0 critical · 3 high · 0 medium · 0 low · 3 total (deduped by advisory)
NPM package @datagrok/curves@1.13.0 — production dependency tree audited with npm audit.
| Advisory | Severity | Dependency | Installed | Vulnerable range | Fixed by | CVSS | Description |
|---|---|---|---|---|---|---|---|
| GHSA-5p4m-2wfm-xmqj | HIGH | js-yaml | 4.3.0 | >=4.0.0 <4.3.1 | available | 7.5 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported |
| GHSA-mh99-v99m-4gvg | HIGH | brace-expansion | 1.1.16 | <1.1.17 | available | 7.5 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash |
| GHSA-rgw5-rvv9-x895 | HIGH | brace-expansion | 1.1.16 | >=2.0.0 <2.1.4 | available | 7.5 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation |