Skip to content

Update checkmarx-ast-cli binaries with 2.3.46#968

Merged
cx-anurag-dalke merged 2 commits intomainfrom
feature/update_cli_2.3.46
Mar 1, 2026
Merged

Update checkmarx-ast-cli binaries with 2.3.46#968
cx-anurag-dalke merged 2 commits intomainfrom
feature/update_cli_2.3.46

Conversation

@cx-rahul-pidde
Copy link
Collaborator

Updates checkmarx-ast-cli to 2.3.46

Auto-generated by [create-pull-request][2]

@cx-ben-alvo
Copy link
Collaborator

Logo
Checkmarx One – Scan Summary & Details614b0582-1d0e-4adc-ba94-95b88a61ac39


New Issues (10) Checkmarx found the following issues in this Pull Request
# Severity Issue Source File / Package Checkmarx Insight
1 HIGH CVE-2026-26996 Npm-minimatch-5.0.1
detailsRecommended version: 5.1.8
Description: minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions prior to 3.1.3, 4.0.0 prior to 4.2...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
2 HIGH CVE-2026-26996 Npm-minimatch-3.1.2
detailsRecommended version: 3.1.4
Description: minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions prior to 3.1.3, 4.0.0 prior to 4.2...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
3 HIGH CVE-2026-26996 Npm-minimatch-5.1.6
detailsRecommended version: 5.1.8
Description: minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions prior to 3.1.3, 4.0.0 prior to 4.2...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
4 HIGH CVE-2026-27903 Npm-minimatch-3.1.2
detailsRecommended version: 3.1.4
Description: minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. All versions starting from 3.0.0 and prior ...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
5 HIGH CVE-2026-27903 Npm-minimatch-5.0.1
detailsRecommended version: 5.1.8
Description: minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. All versions starting from 3.0.0 and prior ...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
6 HIGH CVE-2026-27903 Npm-minimatch-5.1.6
detailsRecommended version: 5.1.8
Description: minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. All versions starting from 3.0.0 and prior ...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
7 HIGH CVE-2026-27904 Npm-minimatch-5.0.1
detailsRecommended version: 5.1.8
Description: minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. All versions starting from 3.0.0 and prior ...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
8 HIGH CVE-2026-27904 Npm-minimatch-5.1.6
detailsRecommended version: 5.1.8
Description: minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. All versions starting from 3.0.0 and prior ...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
9 HIGH CVE-2026-27904 Npm-minimatch-3.1.2
detailsRecommended version: 3.1.4
Description: minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. All versions starting from 3.0.0 and prior ...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
10 LOW CVE-2025-69873 Npm-ajv-6.12.6
detailsRecommended version: 6.14.0
Description: ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable to Regular Expression Denial of Service (ReDoS) when the "$data" option is...
Attack Vector: LOCAL
Attack Complexity: HIGH
Vulnerable Package

Fixed Issues (2) Great job! The following issues were fixed in this Pull Request
Severity Issue Source File / Package
MEDIUM CVE-2025-50537 Npm-eslint-8.1.0
MEDIUM CVE-2025-50537 Npm-eslint-8.56.0

Use @Checkmarx to interact with Checkmarx PR Assistant.
Examples:
@Checkmarx how are you able to help me?
@Checkmarx rescan this PR

@cx-anurag-dalke cx-anurag-dalke merged commit 829594e into main Mar 1, 2026
6 of 7 checks passed
@cx-anurag-dalke cx-anurag-dalke deleted the feature/update_cli_2.3.46 branch March 1, 2026 08:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants