Skip to content

πŸ”’ Security Alerts β€” IBM/plexΒ #721

Description

@security-ops-bot

πŸ”’ Security Alerts β€” IBM/plex

Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.

SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only β€”
they will never trigger warnings or archiving.

πŸ’‘ Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings β†’ Advanced Security β†’ Dependabot security updates β†’ Enable.

Attention: @jeffchew @sstrubberg @ibmdotcom-bot @Palke @Lingaraj-13 @stephharrington1 @Dan-Pastrolin-IBM @leonardo-costa-IBM @rsebade-ibm

Dependabot Alerts

Severity CVE/GHSA Package Affected Patched Fix PR
πŸ”΄ critical CVE-2025-7783 form-data >= 4.0.0, < 4.0.4 4.0.4 β€”
🟠 high CVE-2024-4068 braces < 3.0.3 3.0.3 β€”
🟠 high CVE-2024-37890 ws >= 8.0.0, < 8.17.1 8.17.1 β€”
🟠 high CVE-2024-39338 axios >= 1.3.2, <= 1.7.3 1.7.4 β€”
🟠 high CVE-2024-45590 body-parser < 1.20.3 1.20.3 β€”
🟠 high CVE-2024-21538 cross-spawn >= 7.0.0, < 7.0.5 7.0.5 β€”
🟠 high CVE-2025-27152 axios >= 1.0.0, < 1.8.2 1.8.2 β€”
🟠 high CVE-2025-58754 axios >= 1.0.0, < 1.12.0 1.12.0 β€”
🟠 high CVE-2025-64756 glob >= 10.2.0, < 10.5.0 10.5.0 β€”
🟠 high CVE-2026-23745 tar <= 7.5.2 7.5.3 β€”
🟠 high CVE-2026-23950 tar <= 7.5.3 7.5.4 β€”
🟠 high CVE-2026-45623 postcss <= 8.5.11 8.5.12 β€”
🟠 high CVE-2026-73646 postcss <= 8.5.17 8.5.18 β€”
🟠 high CVE-2026-14257 brace-expansion >= 2.0.0, < 2.1.3 2.1.3 β€”
🟠 high CVE-2026-69152 brace-expansion >= 2.0.0, < 2.1.4 2.1.4 β€”
🟠 high CVE-2026-69185 socket.io-parser >= 4.0.0, < 4.2.7 4.2.7 β€”
🟠 high CVE-2026-69192 ip-address <= 10.3.0 10.3.1 β€”
🟠 high GHSA-5p4m-2wfm-xmqj js-yaml >= 3.0.0, < 3.15.1 3.15.1 β€”
🟠 high CVE-2026-56876 extract-zip <= 2.0.1 β€” β€”
🟠 high CVE-2026-59724 engine.io >= 6.5.0, < 6.6.7 6.6.7 β€”
🟠 high CVE-2026-73086 nanoid < 3.3.12 3.3.12 β€”
🟠 high CVE-2026-59880 immutable >= 4.0.0-beta.1, < 4.3.9 4.3.9 β€”
🟠 high CVE-2026-73088 browserslist <= 4.28.6 4.28.7 β€”
🟠 high CVE-2026-19693 extract-zip <= 2.0.1 β€” β€”
🟠 high CVE-2026-84375 js-yaml >= 4.0.0, < 4.3.2 4.3.2 β€”
🟑 medium CVE-2023-28155 @cypress/request <= 2.88.12 3.0.0 β€”
🟑 medium CVE-2023-45857 axios >= 0.8.1, < 0.28.0 0.28.0 β€”
🟑 medium CVE-2024-28849 follow-redirects <= 1.15.5 1.15.6 β€”
🟑 medium CVE-2024-43788 webpack >= 5.0.0-alpha.0, < 5.94.0 5.94.0 β€”
🟑 medium CVE-2025-26791 dompurify < 3.2.4 3.2.4 β€”
🟑 medium CVE-2025-27789 @babel/runtime < 7.26.10 7.26.10 β€”
🟑 medium CVE-2025-64718 js-yaml >= 4.0.0, < 4.1.1 4.1.1 β€”
🟑 medium CVE-2025-15284 qs < 6.14.1 6.14.1 β€”
🟑 medium CVE-2025-13465 lodash >= 4.0.0, <= 4.17.22 4.17.23 β€”
🟑 medium CVE-2026-54753 nx >= 17.0.4, < 22.7.2 22.7.2 β€”
🟑 medium CVE-2026-69153 postcss <= 8.5.22 8.5.23 β€”
🟑 medium GHSA-55q2-fjhq-7xh7 dompurify <= 3.4.12 3.4.13 β€”
🟑 medium CVE-2026-45822 decode-uri-component <= 0.4.2 0.5.0 β€”
πŸ”΅ low CVE-2024-43796 express < 4.20.0 4.20.0 β€”
πŸ”΅ low CVE-2024-43800 serve-static < 1.16.0 1.16.0 β€”
πŸ”΅ low CVE-2024-43799 send < 0.19.0 0.19.0 β€”
πŸ”΅ low CVE-2024-47764 cookie < 0.7.0 0.7.0 β€”
πŸ”΅ low CVE-2025-46653 formidable >= 2.1.0, < 2.1.3 2.1.3 β€”
πŸ”΅ low CVE-2025-5889 brace-expansion >= 2.0.0, <= 2.0.1 2.0.2 β€”
πŸ”΅ low CVE-2025-7339 on-headers < 1.1.0 1.1.0 β€”
πŸ”΅ low CVE-2025-54798 tmp <= 0.2.3 0.2.4 β€”
πŸ”΅ low CVE-2026-84367 joi >= 16.0.0, < 17.13.5 17.13.5 β€”
πŸ”΅ low CVE-2026-84368 joi >= 17.2.0, < 17.13.6 17.13.6 β€”

Code Scanning Alerts

Severity Rule Tool
🟑 medium actions/missing-workflow-permissions CodeQL
🟑 medium actions/missing-workflow-permissions CodeQL

Secret Scanning Alerts

No open secret scanning alerts.


Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions