Generated by audit-report.yml on 2026-08-10.
Run yarn npm audit --all --recursive --no-deprecations locally to reproduce.
Report
├─ �[38;5;173mdompurify�[39m
│ ├─ ID: �[38;5;220m1138538�[39m
│ ├─ Issue: DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
│ ├─ URL: �[38;5;170mhttps://github.com/advisories/GHSA-55q2-fjhq-7xh7�[39m
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: �[38;5;37m<=3.4.12�[39m
│ │
│ ├─ Tree Versions
│ │ └─ �[38;5;111m3.4.12�[39m
│ │
│ └─ Dependents
│ └─ �[38;5;173mjspdf�[39m�[38;5;111m@�[39m�[38;5;111mnpm:4.2.1�[39m
│
├─ �[38;5;173mimage-size�[39m
│ ├─ ID: �[38;5;220m1138808�[39m
│ ├─ Issue: image-size: ICNS parser allows denial of service through an infinite loop
│ ├─ URL: �[38;5;170mhttps://github.com/advisories/GHSA-w3rx-r6r6-pgpr�[39m
│ ├─ Severity: high
│ ├─ Vulnerable Versions: �[38;5;37m<=2.0.2�[39m
│ │
│ ├─ Tree Versions
│ │ └─ �[38;5;111m0.5.5�[39m
│ │
│ └─ Dependents
│ └─ �[38;5;173mless�[39m�[38;5;111m@�[39m�[38;5;111mnpm:4.4.0�[39m
│
├─ �[38;5;173mimage-size�[39m
│ ├─ ID: �[38;5;220m1138809�[39m
│ ├─ Issue: image-size: JXL and HEIF parsers allow denial of service through infinite loops
│ ├─ URL: �[38;5;170mhttps://github.com/advisories/GHSA-5p2g-fcmc-qvqq�[39m
│ ├─ Severity: high
│ ├─ Vulnerable Versions: �[38;5;37m<=2.0.2�[39m
│ │
│ ├─ Tree Versions
│ │ └─ �[38;5;111m0.5.5�[39m
│ │
│ └─ Dependents
│ └─ �[38;5;173mless�[39m�[38;5;111m@�[39m�[38;5;111mnpm:4.4.0�[39m
│
├─ �[38;5;173mjs-yaml�[39m
│ ├─ ID: �[38;5;220m1138114�[39m
│ ├─ Issue: JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
│ ├─ URL: �[38;5;170mhttps://github.com/advisories/GHSA-5p4m-2wfm-xmqj�[39m
│ ├─ Severity: high
│ ├─ Vulnerable Versions: �[38;5;37m>=3.0.0 <3.15.1�[39m
│ │
│ ├─ Tree Versions
│ │ └─ �[38;5;111m3.15.0�[39m
│ │
│ └─ Dependents
│ └─ �[38;5;166m@istanbuljs/�[39m�[38;5;173mload-nyc-config�[39m�[38;5;111m@�[39m�[38;5;111mnpm:1.1.0�[39m
│
├─ �[38;5;173mjs-yaml�[39m
│ ├─ ID: �[38;5;220m1138115�[39m
│ ├─ Issue: JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
│ ├─ URL: �[38;5;170mhttps://github.com/advisories/GHSA-5p4m-2wfm-xmqj�[39m
│ ├─ Severity: high
│ ├─ Vulnerable Versions: �[38;5;37m>=4.0.0 <4.3.1�[39m
│ │
│ ├─ Tree Versions
│ │ └─ �[38;5;111m4.3.0�[39m
│ │
│ └─ Dependents
│ └─ �[38;5;173mcosmiconfig�[39m�[38;5;111m@�[39m�[38;5;111mnpm:9.0.2 [c54d6]�[39m
│
└─ �[38;5;173mnanoid�[39m
├─ ID: �[38;5;220m1138813�[39m
├─ Issue: nanoid: custom generators can loop indefinitely when size is zero
├─ URL: �[38;5;170mhttps://github.com/advisories/GHSA-2v37-7h3g-55p8�[39m
├─ Severity: high
├─ Vulnerable Versions: �[38;5;37m<3.3.17�[39m
│
├─ Tree Versions
│ └─ �[38;5;111m3.3.16�[39m
│
└─ Dependents
└─ �[38;5;173mpostcss�[39m�[38;5;111m@�[39m�[38;5;111mnpm:8.5.25�[39m
Advisories with no available fix are recorded in .yarnrc.yml
(npmAuditExcludePackages / npmAuditIgnoreAdvisories), each with the
reasoning and the condition for removing it.
Generated by
audit-report.ymlon 2026-08-10.Run
yarn npm audit --all --recursive --no-deprecationslocally to reproduce.Report
Advisories with no available fix are recorded in
.yarnrc.yml(
npmAuditExcludePackages/npmAuditIgnoreAdvisories), each with thereasoning and the condition for removing it.