@datagrok/curves@1.13.0 — npm dependency audit

0 critical · 3 high · 0 medium · 0 low · 3 total (deduped by advisory)

NPM package @datagrok/curves@1.13.0 — production dependency tree audited with npm audit.

AdvisorySeverityDependency InstalledVulnerable rangeFixed byCVSSDescription
GHSA-5p4m-2wfm-xmqjHIGHjs-yaml4.3.0>=4.0.0 <4.3.1available7.5JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
GHSA-mh99-v99m-4gvgHIGHbrace-expansion1.1.16<1.1.17available7.5brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
GHSA-rgw5-rvv9-x895HIGHbrace-expansion1.1.16>=2.0.0 <2.1.4available7.5brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation