVE-2022-25860, as Git's flexible option parsing allows numerous character combinations (e.g., -vu, -4u, -nu) to circumvent the regular-expression-based blocklist in the unsafe operations plugin. Due to the virtually infinite number of valid option variants that Git accepts, a complete blocklist-based mitigation may be infeasible without fully emulating Git's option parsing behavior. This issue has been fixed in version 3.32.0.

Publish Date: 2026-04-13

URL: CVE-2026-28291

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-04-13

Fix Resolution: https://github.com/steveukx/git-js.git - simple-git@3.32.0

Step up your Open Source Security Game with Mend here

CVE-2024-29415

Vulnerable Library - ip-1.1.5.tgz

[![](https://badge.fury.io/js/ip.svg)](https://www.npmjs.com/package/ip)

Library home page: https://registry.npmjs.org/ip/-/ip-1.1.5.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • korojscommands-1.2.20.tgz (Root Library)
    • gitmoji-changelog-2.3.0.tgz
      • libnpm-3.0.1.tgz
        • npm-registry-fetch-4.0.7.tgz
          • make-fetch-happen-5.0.2.tgz
            • socks-proxy-agent-4.0.2.tgz
              • socks-2.3.3.tgz
                • ip-1.1.5.tgz (Vulnerable Library)

Found in HEAD commit: d95b6caec2b8ac8d1ac6383ee1f7faee94f527c4

Found in base branch: main

Vulnerability Details

The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2023-42282.

Publish Date: 2024-05-27

URL: CVE-2024-29415

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Step up your Open Source Security Game with Mend here

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions