Skip to content

Update dependency lodash to v4.17.23 - #96

Open
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/lodash-4.x-lockfile
Open

Update dependency lodash to v4.17.23#96
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/lodash-4.x-lockfile

Update dependency lodash to v4.17.23

56f631c
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / Mend Security Check failed Jun 10, 2026 in 55s

Security Report

You have successfully remediated 3 vulnerabilities, but introduced 8 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2026-41907

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> aws-sdk-2.1307.0.tgz (Root Library)

   -> ❌ uuid-8.0.0.tgz (Vulnerable Library)

Critical 9.8 Transitive uuid-8.0.0.tgz aws-sdk-2.1307.0.tgz Transitive https://github.com/uuidjs/uuid.git - v11.1.1,https://github.com/uuidjs/uuid.git - v12.0.1,https://github.com/uuidjs/uuid.git - v13.0.1 #⁠37
CVE-2026-33937

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nodemailer-express-handlebars-5.0.0.tgz (Root Library)

   -> express-handlebars-6.0.7.tgz

     -> ❌ handlebars-4.7.7.tgz (Vulnerable Library)

Critical 9.8 Transitive handlebars-4.7.7.tgz nodemailer-express-handlebars-5.0.0.tgz Transitive https://github.com/handlebars-lang/handlebars.js.git - v4.7.9 None
CVE-2026-33941

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nodemailer-express-handlebars-5.0.0.tgz (Root Library)

   -> express-handlebars-6.0.7.tgz

     -> ❌ handlebars-4.7.7.tgz (Vulnerable Library)

High 8.2 Transitive handlebars-4.7.7.tgz nodemailer-express-handlebars-5.0.0.tgz Transitive https://github.com/handlebars-lang/handlebars.js.git - v4.7.9 None
CVE-2026-33940

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nodemailer-express-handlebars-5.0.0.tgz (Root Library)

   -> express-handlebars-6.0.7.tgz

     -> ❌ handlebars-4.7.7.tgz (Vulnerable Library)

High 8.1 Transitive handlebars-4.7.7.tgz nodemailer-express-handlebars-5.0.0.tgz Transitive https://github.com/handlebars-lang/handlebars.js.git - v4.7.9 None
CVE-2026-33938

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nodemailer-express-handlebars-5.0.0.tgz (Root Library)

   -> express-handlebars-6.0.7.tgz

     -> ❌ handlebars-4.7.7.tgz (Vulnerable Library)

High 8.1 Transitive handlebars-4.7.7.tgz nodemailer-express-handlebars-5.0.0.tgz Transitive https://github.com/handlebars-lang/handlebars.js.git - v4.7.9 None
CVE-2026-33939

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nodemailer-express-handlebars-5.0.0.tgz (Root Library)

   -> express-handlebars-6.0.7.tgz

     -> ❌ handlebars-4.7.7.tgz (Vulnerable Library)

High 7.5 Transitive handlebars-4.7.7.tgz nodemailer-express-handlebars-5.0.0.tgz Transitive https://github.com/handlebars-lang/handlebars.js.git - v4.7.9 None
CVE-2026-33916

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nodemailer-express-handlebars-5.0.0.tgz (Root Library)

   -> express-handlebars-6.0.7.tgz

     -> ❌ handlebars-4.7.7.tgz (Vulnerable Library)

Medium 4.7 Transitive handlebars-4.7.7.tgz nodemailer-express-handlebars-5.0.0.tgz Transitive https://github.com/handlebars-lang/handlebars.js.git - v4.7.9 None
CVE-2026-45736

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> jsdom-20.0.3.tgz (Root Library)

   -> ❌ ws-8.18.0.tgz (Vulnerable Library)

Medium 4.4 Transitive ws-8.18.0.tgz jsdom-20.0.3.tgz Transitive 8.20.1 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2025-13465 lodash-4.17.21.tgz
CVE-2026-2950 lodash-4.17.21.tgz
CVE-2026-4800 lodash-4.17.21.tgz

Base branch total remaining vulnerabilities: 26
Base branch commit: null


Total libraries scanned: 172

Scan token: a6e3fdf7e70542129255f34dde87d3f0