Skip to content

AST-142374: update cx-one-scan#990

Open
cx-eyal-kleiner wants to merge 3 commits intomainfrom
ast-142374-update-cxone
Open

AST-142374: update cx-one-scan#990
cx-eyal-kleiner wants to merge 3 commits intomainfrom
ast-142374-update-cxone

Conversation

@cx-eyal-kleiner
Copy link

No description provided.

@cx-ben-alvo
Copy link
Collaborator

cx-ben-alvo commented Mar 22, 2026

Logo
Checkmarx One – Scan Summary & Detailsbf2d14b2-7297-43a1-a6b4-e8e513d8650d


New Issues (5) Checkmarx found the following issues in this Pull Request
# Severity Issue Source File / Package Checkmarx Insight
1 HIGH CVE-2026-32141 Npm-flatted-3.2.9
detailsRecommended version: 3.4.2
Description: flatted is a circular JSON parser. Prior to 3.4.0, flatted's "parse()" function uses a recursive "revive()" phase to resolve circular references in...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
2 HIGH CVE-2026-33228 Npm-flatted-3.4.1
detailsRecommended version: 3.4.2
Description: The "parse()" function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating t...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
3 HIGH CVE-2026-33228 Npm-flatted-3.2.9
detailsRecommended version: 3.4.2
Description: The "parse()" function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating t...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
4 HIGH Cxf5fb15b0-6576 Npm-serialize-javascript-6.0.2
detailsRecommended version: 7.0.3
Description: serialize-javascript through 7.0.2 contains a code injection vulnerability due to improper escaping of "RegExp.flags" during serialization. Althoug...
Attack Vector: NETWORK
Attack Complexity: HIGH
Vulnerable Package
5 HIGH Cxf5fb15b0-6576 Npm-serialize-javascript-6.0.0
detailsRecommended version: 7.0.3
Description: serialize-javascript through 7.0.2 contains a code injection vulnerability due to improper escaping of "RegExp.flags" during serialization. Althoug...
Attack Vector: NETWORK
Attack Complexity: HIGH
Vulnerable Package

Use @Checkmarx to interact with Checkmarx PR Assistant.
Examples:
@Checkmarx how are you able to help me?
@Checkmarx rescan this PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants