Skip to content

Update checkmarx-ast-cli binaries with 2.3.45#153

Open
cx-anurag-dalke wants to merge 1 commit intomainfrom
feature/update_cli_2.3.45
Open

Update checkmarx-ast-cli binaries with 2.3.45#153
cx-anurag-dalke wants to merge 1 commit intomainfrom
feature/update_cli_2.3.45

Conversation

@cx-anurag-dalke
Copy link
Collaborator

Updates checkmarx-ast-cli to 2.3.45

Auto-generated by [create-pull-request][2]

@cx-ben-alvo
Copy link
Collaborator

Logo
Checkmarx One – Scan Summary & Details921291f8-37de-47b1-82a5-7299fa149447

New Issues (9)

Checkmarx found the following issues in this Pull Request

# Severity Issue Source File / Package Checkmarx Insight
1 HIGH CVE-2026-23950 Npm-tar-7.4.3
detailsRecommended version: 7.5.7
Description: node-tar,a Tar for Node.js, has a race condition vulnerability in versions through 7.5.3. This is due to an incomplete handling of Unicode path col...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
2 HIGH CVE-2026-24842 Npm-tar-7.4.3
detailsRecommended version: 7.5.7
Description: node-tar, a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path ...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
3 MEDIUM CVE-2025-13465 Npm-lodash-4.17.21
detailsRecommended version: 4.17.23
Description: Lodash versions from 4.0.0 through 4.17.22 are vulnerable to Prototype Pollution in the "_.unset" and "_.omit" functions. An attacker can pass craf...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
4 MEDIUM CVE-2025-50537 Npm-eslint-8.1.0
detailsRecommended version: 9.26.0
Description: Stack Overflow vulnerability in ESLint prior to 9.26.0 when serializing objects with circular references in "eslint/lib/shared/serialization.js". T...
Attack Vector: LOCAL
Attack Complexity: LOW
Vulnerable Package
5 MEDIUM CVE-2025-50537 Npm-eslint-8.57.1
detailsRecommended version: 9.26.0
Description: Stack Overflow vulnerability in ESLint prior to 9.26.0 when serializing objects with circular references in "eslint/lib/shared/serialization.js". T...
Attack Vector: LOCAL
Attack Complexity: LOW
Vulnerable Package
6 MEDIUM CVE-2026-2391 Npm-qs-6.14.0
detailsRecommended version: 6.14.2
Description: ### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to c...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
7 LOW CVE-2025-68157 Npm-webpack-5.98.0
detailsRecommended version: 5.104.1
Description: Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpacks HTTP(S) resolver (HttpUriPlugin...
Attack Vector: NETWORK
Attack Complexity: HIGH
Vulnerable Package
8 LOW CVE-2025-68458 Npm-webpack-5.98.0
detailsRecommended version: 5.104.1
Description: Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpacks HTTP(S) resolver (HttpUriPlugin...
Attack Vector: NETWORK
Attack Complexity: HIGH
Vulnerable Package
9 LOW CVE-2026-24001 Npm-diff-5.0.0
detailsRecommended version: 5.2.1
Description: jsdiff is a JavaScript text differencing implementation. Prior to versions 4.0.3, 5.x prior to 5.2.1 and 6.x through 8.x prior to 8.0.3, attempting...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package

Use @Checkmarx to interact with Checkmarx PR Assistant.
Examples:
@Checkmarx how are you able to help me?
@Checkmarx rescan this PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants