### Target `bun.lock` #### ⚠️ Vulnerabilities (18) | Package | ID | Severity | Installed Version | Fixed Version | Links | |---------|----|---------:|------------------:|--------------|-------| | `astro` | CVE-2026-59729 | **MEDIUM** | 7.0.4 | 7.0.6 |[🔗](https://github.com/withastro/astro) [🔗](https://github.com/withastro/astro/commit/5240e26c9dd91f9bc7140dcfacdb48d5a132830d) [🔗](https://github.com/withastro/astro/pull/17251) [🔗](https://github.com/withastro/astro/releases/tag/astro@7.0.6) [🔗](https://github.com/withastro/astro/security/advisories/GHSA-f48w-9m4c-m7f5) | | `astro` | GHSA-4g3v-8h47-v7g6 | **MEDIUM** | 7.0.4 | 7.1.0 |[🔗](https://github.com/withastro/astro) [🔗](https://github.com/withastro/astro/commit/092da560eea77ee63a3e2c583c80d8238544e42b) [🔗](https://github.com/withastro/astro/pull/17393) [🔗](https://github.com/withastro/astro/releases/tag/astro@7.1.0) [🔗](https://github.com/withastro/astro/security/advisories/GHSA-4g3v-8h47-v7g6) | | `astro` | GHSA-8mv7-9c27-98vc | **MEDIUM** | 7.0.4 | 7.0.6 |[🔗](https://github.com/withastro/astro) [🔗](https://github.com/withastro/astro/commit/0b30b35f864310bee8485c952d1877e82e2b9b1a) [🔗](https://github.com/withastro/astro/pull/17250) [🔗](https://github.com/withastro/astro/releases/tag/astro@7.0.6) [🔗](https://github.com/withastro/astro/security/advisories/GHSA-8mv7-9c27-98vc) | | `dompurify` | CVE-2026-65898 | **MEDIUM** | 3.4.10 | 3.4.11 |[🔗](https://github.com/cure53/DOMPurify) [🔗](https://github.com/cure53/DOMPurify/commit/011bc3b2fcc4be17aa76f9030e8668207717acb9) [🔗](https://github.com/cure53/DOMPurify/pull/1482) [🔗](https://github.com/cure53/DOMPurify/releases/tag/3.4.11) [🔗](https://github.com/cure53/DOMPurify/security/advisories/GHSA-cmwh-pvxp-8882) [🔗](https://www.vulncheck.com/advisories/dompurify-before-permanent-attribute-allowlist-pollution-via-setconfig) | | `dompurify` | GHSA-55q2-fjhq-7xh7 | **MEDIUM** | 3.4.10 | 3.4.13 |[🔗](https://github.com/cure53/DOMPurify) [🔗](https://github.com/cure53/DOMPurify/commit/3067f7746769) [🔗](https://github.com/cure53/DOMPurify/pull/1557) [🔗](https://github.com/cure53/DOMPurify/releases/tag/3.4.13) [🔗](https://github.com/cure53/DOMPurify/security/advisories/GHSA-55q2-fjhq-7xh7) | | `dompurify` | GHSA-c2j3-45gr-mqc4 | **LOW** | 3.4.10 | 3.4.12 |[🔗](https://github.com/cure53/DOMPurify) [🔗](https://github.com/cure53/DOMPurify/commit/a9ca1e537422319a557a9a2aa61f003b23b4a197) [🔗](https://github.com/cure53/DOMPurify/pull/1537) [🔗](https://github.com/cure53/DOMPurify/releases/tag/3.4.12) [🔗](https://github.com/cure53/DOMPurify/security/advisories/GHSA-c2j3-45gr-mqc4) | | `js-yaml` | CVE-2026-59869 | **HIGH** | 4.2.0 | 3.15.0, 4.3.0 |[🔗](https://access.redhat.com/security/cve/CVE-2026-59869) [🔗](https://github.com/nodeca/js-yaml) [🔗](https://github.com/nodeca/js-yaml/commit/24f13e79ee1343a7e30bd6f6c9d9cdbf0ac9b2b7) [🔗](https://github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e4) [🔗](https://github.com/nodeca/js-yaml/releases/tag/3.15.0) [🔗](https://github.com/nodeca/js-yaml/releases/tag/4.3.0) [🔗](https://github.com/nodeca/js-yaml/security/advisories/GHSA-52cp-r559-cp3m) [🔗](https://nvd.nist.gov/vuln/detail/CVE-2026-59869) [🔗](https://www.cve.org/CVERecord?id=CVE-2026-59869) | | `js-yaml` | GHSA-5p4m-2wfm-xmqj | **HIGH** | 4.2.0 | 4.3.1, 3.15.1 |[🔗](https://github.com/nodeca/js-yaml) [🔗](https://github.com/nodeca/js-yaml/security/advisories/GHSA-5p4m-2wfm-xmqj) | | `mermaid` | CVE-2026-50159 | **MEDIUM** | 11.15.0 | 11.16.1, 10.9.8 |[🔗](https://github.com/mermaid-js/mermaid) [🔗](https://github.com/mermaid-js/mermaid/commit/12d472c9ed43f94814b110da8d7a9ae6dd5266ed) [🔗](https://github.com/mermaid-js/mermaid/commit/7e83f1533318b307764d961906a73377266f4c5e) [🔗](https://github.com/mermaid-js/mermaid/pull/8022) [🔗](https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1) [🔗](https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8) [🔗](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-6x64-9x62-f2gx) | | `mermaid` | CVE-2026-71436 | **MEDIUM** | 11.15.0 | 10.9.8, 11.16.1 |[🔗](https://access.redhat.com/security/cve/CVE-2026-71436) [🔗](https://github.com/mermaid-js/mermaid) [🔗](https://github.com/mermaid-js/mermaid/commit/630aa7e5dd417e1f56bff2a1ce8df2c5ad08d289) [🔗](https://github.com/mermaid-js/mermaid/commit/ef60adc837d9d5107af21285f01e83dea309bd0a) [🔗](https://github.com/mermaid-js/mermaid/pull/8022) [🔗](https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1) [🔗](https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8) [🔗](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-2v8p-3f2j-5mp7) [🔗](https://nvd.nist.gov/vuln/detail/CVE-2026-71436) [🔗](https://www.cve.org/CVERecord?id=CVE-2026-71436) | | `mermaid` | CVE-2026-71437 | **MEDIUM** | 11.15.0 | 11.16.1 |[🔗](https://access.redhat.com/security/cve/CVE-2026-71437) [🔗](https://github.com/mermaid-js/mermaid) [🔗](https://github.com/mermaid-js/mermaid/commit/99af3fc35ef0a9a9c8c6314521344d67523ddccf) [🔗](https://github.com/mermaid-js/mermaid/pull/8022) [🔗](https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1) [🔗](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-3rrr-jr9j-h3q3) [🔗](https://nvd.nist.gov/vuln/detail/CVE-2026-71437) [🔗](https://www.cve.org/CVERecord?id=CVE-2026-71437) | | `mermaid` | CVE-2026-71439 | **MEDIUM** | 11.15.0 | 11.16.1 |[🔗](https://github.com/mermaid-js/mermaid) [🔗](https://github.com/mermaid-js/mermaid/commit/59b22fad2b3bb04f87a476c84a8a2b24679e607e) [🔗](https://github.com/mermaid-js/mermaid/pull/8022) [🔗](https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1) [🔗](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-rhh3-jpg6-66xh) | | `mermaid` | CVE-2026-71438 | **LOW** | 11.15.0 | 11.16.1, 10.9.8 |[🔗](https://access.redhat.com/security/cve/CVE-2026-71438) [🔗](https://github.com/mermaid-js/mermaid) [🔗](https://github.com/mermaid-js/mermaid/commit/2cd6dcf735533b323507e3e889ffdea870540b43) [🔗](https://github.com/mermaid-js/mermaid/commit/c34b07a0815842327e70794d69b0c8c5a1e2a956) [🔗](https://github.com/mermaid-js/mermaid/pull/8022) [🔗](https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1) [🔗](https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8) [🔗](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-c4c3-pg64-4m4v) [🔗](https://nvd.nist.gov/vuln/detail/CVE-2026-71438) [🔗](https://www.cve.org/CVERecord?id=CVE-2026-71438) | | `nanoid` | CVE-2026-67213 | **HIGH** | 3.3.12 | 3.3.17, 5.1.6 |[🔗](https://github.com/ai/nanoid) [🔗](https://github.com/ai/nanoid/commit/cb3626d0f3342fdf179cd425fd9c4fbb92c7d0e7) [🔗](https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b) [🔗](https://github.com/ai/nanoid/releases/tag/3.3.17) [🔗](https://github.com/ai/nanoid/releases/tag/5.1.6) [🔗](https://nvd.nist.gov/vuln/detail/CVE-2026-67213) [🔗](https://www.vulncheck.com/advisories/nanoid-before-infinite-loop-via-zero-size-in-customalphabet-and-customrandom) | | `nanoid` | CVE-2026-67214 | **HIGH** | 3.3.12 | 3.3.16, 5.1.16 |[🔗](https://github.com/ai/nanoid) [🔗](https://github.com/ai/nanoid/commit/6ccc67bbaba71d3d77a21d9b636f4171a268ce49) [🔗](https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d) [🔗](https://github.com/ai/nanoid/pull/600) [🔗](https://github.com/ai/nanoid/pull/601) [🔗](https://github.com/ai/nanoid/releases/tag/5.1.16) [🔗](https://nvd.nist.gov/vuln/detail/CVE-2026-67214) [🔗](https://www.vulncheck.com/advisories/nanoid-before-infinite-loop-via-negative-size-in-non-secure-module) | | `postcss` | GHSA-r28c-9q8g-f849 | **HIGH** | 8.5.15 | 8.5.18 |[🔗](https://github.com/postcss/postcss) [🔗](https://github.com/postcss/postcss/commit/95663d3eb7ba26f4854dd19d3b4f4425760cf56c) [🔗](https://github.com/postcss/postcss/releases/tag/8.5.18) [🔗](https://github.com/postcss/postcss/security/advisories/GHSA-r28c-9q8g-f849) | | `postcss` | CVE-2026-69153 | **MEDIUM** | 8.5.15 | 8.5.23 |[🔗](https://access.redhat.com/security/cve/CVE-2026-69153) [🔗](https://github.com/postcss/postcss) [🔗](https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8) [🔗](https://github.com/postcss/postcss/releases/tag/8.5.19) [🔗](https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp) [🔗](https://nvd.nist.gov/vuln/detail/CVE-2026-69153) [🔗](https://www.cve.org/CVERecord?id=CVE-2026-69153) | | `svgo` | GHSA-2p49-hgcm-8545 | **HIGH** | 4.0.1 | 2.8.3, 3.3.4, 4.0.2 |[🔗](https://github.com/svg/svgo) [🔗](https://github.com/svg/svgo/commit/628e3bc7336625a30365d0a9b60185307d852466) [🔗](https://github.com/svg/svgo/commit/72a23886b4698b27624b936f3a15a80afd36d75f) [🔗](https://github.com/svg/svgo/commit/f529cfccc6c154d6f6eabe276ec637a8c5db6763) [🔗](https://github.com/svg/svgo/releases/tag/v2.8.3) [🔗](https://github.com/svg/svgo/releases/tag/v3.3.4) [🔗](https://github.com/svg/svgo/releases/tag/v4.0.2) [🔗](https://github.com/svg/svgo/security/advisories/GHSA-2p49-hgcm-8545) | #### ✅ No Misconfigurations found ### Target `pnpm-lock.yaml` #### ⚠️ Vulnerabilities (5) | Package | ID | Severity | Installed Version | Fixed Version | Links | |---------|----|---------:|------------------:|--------------|-------| | `mermaid` | CVE-2026-50159 | **MEDIUM** | 11.16.0 | 11.16.1, 10.9.8 |[🔗](https://github.com/mermaid-js/mermaid) [🔗](https://github.com/mermaid-js/mermaid/commit/12d472c9ed43f94814b110da8d7a9ae6dd5266ed) [🔗](https://github.com/mermaid-js/mermaid/commit/7e83f1533318b307764d961906a73377266f4c5e) [🔗](https://github.com/mermaid-js/mermaid/pull/8022) [🔗](https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1) [🔗](https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8) [🔗](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-6x64-9x62-f2gx) | | `mermaid` | CVE-2026-71436 | **MEDIUM** | 11.16.0 | 10.9.8, 11.16.1 |[🔗](https://access.redhat.com/security/cve/CVE-2026-71436) [🔗](https://github.com/mermaid-js/mermaid) [🔗](https://github.com/mermaid-js/mermaid/commit/630aa7e5dd417e1f56bff2a1ce8df2c5ad08d289) [🔗](https://github.com/mermaid-js/mermaid/commit/ef60adc837d9d5107af21285f01e83dea309bd0a) [🔗](https://github.com/mermaid-js/mermaid/pull/8022) [🔗](https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1) [🔗](https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8) [🔗](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-2v8p-3f2j-5mp7) [🔗](https://nvd.nist.gov/vuln/detail/CVE-2026-71436) [🔗](https://www.cve.org/CVERecord?id=CVE-2026-71436) | | `mermaid` | CVE-2026-71437 | **MEDIUM** | 11.16.0 | 11.16.1 |[🔗](https://access.redhat.com/security/cve/CVE-2026-71437) [🔗](https://github.com/mermaid-js/mermaid) [🔗](https://github.com/mermaid-js/mermaid/commit/99af3fc35ef0a9a9c8c6314521344d67523ddccf) [🔗](https://github.com/mermaid-js/mermaid/pull/8022) [🔗](https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1) [🔗](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-3rrr-jr9j-h3q3) [🔗](https://nvd.nist.gov/vuln/detail/CVE-2026-71437) [🔗](https://www.cve.org/CVERecord?id=CVE-2026-71437) | | `mermaid` | CVE-2026-71439 | **MEDIUM** | 11.16.0 | 11.16.1 |[🔗](https://github.com/mermaid-js/mermaid) [🔗](https://github.com/mermaid-js/mermaid/commit/59b22fad2b3bb04f87a476c84a8a2b24679e607e) [🔗](https://github.com/mermaid-js/mermaid/pull/8022) [🔗](https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1) [🔗](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-rhh3-jpg6-66xh) | | `mermaid` | CVE-2026-71438 | **LOW** | 11.16.0 | 11.16.1, 10.9.8 |[🔗](https://access.redhat.com/security/cve/CVE-2026-71438) [🔗](https://github.com/mermaid-js/mermaid) [🔗](https://github.com/mermaid-js/mermaid/commit/2cd6dcf735533b323507e3e889ffdea870540b43) [🔗](https://github.com/mermaid-js/mermaid/commit/c34b07a0815842327e70794d69b0c8c5a1e2a956) [🔗](https://github.com/mermaid-js/mermaid/pull/8022) [🔗](https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1) [🔗](https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8) [🔗](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-c4c3-pg64-4m4v) [🔗](https://nvd.nist.gov/vuln/detail/CVE-2026-71438) [🔗](https://www.cve.org/CVERecord?id=CVE-2026-71438) | #### ✅ No Misconfigurations found
Target
bun.lockastroastroastrodompurifydompurifydompurifyjs-yamljs-yamlmermaidmermaidmermaidmermaidmermaidnanoidnanoidpostcsspostcsssvgo✅ No Misconfigurations found
Target
pnpm-lock.yamlmermaidmermaidmermaidmermaidmermaid✅ No Misconfigurations found