π Security Alerts β IBM/plex
Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.
SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only β
they will never trigger warnings or archiving.
π‘ Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings β Advanced Security β Dependabot security updates β Enable.
Attention: @jeffchew @sstrubberg @ibmdotcom-bot @Palke @Lingaraj-13 @stephharrington1 @Dan-Pastrolin-IBM @leonardo-costa-IBM @rsebade-ibm
Dependabot Alerts
| Severity |
CVE/GHSA |
Package |
Affected |
Patched |
Fix PR |
| π΄ critical |
CVE-2025-7783 |
form-data |
>= 4.0.0, < 4.0.4 |
4.0.4 |
β |
| π high |
CVE-2024-4068 |
braces |
< 3.0.3 |
3.0.3 |
β |
| π high |
CVE-2024-37890 |
ws |
>= 8.0.0, < 8.17.1 |
8.17.1 |
β |
| π high |
CVE-2024-39338 |
axios |
>= 1.3.2, <= 1.7.3 |
1.7.4 |
β |
| π high |
CVE-2024-45590 |
body-parser |
< 1.20.3 |
1.20.3 |
β |
| π high |
CVE-2024-21538 |
cross-spawn |
>= 7.0.0, < 7.0.5 |
7.0.5 |
β |
| π high |
CVE-2025-27152 |
axios |
>= 1.0.0, < 1.8.2 |
1.8.2 |
β |
| π high |
CVE-2025-58754 |
axios |
>= 1.0.0, < 1.12.0 |
1.12.0 |
β |
| π high |
CVE-2025-64756 |
glob |
>= 10.2.0, < 10.5.0 |
10.5.0 |
β |
| π high |
CVE-2026-23745 |
tar |
<= 7.5.2 |
7.5.3 |
β |
| π high |
CVE-2026-23950 |
tar |
<= 7.5.3 |
7.5.4 |
β |
| π high |
CVE-2026-45623 |
postcss |
<= 8.5.11 |
8.5.12 |
β |
| π high |
CVE-2026-73646 |
postcss |
<= 8.5.17 |
8.5.18 |
β |
| π high |
CVE-2026-14257 |
brace-expansion |
>= 2.0.0, < 2.1.3 |
2.1.3 |
β |
| π high |
CVE-2026-69152 |
brace-expansion |
>= 2.0.0, < 2.1.4 |
2.1.4 |
β |
| π high |
CVE-2026-69185 |
socket.io-parser |
>= 4.0.0, < 4.2.7 |
4.2.7 |
β |
| π high |
CVE-2026-69192 |
ip-address |
<= 10.3.0 |
10.3.1 |
β |
| π high |
GHSA-5p4m-2wfm-xmqj |
js-yaml |
>= 3.0.0, < 3.15.1 |
3.15.1 |
β |
| π high |
CVE-2026-56876 |
extract-zip |
<= 2.0.1 |
β |
β |
| π high |
CVE-2026-59724 |
engine.io |
>= 6.5.0, < 6.6.7 |
6.6.7 |
β |
| π high |
CVE-2026-73086 |
nanoid |
< 3.3.12 |
3.3.12 |
β |
| π high |
CVE-2026-59880 |
immutable |
>= 4.0.0-beta.1, < 4.3.9 |
4.3.9 |
β |
| π high |
CVE-2026-73088 |
browserslist |
<= 4.28.6 |
4.28.7 |
β |
| π high |
CVE-2026-19693 |
extract-zip |
<= 2.0.1 |
β |
β |
| π high |
CVE-2026-84375 |
js-yaml |
>= 4.0.0, < 4.3.2 |
4.3.2 |
β |
| π‘ medium |
CVE-2023-28155 |
@cypress/request |
<= 2.88.12 |
3.0.0 |
β |
| π‘ medium |
CVE-2023-45857 |
axios |
>= 0.8.1, < 0.28.0 |
0.28.0 |
β |
| π‘ medium |
CVE-2024-28849 |
follow-redirects |
<= 1.15.5 |
1.15.6 |
β |
| π‘ medium |
CVE-2024-43788 |
webpack |
>= 5.0.0-alpha.0, < 5.94.0 |
5.94.0 |
β |
| π‘ medium |
CVE-2025-26791 |
dompurify |
< 3.2.4 |
3.2.4 |
β |
| π‘ medium |
CVE-2025-27789 |
@babel/runtime |
< 7.26.10 |
7.26.10 |
β |
| π‘ medium |
CVE-2025-64718 |
js-yaml |
>= 4.0.0, < 4.1.1 |
4.1.1 |
β |
| π‘ medium |
CVE-2025-15284 |
qs |
< 6.14.1 |
6.14.1 |
β |
| π‘ medium |
CVE-2025-13465 |
lodash |
>= 4.0.0, <= 4.17.22 |
4.17.23 |
β |
| π‘ medium |
CVE-2026-54753 |
nx |
>= 17.0.4, < 22.7.2 |
22.7.2 |
β |
| π‘ medium |
CVE-2026-69153 |
postcss |
<= 8.5.22 |
8.5.23 |
β |
| π‘ medium |
GHSA-55q2-fjhq-7xh7 |
dompurify |
<= 3.4.12 |
3.4.13 |
β |
| π‘ medium |
CVE-2026-45822 |
decode-uri-component |
<= 0.4.2 |
0.5.0 |
β |
| π΅ low |
CVE-2024-43796 |
express |
< 4.20.0 |
4.20.0 |
β |
| π΅ low |
CVE-2024-43800 |
serve-static |
< 1.16.0 |
1.16.0 |
β |
| π΅ low |
CVE-2024-43799 |
send |
< 0.19.0 |
0.19.0 |
β |
| π΅ low |
CVE-2024-47764 |
cookie |
< 0.7.0 |
0.7.0 |
β |
| π΅ low |
CVE-2025-46653 |
formidable |
>= 2.1.0, < 2.1.3 |
2.1.3 |
β |
| π΅ low |
CVE-2025-5889 |
brace-expansion |
>= 2.0.0, <= 2.0.1 |
2.0.2 |
β |
| π΅ low |
CVE-2025-7339 |
on-headers |
< 1.1.0 |
1.1.0 |
β |
| π΅ low |
CVE-2025-54798 |
tmp |
<= 0.2.3 |
0.2.4 |
β |
| π΅ low |
CVE-2026-84367 |
joi |
>= 16.0.0, < 17.13.5 |
17.13.5 |
β |
| π΅ low |
CVE-2026-84368 |
joi |
>= 17.2.0, < 17.13.6 |
17.13.6 |
β |
Code Scanning Alerts
| Severity |
Rule |
Tool |
| π‘ medium |
actions/missing-workflow-permissions |
CodeQL |
| π‘ medium |
actions/missing-workflow-permissions |
CodeQL |
Secret Scanning Alerts
No open secret scanning alerts.
π Security Alerts β IBM/plex
Attention: @jeffchew @sstrubberg @ibmdotcom-bot @Palke @Lingaraj-13 @stephharrington1 @Dan-Pastrolin-IBM @leonardo-costa-IBM @rsebade-ibm
Dependabot Alerts
Code Scanning Alerts
Secret Scanning Alerts
No open secret scanning alerts.