{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-bba7087fd4421d03", "name": "Possibly dead Python function: preview_dependency_brief", "shortDescription": {"text": "Possibly dead Python function: preview_dependency_brief"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5c01c136a8507d50", "name": "Possibly dead Python function: fetch_github_releases", "shortDescription": {"text": "Possibly dead Python function: fetch_github_releases"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-86c19a78733a4474", "name": "Possibly dead Python function: handle_starttag", "shortDescription": {"text": "Possibly dead Python function: handle_starttag"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2e4618a760678aec", "name": "Possibly dead Python function: handle_endtag", "shortDescription": {"text": "Possibly dead Python function: handle_endtag"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-18c327cb7ab58508", "name": "Possibly dead Python function: handle_data", "shortDescription": {"text": "Possibly dead Python function: handle_data"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-180fdc7696023a26", "name": "Possibly dead Python function: preview_agent_builder_brief", "shortDescription": {"text": "Possibly dead Python function: preview_agent_builder_brief"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8a4c1a4ddd27139b", "name": "Possibly dead Python function: handle_starttag", "shortDescription": {"text": "Possibly dead Python function: handle_starttag"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-06c31757855e354b", "name": "Possibly dead Python function: handle_endtag", "shortDescription": {"text": "Possibly dead Python function: handle_endtag"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-09f03e050de1efc2", "name": "Possibly dead Python function: handle_data", "shortDescription": {"text": "Possibly dead Python function: handle_data"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c7d76ebb141b9bf", "name": "Possibly dead Python function: add_text_source", "shortDescription": {"text": "Possibly dead Python function: add_text_source"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7f96d096db38fb59", "name": "Possibly dead Python function: add_file_source", "shortDescription": {"text": "Possibly dead Python function: add_file_source"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ad5ec8a6bda97ecb", "name": "Possibly dead Python function: remove_source", "shortDescription": {"text": "Possibly dead Python function: remove_source"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4ce4bb78cf8a74f9", "name": "Possibly dead Python function: retrieve_relevant_context", "shortDescription": {"text": "Possibly dead Python function: retrieve_relevant_context"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-56ab387595ad1bc0", "name": "Possibly dead Python function: retrieve_relevant_context", "shortDescription": {"text": "Possibly dead Python function: retrieve_relevant_context"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6f1deb2f14ab8e51", "name": "Possibly dead Python function: inspect_embedding_space", "shortDescription": {"text": "Possibly dead Python function: inspect_embedding_space"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-413926232ab742b5", "name": "Possibly dead Python function: web_research", "shortDescription": {"text": "Possibly dead Python function: web_research"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b41ced5bd8a51027", "name": "Possibly dead Python function: grade_documents", "shortDescription": {"text": "Possibly dead Python function: grade_documents"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7042eeda14acffdb", "name": "Possibly dead Python function: rewrite", "shortDescription": {"text": "Possibly dead Python function: rewrite"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-58a4f22d951c1cbb", "name": "Possibly dead Python function: check_document_relevance", "shortDescription": {"text": "Possibly dead Python function: check_document_relevance"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-39c88b16e704565e", "name": "Possibly dead Python function: web_research", "shortDescription": {"text": "Possibly dead Python function: web_research"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5d5302c5cdf78401", "name": "Possibly dead Python function: post_process", "shortDescription": {"text": "Possibly dead Python function: post_process"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ace5b37c8bc128e2", "name": "Possibly dead Python function: check_document_relevance", "shortDescription": {"text": "Possibly dead Python function: check_document_relevance"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ec6a7e4b3d678716", "name": "Possibly dead Python function: format_docs", "shortDescription": {"text": "Possibly dead Python function: format_docs"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-260f3fb9197de879", "name": "Possibly dead Python function: check_document_relevance", "shortDescription": {"text": "Possibly dead Python function: check_document_relevance"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9f2e1fb12b8b057a", "name": "Possibly dead Python function: web_search", "shortDescription": {"text": "Possibly dead Python function: web_search"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6da5b28065159d0b", "name": "Possibly dead Python function: grade_documents", "shortDescription": {"text": "Possibly dead Python function: grade_documents"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1e6111f6b840a866", "name": "Possibly dead Python function: transform_query", "shortDescription": {"text": "Possibly dead Python function: transform_query"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b1ac5d9b9f150dbf", "name": "Possibly dead Python function: decide_to_generate", "shortDescription": {"text": "Possibly dead Python function: decide_to_generate"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-179e9be40d669bd8", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 agent_skills/self-improving-agent-skills/frontend/src/app/layout.t", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 agent_skills/self-improving-agent-skills/frontend/src/app/layout.tsx:21"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-b6809c56954a4679", "name": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/page.tsx", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/page.tsx:298"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-888244d0beab35e0", "name": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/api/copilotkit", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/api/copilotkit/route.ts:28"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-34a21b761817c78e", "name": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/api/mcp-intros", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/api/mcp-introspect/route.ts:22"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-60913a09d8d76065", "name": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/api/mastra-age", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/api/mastra-agent/route.ts:25"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-8f131a20039851aa", "name": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/components/Cop", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/components/CopilotKitProvider.tsx:57"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-c4b3f742ac3509b9", "name": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/componen", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/components/ToolDetail.tsx:109"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-f4d3f185f3902aea", "name": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/components/Mcp", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/components/McpServerManager.tsx:96"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-683919c6d833c5fa", "name": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/hooks/useToolC", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/hooks/useToolConfigStore.ts:250"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-bd0078a746a2b9af", "name": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/hooks/useMcpIn", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/hooks/useMcpIntrospect.ts:52"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-06f9f823672f0565", "name": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/generative-ui-starter-project/src/compon", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/generative-ui-starter-project/src/components/tool-rendering.tsx:63"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-bbe7166a6036a6ed", "name": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/generative-ui-starter-project/src/compon", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/generative-ui-starter-project/src/components/generative-ui/charts/pie-chart.tsx:139"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-65d98b0470ee410f", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/ui/src/com", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/ui/src/components/ui/chart.tsx:75"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-61143edfa6bd6acc", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 generative_ui_agents/ai-dashboard-canvas-agent/src/components/ui/c", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 generative_ui_agents/ai-dashboard-canvas-agent/src/components/ui/chart.tsx:83"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-9fa067d230488315", "name": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/ai-dashboard-canvas-agent/src/components", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/ai-dashboard-canvas-agent/src/components/dashboard/metrics/pinnedMetrics.tsx:82"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-432429b55cbfb655", "name": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/ai-dashboard-canvas-agent/src/components", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/ai-dashboard-canvas-agent/src/components/chat/actions/search.tsx:18"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-454a3dc69dcf33a0", "name": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/ai-deep-research-agent/src/components/Wo", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/ai-deep-research-agent/src/components/Workspace.tsx:284"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-4f75437abd9e08a4", "name": "TODO/FIXME marker in shipping code \u2014 generative_ui_agents/ai-deep-research-agent/src/components/Workspace.tsx:89", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 generative_ui_agents/ai-deep-research-agent/src/components/Workspace.tsx:89"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-a6e9bca015593811", "name": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/ai-deep-research-agent/src/components/Fi", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/ai-deep-research-agent/src/components/FileViewerModal.tsx:114"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-0f658eb5d3eb6dc0", "name": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-deep-research-agent/src/app/page.tsx:53", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-deep-research-agent/src/app/page.tsx:53"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-691086a6b4a7c34a", "name": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_a", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/middleware.ts:7"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-3eb0d152e4f10e84", "name": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_a", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/app/api/plans/[id]/retry/route.ts:106"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-81eaa720ee6359e9", "name": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_a", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/app/api/plan/submit/route.ts:34"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-2ff81f242157225a", "name": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_a", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/app/plan/page.tsx:286"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-b03bed969c46952f", "name": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_a", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/app/plan/[id]/page.tsx:229"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-88621956d0d56c36", "name": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agent", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ScriptConfirmation.js:279"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-3db911dcddadb5a3", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ScriptConfirmation.js:116"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-b3608f3d2bd2b53f", "name": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agent", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/Sidebar.js:529"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-37262d32e58e89c5", "name": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agent", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ActivePodcastPreview.js:260"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-680e4b024e3226c9", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ChatMessage.js:320"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-19143002a9841dbe", "name": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agent", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/social/PostItem.js:180"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-804788381737ff14", "name": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agent", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/social/AnalyticsCards.js:177"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-e1105076cdfcc139", "name": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agent", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/social/StatsTab.js:614"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-4ad55f79229e8f9a", "name": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agent", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/SourceDetail.js:381"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-12ae5487b0d91e8b", "name": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agent", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/Sources.js:545"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-650522f022f48c9e", "name": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agent", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/StudioChat.js:726"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-ada5b7b4d2420b51", "name": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/StudioChat.js:40"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-9a6b2c79c7a351a7", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/ArticleDetail.js:217"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-933951cc42aecfff", "name": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agent", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/Voyager.js:441"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-d4835bdecbfb6f5e", "name": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agent", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/PodcastDetail.js:503"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-8c31c58cc4369879", "name": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/src/app/page.tsx:283"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-d98d9ba5f7924c7f", "name": "subprocess shell true \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/scheduler.py:99", "shortDescription": {"text": "subprocess shell true \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/scheduler.py:99"}, "fullDescription": {"text": "Found 'subprocess' function 'Popen' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.\n\nRule: python.lang.security.audit.subprocess-shell-true.subprocess-shell-true\nSeverity: ERROR\nOWASP: A01:2017 - Injection, A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.7}}, {"id": "scanner-f89eebcbfcf07ed2", "name": "react dangerouslysetinnerhtml \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ChatMe", "shortDescription": {"text": "react dangerouslysetinnerhtml \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ChatMessage.js:320"}, "fullDescription": {"text": "Detection of dangerouslySetInnerHTML from non-constant definition. This can inadvertently expose users to cross-site scripting (XSS) attacks if this comes from user-provided input. If you have to use dangerouslySetInnerHTML, consider using a sanitization library such as DOMPurify to sanitize your HTML.\n\nRule: typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-11ee1db73659aee7", "name": "react dangerouslysetinnerhtml \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/Script", "shortDescription": {"text": "react dangerouslysetinnerhtml \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ScriptConfirmation.js:117"}, "fullDescription": {"text": "Detection of dangerouslySetInnerHTML from non-constant definition. This can inadvertently expose users to cross-site scripting (XSS) attacks if this comes from user-provided input. If you have to use dangerouslySetInnerHTML, consider using a sanitization library such as DOMPurify to sanitize your HTML.\n\nRule: typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-a2bfa3597bd731e8", "name": "use defused xml \u2014 advanced_ai_agents/multi_agent_apps/devpulse_ai/adapters/arxiv.py:9", "shortDescription": {"text": "use defused xml \u2014 advanced_ai_agents/multi_agent_apps/devpulse_ai/adapters/arxiv.py:9"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-4c24056072eadb40", "name": "insecure hash algorithm sha1 \u2014 advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent/agent.py:212", "shortDescription": {"text": "insecure hash algorithm sha1 \u2014 advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent/agent.py:212"}, "fullDescription": {"text": "Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead.\n\nRule: python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1\nSeverity: WARNING\nOWASP: A03:2017 - Sensitive Data Exposure, A02:2021 - Cryptographic Failures, A04:2025 - Cryptographic Failures\nCWE: CWE-327: Use of a Broken or Risky Cryptographic Algorithm\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.75}}, {"id": "scanner-e5d7ddfba8509e57", "name": "eval detected \u2014 ai_agent_framework_crash_course/google_adk_crash_course/4_tool_using_agent/4_2_function_tools/calculator", "shortDescription": {"text": "eval detected \u2014 ai_agent_framework_crash_course/google_adk_crash_course/4_tool_using_agent/4_2_function_tools/calculator_agent/tools.py:30"}, "fullDescription": {"text": "Detected the use of eval(). eval() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.eval-detected.eval-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-9c294554701f421c", "name": "dynamic urllib use detected \u2014 always_on_agents/always_on_hn_briefing_agent/delivery.py:73", "shortDescription": {"text": "dynamic urllib use detected \u2014 always_on_agents/always_on_hn_briefing_agent/delivery.py:73"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A01:2017 - Injection\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-66060256a17bb798", "name": "dynamic urllib use detected \u2014 always_on_agents/always_on_hn_briefing_agent/scout.py:239", "shortDescription": {"text": "dynamic urllib use detected \u2014 always_on_agents/always_on_hn_briefing_agent/scout.py:239"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A01:2017 - Injection\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-ce482863b0d41788", "name": "dynamic urllib use detected \u2014 always_on_agents/release_radar_agent/delivery.py:196", "shortDescription": {"text": "dynamic urllib use detected \u2014 always_on_agents/release_radar_agent/delivery.py:196"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A01:2017 - Injection\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-cecb2ce6c7d930d1", "name": "dynamic urllib use detected \u2014 always_on_agents/release_radar_agent/radar.py:270", "shortDescription": {"text": "dynamic urllib use detected \u2014 always_on_agents/release_radar_agent/radar.py:270"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A01:2017 - Injection\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-f994bb697401c428", "name": "CVE-2026-42215: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requiremen", "shortDescription": {"text": "CVE-2026-42215: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "GitPython is a python library used to interact with Git repositories.  ...\n\nGitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at it\n\nPackage: gitpython\nInstalled: 3.1.44\nFixed in: 3.1.47\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.47"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ab8c23027e464eb8", "name": "CVE-2026-42284: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requiremen", "shortDescription": {"text": "CVE-2026-42284: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "GitPython is a python library used to interact with Git repositories.  ...\n\nGitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(\" \".join(multi_options)). A string like \"--branch main --config core.hooksPath=/x\" passes validation (starts with --branch), but after split becomes [\"--branch\", \"main\", \"--config\", \"core.hooksPath=/x\"]. Git applies the config and executes attacker hooks during clone. This issue has been patched in version 3.1.47.\n\nPackage: gitpython\nInstalled: 3.1.44\nFixed in: 3.1.47\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.47"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-95cdc6a1a275a6bc", "name": "CVE-2026-44243: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requiremen", "shortDescription": {"text": "CVE-2026-44243: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "GitPython: GitPython: Arbitrary file write via crafted reference paths\n\nGitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository\u2019s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.\n\nPackage: gitpython\nInstalled: 3.1.44\nFixed in: 3.1.48\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.48"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0110e35afb3d7cee", "name": "CVE-2026-44244: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requiremen", "shortDescription": {"text": "CVE-2026-44244: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "GitPython is a python library used to interact with Git repositories.  ...\n\nGitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \\n becomes \\n\\t), but Git still accepts an indented [core] stanza as a section header \u2014 so the injected core.hooksPath becomes effective configuration. Any Git operation that invokes hooks (commit, merge, checkout)\n\nPackage: gitpython\nInstalled: 3.1.44\nFixed in: 3.1.49\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.49"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-efeabb24fb1ba4b8", "name": "GHSA-2f96-g7mh-g2hx: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requi", "shortDescription": {"text": "GHSA-2f96-g7mh-g2hx: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist\n\n## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**CWE:** CWE-184 (Incomplete List of Disallowed Inputs) \u2192 CWE-78 (OS Command Injection)\n**Severity:** inherits the parent CVE-2026-42215 surface; estimated Hi\n\nPackage: gitpython\nInstalled: 3.1.44\nFixed in: 3.1.51\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.51"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cacd18fcc6e94ca2", "name": "GHSA-956x-8gvw-wg5v: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requi", "shortDescription": {"text": "GHSA-956x-8gvw-wg5v: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`\n\n## Summary\n\nGitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of \"unsafe\" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, \u2026) that can be abused to run arbitrary commands, and enforces them with `Git.check_unsafe_options()`.\n\nThat enforcement is only wired into the **network** commands \u2014 `clone_from`, `Remote.fetch`, `Remote.pull`, `Remote.push`. Several other p\n\nPackage: gitpython\nInstalled: 3.1.44\nFixed in: 3.1.51\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.51"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7f32f3f8258b7db7", "name": "GHSA-mv93-w799-cj2w: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requi", "shortDescription": {"text": "GHSA-mv93-w799-cj2w: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath\n\nSummary\n\nThe patch for CVE-2026-42215 (GitPython 3.1.49) validates newlines only in the value parameter of set_value(). The section and option parameters are passed to configparser without any newline validation. An attacker who controls the section argument can inject \\n to write arbitrary section headers into .git/config, including a forged [core] section with hooksPath pointing to an attacker-controlled directory, leading to RCE when any git hook is triggered.\n\nDetails\n\nFile: git/config.py \u2014 \n\nPackage: gitpython\nInstalled: 3.1.44\nFixed in: 3.1.50\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.50"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a02f30d6bb516284", "name": "GHSA-rwj8-pgh3-r573: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requi", "shortDescription": {"text": "GHSA-rwj8-pgh3-r573: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL\n\n### Summary\n`Repo.clone_from()` passes the caller-supplied remote URL through `Git.polish_url()`, which on every non-Cygwin platform calls `os.path.expandvars()` on the URL before handing it to `git clone`. An attacker who controls the URL argument \u2014 the documented use case for `clone_from()` in \"import repository from URL\" features of CI servers, git-hosting mirrors, and dependency scanners \u2014 can embed `$NAME` / `${NAME}` tokens that are expanded server-side to the values of the hosting process\n\nPackage: gitpython\nInstalled: 3.1.44\nFixed in: 3.1.52\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.52"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-26a070528d22225b", "name": "CVE-2025-43859: h11 0.14.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt", "shortDescription": {"text": "CVE-2025-43859: h11 0.14.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "h11: h11 accepts some malformed Chunked-Encoding bodies\n\nh11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since exploitation requires the combination of buggy h11 with a buggy (reverse) proxy, fixing either component is sufficient to mitigate this issue.\n\nPackage: h11\nInstalled: 0.14.0\nFixed in: 0.16.0\nSeverity: CRITICAL\nFix: Upgrade h11 to 0.16.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-badc8117fe004997", "name": "CVE-2026-45409: idna 3.10 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-45409: idna 3.10 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "python-idna: idna: Denial of Service via specially crafted long inputs\n\nInternationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fi\n\nPackage: idna\nInstalled: 3.10\nFixed in: 3.15\nSeverity: MEDIUM\nFix: Upgrade idna to 3.15"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0e9363d965ae91b5", "name": "CVE-2025-27516: jinja2 3.1.5 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.t", "shortDescription": {"text": "CVE-2025-27516: jinja2 3.1.5 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "jinja2: Jinja sandbox breakout through attr filter selecting format method\n\nJinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacker that controls the content of a template to execute arbitrary Python code. To exploit the vulnerability, an attacker needs to control the content of a template. Whether that is the case depends on the type of application using Jinja. This vulnerability impacts users of applications which execute untrusted templates. Jinja's sandbox does c\n\nPackage: jinja2\nInstalled: 3.1.5\nFixed in: 3.1.6\nSeverity: MEDIUM\nFix: Upgrade jinja2 to 3.1.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-98c3eab0fb1cbdaa", "name": "CVE-2026-25990: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-25990: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image\n\nPillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.1.1\nSeverity: HIGH\nFix: Upgrade pillow to 12.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-893c85b8249e8eec", "name": "CVE-2026-40192: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-40192: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing\n\nPillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.2.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-84711fadc86eb3a4", "name": "CVE-2026-42311: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-42311: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing\n\nPillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.2.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-50ae30223e7d0d9c", "name": "CVE-2026-54058: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-54058: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image\n\nPillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7d3d692483592c76", "name": "CVE-2026-54059: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-54059: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted PCF font data\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7e09a96b8ab967db", "name": "CVE-2026-54060: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-54060: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(\"1\", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e6e7e3cabee106fd", "name": "CVE-2026-55379: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-55379: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted BDF font file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-91149532c47915ea", "name": "CVE-2026-55380: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-55380: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted GD 2.x image file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dfbb75f819056c32", "name": "CVE-2026-59197: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-59197: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Native heap out-of-bounds write\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-36c13625493bc341", "name": "CVE-2026-59199: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-59199: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via out-of-bounds write in image processing\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0d45ee505a37afb7", "name": "CVE-2026-59200: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-59200: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of service via crafted PDF stream\n\nPillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-38ebd50f4fc57afd", "name": "CVE-2026-59204: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-59204: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via crafted JPEG2000 image\n\nPillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1e36c8d8e7fcf10f", "name": "CVE-2026-59205: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-59205: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-46bf61be261a799c", "name": "CVE-2026-42308: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-42308: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: python: Pillow: Denial of Service via integer overflow in font processing\n\nPillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-842a2d8b246ee9fa", "name": "CVE-2026-42310: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-42310: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via malicious PDF processing\n\nPillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9cd4a825f01e53ca", "name": "CVE-2026-55798: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-55798: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Arbitrary command injection via shell metacharacters in file paths\n\nPillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-878c29e7792f130b", "name": "CVE-2026-59198: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-59198: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Information disclosure via TGA RLE encoder out-of-bounds read\n\nPillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-53652323d3acd0b0", "name": "CVE-2025-8869: pip 25.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt", "shortDescription": {"text": "CVE-2025-8869: pip 25.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "pip: pip missing checks on symbolic link extraction\n\nWhen extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706.\nNote that upgrading pip to a \"fixed\" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706.\n\nNote that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706\nand therefore are not secure to all vuln\n\nPackage: pip\nInstalled: 25.0.1\nFixed in: 25.3\nSeverity: MEDIUM\nFix: Upgrade pip to 25.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-efa4460d948511aa", "name": "CVE-2026-3219: pip 25.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-3219: pip 25.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "pip: pip: Incorrect file installation due to improper archive handling\n\npip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing \"incorrect\" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.\n\nPackage: pip\nInstalled: 25.0.1\nFixed in: 26.1\nSeverity: MEDIUM\nFix: Upgrade pip to 26.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b30b30a425c9a4a4", "name": "CVE-2026-6357: pip 25.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-6357: pip 25.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "pip: pip: Arbitrary code execution or information disclosure via malicious wheel package installation\n\npip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.\n\nPackage: pip\nInstalled: 25.0.1\nFixed in: 26.1\nSeverity: MEDIUM\nFix: Upgrade pip to 26.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-815d906057c4af44", "name": "CVE-2026-8643: pip 25.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-8643: pip 25.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite\n\npip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.\n\nPackage: pip\nInstalled: 25.0.1\nFixed in: 26.1.2\nSeverity: MEDIUM\nFix: Upgrade pip to 26.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2c6cb61c1d658d0e", "name": "CVE-2026-1703: pip 25.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-1703: pip 25.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "pip: pip: Information disclosure via path traversal when installing crafted wheel archives\n\nWhen pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.\n\nPackage: pip\nInstalled: 25.0.1\nFixed in: 26.0\nSeverity: LOW\nFix: Upgrade pip to 26.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-165beb0deb0ad2d3", "name": "CVE-2025-4565: protobuf 5.29.3 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements", "shortDescription": {"text": "CVE-2025-4565: protobuf 5.29.3 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "python-protobuf: Unbounded recursion in Python Protobuf\n\nAny project that uses Protobuf Pure-Python backend\u00a0to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP\u00a0tags can be corrupted by exceeding the Python recursion limit. This can result in a Denial of service by crashing the application with a RecursionError. We recommend upgrading to version =>6.31.1 or beyond commit\u00a017838beda2943d08b8a9d4df5b68f5f04f26d901\n\nPackage: protobuf\nInstalled: 5.29.3\nFixed in: 4.25.8, 5.29.5, 6.31.1\nSeverity: HIGH\nFix: Upgrade protobuf to 4.25.8, 5.29.5, 6.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-59c73b64e081cdc8", "name": "CVE-2026-0994: protobuf 5.29.3 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements", "shortDescription": {"text": "CVE-2026-0994: protobuf 5.29.3 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "python: protobuf: Protobuf: Denial of Service due to recursion depth bypass\n\nA denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages.\n\nDue to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python\u2019s recursion stack and causing a RecursionError.\n\nPackage: protobuf\nInstalled: 5.29.3\nFixed in: 6.33.5, 5.29.6\nSeverity: HIGH\nFix: Upgrade protobuf to 6.33.5, 5.29.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1c03f4c89ad36e6a", "name": "CVE-2026-25087: pyarrow 19.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements", "shortDescription": {"text": "CVE-2026-25087: pyarrow 19.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "apache-arrow: Apache Arrow C++: Denial of Service via Use After Free vulnerability when reading IPC files\n\nUse After Free vulnerability in Apache Arrow C++.\n\nThis issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-buffering enabled, if the IPC file contains data with variadic buffers (such as Binary View and String View data). Depending on the number of variadic buffers in a record batch column and on the temporal sequence of multi-threaded IO, a write to a dangling pointer could occur. The value (a `std::shar\n\nPackage: pyarrow\nInstalled: 19.0.1\nFixed in: 23.0.1\nSeverity: HIGH\nFix: Upgrade pyarrow to 23.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-58545354f7bfcb8b", "name": "CVE-2026-23490: pyasn1 0.6.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.t", "shortDescription": {"text": "CVE-2026-23490: pyasn1 0.6.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.2\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-77e8f2a819b07175", "name": "CVE-2026-30922: pyasn1 0.6.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.t", "shortDescription": {"text": "CVE-2026-30922: pyasn1 0.6.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with \"Indefinite Length\" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consu\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.3\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4e9008472c4f55df", "name": "CVE-2026-59885: pyasn1 0.6.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.t", "shortDescription": {"text": "CVE-2026-59885: pyasn1 0.6.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values.\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.4\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-464b62309026d71a", "name": "CVE-2026-59886: pyasn1 0.6.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.t", "shortDescription": {"text": "CVE-2026-59886: pyasn1 0.6.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.4\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c0ca5e597fce152a", "name": "CVE-2026-4539: pygments 2.19.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements", "shortDescription": {"text": "CVE-2026-4539: pygments 2.19.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "pygments: Pygments: Denial of Service via inefficient regular expression processing in AdlLexer\n\nA security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.\n\nPackage: pygments\nInstalled: 2.19.1\nFixed in: 2.20.0\nSeverity: LOW\nFix: Upgrade pygments to 2.20.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6653bafa3c9f8119", "name": "CVE-2026-28684: python-dotenv 1.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/require", "shortDescription": {"text": "CVE-2026-28684: python-dotenv 1.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following\n\npython-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when a cross-device rename fallback is triggered. Users should upgrade to v.1.2.2 or, as a workaround, apply the patch manually.\n\nPackage: python-dotenv\nInstalled: 1.0.1\nFixed in: 1.2.2\nSeverity: MEDIUM\nFix: Upgrade python-dotenv to 1.2.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-31e9f85019784c93", "name": "CVE-2026-24486: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/req", "shortDescription": {"text": "CVE-2026-24486: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Arbitrary file write via path traversal vulnerability\n\nPython-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write uploaded files to arbitrary locations on the filesystem by crafting a malicious filename. Users should upgrade to version 0.0.22 to receive a patch or, as a workaround, avoid using `UPLOAD_KEEP_FILENAME=True` in project configurations.\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.22\nSeverity: HIGH\nFix: Upgrade python-multipart to 0.0.22"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b83893534e90508d", "name": "CVE-2026-42561: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/req", "shortDescription": {"text": "CVE-2026-42561: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "python-multipart: python-multipart: Denial of Service via excessive multipart part headers\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, MultipartParser previously had no limit on the number of part headers or the size of an individual part header. An attacker could send a request with either many repeated headers without terminating the header block or a single very large header value, causing excessive CPU work before request reje\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.27\nSeverity: HIGH\nFix: Upgrade python-multipart to 0.0.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-87601c7c2d832a86", "name": "CVE-2026-53539: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/req", "shortDescription": {"text": "CVE-2026-53539: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Denial of Service via crafted form-urlencoded bodies\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step lookup: it first scanned the entire remaining buffer for &, and only when no & existed anywhere ahead did it fall back to scanning for ;. For a body that uses ; as the separator and contains no &, every field iteration performed a full failed & scan over the entire remaining buffer before locating the ne\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.30\nSeverity: HIGH\nFix: Upgrade python-multipart to 0.0.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-951ae750292179d4", "name": "CVE-2026-40347: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/req", "shortDescription": {"text": "CVE-2026-40347: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Denial of Service via crafted multipart/form-data requests\n\nPython-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candidate when processing leading CR/LF data and immediately discards epilogue data after the closing boundary.\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.26\nSeverity: MEDIUM\nFix: Upgrade python-multipart to 0.0.26"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7e9337670943e85e", "name": "CVE-2026-53537: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/req", "shortDescription": {"text": "CVE-2026-53537: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "multipart: Python-Multipart: Information disclosure via header parsing discrepancy\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message, which transparently applies RFC 2231/5987 decoding. The extended parameter syntax (filename*=charset'lang'value, name*=..., and the filename*0/filename*1 continuation form) is decoded and surfaced under the bare filename/name key, and overrides the plain parameter when both are present. RFC 7578 \u00a74.2 explicitly forbid\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.30\nSeverity: LOW\nFix: Upgrade python-multipart to 0.0.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-127bccbcb604a22d", "name": "CVE-2026-53538: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/req", "shortDescription": {"text": "CVE-2026-53538: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Information disclosure due to parser differential in form data handling\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator. This creates a parser differential: the same bytes are tokenized into different fields than a WHATWG compliant intermediary would produce, allowing an attacker to smuggle extra form \n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.30\nSeverity: LOW\nFix: Upgrade python-multipart to 0.0.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e1d0edbed10262bd", "name": "CVE-2026-53540: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/req", "shortDescription": {"text": "CVE-2026-53540: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Negative Content-Length in parse_form buffers the entire body in memory\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned the bounded read into a read-until-EOF, so the entire body was loaded into memory in a single read instead of in fixed-size chunks. This vulnerability is fixed in 0.0.31.\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.31\nSeverity: LOW\nFix: Upgrade python-multipart to 0.0.31"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5ce6899171c9a270", "name": "CVE-2024-47081: requests 2.32.3 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirement", "shortDescription": {"text": "CVE-2024-47081: requests 2.32.3 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "requests: Requests vulnerable to .netrc credentials leak via malicious URLs\n\nRequests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.\n\nPackage: requests\nInstalled: 2.32.3\nFixed in: 2.32.4\nSeverity: MEDIUM\nFix: Upgrade requests to 2.32.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6abb67f2cd74ae0f", "name": "CVE-2026-25645: requests 2.32.3 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirement", "shortDescription": {"text": "CVE-2026-25645: requests 2.32.3 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "requests: Requests: Security bypass due to predictable temporary file creation\n\nRequests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulner\n\nPackage: requests\nInstalled: 2.32.3\nFixed in: 2.33.0\nSeverity: MEDIUM\nFix: Upgrade requests to 2.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c9fa3b95cc82f9c1", "name": "CVE-2025-47273: setuptools 75.8.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requireme", "shortDescription": {"text": "CVE-2025-47273: setuptools 75.8.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "setuptools: Path Traversal Vulnerability in setuptools PackageIndex\n\nsetuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.\n\nPackage: setuptools\nInstalled: 75.8.0\nFixed in: 78.1.1\nSeverity: HIGH\nFix: Upgrade setuptools to 78.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-67385b65da3eb88f", "name": "CVE-2026-59890: setuptools 75.8.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requireme", "shortDescription": {"text": "CVE-2026-59890: setuptools 75.8.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD)\n\nsetuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.\n\nPackage: setuptools\nInstalled: 75.8.0\nFixed in: 83.0.0\nSeverity: MEDIUM\nFix: Upgrade setuptools to 83.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-15604435eb6989ae", "name": "CVE-2026-33682: streamlit 1.42.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requiremen", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.42.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.42.2\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6ef582ba768dc289", "name": "CVE-2026-10804: streamlit 1.42.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requiremen", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.42.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.42.2\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ee3d599ceb8f88ca", "name": "CVE-2025-47287: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2025-47287: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "tornado: Tornado Multipart Form-Data Denial of Service\n\nTornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upg\n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5\nSeverity: HIGH\nFix: Upgrade tornado to 6.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-170bb0a8d70a7334", "name": "CVE-2025-67725: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2025-67725: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "tornado: Tornado Quadratic DoS via Repeated Header Coalescing\n\nTornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add method. The function accumulates values using string concatenation when the same header name is repeated, causing a Denial of Service (DoS).  Due to Python string immutability, each concatenation copies the entire string, resulting in O(n\u00b2) time complexity. The severity\n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5.3\nSeverity: HIGH\nFix: Upgrade tornado to 6.5.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f4c2fbb33b0c02d0", "name": "CVE-2025-67726: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2025-67726: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "tornado: Tornado Quadratic DoS via Crafted Multipart Parameters\n\nTornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potentially causing a DoS. The _parseparam function in httputil.py is used to parse specific HTTP header values, such as those in multipart/form-data and repeatedly calls string.count() within a nested loop while processing quoted semicolons. If an attacker sends a request with a large number of maliciously crafted parameters\n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5.3\nSeverity: HIGH\nFix: Upgrade tornado to 6.5.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-10619e73478030c1", "name": "CVE-2026-31958: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-31958: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "tornado-python: Tornado: Denial of Service via large multipart bodies\n\nTornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.\n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5.5\nSeverity: HIGH\nFix: Upgrade tornado to 6.5.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8e3decac588f7788", "name": "CVE-2026-35536: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-35536: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments\n\nIn Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.\n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5.5\nSeverity: HIGH\nFix: Upgrade tornado to 6.5.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-817e8344c4b1e8e7", "name": "CVE-2026-49853: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-49853: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "Tornado is a Python web framework and asynchronous networking library. ...\n\nTornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6.\n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5.6\nSeverity: HIGH\nFix: Upgrade tornado to 6.5.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-14a50c38e805d8ab", "name": "CVE-2026-49855: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-49855: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "Tornado is a Python web framework and asynchronous networking library. ...\n\nTornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6.\n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5.6\nSeverity: HIGH\nFix: Upgrade tornado to 6.5.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-48c697cd6cf8b3e8", "name": "CVE-2025-67724: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2025-67724: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "tornado: Tornado Header Injection and XSS via reason argument\n\nTornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom \"reason\" \n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5.3\nSeverity: MEDIUM\nFix: Upgrade tornado to 6.5.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b4da03a8726512c0", "name": "GHSA-78cv-mqj4-43f7: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirem", "shortDescription": {"text": "GHSA-78cv-mqj4-43f7: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "Tornado has incomplete validation of cookie attributes\n\nValues passed to the `domain`, `path`, and `samesite` arguments of `RequestHandler.set_cookie` were not completely validated in versions of Tornado prior to 6.5.5. In particular, semicolons would be allowed, which could be used to inject attacker-controlled values for other cookie attributes.\n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5.5\nSeverity: MEDIUM\nFix: Upgrade tornado to 6.5.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-09459af5cf2352e1", "name": "GHSA-pw6j-qg29-8w7f: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirem", "shortDescription": {"text": "GHSA-pw6j-qg29-8w7f: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse\n\n# CurlAsyncHTTPClient leaks per-request credentials on handle reuse\n\n## Summary\n\n`CurlAsyncHTTPClient` pools and reuses `pycurl` handles across requests but does\nnot reset them between requests, and several per-request options are applied with\nno clearing branch. As a result, sensitive state set by one request persists onto\na later request on the same client that does not set it. Two credential vectors\nare demonstrated below \u2014 a client TLS certificate (`SSLCERT`/`SSLKEY`) and proxy\nbasic-auth cr\n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5.7\nSeverity: MEDIUM\nFix: Upgrade tornado to 6.5.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-db8de70b327eb784", "name": "CVE-2026-49854: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-49854: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "tornado: Tornado: Information disclosure via out-of-bounds read in websocket_mask\n\nTornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.\n\nPackage: tornado\nInstalled: 6.4.2\nFixed in: 6.5.6\nSeverity: LOW\nFix: Upgrade tornado to 6.5.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dcc12ded09206c0a", "name": "CVE-2025-66418: urllib3 2.3.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2025-66418: urllib3 2.3.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.\n\nPackage: urllib3\nInstalled: 2.3.0\nFixed in: 2.6.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3e6bbf81eddf9c63", "name": "CVE-2025-66471: urllib3 2.3.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2025-66471: urllib3 2.3.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "urllib3: urllib3 Streaming API improperly handles highly compressed data\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, b\n\nPackage: urllib3\nInstalled: 2.3.0\nFixed in: 2.6.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ebbdd8053e7f6a50", "name": "CVE-2026-21441: urllib3 2.3.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-21441: urllib3 2.3.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)\n\nurllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in ve\n\nPackage: urllib3\nInstalled: 2.3.0\nFixed in: 2.6.3\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2405f10a982c9287", "name": "CVE-2026-44431: urllib3 2.3.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2026-44431: urllib3 2.3.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers\n\nurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.\n\nPackage: urllib3\nInstalled: 2.3.0\nFixed in: 2.7.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5d3d7f9fca83e27b", "name": "CVE-2025-50181: urllib3 2.3.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2025-50181: urllib3 2.3.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation\n\nurllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.\n\nPackage: urllib3\nInstalled: 2.3.0\nFixed in: 2.5.0\nSeverity: MEDIUM\nFix: Upgrade urllib3 to 2.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c07e90c498947808", "name": "CVE-2025-50182: urllib3 2.3.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.", "shortDescription": {"text": "CVE-2025-50182: urllib3 2.3.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "urllib3: urllib3 does not control redirects in browsers and Node.js\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest. This means Python libraries can be used to make HTTP requests from a browser or Node.js. Additionally, urllib3 provides a mechanism to control redirects, but the retries and redirect parameters are ignored with Pyodi\n\nPackage: urllib3\nInstalled: 2.3.0\nFixed in: 2.5.0\nSeverity: MEDIUM\nFix: Upgrade urllib3 to 2.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6dbadd36ee0d90f8", "name": "CVE-2026-24049: wheel 0.45.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.t", "shortDescription": {"text": "CVE-2026-24049: wheel 0.45.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "fullDescription": {"text": "wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking\n\nwheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of c\n\nPackage: wheel\nInstalled: 0.45.1\nFixed in: 0.46.2\nSeverity: HIGH\nFix: Upgrade wheel to 0.46.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c23be08978c6b68c", "name": "CVE-2026-33682: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_competitor_intelligence_agent_team", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_competitor_intelligence_agent_team/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.41.1\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-33c70811b704cba4", "name": "CVE-2026-10804: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_competitor_intelligence_agent_team", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_competitor_intelligence_agent_team/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.41.1\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-de6eba61959ade4a", "name": "CVE-2026-33682: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_game_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_game_design_agent_team/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.41.1\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-df1e94e9ced407af", "name": "CVE-2026-10804: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_game_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_game_design_agent_team/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.41.1\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7fa436897a46e4ed", "name": "CVE-2026-33682: streamlit 1.40.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_legal_agent_team/local_ai_legal_ag", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.40.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_legal_agent_team/local_ai_legal_agent_team/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.40.2\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ca1f7bf55c618884", "name": "CVE-2026-10804: streamlit 1.40.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_legal_agent_team/local_ai_legal_ag", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.40.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_legal_agent_team/local_ai_legal_agent_team/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.40.2\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-de65a1150d351ec2", "name": "CVE-2023-36464: PyPDF2 3.0.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_recruitment_agent_team/requirements.tx", "shortDescription": {"text": "CVE-2023-36464: PyPDF2 3.0.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_recruitment_agent_team/requirements.txt"}, "fullDescription": {"text": "pypdf: Possible Infinite Loop when a comment isn't followed by a character\n\npypdf is an open source, pure-python PDF library. In affected versions an attacker may craft a PDF which leads to an infinite loop if `__parse_content_stream` is executed. That is, for example, the case if the user extracted text from such a PDF. This issue was introduced in pull request #969 and resolved in pull request #1828. Users are advised to upgrade. Users unable to upgrade may modify the line `while peek not in (b\"\\r\", b\"\\n\")` in `pypdf/generic/_data_structures.py` to `while peek not in \n\nPackage: PyPDF2\nInstalled: 3.0.1\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-07804eb4dcc7b6d3", "name": "CVE-2024-47081: requests 2.32.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_recruitment_agent_team/requirements", "shortDescription": {"text": "CVE-2024-47081: requests 2.32.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_recruitment_agent_team/requirements.txt"}, "fullDescription": {"text": "requests: Requests vulnerable to .netrc credentials leak via malicious URLs\n\nRequests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.\n\nPackage: requests\nInstalled: 2.32.3\nFixed in: 2.32.4\nSeverity: MEDIUM\nFix: Upgrade requests to 2.32.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-45c647978483485e", "name": "CVE-2026-25645: requests 2.32.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_recruitment_agent_team/requirements", "shortDescription": {"text": "CVE-2026-25645: requests 2.32.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_recruitment_agent_team/requirements.txt"}, "fullDescription": {"text": "requests: Requests: Security bypass due to predictable temporary file creation\n\nRequests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulner\n\nPackage: requests\nInstalled: 2.32.3\nFixed in: 2.33.0\nSeverity: MEDIUM\nFix: Upgrade requests to 2.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ee99cec7f0c8876c", "name": "CVE-2026-33682: streamlit 1.40.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_recruitment_agent_team/requirement", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.40.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_recruitment_agent_team/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.40.2\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f45025d273af5d6c", "name": "CVE-2026-10804: streamlit 1.40.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_recruitment_agent_team/requirement", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.40.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_recruitment_agent_team/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.40.2\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5959d960fb5c4919", "name": "CVE-2026-28684: python-dotenv 1.1.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_services_agency/requirements.tx", "shortDescription": {"text": "CVE-2026-28684: python-dotenv 1.1.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_services_agency/requirements.txt"}, "fullDescription": {"text": "python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following\n\npython-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when a cross-device rename fallback is triggered. Users should upgrade to v.1.2.2 or, as a workaround, apply the patch manually.\n\nPackage: python-dotenv\nInstalled: 1.1.1\nFixed in: 1.2.2\nSeverity: MEDIUM\nFix: Upgrade python-dotenv to 1.2.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-225e08d674d93b42", "name": "CVE-2025-56427: composio 0.1.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_teaching_agent_team/requirements.txt", "shortDescription": {"text": "CVE-2025-56427: composio 0.1.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_teaching_agent_team/requirements.txt"}, "fullDescription": {"text": "ComposioHQ has a directory traversal vulnerability\n\nDirectory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir function.\n\nPackage: composio\nInstalled: 0.1.1\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-33b7f6688217c41f", "name": "CVE-2026-33682: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_teaching_agent_team/requirements.t", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_teaching_agent_team/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.41.1\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-369a2c4e656be986", "name": "CVE-2026-10804: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_teaching_agent_team/requirements.t", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_teaching_agent_team/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.41.1\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6ff77703f54db24d", "name": "CVE-2026-35002: agno 1.5.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.loc", "shortDescription": {"text": "CVE-2026-35002: agno 1.5.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "Agno is vulnerable to Eval Injection\n\nAgno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers can influence the field_type value in a FunctionCall to achieve remote code execution.\n\nPackage: agno\nInstalled: 1.5.6\nFixed in: 2.3.24\nSeverity: CRITICAL\nFix: Upgrade agno to 2.3.24"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-67e4bd86cdca49c4", "name": "CVE-2026-10105: agno 1.5.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.loc", "shortDescription": {"text": "CVE-2026-10105: agno 1.5.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "agno contains a SQL injection vulnerability\n\nagno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplying malicious metadata keys and values to the delete_by_metadata() method. Attackers can exploit the unsafe f-string interpolation in clickhousedb.py to delete all rows, target specific rows, or extract information through error-based or blind SQL injection techniques.\n\nPackage: agno\nInstalled: 1.5.6\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4c33bda89ed6c3ca", "name": "CVE-2025-69223: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2025-69223: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.13.3\nSeverity: HIGH\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4a6694bfd514b6ee", "name": "CVE-2025-69227: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2025-69227: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via specially crafted POST request\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an infinite loop to occur when assert statements are bypassed, resulting in a DoS attack when processing a POST body. If optimizations are enabled (-O or PYTHONOPTIMIZE=1), and the application includes a handler that uses the Request.post() method, then an attacker may be able to execute a DoS attack with a specially crafted message. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.13.3\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-70484482fae6cbf0", "name": "CVE-2025-69228: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2025-69228: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an application includes a handler that uses the Request.post() method, an attacker may be able to freeze the server by exhausting the memory. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.13.3\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a222ca1abbe9c5ba", "name": "CVE-2025-69229: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2025-69229: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via excessive CPU usage in chunked message handling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usage when receiving a large number of chunks. If an application makes use of the request.read() method in an endpoint, it may be possible for an attacker to cause the server to spend a moderate amount of blocking CPU time (e.g. 1 second) while processing the request. This could potentially lead to DoS as the server would \n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.13.3\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-32eaca897e9dcf48", "name": "CVE-2026-22815: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-22815: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via insufficient header/trailer handling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-62ac2b6a1433ba91", "name": "CVE-2026-34515: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-34515: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Information disclosure via static resource handler on Windows\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-434bfb16a22eac55", "name": "CVE-2026-34516: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-34516: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via excessive multipart headers\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multipart headers may be allowed to use more memory than intended, potentially allowing a DoS vulnerability. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5c86180485a845b2", "name": "CVE-2026-34525: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-34525: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Security bypass via multiple Host headers\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a11f6b05338ffa8d", "name": "CVE-2026-34993: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-34993: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load()\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.14.0\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e0d9233daebe392b", "name": "CVE-2026-47265: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-47265: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "python-aiohttp: AIOHTTP: Information disclosure via improper handling of cookies during cross-origin redirects\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect. If a developer uses the `cookies` parameter on a per-request basis then sensitive data might be leaked to an attacker if they manage to control a redirect. Version 3.14.0 patches the issue. If unable to upgrade, using a `Cookie` header in the `headers` parameter is not vulnerable.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.14.0\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-175bef58967cceae", "name": "CVE-2026-54273: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-54273: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via excessive pipelined requests\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An attacker may be able to use pipelined requests to use excessive amounts of memory, potentially leading to DoS. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-99d7e8662c9f9b2f", "name": "CVE-2026-54274: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-54274: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via incomplete websocket frame payloads\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4dc7ad98b515a22e", "name": "CVE-2026-54276: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-54276: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Information disclosure via DigestAuthMiddleware after cross-origin redirect\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vulnerability or similar on the target domain for an attacker to be able to execute. Further, the attacker is only receiving the digest, so should only be able to extract the user's credentials if the cryptography is weak or there is some kind of password reuse. This\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-da9af0261d30e082", "name": "CVE-2026-54277: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-54277: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via oversized HTTP request lines bypassing max_line_size check\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in parts of an HTTP request in the C parser. If using the optimised C parser (the default in pre-built wheels), then an attacker may be able to send oversized lines through the HTTP parser and use an excessive amount of memory, potentially leading to DoS. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1481c995edfa6a31", "name": "CVE-2026-54278: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-54278: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service due to excessive memory consumption from compressed request body\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-595497baed9ef17c", "name": "CVE-2025-53643: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2025-53643: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP HTTP Request/Response Smuggling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request. If a pure Python version of aiohttp is installed (i.e. without the usual C extensions) or AIOHTTP_NO_EXTENSIONS is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections. Version 3.12.14 contains a p\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.12.14\nSeverity: LOW\nFix: Upgrade aiohttp to 3.12.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-49aaa60399d891e6", "name": "CVE-2025-69224: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2025-69224: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Request smuggling via non-ASCII characters in HTTP parser\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python HTTP parser may allow a request smuggling attack with the presence of non-ASCII characters. If a pure Python version of AIOHTTP is installed (i.e. without the usual C extensions) or AIOHTTP_NO_EXTENSIONS is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.13.3\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-87696374ad9fe8b4", "name": "CVE-2025-69225: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2025-69225: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Request smuggling vulnerability via non-ASCII decimals in Range header\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.13.3\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9d3c494ede67fb6d", "name": "CVE-2025-69226: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2025-69226: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Information disclosure of path components via static file path normalization\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.13.3\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-41d59b66526625b2", "name": "CVE-2025-69230: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2025-69230: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via specially crafted invalid cookies\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is accessed in an application, then an attacker may be able to trigger a storm of warning-level logs using a specially crafted Cookie header. This issue is fixed in 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.13.3\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1967d656156d029e", "name": "CVE-2026-34513: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-34513: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service due to unbounded DNS cache\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-820cd23fede41311", "name": "CVE-2026-34514: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-34514: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Header Injection via content_type parameter manipulation\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f69d3ed248fc2a1a", "name": "CVE-2026-34517: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-34517: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via large multipart form fields\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multipart form fields, aiohttp read the entire field into memory before checking client_max_size. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c33ccff139d68a9b", "name": "CVE-2026-34518: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-34518: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Information disclosure via retained Cookie and Proxy-Authorization headers during redirects\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following redirects to a different origin, aiohttp drops the Authorization header, but retains the Cookie and Proxy-Authorization headers. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba2f82a6e54a02ad", "name": "CVE-2026-34519: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-34519: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Header injection vulnerability via reason parameter\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the reason parameter when creating a Response may be able to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-62c604a3902f3c83", "name": "CVE-2026-34520: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-34520: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Header injection vulnerability due to improper character handling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9889f056296bb0f8", "name": "CVE-2026-50269: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-50269: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: CRLF injection in multipart headers\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar. In the unlikely situation that an application is passing user-controlled strings into MultipartWriter.append(headers=...) or Payload.headers, then an attacker may be able to modify the request to inject headers or change the contents of the request. This vulnerabi\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.14.0\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-de8ef3ed04e6117b", "name": "CVE-2026-54275: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-54275: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: TLS SNI check bypass via connection reuse\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an application makes multiple requests to the same domain, but with different per-request server_hostname parameters, then the later calls may succeed by reusing the existing connection when they should have been rejected due to the TLS SNI check. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.14.1\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d422e3cf9949cda1", "name": "CVE-2026-54279: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-54279: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Host-Only Cookies Become Domain Cookies After CookieJar Persistence\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.14.1\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2dc3eead15bd773a", "name": "CVE-2026-54280: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-54280: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be able to cause resource starvation temporarily until garbage collection or similar closes the file. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.12.6\nFixed in: 3.14.1\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1caadde6c5f8b666", "name": "CVE-2026-42215: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/", "shortDescription": {"text": "CVE-2026-42215: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "GitPython is a python library used to interact with Git repositories.  ...\n\nGitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at it\n\nPackage: gitpython\nInstalled: 3.1.44\nFixed in: 3.1.47\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.47"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d7dd9d5eecfab0d8", "name": "CVE-2026-42284: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/", "shortDescription": {"text": "CVE-2026-42284: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "GitPython is a python library used to interact with Git repositories.  ...\n\nGitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(\" \".join(multi_options)). A string like \"--branch main --config core.hooksPath=/x\" passes validation (starts with --branch), but after split becomes [\"--branch\", \"main\", \"--config\", \"core.hooksPath=/x\"]. Git applies the config and executes attacker hooks during clone. This issue has been patched in version 3.1.47.\n\nPackage: gitpython\nInstalled: 3.1.44\nFixed in: 3.1.47\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.47"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bc0d2f4f0ea34362", "name": "CVE-2026-44243: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/", "shortDescription": {"text": "CVE-2026-44243: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "GitPython: GitPython: Arbitrary file write via crafted reference paths\n\nGitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository\u2019s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.\n\nPackage: gitpython\nInstalled: 3.1.44\nFixed in: 3.1.48\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.48"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c274de8ed08eb46b", "name": "CVE-2026-44244: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/", "shortDescription": {"text": "CVE-2026-44244: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "GitPython is a python library used to interact with Git repositories.  ...\n\nGitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \\n becomes \\n\\t), but Git still accepts an indented [core] stanza as a section header \u2014 so the injected core.hooksPath becomes effective configuration. Any Git operation that invokes hooks (commit, merge, checkout)\n\nPackage: gitpython\nInstalled: 3.1.44\nFixed in: 3.1.49\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.49"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-028af81833b92cf2", "name": "GHSA-2f96-g7mh-g2hx: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/bac", "shortDescription": {"text": "GHSA-2f96-g7mh-g2hx: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist\n\n## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**CWE:** CWE-184 (Incomplete List of Disallowed Inputs) \u2192 CWE-78 (OS Command Injection)\n**Severity:** inherits the parent CVE-2026-42215 surface; estimated Hi\n\nPackage: gitpython\nInstalled: 3.1.44\nFixed in: 3.1.51\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.51"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4bc751500e3588f3", "name": "GHSA-956x-8gvw-wg5v: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/bac", "shortDescription": {"text": "GHSA-956x-8gvw-wg5v: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`\n\n## Summary\n\nGitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of \"unsafe\" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, \u2026) that can be abused to run arbitrary commands, and enforces them with `Git.check_unsafe_options()`.\n\nThat enforcement is only wired into the **network** commands \u2014 `clone_from`, `Remote.fetch`, `Remote.pull`, `Remote.push`. Several other p\n\nPackage: gitpython\nInstalled: 3.1.44\nFixed in: 3.1.51\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.51"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f1cc9c705bceea92", "name": "GHSA-mv93-w799-cj2w: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/bac", "shortDescription": {"text": "GHSA-mv93-w799-cj2w: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath\n\nSummary\n\nThe patch for CVE-2026-42215 (GitPython 3.1.49) validates newlines only in the value parameter of set_value(). The section and option parameters are passed to configparser without any newline validation. An attacker who controls the section argument can inject \\n to write arbitrary section headers into .git/config, including a forged [core] section with hooksPath pointing to an attacker-controlled directory, leading to RCE when any git hook is triggered.\n\nDetails\n\nFile: git/config.py \u2014 \n\nPackage: gitpython\nInstalled: 3.1.44\nFixed in: 3.1.50\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.50"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-df268f25bfea14d3", "name": "GHSA-rwj8-pgh3-r573: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/bac", "shortDescription": {"text": "GHSA-rwj8-pgh3-r573: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL\n\n### Summary\n`Repo.clone_from()` passes the caller-supplied remote URL through `Git.polish_url()`, which on every non-Cygwin platform calls `os.path.expandvars()` on the URL before handing it to `git clone`. An attacker who controls the URL argument \u2014 the documented use case for `clone_from()` in \"import repository from URL\" features of CI servers, git-hosting mirrors, and dependency scanners \u2014 can embed `$NAME` / `${NAME}` tokens that are expanded server-side to the values of the hosting process\n\nPackage: gitpython\nInstalled: 3.1.44\nFixed in: 3.1.52\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.52"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-43da8ca3e353d6dc", "name": "CVE-2025-57804: h2 4.2.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock", "shortDescription": {"text": "CVE-2025-57804: h2 4.2.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "h2: h2 allows HTTP Request Smuggling due to illegal characters in headers\n\nh2 is a pure-Python implementation of a HTTP/2 protocol stack. Prior to version 4.3.0, an HTTP/2 request splitting vulnerability allows attackers to perform request smuggling attacks by injecting CRLF characters into headers. This occurs when servers downgrade HTTP/2 requests to HTTP/1.1 without properly validating header names/values, enabling attackers to manipulate request boundaries and bypass security controls. This issue has been patched in version 4.3.0.\n\nPackage: h2\nInstalled: 4.2.0\nFixed in: 4.3.0\nSeverity: MEDIUM\nFix: Upgrade h2 to 4.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-342377025a41a82b", "name": "CVE-2026-45409: idna 3.10 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock", "shortDescription": {"text": "CVE-2026-45409: idna 3.10 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "python-idna: idna: Denial of Service via specially crafted long inputs\n\nInternationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fi\n\nPackage: idna\nInstalled: 3.10\nFixed in: 3.15\nSeverity: MEDIUM\nFix: Upgrade idna to 3.15"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0db441e713754e1b", "name": "CVE-2026-31240: mem0ai 0.1.102 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-31240: mem0ai 0.1.102 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory management API endpoints\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss.\n\nPackage: mem0ai\nInstalled: 0.1.102\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-084be3b1db8ab3e1", "name": "CVE-2026-31241: mem0ai 0.1.102 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-31241: mem0ai 0.1.102 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory deletion API endpoint\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service.\n\nPackage: mem0ai\nInstalled: 0.1.102\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e3aeb2fef11dc3e1", "name": "CVE-2026-31245: mem0ai 0.1.102 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-31245: mem0ai 0.1.102 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory creation API endpoint\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution.\n\nPackage: mem0ai\nInstalled: 0.1.102\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6229792054c09829", "name": "CVE-2026-7597: mem0ai 0.1.102 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.", "shortDescription": {"text": "CVE-2026-7597: mem0ai 0.1.102 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "mem0ai mem0 has an Improper Input Validation Issue\n\nA vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue.\n\nPackage: mem0ai\nInstalled: 0.1.102\nFixed in: 2.0.0b2\nSeverity: LOW\nFix: Upgrade mem0ai to 2.0.0b2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-55a2832ec566db2c", "name": "CVE-2026-0994: protobuf 6.31.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-0994: protobuf 6.31.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "python: protobuf: Protobuf: Denial of Service due to recursion depth bypass\n\nA denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages.\n\nDue to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python\u2019s recursion stack and causing a RecursionError.\n\nPackage: protobuf\nInstalled: 6.31.1\nFixed in: 6.33.5, 5.29.6\nSeverity: HIGH\nFix: Upgrade protobuf to 6.33.5, 5.29.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c3f1dd55ad918c62", "name": "CVE-2026-23490: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.l", "shortDescription": {"text": "CVE-2026-23490: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.2\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d559408a1a115f70", "name": "CVE-2026-30922: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.l", "shortDescription": {"text": "CVE-2026-30922: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with \"Indefinite Length\" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consu\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.3\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e30e23c3f46dd2da", "name": "CVE-2026-59885: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.l", "shortDescription": {"text": "CVE-2026-59885: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values.\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.4\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-16e948d5ea8b0d47", "name": "CVE-2026-59886: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.l", "shortDescription": {"text": "CVE-2026-59886: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.4\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-66a63c03a37911ef", "name": "CVE-2026-4539: pygments 2.19.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv", "shortDescription": {"text": "CVE-2026-4539: pygments 2.19.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "pygments: Pygments: Denial of Service via inefficient regular expression processing in AdlLexer\n\nA security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.\n\nPackage: pygments\nInstalled: 2.19.1\nFixed in: 2.20.0\nSeverity: LOW\nFix: Upgrade pygments to 2.20.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f78e95530b59592", "name": "CVE-2025-71176: pytest 8.3.5 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.l", "shortDescription": {"text": "CVE-2025-71176: pytest 8.3.5 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "pytest: pytest: Denial of Service or Privilege Escalation via insecure temporary directory handling\n\npytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.\n\nPackage: pytest\nInstalled: 8.3.5\nFixed in: 9.0.3\nSeverity: MEDIUM\nFix: Upgrade pytest to 9.0.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d9641f282c39073f", "name": "CVE-2026-28684: python-dotenv 1.1.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backe", "shortDescription": {"text": "CVE-2026-28684: python-dotenv 1.1.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following\n\npython-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when a cross-device rename fallback is triggered. Users should upgrade to v.1.2.2 or, as a workaround, apply the patch manually.\n\nPackage: python-dotenv\nInstalled: 1.1.0\nFixed in: 1.2.2\nSeverity: MEDIUM\nFix: Upgrade python-dotenv to 1.2.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-92e9bfe1ecfb19df", "name": "CVE-2026-24486: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/b", "shortDescription": {"text": "CVE-2026-24486: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Arbitrary file write via path traversal vulnerability\n\nPython-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write uploaded files to arbitrary locations on the filesystem by crafting a malicious filename. Users should upgrade to version 0.0.22 to receive a patch or, as a workaround, avoid using `UPLOAD_KEEP_FILENAME=True` in project configurations.\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.22\nSeverity: HIGH\nFix: Upgrade python-multipart to 0.0.22"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c2535a55acb31d50", "name": "CVE-2026-42561: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/b", "shortDescription": {"text": "CVE-2026-42561: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "python-multipart: python-multipart: Denial of Service via excessive multipart part headers\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, MultipartParser previously had no limit on the number of part headers or the size of an individual part header. An attacker could send a request with either many repeated headers without terminating the header block or a single very large header value, causing excessive CPU work before request reje\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.27\nSeverity: HIGH\nFix: Upgrade python-multipart to 0.0.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-876c287bfd6e2639", "name": "CVE-2026-53539: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/b", "shortDescription": {"text": "CVE-2026-53539: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Denial of Service via crafted form-urlencoded bodies\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step lookup: it first scanned the entire remaining buffer for &, and only when no & existed anywhere ahead did it fall back to scanning for ;. For a body that uses ; as the separator and contains no &, every field iteration performed a full failed & scan over the entire remaining buffer before locating the ne\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.30\nSeverity: HIGH\nFix: Upgrade python-multipart to 0.0.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f43255590e1c21a1", "name": "CVE-2026-40347: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/b", "shortDescription": {"text": "CVE-2026-40347: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Denial of Service via crafted multipart/form-data requests\n\nPython-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candidate when processing leading CR/LF data and immediately discards epilogue data after the closing boundary.\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.26\nSeverity: MEDIUM\nFix: Upgrade python-multipart to 0.0.26"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a64c848fe6c0d709", "name": "CVE-2026-53537: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/b", "shortDescription": {"text": "CVE-2026-53537: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "multipart: Python-Multipart: Information disclosure via header parsing discrepancy\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message, which transparently applies RFC 2231/5987 decoding. The extended parameter syntax (filename*=charset'lang'value, name*=..., and the filename*0/filename*1 continuation form) is decoded and surfaced under the bare filename/name key, and overrides the plain parameter when both are present. RFC 7578 \u00a74.2 explicitly forbid\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.30\nSeverity: LOW\nFix: Upgrade python-multipart to 0.0.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a1236deaf1ef997", "name": "CVE-2026-53538: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/b", "shortDescription": {"text": "CVE-2026-53538: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Information disclosure due to parser differential in form data handling\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator. This creates a parser differential: the same bytes are tokenized into different fields than a WHATWG compliant intermediary would produce, allowing an attacker to smuggle extra form \n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.30\nSeverity: LOW\nFix: Upgrade python-multipart to 0.0.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b810e5aecdc4b92a", "name": "CVE-2026-53540: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/b", "shortDescription": {"text": "CVE-2026-53540: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Negative Content-Length in parse_form buffers the entire body in memory\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned the bounded read into a read-until-EOF, so the entire body was loaded into memory in a single read instead of in fixed-size chunks. This vulnerability is fixed in 0.0.31.\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.31\nSeverity: LOW\nFix: Upgrade python-multipart to 0.0.31"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0b203871a3974878", "name": "CVE-2024-47081: requests 2.32.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/u", "shortDescription": {"text": "CVE-2024-47081: requests 2.32.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "requests: Requests vulnerable to .netrc credentials leak via malicious URLs\n\nRequests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.\n\nPackage: requests\nInstalled: 2.32.3\nFixed in: 2.32.4\nSeverity: MEDIUM\nFix: Upgrade requests to 2.32.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9fdea612cd195d1c", "name": "CVE-2026-25645: requests 2.32.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/u", "shortDescription": {"text": "CVE-2026-25645: requests 2.32.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "requests: Requests: Security bypass due to predictable temporary file creation\n\nRequests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulner\n\nPackage: requests\nInstalled: 2.32.3\nFixed in: 2.33.0\nSeverity: MEDIUM\nFix: Upgrade requests to 2.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-86f4935868342d0e", "name": "CVE-2025-62727: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/", "shortDescription": {"text": "CVE-2025-62727: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "starlette: Starlette DoS via Range header merging\n\nStarlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileResponse Range parsing/merging logic. This enables CPU exhaustion per request, causing denial\u2011of\u2011service for endpoints serving files (e.g., StaticFiles or any use of FileResponse). This vulnerability is fixed in 0.49.1.\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 0.49.1\nSeverity: HIGH\nFix: Upgrade starlette to 0.49.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-45c78b00191568df", "name": "CVE-2026-48818: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/", "shortDescription": {"text": "CVE-2026-48818: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows\n\nStarlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\\\attacker.com\\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account\u2019s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as Fas\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.1.0\nSeverity: HIGH\nFix: Upgrade starlette to 1.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f6be8609a2a6ba96", "name": "CVE-2026-54283: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/", "shortDescription": {"text": "CVE-2026-54283: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS\n\nStarlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, but silently ignored for application/x-www-form-urlencoded. An unauthenticated attacker can therefore send a urlencoded body with an arbitrarily large number of fields or an arbitrarily large field, even when the application configured limits it believed would apply.\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.3.1\nSeverity: HIGH\nFix: Upgrade starlette to 1.3.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-798b3720452930a8", "name": "CVE-2025-54121: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/", "shortDescription": {"text": "CVE-2025-54121: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "starlette: Starlette denial-of-service\n\nStarlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In versions 0.47.1 and below, when parsing a multi-part form with large files (greater than the default max spool size) starlette will block the main thread to roll the file over to disk. This blocks the event thread which means the application can't accept new connections. The UploadFile code has a minor bug where instead of just checking for self._in_me\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 0.47.2\nSeverity: MEDIUM\nFix: Upgrade starlette to 0.47.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-db9bab7abb7157c6", "name": "CVE-2026-48710: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/", "shortDescription": {"text": "CVE-2026-48710: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Security restriction bypass via malformed HTTP Host header\n\nStarlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) \n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.0.1\nSeverity: MEDIUM\nFix: Upgrade starlette to 1.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1d4677b47b244bae", "name": "CVE-2026-48817: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/", "shortDescription": {"text": "CVE-2026-48817: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Information disclosure and unintended method execution via non-standard HTTP methods\n\nStarlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs. When an HTTPEndpoint subclass is registered through Route(...) without an explicit methods= argument, the route does not constrain the method and every method reaches the endpoint. If a non-standard HTTP method whose lo\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.1.0\nSeverity: MEDIUM\nFix: Upgrade starlette to 1.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-758eb6ec50042ff4", "name": "CVE-2026-54282: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/", "shortDescription": {"text": "CVE-2026-54282: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Information disclosure due to improper HTTP request path validation\n\nStarlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path} and re-parsing the result, a path that does not begin with / (for example @google.com) moves the authority boundary during re-parsing, so request.url.hostname and request.url.netloc become attacker-controlled. Code that reads request.url.hostname (rather than the Host header \n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.3.0\nSeverity: LOW\nFix: Upgrade starlette to 1.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a5b47f3d55f203cf", "name": "CVE-2025-66418: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.", "shortDescription": {"text": "CVE-2025-66418: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.\n\nPackage: urllib3\nInstalled: 2.4.0\nFixed in: 2.6.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-699d2df981b913c6", "name": "CVE-2025-66471: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.", "shortDescription": {"text": "CVE-2025-66471: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3 Streaming API improperly handles highly compressed data\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, b\n\nPackage: urllib3\nInstalled: 2.4.0\nFixed in: 2.6.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eaf45dd96f79c169", "name": "CVE-2026-21441: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.", "shortDescription": {"text": "CVE-2026-21441: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)\n\nurllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in ve\n\nPackage: urllib3\nInstalled: 2.4.0\nFixed in: 2.6.3\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-be980db29bafa8de", "name": "CVE-2026-44431: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.", "shortDescription": {"text": "CVE-2026-44431: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers\n\nurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.\n\nPackage: urllib3\nInstalled: 2.4.0\nFixed in: 2.7.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-36341deafaff9827", "name": "CVE-2025-50181: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.", "shortDescription": {"text": "CVE-2025-50181: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation\n\nurllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.\n\nPackage: urllib3\nInstalled: 2.4.0\nFixed in: 2.5.0\nSeverity: MEDIUM\nFix: Upgrade urllib3 to 2.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f5ac93ee23269a0c", "name": "CVE-2025-50182: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.", "shortDescription": {"text": "CVE-2025-50182: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3 does not control redirects in browsers and Node.js\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest. This means Python libraries can be used to make HTTP requests from a browser or Node.js. Additionally, urllib3 provides a mechanism to control redirects, but the retries and redirect parameters are ignored with Pyodi\n\nPackage: urllib3\nInstalled: 2.4.0\nFixed in: 2.5.0\nSeverity: MEDIUM\nFix: Upgrade urllib3 to 2.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e9dda8f6602a2279", "name": "CVE-2026-53512: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/", "shortDescription": {"text": "CVE-2026-53512: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins\n\nBetter Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession of the bound refreshToken row and matching client_id, without verifying the confidential client's client_secret, allowing an attacker with a valid refresh_token to mint access tokens and rotated refresh tokens through /api/auth/oauth2/token or /api/auth/mcp/token. The @better-auth/o\n\nPackage: better-auth\nInstalled: 1.2.8\nFixed in: 1.6.11\nSeverity: CRITICAL\nFix: Upgrade better-auth to 1.6.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-ac44eb029689d7af", "name": "GHSA-xg6x-h9c9-2m83: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/cl", "shortDescription": {"text": "GHSA-xg6x-h9c9-2m83: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)\n\n### Summary\n\nUnder certain configurations, sessions may be considered valid before two-factor authentication (2FA) is fully completed. This can allow access to authenticated routes without verifying the second factor.\n\n---\n\n### Description\n\nWhen two-factor authentication is enabled, the authentication flow correctly identifies users who require additional verification and defers full authentication until the second factor is completed.\n\nHowever, when `session.cookieCache` is enabled, the session\n\nPackage: better-auth\nInstalled: 1.2.8\nFixed in: 1.4.9\nSeverity: CRITICAL\nFix: Upgrade better-auth to 1.4.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-eb6dfa6bda9a3570", "name": "CVE-2025-61928: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/", "shortDescription": {"text": "CVE-2025-61928: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Better Auth: Unauthenticated API key creation through api-key plugin\n\nBetter Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated attackers can create or modify API keys for any user by passing that user's id in the request body to the `api/auth/api-key/create` route. `session?.user ?? (authRequired ? null : { id: ctx.body.userId })`. When no session exists but `userId` is present in the request body, `authRequired` becomes false and the user object is set to the attacker-controlled ID. Server-only field \n\nPackage: better-auth\nInstalled: 1.2.8\nFixed in: 1.3.26\nSeverity: HIGH\nFix: Upgrade better-auth to 1.3.26"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cea750ea258006ca", "name": "CVE-2026-45364: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/", "shortDescription": {"text": "CVE-2026-45364: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation\n\nBetter Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth's HTTP rate limiter keyed each request by the exact textual IP address it received in x-forwarded-for (or the configured IP-bearing header). IPv6 clients controlling a typical /64 allocation could rotate through 2^64 distinct source addresses without exhausting the per-address counter, defeating rate limiting on /sign-in/email, /sign-up/email, /forget-password, and every other\n\nPackage: better-auth\nInstalled: 1.2.8\nFixed in: 1.4.17, 1.5.0-beta.9\nSeverity: HIGH\nFix: Upgrade better-auth to 1.4.17, 1.5.0-beta.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c234a6693fb091e5", "name": "CVE-2026-53514: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/", "shortDescription": {"text": "CVE-2026-53514: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin\n\nBetter Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside the invited mailbox and requireEmailVerificationOnInvitation: true is not enabled, the organization plugin's acceptInvitation, rejectInvitation, getInvitation, and listUserInvitations recipient endpoints use session.user.email and an invitation ID without sufficient verified-email ownership proof, allowing a user with an unverified sessio\n\nPackage: better-auth\nInstalled: 1.2.8\nFixed in: 1.6.11\nSeverity: HIGH\nFix: Upgrade better-auth to 1.6.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-82e99eac1bc26009", "name": "CVE-2026-53516: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/", "shortDescription": {"text": "CVE-2026-53516: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email\n\nBetter Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAuthUserInfo accepts implicit account linking when the OAuth provider asserts email_verified: true without requiring the local user row's emailVerified field to also be true, allowing an attacker who pre-registers a victim email through /sign-up/email to bind the victim's OAuth identity to the attacker's account. The same primitive affects one-tap, and\n\nPackage: better-auth\nInstalled: 1.2.8\nFixed in: 1.6.11\nSeverity: HIGH\nFix: Upgrade better-auth to 1.6.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-022619e1c6c20e65", "name": "CVE-2026-53518: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/", "shortDescription": {"text": "CVE-2026-53518: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive\n\nBetter Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint for the authorization_code grant redeems a single-use authorization code through a non-atomic find-then-delete sequence, allowing two concurrent requests to pass the read step and mint independent access tokens, refresh tokens, and ID tokens; legacy /oauth2/token and /mcp/token paths in oidc-provider and mcp plugins share the same primiti\n\nPackage: better-auth\nInstalled: 1.2.8\nFixed in: 1.6.11\nSeverity: HIGH\nFix: Upgrade better-auth to 1.6.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-541c96bb724b4451", "name": "GHSA-86j7-9j95-vpqj: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/cl", "shortDescription": {"text": "GHSA-86j7-9j95-vpqj: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp\n\n### Am I affected?\n\nCheck each condition. Users are affected when all of the first three hold.\n\n- Their application enables the `oidc-provider` plugin or the `mcp` plugin from `better-auth/plugins`. The `mcp` plugin wraps the same provider and carries the same defect. Both are on the migration path to `@better-auth/oauth-provider`, which is not affected.\n- Their application `better-auth` version is `1.6.12` or earlier on the stable line, or any `1.7.0-beta` build on the pre-release line. Both re\n\nPackage: better-auth\nInstalled: 1.2.8\nFixed in: 1.6.13, 1.7.0-beta.4\nSeverity: HIGH\nFix: Upgrade better-auth to 1.6.13, 1.7.0-beta.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e320ff95e41c4c92", "name": "GHSA-9h47-pqcx-hjr4: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/cl", "shortDescription": {"text": "GHSA-9h47-pqcx-hjr4: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default\n\n### Am I affected?\n\nUsers are affected if all of the following are true:\n\n- Their application uses `better-auth` at a version below the patched release.\n- Their application enables `oidcProvider()` from `better-auth/plugins/oidc-provider` or `mcp()` from `better-auth/plugins/mcp` (the mcp plugin delegates to `oidcProvider` and inherits both defaults).\n- For the algorithm-negotiation impact: relying parties of the application's OIDC server use a JWT verification library that performs algorithm ne\n\nPackage: better-auth\nInstalled: 1.2.8\nFixed in: 1.6.11\nSeverity: HIGH\nFix: Upgrade better-auth to 1.6.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c249ca8e69031ec7", "name": "GHSA-x732-6j76-qmhm: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/cl", "shortDescription": {"text": "GHSA-x732-6j76-qmhm: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits\n\n## Summary\n\nAn issue in the underlying router library **rou3** can cause `/path` and `//path` to be treated as identical routes. If your environment does **not** normalize incoming URLs (e.g., by collapsing multiple slashes), this can allow bypasses of `disabledPaths` and path-based rate limits.\n\n## Details\n\nBetter Auth uses **better-call**, which internally relies on **rou3** for routing. Affected versions of rou3 normalize paths by removing empty segments. As a result:\n\n* `/sign-in/email`\n* `/\n\nPackage: better-auth\nInstalled: 1.2.8\nFixed in: 1.4.5\nSeverity: HIGH\nFix: Upgrade better-auth to 1.4.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bba0752afc67556a", "name": "GHSA-wxw3-q3m9-c3jr: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/cl", "shortDescription": {"text": "GHSA-wxw3-q3m9-c3jr: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE\n\n### Am I affected?\n\nUsers are affected if all of the following are true:\n\n- The application uses `better-auth` at a version below `1.6.2` (or `@better-auth/sso` paired with such a version).\n- `betterAuth({ account: { storeStateStrategy } })` is set to `\"cookie\"`. The default `\"database\"` is not affected.\n- The application wires at least one OAuth provider through `genericOAuth({ config })` with `pkce: false`, or it supplies a custom `getToken` or `tokenUrl` that does not require the stored `code\n\nPackage: better-auth\nInstalled: 1.2.8\nFixed in: 1.6.2\nSeverity: MEDIUM\nFix: Upgrade better-auth to 1.6.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d198b3d7804b82e7", "name": "CVE-2025-53535: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/", "shortDescription": {"text": "CVE-2025-53535: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes\n\nBetter Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the originCheck middleware function, which affects the following routes: /verify-email, /reset-password/:token, /delete-user/callback, /magic-link/verify, /oauth-proxy-callback. This vulnerability is fixed in 1.2.10.\n\nPackage: better-auth\nInstalled: 1.2.8\nFixed in: 1.2.10\nSeverity: LOW\nFix: Upgrade better-auth to 1.2.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-53b6b5b0e8df56bd", "name": "GHSA-2vg6-77g8-24mp: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/cl", "shortDescription": {"text": "GHSA-2vg6-77g8-24mp: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows\n\n### Am I affected?\n\nUsers are affected if all of the following are true:\n\n- They configure `secondaryStorage` on `betterAuth(...)` (Redis, KV, or any external session cache).\n- `session.storeSessionInDatabase` is left unset or set to `false` (the default).\n- Their application's deployment uses one or more of:\n  - The `admin` plugin and calls `auth.api.removeUser(...)` or `authClient.admin.removeUser(...)`.\n  - The `anonymous` plugin and exposes `/delete-anonymous-user` or relies on the after-lin\n\nPackage: better-auth\nInstalled: 1.2.8\nFixed in: 1.6.11\nSeverity: LOW\nFix: Upgrade better-auth to 1.6.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-71c337a7b99c3ed8", "name": "GHSA-569q-mpph-wgww: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/cl", "shortDescription": {"text": "GHSA-569q-mpph-wgww: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Better Auth affected by external request basePath modification DoS\n\n# Summary\n\nAffected versions of Better Auth allow an external request to configure `baseURL` when it isn\u2019t defined through any other means. This can be abused to poison the router\u2019s base path, causing all routes to return 404 for all users.\n\nThis issue is only exploitable when `baseURL` is not explicitly configured (e.g., `BETTER_AUTH_URL` is missing) *and* the attacker is able to make the very first request to the server after startup. In properly configured environments or typical managed host\n\nPackage: better-auth\nInstalled: 1.2.8\nFixed in: 1.4.2\nSeverity: LOW\nFix: Upgrade better-auth to 1.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fe6af4614f163486", "name": "GHSA-hq75-xg7r-rx6c: better-call 1.0.9 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/cl", "shortDescription": {"text": "GHSA-hq75-xg7r-rx6c: better-call 1.0.9 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Better Call routing bug can lead to Cache Deception\n\n### Summary\n\nUsing a CDN that caches (`/**/*.png`, `/**/*.json`, `/**/*.css`, etc...) requests, a cache deception can emerge. This could lead to unauthorized access to user sessions and personal data when cached responses are served to other users.\n\n### Details\n\nThe vulnerability occurs in the request processing logic where path sanitization is insufficient. The library splits the path using `config.basePath` but doesn't properly validate the remaining path components. This allows specially craf\n\nPackage: better-call\nInstalled: 1.0.9\nFixed in: 1.0.12\nSeverity: MEDIUM\nFix: Upgrade better-call to 1.0.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5b6eda0b6fd52ce1", "name": "CVE-2026-35209: defu 6.1.4 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lo", "shortDescription": {"text": "CVE-2026-35209: defu 6.1.4 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "defu: Prototype pollution via `__proto__` key in defaults argument\n\ndefu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or config files from untrusted sources) as the first argument to `defu()` are vulnerable to prototype pollution. A crafted payload containing a `__proto__` key can override intended default values in the merged resul. The internal `_defu` function used `Object.assign({}, defaults)` to copy the default\n\nPackage: defu\nInstalled: 6.1.4\nFixed in: 6.1.5\nSeverity: HIGH\nFix: Upgrade defu to 6.1.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3467653acdca23df", "name": "CVE-2026-32763: kysely 0.28.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm", "shortDescription": {"text": "CVE-2026-32763: kysely 0.28.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "SQL Injection via unsanitized JSON path keys when ignoring/silencing compilation errors or using `Kysely<any>`.\n\nKysely is a type-safe TypeScript SQL query builder. Versions up to and including 0.28.11 has a SQL injection vulnerability in JSON path compilation for MySQL and SQLite dialects. The `visitJSONPathLeg()` function appends user-controlled values from `.key()` and `.at()` directly into single-quoted JSON path string literals (`'$.key'`) without escaping single quotes. An attacker can break out of the JSON path string context and inject arbitrary SQL. This is inconsistent with `sanitizeIdentifier()`\n\nPackage: kysely\nInstalled: 0.28.2\nFixed in: 0.28.12\nSeverity: HIGH\nFix: Upgrade kysely to 0.28.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-517427c8f7143719", "name": "CVE-2026-33468: kysely 0.28.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm", "shortDescription": {"text": "CVE-2026-33468: kysely 0.28.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that append string literal values into the compiled SQL strings\n\nKysely is a type-safe TypeScript SQL query builder. Prior to version 0.28.14, Kysely's `DefaultQueryCompiler.sanitizeStringLiteral()` only escapes single quotes by doubling them (`'` \u2192 `''`) but does not escape backslashes. When used with the MySQL dialect (where `NO_BACKSLASH_ESCAPES` is OFF by default), an attacker can use a backslash to escape the trailing quote of a string literal, breaking out of the string context and injecting arbitrary SQL. This affects any code path that uses `Immediate\n\nPackage: kysely\nInstalled: 0.28.2\nFixed in: 0.28.14\nSeverity: HIGH\nFix: Upgrade kysely to 0.28.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-972e7bf95d3c2000", "name": "CVE-2026-44635: kysely 0.28.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm", "shortDescription": {"text": "CVE-2026-44635: kysely 0.28.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()`\n\nKysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metacharacters (., [, ], *, **, ?). When attacker-controlled input flows into eb.ref(col, '->$').key(input) or .at(input) \u2014 including type-safe code where the JSON column is shaped like Record<string, T> so K extends string is the inferred type \u2014 every dot becomes a path-leg separator, letting an attacker traverse from the intended key into sibling and child\n\nPackage: kysely\nInstalled: 0.28.2\nFixed in: 0.28.17\nSeverity: HIGH\nFix: Upgrade kysely to 0.28.17"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3f319f53538105c0", "name": "CVE-2025-66400: mdast-util-to-hast 13.2.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team", "shortDescription": {"text": "CVE-2025-66400: mdast-util-to-hast 13.2.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "mdast-util-to-hast: mdast-util-to-hast: Markdown code elements can appear as regular page content\n\nmdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdown source by using character references. This could make rendered user supplied markdown code elements appear like the rest of the page. This vulnerability is fixed in 13.2.1.\n\nPackage: mdast-util-to-hast\nInstalled: 13.2.0\nFixed in: 13.2.1\nSeverity: MEDIUM\nFix: Upgrade mdast-util-to-hast to 13.2.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0f69df9d9287111c", "name": "CVE-2025-55182: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2025-55182: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "next: React Server Components: Pre-authentication remote code execution via unsafe deserialization\n\nA pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7\nSeverity: CRITICAL\nFix: Upgrade next to 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-136722a9b063a679", "name": "CVE-2026-44573: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-44573: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed data route, allowing an attacker to retrieve SSR JSON for protected pages without passing the intende\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-64c6837499e85121", "name": "CVE-2026-44575: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-44575: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Unauthorized access to protected content via middleware bypass\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0ec85a0a6ebff72f", "name": "CVE-2026-44578: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-44578: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests\n\nNext.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e051a587d0342800", "name": "CVE-2026-44579: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-44579: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service via crafted POST requests to server actions\n\nNext.js is a React framework for building full-stack web applications. From  to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open for an extended period, consuming file descriptors and server capacity until legitimate users are den\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-958e623d5bd39c18", "name": "CVE-2026-45109: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-45109: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.18, 16.2.6\nSeverity: HIGH\nFix: Upgrade next to 15.5.18, 16.2.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ac7118bf3809d56c", "name": "CVE-2026-64641: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-64641: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Denial of Service in App Router using Server Actions\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.\n\n## Workarounds\n\nNo workaround exists besides upgrading. Applications using Pages Router or not using Server Actions are not vulnerable.\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-922ef0d990b639ee", "name": "CVE-2026-64645: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-64645: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\n## Impact\n\nA `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's\u00a0hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect.\n\nThis affects any destination that puts a dynamic segmen\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b5842c5d8170fe44", "name": "CVE-2026-64649: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-64649: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in Server Actions on custom servers\n\n## Impact\n\nWhen a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization.\n\nApplications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8e0feea1dafefb44", "name": "GHSA-8h8q-6873-q5fj: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/p", "shortDescription": {"text": "GHSA-8h8q-6873-q5fj: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js Vulnerable to Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh). \n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of \n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-62de401c9b41c06f", "name": "GHSA-h25m-26qc-wcjf: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/p", "shortDescription": {"text": "GHSA-h25m-26qc-wcjf: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.0.x, 19.1.x, and 19.2.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23864](https://github.com/facebook/react/security/advisories/GHSA-83fc-fqcc-2hmg).\n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage, out-of-m\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5\nSeverity: HIGH\nFix: Upgrade next to 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f9e0f2ccc6937d3e", "name": "GHSA-mwv6-3258-q52c: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/p", "shortDescription": {"text": "GHSA-mwv6-3258-q52c: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Next Vulnerable to Denial of Service with Server Components\n\nA vulnerability affects certain React packages for versions 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.1.2, 19.2.0, and 19.2.1 and frameworks that use the affected packages, including Next.js 15.x and 16.x using the App Router. The issue is tracked upstream as [CVE-2025-55184](https://www.cve.org/CVERecord?id=CVE-2025-55184).\n\nA malicious HTTP request can be crafted and sent to any App Router endpoint that, when deserialized, can cause the server process to hang and consume CPU. This can result in denia\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 14.2.34, 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 15.6.0-canary.59, 16.0.9, 16.1.0-canary.17\nSeverity: HIGH\nFix: Upgrade next to 14.2.34, 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 15.6.0-canary.59, 16.0.9, 16.1.0-canary.17"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4dedeb93526b1974", "name": "GHSA-q4gf-8mx6-v5v3: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/p", "shortDescription": {"text": "GHSA-q4gf-8mx6-v5v3: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js has a Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react/security/advisories/GHSA-479c-33wc-g2pg). You can read more about this advisory our [this changelog](https://vercel.com/changelog/summary-of-cve-2026-23869).\n\nA specially crafted HTTP request can be sent to any App Rout\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.15, 16.2.3\nSeverity: HIGH\nFix: Upgrade next to 15.5.15, 16.2.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cc04fa964b712808", "name": "CVE-2025-55173: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2025-55173: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "nextjs: Next.js Content Injection Vulnerability for Image Optimization\n\nNext.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Optimization is vulnerable to content injection. The issue allowed attacker-controlled external image sources to trigger file downloads with arbitrary content and filenames under specific configurations. This behavior could be abused for phishing or malicious file delivery. This vulnerability has been fixed in Next.js versions 14.2.31 and 15.4.5.\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 14.2.31, 15.4.5\nSeverity: MEDIUM\nFix: Upgrade next to 14.2.31, 15.4.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c994336b8eacec63", "name": "CVE-2025-57752: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2025-57752: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "nextjs: Next.js Affected by Cache Key Confusion for Image Optimization API Routes\n\nNext.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Optimization API routes are affected by cache key confusion. When images returned from API routes vary based on request headers (such as Cookie or Authorization), these responses could be incorrectly cached and served to unauthorized users due to a cache key confusion bug. This vulnerability has been fixed in Next.js versions 14.2.31 and 15.4.5. All us\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 14.2.31, 15.4.5\nSeverity: MEDIUM\nFix: Upgrade next to 14.2.31, 15.4.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f1ef6af7f14d662b", "name": "CVE-2025-57822: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2025-57822: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js Improper Middleware Redirect Handling Leads to SSRF\n\nNext.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly passing the request object, it could lead to SSRF in self-hosted applications that incorrectly forwarded user-supplied headers. This vulnerability has been fixed in Next.js versions 14.2.32 and 15.4.7. All users implementing custom middleware logic in self-hosted environments are strongly encouraged to upgrade and verify correct usage of the next() \n\nPackage: next\nInstalled: 15.3.3\nFixed in: 14.2.32, 15.4.7\nSeverity: MEDIUM\nFix: Upgrade next to 14.2.32, 15.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7753263f01550694", "name": "CVE-2025-59471: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2025-59471: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "next: NextJS Denial of Service in Image Optimizer\n\nA denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing a maximum size limit, allowing an attacker to cause out-of-memory conditions by requesting optimization of arbitrarily large images. This vulnerability requires that `remotePatterns` is configured to allow image optimization from external domains and\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.10, 16.1.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.10, 16.1.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d9ca5e51cc6d5c5c", "name": "CVE-2026-27980: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-27980: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Unbounded next/image disk cache growth can exhaust storage\n\nNext.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unbounded cache growth. An attacker could generate many unique image-optimization variants and exhaust disk space, causing denial of service. This is fixed in version 16.1.7 by adding an LRU-backed disk cache with `images.maximumDiskCacheSize`, including e\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 16.1.7, 15.5.14\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1f671a796c8e215c", "name": "CVE-2026-29057: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-29057: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: HTTP request smuggling in rewrites\n\nNext.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfer-Encoding: chunked` could trigger request boundary disagreement between the proxy and backend. This could allow request smuggling through rewritten routes. An attacker could smuggle a second request to unintended backend routes (for example, interna\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 16.1.7, 15.5.13\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4c11570196486e50", "name": "CVE-2026-44576: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-44576: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning vulnerability in React Server Components\n\nNext.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later visitors receive component payloads instead of the expected HTML. This vulnerability is fixed in 15.5\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-687c647bafcf038a", "name": "CVE-2026-44577: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-44577: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Next.js: Denial of Service via Image Optimization API\n\nNext.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the /_next/image endpoint that match the images.localPatterns configuration (by default, all patterns are allowed). This vulnerability\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-03746ff066ba0fbd", "name": "CVE-2026-44580: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-44580: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Cross-site scripting allows arbitrary code execution via untrusted script content\n\nNext.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to break out of the intended script context and execute arbitrary JavaScript in a visitor's browser. This vu\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-35b81c45c491dd42", "name": "CVE-2026-44581: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-44581: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Stored Cross-Site Scripting via malformed nonce values in cached responses\n\nNext.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to poison cached responses and cause script execution for later visitors. This vulnerability is fixed i\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-010f6ee5f61eabea", "name": "CVE-2026-64643: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-64643: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Unauthenticated disclosure of internal Server Function endpoints\n\n## Impact\n\nIn Next.js applications using App Router, Server Actions (`use server`) or `use cache` endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used.\n\nServer Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references).\n\nAffected users are applications using App Router + Server Actions.  \n\nBy itself, this disclosure is typically a recon/enumeration primi\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a5fe0b38e0133e37", "name": "CVE-2026-64646: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-64646: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Unbounded Server Action payload in Edge runtime\n\n## Impact\n\nRequests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime\n\n## Workarounds\n\nIf you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should be allowed at max by your hosting provider.\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7fd0187ad045fd28", "name": "CVE-2026-64647: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-64647: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for `\uc083\uc083` and `\uc104\uc104` in the request body would share the same cache.\n\n##\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0ce9cca10d5db591", "name": "CVE-2026-64648: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-64648: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis only applies to `fetch` calls with a request that has a different init than the one passed to `fetch`.\nSafe: `fetch(new Request(init), init)`\nUnsafe: `fetch(new Request(init), aDifferentInit)`\n\n## Work\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a168d5703332d720", "name": "GHSA-w37m-7fhw-fmv9: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/p", "shortDescription": {"text": "GHSA-w37m-7fhw-fmv9: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Next Server Actions Source Code Exposure \n\nA vulnerability affects certain React packages for versions 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.1.2, 19.2.0, and 19.2.1 and frameworks that use the affected packages, including Next.js 15.x and 16.x using the App Router. The issue is tracked upstream as [CVE-2025-55183](https://www.cve.org/CVERecord?id=CVE-2025-55183).\n\nA malicious HTTP request can be crafted and sent to any App Router endpoint that can return the compiled source code of [Server Functions](https://react.dev/reference/rsc/server-f\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 15.6.0-canary.59, 16.0.9, 16.1.0-canary.17\nSeverity: MEDIUM\nFix: Upgrade next to 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 15.6.0-canary.59, 16.0.9, 16.1.0-canary.17"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-13b3d89d695c0453", "name": "CVE-2026-44572: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-44572: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service due to improper handling of x-nextjs-data header with redirects\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When that happened, the middleware/proxy could treat the request as a data request and replace the standard Location redirect header with the internal x-nextjs-redirect header. Browsers do not follow x-nextjs-redirect, so the response became an unusable red\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ddaeb8e8b60471aa", "name": "CVE-2026-44582: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-l", "shortDescription": {"text": "CVE-2026-44582: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning allows incorrect response delivery\n\nNext.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL. This vulnerability is fixed in 15.5.16 and 16.2.5.\n\nPackage: next\nInstalled: 15.3.3\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9c0383b9b9deded4", "name": "CVE-2026-41305: postcss 8.4.31 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnp", "shortDescription": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.4.31\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-152e2df0884d5fea", "name": "GHSA-f88m-g3jw-g9cj: sharp 0.34.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/", "shortDescription": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "fullDescription": {"text": "sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591\n\n### Impact\n\nA number of vulnerabilities, two rated as \"High\" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency.\n\nThose processing untrusted input with versions of sharp prior to 0.35.0 are affected.\n\n### Patches\n\n#### Using prebuilt binaries provided by sharp?\n\nMost people rely on the prebuilt binaries provided by sharp.\n\nPlease upgrade sharp to the latest version, currently 0.35.3, which provides libvips 8.18.3.\n\n#### Using a globally-installed libvips?\n\nP\n\nPackage: sharp\nInstalled: 0.34.2\nFixed in: 0.35.0\nSeverity: HIGH\nFix: Upgrade sharp to 0.35.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b284b438af2d83f7", "name": "CVE-2026-25990: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-25990: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image\n\nPillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.\n\nPackage: Pillow\nInstalled: 11.0.0\nFixed in: 12.1.1\nSeverity: HIGH\nFix: Upgrade Pillow to 12.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0b68eabc267cb64f", "name": "CVE-2026-40192: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-40192: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing\n\nPillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.\n\nPackage: Pillow\nInstalled: 11.0.0\nFixed in: 12.2.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-99042a9b27c1b0d9", "name": "CVE-2026-42311: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-42311: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing\n\nPillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.\n\nPackage: Pillow\nInstalled: 11.0.0\nFixed in: 12.2.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-384f85180eb38b8f", "name": "CVE-2026-54058: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-54058: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image\n\nPillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 11.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8828c24d1ce23950", "name": "CVE-2026-54059: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-54059: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted PCF font data\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 11.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5d8eba57144e1df9", "name": "CVE-2026-54060: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-54060: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(\"1\", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 11.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5c8821e7d78f3cad", "name": "CVE-2026-55379: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-55379: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted BDF font file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 11.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4374165d8ee4d2b2", "name": "CVE-2026-55380: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-55380: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted GD 2.x image file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 11.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c18844ba62ec8581", "name": "CVE-2026-59197: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-59197: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Native heap out-of-bounds write\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 11.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ee9cc4e961429b59", "name": "CVE-2026-59199: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-59199: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via out-of-bounds write in image processing\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 11.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4d7f4c1d3d9287a3", "name": "CVE-2026-59200: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-59200: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of service via crafted PDF stream\n\nPillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 11.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3e31950c41a31c57", "name": "CVE-2026-59204: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-59204: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via crafted JPEG2000 image\n\nPillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 11.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ae98da7bfccf9262", "name": "CVE-2026-59205: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-59205: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 11.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c29d3f28ae4d6786", "name": "CVE-2026-42308: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-42308: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "Pillow: python: Pillow: Denial of Service via integer overflow in font processing\n\nPillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.\n\nPackage: Pillow\nInstalled: 11.0.0\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade Pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9a548f2db0e7e2e", "name": "CVE-2026-42310: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-42310: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via malicious PDF processing\n\nPillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.\n\nPackage: Pillow\nInstalled: 11.0.0\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade Pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4d40d6ebb4f42e24", "name": "CVE-2026-55798: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-55798: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Arbitrary command injection via shell metacharacters in file paths\n\nPillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 11.0.0\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-48aed6213adcd445", "name": "CVE-2026-59198: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirement", "shortDescription": {"text": "CVE-2026-59198: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Information disclosure via TGA RLE encoder out-of-bounds read\n\nPillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 11.0.0\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-90a869230c010e8e", "name": "CVE-2026-33682: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirem", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.41.1\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3f96abcaed2b1d79", "name": "CVE-2026-10804: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirem", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.41.1\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ec4723df0a71f7d3", "name": "CVE-2025-23042: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt", "shortDescription": {"text": "CVE-2025-23042: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "fullDescription": {"text": "Gradio Blocked Path ACL Bypass Vulnerability\n\nGradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Gradio's Access Control List (ACL) for file paths can be bypassed by altering the letter case of a blocked file or directory path. This vulnerability arises due to the lack of case normalization in the file path validation logic. On case-insensitive file systems, such as those used by Windows and macOS, this flaw enables attackers to \n\nPackage: gradio\nInstalled: 5.9.1\nFixed in: 5.11.0\nSeverity: CRITICAL\nFix: Upgrade gradio to 5.11.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-dd5afac30f18a0a8", "name": "CVE-2024-8966: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt", "shortDescription": {"text": "CVE-2024-8966: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "fullDescription": {"text": "Gradio DOS in multipart boundry while uploading the file\n\nA vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Service (DoS) attack. An attacker can append a large number of characters to the end of a multipart boundary, causing the system to continuously process each character and issue warnings. This can render Gradio inaccessible for extended periods, disrupting services and causing significant downtime.\n\nPackage: gradio\nInstalled: 5.9.1\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9a1619d7cf7d2deb", "name": "CVE-2026-28414: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-28414: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "fullDescription": {"text": "Gradio is Vulnerable to Absolute Path Traversal on Windows with Python 3.13+\n\nGradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path traversal issue that enables unauthenticated attackers to read arbitrary files from the file system. Python 3.13+ changed the definition of `os.path.isabs` so that root-relative paths like `/windows/win.ini` on Windows are no longer considered absolute paths, resulting in a vulnerability in Gradio's logic for joining path\n\nPackage: gradio\nInstalled: 5.9.1\nFixed in: 6.7.0\nSeverity: HIGH\nFix: Upgrade gradio to 6.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d48fe973b4124192", "name": "CVE-2026-28416: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-28416: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "fullDescription": {"text": "Gradio: Gradio: Server-Side Request Forgery allows access to internal services via malicious Space loading\n\nGradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to make arbitrary HTTP requests from a victim's server by hosting a malicious Gradio Space. When a victim application uses `gr.load()` to load an attacker-controlled Space, the malicious `proxy_url` from the config is trusted and added to the allowlist, enabling the attacker to access internal services, cloud metadata endp\n\nPackage: gradio\nInstalled: 5.9.1\nFixed in: 6.6.0\nSeverity: HIGH\nFix: Upgrade gradio to 6.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ebfdb5ace0ed16ed", "name": "CVE-2026-48545: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-48545: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "fullDescription": {"text": "Gradio contains a cookie injection vulnerability\n\nGradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client used across all users in the reverse proxy endpoint. Attackers controlling any HF Space can return a parent-domain cookie that the shared client stores and automatically replays into all subsequent proxy requests to other legitimate Spaces, affecting all users of the same Gradio deployment.\n\nPackage: gradio\nInstalled: 5.9.1\nFixed in: 6.15.0\nSeverity: HIGH\nFix: Upgrade gradio to 6.15.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bef903ecddb7b7df", "name": "CVE-2025-48889: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt", "shortDescription": {"text": "CVE-2025-48889: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "fullDescription": {"text": "Gradio Allows Unauthorized File Copy via Path Manipulation\n\nGradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Prior to version 5.31.0, an arbitrary file copy vulnerability in Gradio's flagging feature allows unauthenticated attackers to copy any readable file from the server's filesystem. While attackers can't read these copied files, they can cause DoS by copying large files (like /dev/urandom) to fill disk space. This issue has been patched\n\nPackage: gradio\nInstalled: 5.9.1\nFixed in: 5.31.0\nSeverity: MEDIUM\nFix: Upgrade gradio to 5.31.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-819b8680765bfbdc", "name": "CVE-2026-28415: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-28415: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "fullDescription": {"text": "Gradio: Gradio: Open Redirect vulnerability allows redirection to arbitrary external URLs.\n\nGradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target() function in Gradio's OAuth flow accepts an unvalidated _target_url query parameter, allowing redirection to arbitrary external URLs. This affects the /logout and /login/callback endpoints on Gradio apps with OAuth enabled (i.e. apps running on Hugging Face Spaces with gr.LoginButton). Starting in version 6.6.0, the _target_url parameter is sanitized to only use the path, quer\n\nPackage: gradio\nInstalled: 5.9.1\nFixed in: 6.6.0\nSeverity: MEDIUM\nFix: Upgrade gradio to 6.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a473ea2ac3f4f18c", "name": "CVE-2025-5320: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt", "shortDescription": {"text": "CVE-2025-5320: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "fullDescription": {"text": "Gradio CORS Origin Validation Bypass Vulnerability\n\nA vulnerability classified as problematic has been found in gradio-app gradio up to 5.29.1. This affects the function is_valid_origin of the component CORS Handler. The manipulation of the argument localhost_aliases leads to erweiterte Rechte. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but d\n\nPackage: gradio\nInstalled: 5.9.1\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-83c4c67c8c0d0437", "name": "CVE-2026-10783: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-10783: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "fullDescription": {"text": "Gradio: Audio cache key ignores metadata when saving numpy audio outputs\n\nA security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the component Audio Cache Key Handler. Performing a manipulation results in use of weak hash. The attack must be initiated from a local position. The attack is considered to have high complexity. It is indicated that the exploitability is difficult. The exploit has been released to the public and may be used for attacks. The patch is named 13394. To fix this issue, it is recommended \n\nPackage: gradio\nInstalled: 5.9.1\nFixed in: 6.15.1\nSeverity: LOW\nFix: Upgrade gradio to 6.15.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-751f7ab8a91586fa", "name": "CVE-2026-27167: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-27167: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "fullDescription": {"text": "Gradio: Gradio: Information disclosure due to hardcoded secret in session cookie signing, allowing remote attackers to steal Hugging Face tokens.\n\nGradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically enable \"mocked\" OAuth routes when OAuth components (e.g. `gr.LoginButton`) are used. When a user visits `/login/huggingface`, the server retrieves its own Hugging Face access token via `huggingface_hub.get_token()` and stores it in the visitor's session cookie. If the application is network-accessib\n\nPackage: gradio\nInstalled: 5.9.1\nFixed in: 6.6.0\nSeverity: LOW\nFix: Upgrade gradio to 6.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-636187c0f2dcda4d", "name": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.17 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/front", "shortDescription": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.17 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue\n\nA vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.\n\nPackage: @ai-sdk/provider-utils\nInstalled: 3.0.17\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-db8c44758d337afe", "name": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/front", "shortDescription": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue\n\nA vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.\n\nPackage: @ai-sdk/provider-utils\nInstalled: 3.0.20\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c70f349c41aabbe4", "name": "CVE-2026-29087: @hono/node-server 1.19.9 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/", "shortDescription": {"text": "CVE-2026-29087: @hono/node-server 1.19.9 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware\n\n@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting /admin/*), inconsistent URL decoding can allow protected static resources to be accessed without authorization. In particular, paths containing encoded slashes (%2F) may be evaluated differently by routing/middleware matching versus static file path resolution, enabling a bypass where middl\n\nPackage: @hono/node-server\nInstalled: 1.19.9\nFixed in: 1.19.10\nSeverity: HIGH\nFix: Upgrade @hono/node-server to 1.19.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2a5531e0d3abcd42", "name": "CVE-2026-39406: @hono/node-server 1.19.9 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/", "shortDescription": {"text": "CVE-2026-39406: @hono/node-server 1.19.9 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "@hono/node-server: Middleware bypass via repeated slashes in serveStatic\n\n@hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware (e.g., /admin/*) is used for authorization, the router may not match paths containing repeated slashes, while serveStatic resolves them as normalized paths. This can lead to a middleware bypass. This vulnerability is fixed in 1.19.13.\n\nPackage: @hono/node-server\nInstalled: 1.19.9\nFixed in: 1.19.13\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 1.19.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-201838826ab72974", "name": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.9 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/fron", "shortDescription": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.9 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nThe same as the `hono` core [Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44).\n\n### Summary\n\nOn Windows hosts, an encoded backslash (`%5C`) in the request path decodes to `\\`, which the Windows path resolver treats as a separator. `serve-static` then resolves a single URL segment such as `admin\\secret.txt` into a nested file under the root and serves it, letting an attacker read static files meant t\n\nPackage: @hono/node-server\nInstalled: 1.19.9\nFixed in: 2.0.5\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 2.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3d3016100b5d0cf2", "name": "CVE-2025-69873: ajv 8.17.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.j", "shortDescription": {"text": "CVE-2025-69873: ajv 8.17.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "ajv: ReDoS via $data reference\n\najv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., \"^(a|a)*$\") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds\n\nPackage: ajv\nInstalled: 8.17.1\nFixed in: 8.18.0, 6.14.0\nSeverity: MEDIUM\nFix: Upgrade ajv to 8.18.0, 6.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5722e3250ec31f53", "name": "CVE-2026-12590: body-parser 1.20.4 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/packag", "shortDescription": {"text": "CVE-2026-12590: body-parser 1.20.4 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 1.20.4\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0b9ac68b40cdbc89", "name": "CVE-2026-12590: body-parser 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package", "shortDescription": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 2.2.2\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-12f16d87e7f39415", "name": "CVE-2026-0540: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lo", "shortDescription": {"text": "CVE-2026-0540: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "DOMPurify: DOMPurify: Cross-site scripting vulnerability\n\nDOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like </noscript><img src=x onerror=alert(1)> in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2, 2.5.9\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2, 2.5.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-06a6e51816e1a362", "name": "CVE-2026-41238: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-l", "shortDescription": {"text": "CVE-2026-41238: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "DOMPurify: DOMPurify: Cross-Site Scripting bypass via prototype pollution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (no `CUSTOM_ELEMENT_HANDLING` option), a prior prototype pollution gadget can inject permissive `tagNameCheck` and `attributeNameCheck` regex values into `Object.prototype`, causing DOMPurify to allow arbitrary custom elements with arbitrary attributes\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b3d89cfefd72ce42", "name": "CVE-2026-41239: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-l", "shortDescription": {"text": "CVE-2026-41239: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Vue 2: DOMPurify: Cross-site scripting due to incomplete sanitization of template expressions\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS via template-evaluating frameworks like Vue 2. Version 3.4.0 patches the issue.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6f9980c5aa6a9092", "name": "CVE-2026-41240: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-l", "shortDescription": {"text": "CVE-2026-41240: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TAGS is used. Commit c361baa added an early exit for FORBID_ATTR at line 1214. The same fix was not applied to FORBID_TAGS. At line 1118-1123, when EXTRA_ELEMENT_HANDLING.tagCheck returns true, the short-circuit evaluation skips the FORBID_TAGS check entirely. This allows forbidden elements to survive \n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-80cc29f5676ba1fb", "name": "CVE-2026-49458: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-l", "shortDescription": {"text": "CVE-2026-49458: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting due to improper sanitization of DOM nodes\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks used parent-realm constructors, causing instanceof checks for forms, named node maps, document fragments, and elements to fail and skip clobber, template-content, and shadow-DOM sanitization branches so executable markup could survive. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-946fdac9bca2346e", "name": "CVE-2026-49459: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-l", "shortDescription": {"text": "CVE-2026-49459: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting bypass allows arbitrary script execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dc8dd834ff2dadd5", "name": "CVE-2026-49978: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-l", "shortDescription": {"text": "CVE-2026-49978: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dee754c5def4efbe", "name": "GHSA-39q2-94rc-95cp: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/pack", "shortDescription": {"text": "GHSA-39q2-94rc-95cp: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation\n\n## Summary\nIn `src/purify.ts:1117-1123`, `ADD_TAGS` as a function (via `EXTRA_ELEMENT_HANDLING.tagCheck`) bypasses `FORBID_TAGS` due to short-circuit evaluation.\n\nThe condition:\n```\n!(tagCheck(tagName)) && (!ALLOWED_TAGS[tagName] || FORBID_TAGS[tagName])\n```\nWhen `tagCheck(tagName)` returns `true`, the entire condition is `false` and the element is kept \u2014 `FORBID_TAGS[tagName]` is never evaluated.\n\n## Inconsistency\nThis contradicts the attribute-side pattern at line 1214 where `FORBID_ATTR` expl\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5ca2b63bacfeb4c4", "name": "GHSA-76mc-f452-cxcm: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/pack", "shortDescription": {"text": "GHSA-76mc-f452-cxcm: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\n# Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\n**CWE**: CWE-501 (Trust Boundary Violation \u2014 hook-scoped mutation leaks to global default sets) via CWE-693 (Protection Mechanism Failure \u2014 the default allow-list is silently widened for all subsequent sanitize calls)\n\n## Summary\n\nThe `data.allowedTags` and `data.allowedAttributes` fields passed to `uponSanitizeElement` and `uponSanitizeAttribute` hooks are **dir\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-672c6cb2ba190925", "name": "GHSA-cj63-jhhr-wcxv: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/pack", "shortDescription": {"text": "GHSA-cj63-jhhr-wcxv: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "DOMPurify USE_PROFILES prototype pollution allows event handlers\n\n## Summary\nWhen `USE_PROFILES` is enabled, DOMPurify rebuilds `ALLOWED_ATTR` as a plain array before populating it with the requested allowlists. Because the sanitizer still looks up attributes via `ALLOWED_ATTR[lcName]`, any `Array.prototype` property that is polluted also counts as an allowlisted attribute. An attacker who can set `Array.prototype.onclick = true` (or a runtime already subject to prototype pollution) can thus force DOMPurify to keep event handlers such as `onclick` even when th\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-91590914d91aaa5f", "name": "GHSA-cjmm-f4jc-qw8r: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/pack", "shortDescription": {"text": "GHSA-cjmm-f4jc-qw8r: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "DOMPurify ADD_ATTR predicate skips URI validation\n\n## Summary\nDOMPurify allows `ADD_ATTR` to be provided as a predicate function via `EXTRA_ELEMENT_HANDLING.attributeCheck`. When the predicate returns `true`, `_isValidAttribute` short-circuits the attribute check before URI-safe validation runs. An attacker who supplies a predicate that accepts specific attribute/tag combinations can then sanitize input such as `<a href=\"javascript:alert(document.domain)\">` and have the `javascript:` URL survive, because URI validation is skipped for that attrib\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1f6f3b64bb7a5cf3", "name": "GHSA-cmwh-pvxp-8882: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/pack", "shortDescription": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)\n\n## Summary\n\nDOMPurify 3.4.7 shipped a security fix (\"permanent hook pollution\") that makes a registered `uponSanitizeAttribute` hook's mutation of `data.allowedAttributes` **non-persistent** \u2014 so allowing an attribute for one element does not leak into later `sanitize()` calls. The fix clones `ALLOWED_ATTR` inside `_parseConfig`.\n\nThat guard is **silently bypassed whenever the application uses the persistent-config API `DOMPurify.setConfig()`.** `setConfig()` sets the module flag `SET_CONFIG = t\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.11\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a7617ec97280f293", "name": "GHSA-h8r8-wccr-v5f2: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/pack", "shortDescription": {"text": "GHSA-h8r8-wccr-v5f2: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "DOMPurify is vulnerable to mutation-XSS via Re-Contextualization \n\n## Description\n\nA mutation-XSS (mXSS) condition was confirmed when sanitized HTML is reinserted into a new parsing context using `innerHTML` and special wrappers. The vulnerable wrappers confirmed in browser behavior are `script`, `xmp`, `iframe`, `noembed`, `noframes`, and `noscript`. The payload remains seemingly benign after `DOMPurify.sanitize()`, but mutates during the second parse into executable markup with an event handler, enabling JavaScript execution in the client (`alert(1)` in the P\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b90b5d43abc83696", "name": "GHSA-c2j3-45gr-mqc4: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/pack", "shortDescription": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.\n\n## Summary\n\nThere is a possible hook-policy inconsistency in DOMPurify 3.4.11 involving `CUSTOM_ELEMENT_HANDLING`.\n\nWhen a custom element is allowed via `CUSTOM_ELEMENT_HANDLING.tagNameCheck`, it appears that the element does not go through `afterSanitizeElements` in the same way as a normal element. As a result, an application that relies on `afterSanitizeElements` as a security policy layer to strip sensitive attributes from all elements may see those attributes removed from normal elements bu\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.12\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-59d9b4dcd9bdde4d", "name": "GHSA-gvmj-g25r-r7wr: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/pack", "shortDescription": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes\n\n## Summary\n\nWhen DOMPurify is configured with both `SAFE_FOR_TEMPLATES: true` and `RETURN_DOM: true` (or `IN_PLACE: true`), an attacker can inject template expressions, such as `${evil}`, `{{evil}}`, or `<%evil%>`, that survive the sanitization pass inside `<template>` element content. This bypasses the explicit purpose of `SAFE_FOR_TEMPLATES`, which is to prevent template engine evaluation of user-supplied content.\n\n> **Note:** The string output path is **not** affected. Only the DOM return pat\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.8\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-78a7a9ad120cceda", "name": "GHSA-vxr8-fq34-vvx9: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/pack", "shortDescription": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output\n\n## Impact\n\nA DOMPurify instance that is reused across trust boundaries can stay bound to a previously supplied `TRUSTED_TYPES_POLICY` even after `clearConfig()` is called. A later caller that requests `RETURN_TRUSTED_TYPE` receives a `TrustedHTML` object created by the old policy, not by a clean default configuration.\n\nIf the old policy is unsafe or controlled by a less-trusted integration, this turns a later \"default\" sanitize call into script execution at a Trusted Types sink. `TRUSTED_TYPES_P\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.9\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-51c5a14152f1f386", "name": "GHSA-x4vx-rjvf-j5p4: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/pack", "shortDescription": {"text": "GHSA-x4vx-rjvf-j5p4: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects\n\n## Summary\n\nWhen `DOMPurify.sanitize(root, { IN_PLACE: true })` is called on an attacker-supplied live DOM node, `DOMPurify` still trusts `currentNode.nodeName` for non-`form` nodes in the main `_sanitizeElements` pipeline. A real `<script>` child node whose observable `nodeName` is attacker-controlled can therefore be misclassified as an allowed element and retained. When the sanitized tree is inserted into a live document, the script executes.\n\nThis affects current `3.4.6`. The recent `IN_PLAC\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-09a1ec27fbd0be31", "name": "CVE-2026-30827: express-rate-limit 8.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/", "shortDescription": {"text": "CVE-2026-30827: express-rate-limit 8.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "express-rate-limit: express-rate-limit: Denial of Service for IPv4 clients due to incorrect IPv6 subnet masking\n\nexpress-rate-limit is a basic rate-limiting middleware for Express. In versions starting from 8.0.0 and prior to versions 8.0.2, 8.1.1, 8.2.2, and 8.3.0, the default keyGenerator in express-rate-limit applies IPv6 subnet masking (/56 by default) to all addresses that net.isIPv6() returns true for. This includes IPv4-mapped IPv6 addresses (::ffff:x.x.x.x), which Node.js returns as request.ip on dual-stack servers. Because the first 80 bits of all IPv4-mapped addresses are zero, a /56 (or any /32 \n\nPackage: express-rate-limit\nInstalled: 8.2.1\nFixed in: 8.2.2, 8.1.1, 8.0.2\nSeverity: HIGH\nFix: Upgrade express-rate-limit to 8.2.2, 8.1.1, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4700b2ac38538a67", "name": "CVE-2026-13676: fast-uri 3.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lo", "shortDescription": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization\n\nfast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 4.0.1, 3.1.3, 2.4.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 4.0.1, 3.1.3, 2.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2b8ad42d65df83fa", "name": "CVE-2026-16221: fast-uri 3.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lo", "shortDescription": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...\n\nImpact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 2.4.3, 3.1.4, 4.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 2.4.3, 3.1.4, 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-64abaa25a1a452ee", "name": "CVE-2026-6321: fast-uri 3.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-loc", "shortDescription": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies\n\nfast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Version\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e138671ae9eb6f45", "name": "CVE-2026-6322: fast-uri 3.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-loc", "shortDescription": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: URI authority bypass due to improper delimiter handling\n\nfast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a differ\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f1dbced56b9c6cb6", "name": "CVE-2026-12143: form-data 4.0.5 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-l", "shortDescription": {"text": "CVE-2026-12143: form-data 4.0.5 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "form-data: form-data: Form field override via CRLF injection\n\nform-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (\") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the atta\n\nPackage: form-data\nInstalled: 4.0.5\nFixed in: 2.5.6, 3.0.5, 4.0.6\nSeverity: HIGH\nFix: Upgrade form-data to 2.5.6, 3.0.5, 4.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e578bbc6dd70f8c0", "name": "CVE-2026-29045: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-29045: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono vulnerable to arbitrary file access via serveStatic vulnerability \n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/admin/*', ...)), inconsistent URL decoding allowed protected static resources to be accessed without authorization. The router used decodeURI, while serveStatic used decodeURIComponent. This mismatch allowed paths containing encoded slashes (%2F) to bypass middleware protections while still resolving\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.4\nSeverity: HIGH\nFix: Upgrade hono to 4.12.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-558ec2e5fbb3503e", "name": "CVE-2026-54290: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-54290: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials: true and no explicit origin (the default wildcard), the CORS Middleware reflects the request's Origin and sends Access-Control-Allow-Credentials: true. Any site can then make credentialed cross-origin requests and read the responses, exposing cookie-authenticated endpoints to arbitrary origins. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.25\nSeverity: HIGH\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5cb6621a27615a2a", "name": "CVE-2026-29085: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-29085: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming Helper, the event, id, and retry fields were not validated for carriage return (\\r) or newline (\\n) characters. Because the SSE protocol uses line breaks as field delimiters, this could allow injection of additional SSE fields within the same event frame if untrusted input was passed into these fields. This issue has been patched in version 4.12.4.\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.4\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a44845fcb3d08791", "name": "CVE-2026-29086: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-29086: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, the setCookie() utility did not validate semicolons (;), carriage returns (\\r), or newline characters (\\n) in the domain and path options when constructing the Set-Cookie header. Because cookie attributes are delimited by semicolons, this could allow injection of additional cookie attributes if untrusted input was passed into these fields. This issue has been patched in version 4.12.4.\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.4\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-649fc7533507f3a8", "name": "CVE-2026-39407: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-39407: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono: Middleware bypass via repeated slashes in serveStatic\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware (e.g., /admin/*) is used for authorization, the router may not match paths containing repeated slashes, while serveStatic resolves them as normalized paths. This can lead to a middleware bypass. This vulnerability is fixed in \n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b8d5ea5de13c20f6", "name": "CVE-2026-39408: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-39408: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono: Path traversal in toSSG() allows writing files outside the output directory\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to be written outside the configured output directory during static site generation. When using dynamic route parameters via ssgParams, specially crafted values can cause generated file paths to escape the intended output directory. This vulnerability is fixed in 4.12.12.\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-78bd25e4cf84f806", "name": "CVE-2026-39409: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-39409: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-mapped IPv6 client addresses (e.g. ::ffff:127.0.0.1) before applying IPv4 allow or deny rules. In environments such as Node.js dual-stack, this can cause IPv4 rules to fail to match, leading to unintended authorization behavior. This vulnerability is fixed in 4.12.12.\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-143775611dddfbb9", "name": "CVE-2026-39410: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-39410: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono: Non-breaking space prefix bypass in cookie name handling in getCookie()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy between browser cookie parsing and parse() handling allows cookie prefix protections to be bypassed. Cookie names that are treated as distinct by the browser may be normalized to the same key by parse(), allowing attacker-controlled cookies to override legitimate ones. This vulnerability is fixed in 4.12.12.\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fd4e91b72bbdc3ea", "name": "CVE-2026-44455: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-44455: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handling of JSX element tag names in hono/jsx allowed unvalidated tag names to be directly inserted into the generated HTML output. When untrusted input is used as a tag name via the programmatic jsx() or createElement() APIs during server-side rendering, specially crafted values may break out of the intended element context and inject unintended HTML. This vulnerability is fixed in 4\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.16\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aa3ba9fed688dfb9", "name": "CVE-2026-44456: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-44456: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono: bodyLimit() can be bypassed for chunked / unknown-length requests\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize for requests without a usable Content-Length (e.g. Transfer-Encoding: chunked). Oversized requests can reach handlers and return 200 instead of 413. This vulnerability is fixed in 4.12.16.\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.16\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-98a698dfabb82853", "name": "CVE-2026-44457: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-44457: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for responses that declare per-user variance via Vary: Authorization or Vary: Cookie. As a result, a response cached for one authenticated user may be served to subsequent requests from different users. This vulnerability is fixed in 4.12.18.\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.18\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-65d222a1f0af4579", "name": "CVE-2026-44458: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-44458: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono has CSS Declaration Injection via Style Object Values in JSX SSR\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer escapes style attribute object values for HTML but not for CSS. Untrusted input in a style object value or property name can therefore inject additional CSS declarations into the rendered style attribute. The impact is limited to CSS and does not allow JavaScript execution or HTML attribute breakout. This vulnerability is fixed in 4.12.18.\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.18\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dbdf701762255f5c", "name": "CVE-2026-47673: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-47673: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono: JWT middleware accepts any Authorization scheme, not only Bearer\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that the Authorization header value uses theBearer scheme. Any two-part header value \u2014 regardless of the scheme name in the first position \u2014 proceeds to JWT verification. A request presenting a valid JWT under a non-Bearer scheme identifier (such as Basic or Token) is authenticated identically to a correctly formed Bearer request. This vulnerability is\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bd9a14f41c388060", "name": "CVE-2026-47674: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-47674: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 \n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against configured deny and allow rules using string equality after partial normalization. Non-canonical IPv6 representations of an address already listed in a static rule \u2014 such as compressed forms, explicit-zero forms, or hex-notation IPv4-mapped addresses \u2014 do not match the normalized rule entry, causing the \n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-564efecff5e6a8af", "name": "CVE-2026-47675: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-47675: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters that corrupt Set-Cookie header syntax (;, \\r, \\n), but does not apply the same validation to sameSite and priority. An application that passes user-controlled input into either option may produce a Set-Cookie response header containing attacker-chosen additional attributes. This vulnerability is fixed \n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6f6e620af582b36a", "name": "CVE-2026-47676: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-47676: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request path using the raw URL pathname, while route matching is performed against the percent-decoded path. This inconsistency causes the prefix to be stripped at the wrong position when the path contains percent-encoded multi-byte characters, resulting in the mounted sub-application receiving an incorrect path. This vulnerability is fixed\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e9d6fb809fc0ed9a", "name": "CVE-2026-54286: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-54286: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \\, which the Windows path resolver treats as a separator. serve-static then resolves a single URL segment such as admin\\secret.txt into a nested file under the root and serves it, letting an attacker read static files meant to be protected behind prefix-mounted middleware. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6eeceb13118d32b5", "name": "CVE-2026-54287: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-54287: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, the ALB single-header response and the VPC Lattice v2 response join multiple Set-Cookie headers into one comma-separated value. Because commas also appear inside cookie attributes (for example Expires dates), clients cannot split the value back into individual cookies and silently drop or misparse them. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3423605970184af7", "name": "CVE-2026-54288: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-54288: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit Middleware trusts the request's Content-Length header to decide whether a body is within the limit. On AWS Lambda (API Gateway v1/v2, ALB, VPC Lattice, and Lambda@Edge) the body is delivered fully buffered and the adapter builds the request with the client-declared Content-Length, which need not match the actual payload. A client can declare a tiny Content-Length while sending a\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1846d0a1eb32b0a5", "name": "CVE-2026-54289: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-54289: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Edge, CloudFront delivers a request header that appears more than once as several separate entries. The adapter writes each value with Headers.set instead of Headers.append, so every value overwrites the previous one and only the last reaches the application. Repeated request headers such as X-Forwarded-For, Forwarded, and Via are silently truncated to a single value. Request mid\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8b266f72c6094302", "name": "CVE-2026-56761: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-56761: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR\n\nhono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers can craft specially crafted attribute keys containing characters like quotes or angle brackets to break html tag boundaries and inject arbitrary attributes or elements.\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.14\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-538b6db3ba39304c", "name": "CVE-2026-59895: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-59895: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-39ffc16de1c2d93d", "name": "CVE-2026-59897: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-59897: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete X-Forwarded-For chain, rate limiting, audit logging, or proxy-chain validation can receive incomplete data. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f1011ebab4706351", "name": "GHSA-26pp-8wgv-hjvm: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-", "shortDescription": {"text": "GHSA-26pp-8wgv-hjvm: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono missing validation of cookie name on write path in setCookie()\n\n## Summary\n\nCookie names are not validated on the write path when using `setCookie()`, `serialize()`, or `serializeSigned()` to generate Set-Cookie headers.\n\nWhile certain cookie attributes such as domain and path are validated, the cookie name itself may contain invalid characters.\n\nThis results in inconsistent handling of cookie names between parsing (read path) and serialization (write path).\n\n## Details\n\nWhen applications use `setCookie()`, `serialize()`, or `serializeSigned()` with a user-c\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8d2953e43796d98b", "name": "GHSA-v8w9-8mx6-g223: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-", "shortDescription": {"text": "GHSA-v8w9-8mx6-g223: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })\n\n## Summary\n\nWhen using `parseBody({ dot: true })` in HonoRequest, specially crafted form field names such as `__proto__.x` could create objects containing a `__proto__` property.\n\nIf the parsed result is later merged into regular JavaScript objects using unsafe merge patterns, this may lead to prototype pollution in the target object.\n\n## Details\n\nThe `parseBody({ dot: true })` feature supports dot notation to construct nested objects from form field names.\n\nIn previous versions, the `__proto__`\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.7\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f207eb2e4f4fd17e", "name": "CVE-2026-44459: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-44459: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validation of the JWT NumericDate claims exp, nbf, and iat in hono/utils/jwt allows tokens with non-spec-compliant claim values to silently bypass time-based checks. This issue is not exploitable by an anonymous attacker; it only manifests when a malformed claim value reaches verify() \u2014 typically when the application itself issues such tokens, or when the signing key is otherwise unde\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.12.18\nSeverity: LOW\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a2ebcc4490c9637c", "name": "GHSA-gq3j-xvxp-8hrf: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-", "shortDescription": {"text": "GHSA-gq3j-xvxp-8hrf: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Hono added timing comparison hardening in basicAuth and bearerAuth\n\n## Summary\n\nThe `basicAuth` and `bearerAuth` middlewares previously used a comparison that was not fully timing-safe.\n\nThe `timingSafeEqual` function used normal string equality (`===`) when comparing hash values. This comparison may stop early if values differ, which can theoretically cause small timing differences.\n\nThe implementation has been updated to use a safer comparison method.\n\n\n## Details\n\nThe issue was caused by the use of normal string equality (`===`) when comparing hash values ins\n\nPackage: hono\nInstalled: 4.11.7\nFixed in: 4.11.10\nSeverity: LOW\nFix: Upgrade hono to 4.11.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e8860a21d7738ee4", "name": "CVE-2026-42338: ip-address 10.0.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package", "shortDescription": {"text": "CVE-2026-42338: ip-address 10.0.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input\n\nip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods,\n\nPackage: ip-address\nInstalled: 10.0.1\nFixed in: 10.1.1\nSeverity: MEDIUM\nFix: Upgrade ip-address to 10.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8903203942e78afd", "name": "CVE-2026-45134: langsmith 0.3.87 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-", "shortDescription": {"text": "CVE-2026-45134: langsmith 0.3.87 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest\n\nPackage: langsmith\nInstalled: 0.3.87\nFixed in: 0.6.0\nSeverity: HIGH\nFix: Upgrade langsmith to 0.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2b54cba2c19863ec", "name": "CVE-2026-25528: langsmith 0.3.87 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-", "shortDescription": {"text": "CVE-2026-25528: langsmith 0.3.87 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing feature is vulnerable to Server-Side Request Forgery via malicious HTTP headers. An attacker can inject arbitrary api_url values through the baggage header, causing the SDK to exfiltrate sensitive trace data to attacker-controlled endpoints. When using distributed tracing, the SDK parses incoming HTTP headers via RunTree.from_headers() in Python or RunTree.fromHeaders() in Typ\n\nPackage: langsmith\nInstalled: 0.3.87\nFixed in: 0.4.6\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0cecc4d2d7ab9ebb", "name": "CVE-2026-40190: langsmith 0.3.87 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-", "shortDescription": {"text": "CVE-2026-40190: langsmith 0.3.87 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() utility. The baseAssignValue() function only guards against the __proto__ key, but fails to prevent traversal via constructor.prototype. This allows an attacker who controls keys in data processed by the createAnonymizer() API to pollute Object.prototype, affecti\n\nPackage: langsmith\nInstalled: 0.3.87\nFixed in: 0.5.18\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.5.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6af4ca37c5b3264c", "name": "CVE-2026-41182: langsmith 0.3.87 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-", "shortDescription": {"text": "CVE-2026-41182: langsmith 0.3.87 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "LangSmith SDK: Streaming token events bypass output redaction\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces streaming output, each chunk is recorded as a new_token event containing the raw token value. These events bypass the redaction pipeline entirely \u2014 prepareRunCreateOrUpdateInputs (\n\nPackage: langsmith\nInstalled: 0.3.87\nFixed in: 0.5.19\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.5.19"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1c215766c6e5ed64", "name": "CVE-2026-45134: langsmith 0.4.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-", "shortDescription": {"text": "CVE-2026-45134: langsmith 0.4.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest\n\nPackage: langsmith\nInstalled: 0.4.12\nFixed in: 0.6.0\nSeverity: HIGH\nFix: Upgrade langsmith to 0.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ce89f4499f7a5149", "name": "CVE-2026-40190: langsmith 0.4.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-", "shortDescription": {"text": "CVE-2026-40190: langsmith 0.4.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() utility. The baseAssignValue() function only guards against the __proto__ key, but fails to prevent traversal via constructor.prototype. This allows an attacker who controls keys in data processed by the createAnonymizer() API to pollute Object.prototype, affecti\n\nPackage: langsmith\nInstalled: 0.4.12\nFixed in: 0.5.18\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.5.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1e9cbaf34d8c8c24", "name": "CVE-2026-41182: langsmith 0.4.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-", "shortDescription": {"text": "CVE-2026-41182: langsmith 0.4.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "LangSmith SDK: Streaming token events bypass output redaction\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces streaming output, each chunk is recorded as a new_token event containing the raw token value. These events bypass the redaction pipeline entirely \u2014 prepareRunCreateOrUpdateInputs (\n\nPackage: langsmith\nInstalled: 0.4.12\nFixed in: 0.5.19\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.5.19"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3b03d9e9b7c8f7c3", "name": "CVE-2026-4800: lodash-es 4.17.21 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-", "shortDescription": {"text": "CVE-2026-4800: lodash-es 4.17.21 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-21ccd52ea6c0e24d", "name": "CVE-2025-13465: lodash-es 4.17.21 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package", "shortDescription": {"text": "CVE-2025-13465: lodash-es 4.17.21 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "lodash: prototype pollution in _.unset and _.omit functions\n\nLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset\u00a0and _.omit\u00a0functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.\n\nThe issue permits deletion of properties but does not allow overwriting their original behavior.\n\nThis issue is patched on 4.17.23\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.17.23\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.17.23"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4fdd70b4163141cf", "name": "CVE-2026-2950: lodash-es 4.17.21 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-", "shortDescription": {"text": "CVE-2026-2950: lodash-es 4.17.21 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e5650daced229e03", "name": "CVE-2026-4800: lodash-es 4.17.23 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-", "shortDescription": {"text": "CVE-2026-4800: lodash-es 4.17.23 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash-es\nInstalled: 4.17.23\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a8c97ccb937af6e3", "name": "CVE-2026-2950: lodash-es 4.17.23 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-", "shortDescription": {"text": "CVE-2026-2950: lodash-es 4.17.23 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash-es\nInstalled: 4.17.23\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-546576b656ca40e1", "name": "CVE-2026-41148: mermaid 11.12.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-l", "shortDescription": {"text": "CVE-2026-41148: mermaid 11.12.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: CSS injection vulnerability allows page defacement and information disclosure\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS injection through improper sanitization. The state diagram (and any other diagram type that routes user-controlled style strings through the createCssStyles parser) captures classDef values using an unrestricted regex that matches everything up to a newline. That value then flows unsanitized through \n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7333aee0dc0726d9", "name": "CVE-2026-41149: mermaid 11.12.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-l", "shortDescription": {"text": "CVE-2026-41149: mermaid 11.12.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: HTML injection via classDef directive in state diagrams\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configuration. Specifically, the classDef directive in Mermaid state diagrams permits DOM injection that escapes the SVG context. However, <script> tags are stripped, which prevents cross-site scripting (XSS). This issue has been fixed in versions 10.9.6 and 11.15.0. If de\n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fc1297f01e1e5536", "name": "CVE-2026-41150: mermaid 11.12.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-l", "shortDescription": {"text": "CVE-2026-41150: mermaid 11.12.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: Denial of Service via specially crafted gantt charts\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates. mermaid.parse is unaffected, unless you then call the ganttDb.getTasks() (which is called when rendering a diagram). This vulnerability is fixed in 10.9.6 and 11.15.0.\n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c5b2560b3eed31e4", "name": "CVE-2026-41159: mermaid 11.12.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-l", "shortDescription": {"text": "CVE-2026-41159: mermaid 11.12.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: Information disclosure and page defacement via CSS injection\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0,  Mermaid's default configuration allows injecting CSS that applies outside of the Mermaid diagram via the fontFamily, themeCSS, and altFontFamily configuration options. The injected CSS exploits stylis's & (scope reference) handling. :not(&) escapes the #mermaid-xxx automatic scoping, applying styles to all page elements. Global at-rules (@font-face, @keyframes, @c\n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6ba4a8936a687578", "name": "CVE-2026-44573: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-44573: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed data route, allowing an attacker to retrieve SSR JSON for protected pages without passing the intende\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-572c88e998ed2b6a", "name": "CVE-2026-44574: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-44574: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Authorization bypass via crafted query parameters\n\nNext.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check. This vulnerability is fixed in 1\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3c2407d45afe92c0", "name": "CVE-2026-44575: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-44575: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Unauthorized access to protected content via middleware bypass\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-59123f9faef96283", "name": "CVE-2026-44578: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-44578: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests\n\nNext.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-49a15067c230c5cd", "name": "CVE-2026-44579: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-44579: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service via crafted POST requests to server actions\n\nNext.js is a React framework for building full-stack web applications. From  to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open for an extended period, consuming file descriptors and server capacity until legitimate users are den\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-57055106f5091843", "name": "CVE-2026-45109: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-45109: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.18, 16.2.6\nSeverity: HIGH\nFix: Upgrade next to 15.5.18, 16.2.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-66def54f256524e7", "name": "CVE-2026-64641: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-64641: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Denial of Service in App Router using Server Actions\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.\n\n## Workarounds\n\nNo workaround exists besides upgrading. Applications using Pages Router or not using Server Actions are not vulnerable.\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7b0159511c88f106", "name": "CVE-2026-64645: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-64645: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\n## Impact\n\nA `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's\u00a0hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect.\n\nThis affects any destination that puts a dynamic segmen\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3939689077bb3d81", "name": "CVE-2026-64649: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-64649: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in Server Actions on custom servers\n\n## Impact\n\nWhen a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization.\n\nApplications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-18363ad3488d0594", "name": "GHSA-8h8q-6873-q5fj: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package", "shortDescription": {"text": "GHSA-8h8q-6873-q5fj: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js Vulnerable to Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh). \n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of \n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-70b5879c8780215d", "name": "GHSA-q4gf-8mx6-v5v3: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package", "shortDescription": {"text": "GHSA-q4gf-8mx6-v5v3: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js has a Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react/security/advisories/GHSA-479c-33wc-g2pg). You can read more about this advisory our [this changelog](https://vercel.com/changelog/summary-of-cve-2026-23869).\n\nA specially crafted HTTP request can be sent to any App Rout\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.15, 16.2.3\nSeverity: HIGH\nFix: Upgrade next to 15.5.15, 16.2.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1ad94e91d85cd2e8", "name": "CVE-2026-27980: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-27980: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Unbounded next/image disk cache growth can exhaust storage\n\nNext.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unbounded cache growth. An attacker could generate many unique image-optimization variants and exhaust disk space, causing denial of service. This is fixed in version 16.1.7 by adding an LRU-backed disk cache with `images.maximumDiskCacheSize`, including e\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 16.1.7, 15.5.14\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-60d90e42162542e1", "name": "CVE-2026-29057: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-29057: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: HTTP request smuggling in rewrites\n\nNext.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfer-Encoding: chunked` could trigger request boundary disagreement between the proxy and backend. This could allow request smuggling through rewritten routes. An attacker could smuggle a second request to unintended backend routes (for example, interna\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 16.1.7, 15.5.13\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a1fbef8ada1f4030", "name": "CVE-2026-44576: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-44576: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning vulnerability in React Server Components\n\nNext.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later visitors receive component payloads instead of the expected HTML. This vulnerability is fixed in 15.5\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-54e1c8df43a8b33e", "name": "CVE-2026-44577: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-44577: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Denial of Service via Image Optimization API\n\nNext.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the /_next/image endpoint that match the images.localPatterns configuration (by default, all patterns are allowed). This vulnerability\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4944832c1504511e", "name": "CVE-2026-44580: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-44580: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Cross-site scripting allows arbitrary code execution via untrusted script content\n\nNext.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to break out of the intended script context and execute arbitrary JavaScript in a visitor's browser. This vu\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d97017abc20d069e", "name": "CVE-2026-44581: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-44581: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Stored Cross-Site Scripting via malformed nonce values in cached responses\n\nNext.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to poison cached responses and cause script execution for later visitors. This vulnerability is fixed i\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7ea8f94cba2b99a3", "name": "CVE-2026-64643: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-64643: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Unauthenticated disclosure of internal Server Function endpoints\n\n## Impact\n\nIn Next.js applications using App Router, Server Actions (`use server`) or `use cache` endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used.\n\nServer Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references).\n\nAffected users are applications using App Router + Server Actions.  \n\nBy itself, this disclosure is typically a recon/enumeration primi\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3d594779be44f06e", "name": "CVE-2026-64644: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-64644: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Denial of Service in the Image Optimization API using SVGs\n\n### Impact\n\nWhen self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in  `/_next/image` endpoints.\n\n- If you are using `config.images.remotePatterns`, only the patterns in that array are impacted.\n- If you are using `config.images.unoptimized: true`, you are NOT impacted.\n- If you are using `config.images.loader: 'custom'`\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fcbf2122b30a6b33", "name": "CVE-2026-64646: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-64646: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Unbounded Server Action payload in Edge runtime\n\n## Impact\n\nRequests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime\n\n## Workarounds\n\nIf you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should be allowed at max by your hosting provider.\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1d5de215ac0caa59", "name": "CVE-2026-64647: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-64647: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for `\uc083\uc083` and `\uc104\uc104` in the request body would share the same cache.\n\n##\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-809deb7b5a65dd62", "name": "CVE-2026-64648: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-64648: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis only applies to `fetch` calls with a request that has a different init than the one passed to `fetch`.\nSafe: `fetch(new Request(init), init)`\nUnsafe: `fetch(new Request(init), aDifferentInit)`\n\n## Work\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28e95206c9eb0e5a", "name": "CVE-2026-44572: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-44572: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service due to improper handling of x-nextjs-data header with redirects\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When that happened, the middleware/proxy could treat the request as a data request and replace the standard Location redirect header with the internal x-nextjs-redirect header. Browsers do not follow x-nextjs-redirect, so the response became an unusable red\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f272bd5d444dcc95", "name": "CVE-2026-44582: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock", "shortDescription": {"text": "CVE-2026-44582: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning allows incorrect response delivery\n\nNext.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL. This vulnerability is fixed in 15.5.16 and 16.2.5.\n\nPackage: next\nInstalled: 15.5.12\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cae3aac321982f7c", "name": "CVE-2026-4867: path-to-regexp 0.1.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/pack", "shortDescription": {"text": "CVE-2026-4867: path-to-regexp 0.1.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters\n\nImpact:\n\nA bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c or /:a-:b-:c-:d. The backtrack protection added in path-to-regexp@0.1.12 only prevents ambiguity for two parameters. With three or more, the generated lookahead does not block single separator characters, so capture groups overlap and cause catastrophic backtracking.\n\nPatches:\n\nUpgrade to path-to-regexp@0.1.13\n\n\n\nPackage: path-to-regexp\nInstalled: 0.1.12\nFixed in: 0.1.13\nSeverity: HIGH\nFix: Upgrade path-to-regexp to 0.1.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-faaa24656d99af42", "name": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/packa", "shortDescription": {"text": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions\n\nImpact:\n\nA bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service.\n\nPatches:\n\nFixed in version 8.4.0.\n\nWorkarounds:\n\nLimit the number of sequential optional groups in route patterns. Avoid passing user-controlled input as route patterns.\n\nPackage: path-to-regexp\nInstalled: 8.3.0\nFixed in: 8.4.0\nSeverity: HIGH\nFix: Upgrade path-to-regexp to 8.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8a610f3bc8f5d389", "name": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/packa", "shortDescription": {"text": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via specially crafted paths with multiple wildcards\n\nImpact:\n\nWhen using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path.\n\nUnsafe examples:\n\n/*foo-*bar-:baz\n/*a-:b-*c-:d\n/x/*a-:b/*c/y\n\nSafe examples:\n\n/*foo-:bar\n/*foo-:bar-*baz\n\nPatches:\n\nUpgrade to version 8.4.0.\n\nWorkarounds:\n\nIf you are using multiple wildcard parameters, you can check the regex output with a too\n\nPackage: path-to-regexp\nInstalled: 8.3.0\nFixed in: 8.4.0\nSeverity: MEDIUM\nFix: Upgrade path-to-regexp to 8.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-93e571be4ac9192e", "name": "CVE-2026-41305: postcss 8.4.31 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lo", "shortDescription": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.4.31\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b504a83ffd8fe86a", "name": "CVE-2024-53382: prismjs 1.27.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lo", "shortDescription": {"text": "CVE-2024-53382: prismjs 1.27.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "prismjs: DOM Clobbering vulnerability within the Prism library's prism-autoloader plugin\n\nPrism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.\n\nPackage: prismjs\nInstalled: 1.27.0\nFixed in: 1.30.0\nSeverity: MEDIUM\nFix: Upgrade prismjs to 1.30.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3a5ef3d999d5f39c", "name": "CVE-2026-8723: qs 6.14.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.jso", "shortDescription": {"text": "CVE-2026-8723: qs 6.14.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "### Summary    `qs.stringify` throws `TypeError` when called with `arr ...\n\n### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti\n\nPackage: qs\nInstalled: 6.14.1\nFixed in: 6.15.2\nSeverity: MEDIUM\nFix: Upgrade qs to 6.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-200577ee81beacad", "name": "CVE-2026-2391: qs 6.14.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.jso", "shortDescription": {"text": "CVE-2026-2391: qs 6.14.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "qs: qs's arrayLimit bypass in comma parsing allows denial of service\n\n### Summary\nThe `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).\n\n### Details\nWhen the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?\n\nPackage: qs\nInstalled: 6.14.1\nFixed in: 6.14.2\nSeverity: LOW\nFix: Upgrade qs to 6.14.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-62072bb95abe2e48", "name": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package", "shortDescription": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591\n\n### Impact\n\nA number of vulnerabilities, two rated as \"High\" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency.\n\nThose processing untrusted input with versions of sharp prior to 0.35.0 are affected.\n\n### Patches\n\n#### Using prebuilt binaries provided by sharp?\n\nMost people rely on the prebuilt binaries provided by sharp.\n\nPlease upgrade sharp to the latest version, currently 0.35.3, which provides libvips 8.18.3.\n\n#### Using a globally-installed libvips?\n\nP\n\nPackage: sharp\nInstalled: 0.34.5\nFixed in: 0.35.0\nSeverity: HIGH\nFix: Upgrade sharp to 0.35.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-68c660fa1a677893", "name": "CVE-2026-12644: ts-deepmerge 7.0.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/packag", "shortDescription": {"text": "CVE-2026-12644: ts-deepmerge 7.0.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "ts-deepmerge: Prototype Method Override leads to DoS\n\nVersions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of built-in Object.prototype methods (such as toString, valueOf). When user-controlled input contains these keys with non-function values, the resulting merged object becomes broken \u2014 any string context operation throws a TypeError, crashing the application.\n\nPackage: ts-deepmerge\nInstalled: 7.0.3\nFixed in: 8.0.0\nSeverity: MEDIUM\nFix: Upgrade ts-deepmerge to 8.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-13571d85a3d33dd9", "name": "CVE-2026-41907: uuid 10.0.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-41907: uuid 10.0.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 10.0.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b7cca058a9d08df6", "name": "CVE-2026-41907: uuid 11.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.", "shortDescription": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 11.1.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c8d4c108cf54aa10", "name": "CVE-2026-41907: uuid 9.0.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.j", "shortDescription": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 9.0.1\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-42d70e9df5cf1203", "name": "CVE-2026-42215: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.t", "shortDescription": {"text": "CVE-2026-42215: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "GitPython is a python library used to interact with Git repositories.  ...\n\nGitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at it\n\nPackage: GitPython\nInstalled: 3.1.44\nFixed in: 3.1.47\nSeverity: HIGH\nFix: Upgrade GitPython to 3.1.47"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-64576949139b64ac", "name": "CVE-2026-42284: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.t", "shortDescription": {"text": "CVE-2026-42284: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "GitPython is a python library used to interact with Git repositories.  ...\n\nGitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(\" \".join(multi_options)). A string like \"--branch main --config core.hooksPath=/x\" passes validation (starts with --branch), but after split becomes [\"--branch\", \"main\", \"--config\", \"core.hooksPath=/x\"]. Git applies the config and executes attacker hooks during clone. This issue has been patched in version 3.1.47.\n\nPackage: GitPython\nInstalled: 3.1.44\nFixed in: 3.1.47\nSeverity: HIGH\nFix: Upgrade GitPython to 3.1.47"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b9d09896fc702722", "name": "CVE-2026-44243: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.t", "shortDescription": {"text": "CVE-2026-44243: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "GitPython: GitPython: Arbitrary file write via crafted reference paths\n\nGitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository\u2019s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.\n\nPackage: GitPython\nInstalled: 3.1.44\nFixed in: 3.1.48\nSeverity: HIGH\nFix: Upgrade GitPython to 3.1.48"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1e2c04be9c8b640c", "name": "CVE-2026-44244: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.t", "shortDescription": {"text": "CVE-2026-44244: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "GitPython is a python library used to interact with Git repositories.  ...\n\nGitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \\n becomes \\n\\t), but Git still accepts an indented [core] stanza as a section header \u2014 so the injected core.hooksPath becomes effective configuration. Any Git operation that invokes hooks (commit, merge, checkout)\n\nPackage: GitPython\nInstalled: 3.1.44\nFixed in: 3.1.49\nSeverity: HIGH\nFix: Upgrade GitPython to 3.1.49"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e8fda51dd3353d0c", "name": "GHSA-2f96-g7mh-g2hx: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requireme", "shortDescription": {"text": "GHSA-2f96-g7mh-g2hx: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist\n\n## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**CWE:** CWE-184 (Incomplete List of Disallowed Inputs) \u2192 CWE-78 (OS Command Injection)\n**Severity:** inherits the parent CVE-2026-42215 surface; estimated Hi\n\nPackage: GitPython\nInstalled: 3.1.44\nFixed in: 3.1.51\nSeverity: HIGH\nFix: Upgrade GitPython to 3.1.51"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ea1fdd012bbf8555", "name": "GHSA-956x-8gvw-wg5v: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requireme", "shortDescription": {"text": "GHSA-956x-8gvw-wg5v: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`\n\n## Summary\n\nGitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of \"unsafe\" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, \u2026) that can be abused to run arbitrary commands, and enforces them with `Git.check_unsafe_options()`.\n\nThat enforcement is only wired into the **network** commands \u2014 `clone_from`, `Remote.fetch`, `Remote.pull`, `Remote.push`. Several other p\n\nPackage: GitPython\nInstalled: 3.1.44\nFixed in: 3.1.51\nSeverity: HIGH\nFix: Upgrade GitPython to 3.1.51"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4c50187873096d50", "name": "GHSA-mv93-w799-cj2w: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requireme", "shortDescription": {"text": "GHSA-mv93-w799-cj2w: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath\n\nSummary\n\nThe patch for CVE-2026-42215 (GitPython 3.1.49) validates newlines only in the value parameter of set_value(). The section and option parameters are passed to configparser without any newline validation. An attacker who controls the section argument can inject \\n to write arbitrary section headers into .git/config, including a forged [core] section with hooksPath pointing to an attacker-controlled directory, leading to RCE when any git hook is triggered.\n\nDetails\n\nFile: git/config.py \u2014 \n\nPackage: GitPython\nInstalled: 3.1.44\nFixed in: 3.1.50\nSeverity: HIGH\nFix: Upgrade GitPython to 3.1.50"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bd525d32ce409f0e", "name": "GHSA-rwj8-pgh3-r573: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requireme", "shortDescription": {"text": "GHSA-rwj8-pgh3-r573: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL\n\n### Summary\n`Repo.clone_from()` passes the caller-supplied remote URL through `Git.polish_url()`, which on every non-Cygwin platform calls `os.path.expandvars()` on the URL before handing it to `git clone`. An attacker who controls the URL argument \u2014 the documented use case for `clone_from()` in \"import repository from URL\" features of CI servers, git-hosting mirrors, and dependency scanners \u2014 can embed `$NAME` / `${NAME}` tokens that are expanded server-side to the values of the hosting process\n\nPackage: GitPython\nInstalled: 3.1.44\nFixed in: 3.1.52\nSeverity: HIGH\nFix: Upgrade GitPython to 3.1.52"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-38e516be504806a3", "name": "CVE-2026-32597: PyJWT 2.9.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-32597: PyJWT 2.9.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 \u00a74.1.11 MUST violation)\n\nPyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 \u00a74.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.\n\nPackage: PyJWT\nInstalled: 2.9.0\nFixed in: 2.12.0\nSeverity: HIGH\nFix: Upgrade PyJWT to 2.12.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-282ad11b28f5348a", "name": "CVE-2026-48526: PyJWT 2.9.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-48526: PyJWT 2.9.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens\n\nPyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.\n\nPackage: PyJWT\nInstalled: 2.9.0\nFixed in: 2.13.0\nSeverity: HIGH\nFix: Upgrade PyJWT to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7c053f33dac36498", "name": "CVE-2026-48522: PyJWT 2.9.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-48522: PyJWT 2.9.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Server-Side Request Forgery (SSRF) via uncontrolled URL fetching in PyJWKClient\n\nPyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registering HTTPHandler, HTTPSHandler, FTPHandler, FileHandler, and DataHandler. There is currently no documented option to restrict which schemes PyJWKClient will fetch. If an application's jku URL ingestion path accepts attacker-influenced URLs (e.g., from JWT header, configuration file, OAuth flow parame\n\nPackage: PyJWT\nInstalled: 2.9.0\nFixed in: 2.13.0\nSeverity: MEDIUM\nFix: Upgrade PyJWT to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e4e189f23b847a5f", "name": "CVE-2026-48523: PyJWT 2.9.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-48523: PyJWT 2.9.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Verifier-side algorithm bypass leads to unauthorized information access\n\nPyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-supplied algorithms allow-list, but signature verification is performed with the algorithm bound to the PyJWK object instead of the header algorithm. An attacker who controls a registered JWK/JWKS private key can sign with a disallowed algorithm, adv\n\nPackage: PyJWT\nInstalled: 2.9.0\nFixed in: 2.13.0\nSeverity: MEDIUM\nFix: Upgrade PyJWT to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4b8b21124eb507d4", "name": "CVE-2026-48525: PyJWT 2.9.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-48525: PyJWT 2.9.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Denial of Service via processing of crafted detached JWS tokens\n\nPyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option (\"b64\": false, RFC 7797), PyJWT performs Base64URL decoding of the compact-serialization payload segment before enforcing the detached-payload rules. For b64=false, PyJWT later discards that decoded payload and replaces it with the caller-provided detached_payload. In practice, this turns the middle segment into an attacker-controlled \u201cwork amplifier\u201d: a\n\nPackage: PyJWT\nInstalled: 2.9.0\nFixed in: 2.13.0\nSeverity: MEDIUM\nFix: Upgrade PyJWT to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-651aa47f1fac0967", "name": "CVE-2026-48524: PyJWT 2.9.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-48524: PyJWT 2.9.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Denial of Service via unverified JSON Web Token key IDs\n\nPyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no rate limiting. Since kid comes from the unverified token header, an attacker can trigger unlimited outbound requests. The vulnerability surfaces only when a JWKS fetch fails; an attacker can attempt to provoke that with sustained unknown-kid traffic, but the outcome depends on upstream JWKS-endpoint be\n\nPackage: PyJWT\nInstalled: 2.9.0\nFixed in: 2.13.0\nSeverity: LOW\nFix: Upgrade PyJWT to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9d46ffc5a02564c9", "name": "CVE-2026-35002: agno 1.4.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-35002: agno 1.4.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "Agno is vulnerable to Eval Injection\n\nAgno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers can influence the field_type value in a FunctionCall to achieve remote code execution.\n\nPackage: agno\nInstalled: 1.4.2\nFixed in: 2.3.24\nSeverity: CRITICAL\nFix: Upgrade agno to 2.3.24"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-d84772eba72837fb", "name": "CVE-2026-10105: agno 1.4.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-10105: agno 1.4.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "agno contains a SQL injection vulnerability\n\nagno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplying malicious metadata keys and values to the delete_by_metadata() method. Attackers can exploit the unsafe f-string interpolation in clickhousedb.py to delete all rows, target specific rows, or extract information through error-based or blind SQL injection techniques.\n\nPackage: agno\nInstalled: 1.4.2\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f6675bd101780315", "name": "CVE-2025-69223: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2025-69223: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.13.3\nSeverity: HIGH\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-918c370c332d0340", "name": "CVE-2025-69227: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2025-69227: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via specially crafted POST request\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an infinite loop to occur when assert statements are bypassed, resulting in a DoS attack when processing a POST body. If optimizations are enabled (-O or PYTHONOPTIMIZE=1), and the application includes a handler that uses the Request.post() method, then an attacker may be able to execute a DoS attack with a specially crafted message. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.13.3\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f0007d8396211c43", "name": "CVE-2025-69228: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2025-69228: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an application includes a handler that uses the Request.post() method, an attacker may be able to freeze the server by exhausting the memory. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.13.3\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-46461deb497f99ca", "name": "CVE-2025-69229: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2025-69229: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via excessive CPU usage in chunked message handling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usage when receiving a large number of chunks. If an application makes use of the request.read() method in an endpoint, it may be possible for an attacker to cause the server to spend a moderate amount of blocking CPU time (e.g. 1 second) while processing the request. This could potentially lead to DoS as the server would \n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.13.3\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1166cccac204bf63", "name": "CVE-2026-22815: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-22815: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via insufficient header/trailer handling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c5c2606bfc725d67", "name": "CVE-2026-34515: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-34515: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Information disclosure via static resource handler on Windows\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-658f6ac22bc43c9e", "name": "CVE-2026-34516: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-34516: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via excessive multipart headers\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multipart headers may be allowed to use more memory than intended, potentially allowing a DoS vulnerability. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cf397fcb3ab04513", "name": "CVE-2026-34525: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-34525: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: aiohttp: Security bypass via multiple Host headers\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-612a030398ac1d2d", "name": "CVE-2026-34993: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-34993: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load()\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.14.0\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-101132809b2c64f2", "name": "CVE-2026-47265: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-47265: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-aiohttp: AIOHTTP: Information disclosure via improper handling of cookies during cross-origin redirects\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect. If a developer uses the `cookies` parameter on a per-request basis then sensitive data might be leaked to an attacker if they manage to control a redirect. Version 3.14.0 patches the issue. If unable to upgrade, using a `Cookie` header in the `headers` parameter is not vulnerable.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.14.0\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f9201f2e76c706d4", "name": "CVE-2026-54273: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-54273: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via excessive pipelined requests\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An attacker may be able to use pipelined requests to use excessive amounts of memory, potentially leading to DoS. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-88acfb41e1b85d13", "name": "CVE-2026-54274: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-54274: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via incomplete websocket frame payloads\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dd92f414f9ecf07d", "name": "CVE-2026-54276: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-54276: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: aiohttp: Information disclosure via DigestAuthMiddleware after cross-origin redirect\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vulnerability or similar on the target domain for an attacker to be able to execute. Further, the attacker is only receiving the digest, so should only be able to extract the user's credentials if the cryptography is weak or there is some kind of password reuse. This\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c9c242f90888d3b9", "name": "CVE-2026-54277: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-54277: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via oversized HTTP request lines bypassing max_line_size check\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in parts of an HTTP request in the C parser. If using the optimised C parser (the default in pre-built wheels), then an attacker may be able to send oversized lines through the HTTP parser and use an excessive amount of memory, potentially leading to DoS. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-148cb76d5849e6c3", "name": "CVE-2026-54278: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-54278: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service due to excessive memory consumption from compressed request body\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f4162eb745914132", "name": "CVE-2025-53643: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2025-53643: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: AIOHTTP HTTP Request/Response Smuggling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request. If a pure Python version of aiohttp is installed (i.e. without the usual C extensions) or AIOHTTP_NO_EXTENSIONS is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections. Version 3.12.14 contains a p\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.12.14\nSeverity: LOW\nFix: Upgrade aiohttp to 3.12.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e8b14ce34ab9e9c8", "name": "CVE-2025-69224: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2025-69224: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: aiohttp: Request smuggling via non-ASCII characters in HTTP parser\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python HTTP parser may allow a request smuggling attack with the presence of non-ASCII characters. If a pure Python version of AIOHTTP is installed (i.e. without the usual C extensions) or AIOHTTP_NO_EXTENSIONS is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.13.3\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fff138aac2d0e148", "name": "CVE-2025-69225: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2025-69225: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: aiohttp: Request smuggling vulnerability via non-ASCII decimals in Range header\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.13.3\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7ac1ec805423f930", "name": "CVE-2025-69226: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2025-69226: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: aiohttp: Information disclosure of path components via static file path normalization\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.13.3\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c9b121bf0ef27989", "name": "CVE-2025-69230: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2025-69230: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via specially crafted invalid cookies\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is accessed in an application, then an attacker may be able to trigger a storm of warning-level logs using a specially crafted Cookie header. This issue is fixed in 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.13.3\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e2e0004d51f857a8", "name": "CVE-2026-34513: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-34513: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service due to unbounded DNS cache\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-04e3129a40024a81", "name": "CVE-2026-34514: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-34514: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Header Injection via content_type parameter manipulation\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f18902e12cd7ba32", "name": "CVE-2026-34517: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-34517: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via large multipart form fields\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multipart form fields, aiohttp read the entire field into memory before checking client_max_size. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0c4c07ef6a0881c8", "name": "CVE-2026-34518: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-34518: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Information disclosure via retained Cookie and Proxy-Authorization headers during redirects\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following redirects to a different origin, aiohttp drops the Authorization header, but retains the Cookie and Proxy-Authorization headers. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-13b3297ae42deafe", "name": "CVE-2026-34519: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-34519: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: aiohttp: Header injection vulnerability via reason parameter\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the reason parameter when creating a Response may be able to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aebd205be4735b22", "name": "CVE-2026-34520: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-34520: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Header injection vulnerability due to improper character handling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a92f8fb17c7752c0", "name": "CVE-2026-50269: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-50269: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: AIOHTTP: CRLF injection in multipart headers\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar. In the unlikely situation that an application is passing user-controlled strings into MultipartWriter.append(headers=...) or Payload.headers, then an attacker may be able to modify the request to inject headers or change the contents of the request. This vulnerabi\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.14.0\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b034a92a9d658711", "name": "CVE-2026-54275: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-54275: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: AIOHTTP: TLS SNI check bypass via connection reuse\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an application makes multiple requests to the same domain, but with different per-request server_hostname parameters, then the later calls may succeed by reusing the existing connection when they should have been rejected due to the TLS SNI check. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.14.1\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c24191b4c16d3aef", "name": "CVE-2026-54279: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-54279: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Host-Only Cookies Become Domain Cookies After CookieJar Persistence\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.14.1\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-27beaad0a4732854", "name": "CVE-2026-54280: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-54280: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be able to cause resource starvation temporarily until garbage collection or similar closes the file. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.11.18\nFixed in: 3.14.1\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-286823c8e27e6a84", "name": "CVE-2025-64481: datasette 0.65.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.t", "shortDescription": {"text": "CVE-2025-64481: datasette 0.65.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "Open redirect endpoint in Datasette\n\nDatasette is an open source multi-tool for exploring and publishing data. In versions 0.65.1 and below and 1.0a0 through 1.0a19, deployed instances of Datasette include an open redirect vulnerability. Hits to the path //example.com/foo/bar/ (the trailing slash is required) will redirect the user to https://example.com/foo/bar. This problem has been patched in both Datasette 0.65.2 and 1.0a21. To workaround this issue, if Datasette is running behind a proxy, that proxy could be configured to repl\n\nPackage: datasette\nInstalled: 0.65.1\nFixed in: 0.65.2, 1.0a21\nSeverity: LOW\nFix: Upgrade datasette to 0.65.2, 1.0a21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ce6379c5690e2eee", "name": "CVE-2025-68146: filelock 3.18.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2025-68146: filelock 3.18.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "filelock: filelock: Time-of-Check-Time-of-Use (TOCTOU) race condition and symlink attack allows arbitrary file corruption or truncation\n\nfilelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user files through symlink attacks. The vulnerability exists in both Unix and Windows lock file creation where filelock checks if a file exists before opening it with O_TRUNC. An attacker can create a symlink pointing to a victim file in the time gap between the check and open, causing os.open() to follow\n\nPackage: filelock\nInstalled: 3.18.0\nFixed in: 3.20.1\nSeverity: MEDIUM\nFix: Upgrade filelock to 3.20.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-96f8fc9dcd9caadc", "name": "CVE-2026-22701: filelock 3.18.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-22701: filelock 3.18.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "filelock: filelock Time-of-Check-Time-of-Use (TOCTOU) in SoftFileLock\n\nfilelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the _acquire() method between raise_on_not_writable_file() (permission c\n\nPackage: filelock\nInstalled: 3.18.0\nFixed in: 3.20.3\nSeverity: MEDIUM\nFix: Upgrade filelock to 3.20.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-efdf0bdbbd843fed", "name": "CVE-2025-43859: h11 0.14.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-43859: h11 0.14.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "h11: h11 accepts some malformed Chunked-Encoding bodies\n\nh11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since exploitation requires the combination of buggy h11 with a buggy (reverse) proxy, fixing either component is sufficient to mitigate this issue.\n\nPackage: h11\nInstalled: 0.14.0\nFixed in: 0.16.0\nSeverity: CRITICAL\nFix: Upgrade h11 to 0.16.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-0ca121337f50b2ec", "name": "CVE-2025-57804: h2 4.2.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-57804: h2 4.2.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "h2: h2 allows HTTP Request Smuggling due to illegal characters in headers\n\nh2 is a pure-Python implementation of a HTTP/2 protocol stack. Prior to version 4.3.0, an HTTP/2 request splitting vulnerability allows attackers to perform request smuggling attacks by injecting CRLF characters into headers. This occurs when servers downgrade HTTP/2 requests to HTTP/1.1 without properly validating header names/values, enabling attackers to manipulate request boundaries and bypass security controls. This issue has been patched in version 4.3.0.\n\nPackage: h2\nInstalled: 4.2.0\nFixed in: 4.3.0\nSeverity: MEDIUM\nFix: Upgrade h2 to 4.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1807dc42a079a244", "name": "CVE-2026-45409: idna 3.10 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-45409: idna 3.10 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-idna: idna: Denial of Service via specially crafted long inputs\n\nInternationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fi\n\nPackage: idna\nInstalled: 3.10\nFixed in: 3.15\nSeverity: MEDIUM\nFix: Upgrade idna to 3.15"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c66fc5fab98040ad", "name": "CVE-2026-45134: langchain 0.3.22 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.t", "shortDescription": {"text": "CVE-2026-45134: langchain 0.3.22 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest\n\nPackage: langchain\nInstalled: 0.3.22\nFixed in: 0.3.30\nSeverity: HIGH\nFix: Upgrade langchain to 0.3.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e4b2a1ea38f4fd80", "name": "CVE-2026-55443: langchain 0.3.22 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.t", "shortDescription": {"text": "CVE-2026-55443: langchain 0.3.22 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended root directory. Affected behaviors include: a file-search agent middleware that validates a starting directory but not the search pattern or the resolved target of matched files, so glob patterns and symlinks can reach files outside the configured root; prompt- \n\nPackage: langchain\nInstalled: 0.3.22\nFixed in: 1.3.9\nSeverity: MEDIUM\nFix: Upgrade langchain to 1.3.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fa749df17a65f322", "name": "CVE-2026-55443: langchain-anthropic 0.3.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requi", "shortDescription": {"text": "CVE-2026-55443: langchain-anthropic 0.3.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended root directory. Affected behaviors include: a file-search agent middleware that validates a starting directory but not the search pattern or the resolved target of matched files, so glob patterns and symlinks can reach files outside the configured root; prompt- \n\nPackage: langchain-anthropic\nInstalled: 0.3.3\nFixed in: 1.4.6\nSeverity: MEDIUM\nFix: Upgrade langchain-anthropic to 1.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eea8ae764d431f78", "name": "CVE-2025-68664: langchain-core 0.3.49 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requireme", "shortDescription": {"text": "CVE-2025-68664: langchain-core 0.3.49 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "langchain-core: LangChain: Arbitrary code execution via serialization injection\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd() functions. The functions do not escape dictionaries with 'lc' keys when serializing free-form dictionaries. The 'lc' key is used internally by LangChain to mark serialized objects. When user-controlled data contains this key structure, it is treated as a legitimate LangChain object during deserialization r\n\nPackage: langchain-core\nInstalled: 0.3.49\nFixed in: 1.2.5, 0.3.81\nSeverity: CRITICAL\nFix: Upgrade langchain-core to 1.2.5, 0.3.81"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-aa1f680438f06863", "name": "CVE-2025-65106: langchain-core 0.3.49 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requireme", "shortDescription": {"text": "CVE-2025-65106: langchain-core 0.3.49 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "langchain-core: LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates\n\nLangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template system that allows attackers to access Python object internals through template syntax. This vulnerability affects applications that accept untrusted template strings (not just template variables) in ChatPromptTemplate and related prompt template classes. This issue has been patched in versions 0.3.8\n\nPackage: langchain-core\nInstalled: 0.3.49\nFixed in: 1.0.7, 0.3.80\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.0.7, 0.3.80"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a98ac1a49cf77ea4", "name": "CVE-2026-34070: langchain-core 0.3.49 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requireme", "shortDescription": {"text": "CVE-2026-34070: langchain-core 0.3.49 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "langchain: path traversal in legacy load_prompt functions in langchain-core\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path injection. When an application passes user-influenced prompt configurations to load_prompt() or load_prompt_from_config(), an attacker can read arbitrary files on the host filesystem, constrained only by file-extension chec\n\nPackage: langchain-core\nInstalled: 0.3.49\nFixed in: 1.2.22\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.2.22"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4d43da82e6d1cdca", "name": "CVE-2026-44843: langchain-core 0.3.49 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requireme", "shortDescription": {"text": "CVE-2026-44843: langchain-core 0.3.49 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call load() with allowed_objects=\"all\". This does not enable arbitrary Python object deserialization, but it does allow any trusted LangChain-serializable object to be revived, which is broader than these runtime path\n\nPackage: langchain-core\nInstalled: 0.3.49\nFixed in: 1.3.3, 0.3.85\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.3.3, 0.3.85"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4fbfe3edcf5e759b", "name": "CVE-2026-40087: langchain-core 0.3.49 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requireme", "shortDescription": {"text": "CVE-2026-40087: langchain-core 0.3.49 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "langchain: incomplete f-string validation in prompt templates\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-string prompt-template validation was incomplete in two respects. First, some prompt template classes accepted f-string templates and formatted them without enforcing the same attribute-access validation as PromptTemplate. In particular, DictPromptTemplate and ImagePromptTemplate could accept templates containing attribute access or indexing expressions and subsequently evaluate t\n\nPackage: langchain-core\nInstalled: 0.3.49\nFixed in: 0.3.84, 1.2.28\nSeverity: MEDIUM\nFix: Upgrade langchain-core to 0.3.84, 1.2.28"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5b8a1b96dbb92de4", "name": "CVE-2026-26013: langchain-core 0.3.49 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requireme", "shortDescription": {"text": "CVE-2026-26013: langchain-core 0.3.49 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "langchain: SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side Request Forgery (SSRF) attacks by providing malicious image URLs in user input. This vulnerability is fixed in 1.2.11.\n\nPackage: langchain-core\nInstalled: 0.3.49\nFixed in: 1.2.11\nSeverity: LOW\nFix: Upgrade langchain-core to 1.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-250aea46b9dc58db", "name": "CVE-2026-41488: langchain-openai 0.3.11 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/require", "shortDescription": {"text": "CVE-2026-41488: langchain-openai 0.3.11 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "langchain-openai: Langchain-openai: Server-Side Request Forgery (SSRF) protection bypass via DNS rebinding\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size() helper (used by get_num_tokens_from_messages for image token counting) validated URLs for SSRF protection and then fetched them in a separate network operation with independent DNS resolution. This left a TOCTOU / DNS rebinding window: an attacker-controlled hostname could resolve to a public IP during validation and then to a private/localhost IP during the actual fetch.\n\nPackage: langchain-openai\nInstalled: 0.3.11\nFixed in: 1.1.14\nSeverity: LOW\nFix: Upgrade langchain-openai to 1.1.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-774416b44f1dabe1", "name": "CVE-2025-6985: langchain-text-splitters 0.3.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/r", "shortDescription": {"text": "CVE-2025-6985: langchain-text-splitters 0.3.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "langchain-text-splitters: XXE Vulnerability in langchain-text-splitters\n\nThe HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing. This vulnerability arises because the class allows the use of arbitrary XSLT stylesheets, which are parsed using lxml.etree.parse() and lxml.etree.XSLT() without any hardening measures. In lxml versions up to 4.9.x, external entities are resolved by default, allowing attackers to read arbitrary local files or perform outbound HTTP(S) fetches. In l\n\nPackage: langchain-text-splitters\nInstalled: 0.3.7\nFixed in: 0.3.9\nSeverity: HIGH\nFix: Upgrade langchain-text-splitters to 0.3.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-134350120b55ec15", "name": "CVE-2026-41481: langchain-text-splitters 0.3.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/", "shortDescription": {"text": "CVE-2026-41481: langchain-text-splitters 0.3.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "langchain-text-splitters: LangChain: Information Disclosure via Server-Side Request Forgery (SSRF) Redirect Bypass\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters\n 1.1.2, HTMLHeaderTextSplitter.split_text_from_url() validated the initial URL using validate_safe_url() but then performed the fetch with requests.get() with redirects enabled (the default). Because redirect targets were not revalidated, a URL pointing to an attacker-controlled server could redirect to internal, localhost, or cloud metadata endpoints, bypassing SSRF protections. The resp\n\nPackage: langchain-text-splitters\nInstalled: 0.3.7\nFixed in: 1.1.2\nSeverity: MEDIUM\nFix: Upgrade langchain-text-splitters to 1.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0d3db040e359b227", "name": "CVE-2026-45134: langsmith 0.3.31 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.t", "shortDescription": {"text": "CVE-2026-45134: langsmith 0.3.31 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest\n\nPackage: langsmith\nInstalled: 0.3.31\nFixed in: 0.8.0\nSeverity: HIGH\nFix: Upgrade langsmith to 0.8.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0ded2f1935a804f0", "name": "GHSA-f4xh-w4cj-qxq8: langsmith 0.3.31 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requireme", "shortDescription": {"text": "GHSA-f4xh-w4cj-qxq8: langsmith 0.3.31 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "LangSmith SDK TracingMiddleware: Arbitrary server-side file read\n\n# Summary\n\nAn attacker who can send an HTTP request to a server running the LangSmith SDK's `TracingMiddleware` can cause that server to read an arbitrary file from its local filesystem and upload the contents to LangSmith as a trace attachment. Depending on how the distributed trace system is deployed, triggering a read may not require authentication. Retrieving the contents requires read access to the LangSmith workspace the traces are sent to. The net effect is a trust-boundary crossing: a pa\n\nPackage: langsmith\nInstalled: 0.3.31\nFixed in: 0.8.18\nSeverity: HIGH\nFix: Upgrade langsmith to 0.8.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1881f0d87c6e1e90", "name": "CVE-2026-41182: langsmith 0.3.31 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.t", "shortDescription": {"text": "CVE-2026-41182: langsmith 0.3.31 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "LangSmith SDK: Streaming token events bypass output redaction\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces streaming output, each chunk is recorded as a new_token event containing the raw token value. These events bypass the redaction pipeline entirely \u2014 prepareRunCreateOrUpdateInputs (\n\nPackage: langsmith\nInstalled: 0.3.31\nFixed in: 0.7.31\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.7.31"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ccb27d4f9cde9fa6", "name": "CVE-2026-41066: lxml 5.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-41066: lxml 5.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "lxml: python: lxml: Information disclosure via untrusted XML input leading to local file read\n\nlxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input to read local files. Setting the resolve_entities option explicitly to resolve_entities='internal' or resolve_entities=False disables the local file access. This vulnerability is fixed in 6.1.0.\n\nPackage: lxml\nInstalled: 5.4.0\nFixed in: 6.1.0\nSeverity: HIGH\nFix: Upgrade lxml to 6.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b4823e1ec8ba013e", "name": "CVE-2026-49825: lxml_html_clean 0.4.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requireme", "shortDescription": {"text": "CVE-2026-49825: lxml_html_clean 0.4.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes\n\n# `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (`xlink:href`)\n\n**Reporter:** Guillem Lefait <guillem@datamq.com> \u00b7 **Date:** 2026-05-10\n**Affected:** `lxml` \u2264 6.1.0 and `lxml_html_clean` \u2264 0.4.4 (latest stable)\n**Confirmed against:** lxml 6.1.0 + lxml_html_clean 0.4.4 on Python 3.13.5, 3.14.4, and 3.15.0a8 (libxml2 2.14.6 / 2.9.14 \u2014 bug is in pure-Python sanitizer logic, independent of the libxml2 backend)\n**Root-cause class:** same as CVE-2021-28957\n\nPackage: lxml_html_clean\nInstalled: 0.4.2\nFixed in: 0.4.5\nSeverity: HIGH\nFix: Upgrade lxml_html_clean to 0.4.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e7c22a4f6becea54", "name": "CVE-2026-28348: lxml_html_clean 0.4.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requireme", "shortDescription": {"text": "CVE-2026-28348: lxml_html_clean 0.4.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "lxml_html_clean is a project for HTML cleaning functionalities copied  ...\n\nlxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the _has_sneaky_javascript() method strips backslashes before checking for dangerous CSS keywords. This causes CSS Unicode escape sequences to bypass the @import and expression() filters, allowing external CSS loading or XSS in older browsers. This issue has been patched in version 0.4.4.\n\nPackage: lxml_html_clean\nInstalled: 0.4.2\nFixed in: 0.4.4\nSeverity: MEDIUM\nFix: Upgrade lxml_html_clean to 0.4.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4c9898c71ee4af49", "name": "CVE-2026-28350: lxml_html_clean 0.4.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requireme", "shortDescription": {"text": "CVE-2026-28350: lxml_html_clean 0.4.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "lxml_html_clean is a project for HTML cleaning functionalities copied  ...\n\nlxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the <base> tag passes through the default Cleaner configuration. While page_structure=True removes html, head, and title tags, there is no specific handling for <base>, allowing an attacker to inject it and hijack relative links on the page. This issue has been patched in version 0.4.4.\n\nPackage: lxml_html_clean\nInstalled: 0.4.2\nFixed in: 0.4.4\nSeverity: MEDIUM\nFix: Upgrade lxml_html_clean to 0.4.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7c382b8c008cd64f", "name": "CVE-2026-31240: mem0ai 0.1.93 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-31240: mem0ai 0.1.93 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory management API endpoints\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss.\n\nPackage: mem0ai\nInstalled: 0.1.93\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bd6a865cc63a86a2", "name": "CVE-2026-31241: mem0ai 0.1.93 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-31241: mem0ai 0.1.93 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory deletion API endpoint\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service.\n\nPackage: mem0ai\nInstalled: 0.1.93\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-508c6ab5c59295ca", "name": "CVE-2026-31245: mem0ai 0.1.93 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-31245: mem0ai 0.1.93 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory creation API endpoint\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution.\n\nPackage: mem0ai\nInstalled: 0.1.93\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8fd35460689aeeab", "name": "CVE-2026-7597: mem0ai 0.1.93 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-7597: mem0ai 0.1.93 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "mem0ai mem0 has an Improper Input Validation Issue\n\nA vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue.\n\nPackage: mem0ai\nInstalled: 0.1.93\nFixed in: 2.0.0b2\nSeverity: LOW\nFix: Upgrade mem0ai to 2.0.0b2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e577dfd46645672b", "name": "GHSA-6v7p-g79w-8964: msgpack 1.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements", "shortDescription": {"text": "GHSA-6v7p-g79w-8964: msgpack 1.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error\n\n### Impact\n\nIf the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV.\n\nIf the Unpacker is used repeatedly to unpack untrusted input from external sources, it may be vulnerable to a DoS attack.\n\n### Patches\n\nv1.2.1\n\n### Workarounds\n\nUsers should create a new Unpacker instead of reusing the same Unpacker after an error occurs.\n\nApplying the above patch can prevent SEGV, but reusing the Streaming Unpacker after it has encountered an error will not yield correct da\n\nPackage: msgpack\nInstalled: 1.1.0\nFixed in: 1.2.1\nSeverity: HIGH\nFix: Upgrade msgpack to 1.2.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e1cdf9f23a540946", "name": "CVE-2025-14009: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-14009: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "nltk: Zip Slip Vulnerability in nltk Leading to Code Execution\n\nA critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks. This allows attackers to craft malicious zip packages that, when downloaded and extracted by NLTK, can execute arbitrary code. The vulnerability arises because NLTK assumes all downloaded packages are trusted and extracts them without validation. If a malicious package\n\nPackage: nltk\nInstalled: 3.9.1\nFixed in: 3.9.3\nSeverity: CRITICAL\nFix: Upgrade nltk to 3.9.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-7204ade5dbb26d38", "name": "CVE-2026-0846: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-0846: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function\n\nA vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensitive system files by providing absolute paths or traversal paths. This vulnerability can be exploited locally or remotely, particularly in scenarios where the function is used in web APIs or other interfaces that accept u\n\nPackage: nltk\nInstalled: 3.9.1\nFixed in: 3.9.3\nSeverity: HIGH\nFix: Upgrade nltk to 3.9.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0a3f74ef126f2a22", "name": "CVE-2026-0847: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-0847: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "nltk: NLTK: Arbitrary file read via path traversal vulnerability\n\nA vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These classes fail to properly sanitize or validate file paths, enabling attackers to traverse directories and access sensitive files on the server. This issue is particularly critical in scenarios where user-controlled file inputs are processed, such as in machine learning APIs\n\nPackage: nltk\nInstalled: 3.9.1\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7eac932676a25e73", "name": "CVE-2026-33231: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-33231: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "nltk: NLTK: Denial of Service via unauthenticated remote shutdown\n\nNLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when it is started in its default mode. A simple `GET /SHUTDOWN%20THE%20SERVER` request causes the process to terminate immediately via `os._exit(0)`, resulting in a denial of service. Commit bbaae83db\n\nPackage: nltk\nInstalled: 3.9.1\nFixed in: 3.9.4\nSeverity: HIGH\nFix: Upgrade nltk to 3.9.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-53dd9e1f6851e1f0", "name": "CVE-2026-33236: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-33236: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "nltk: NLTK: Arbitrary file overwrite and creation via path traversal in XML index files\n\nNLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not validate the `subdir` and `id` attributes when processing remote XML index files. Attackers can control a remote XML index server to provide malicious values containing path traversal sequences (such as `../`), which can lead to arbitrary directory creation, arbitrary file c\n\nPackage: nltk\nInstalled: 3.9.1\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5f1280b20678b747", "name": "CVE-2026-54293: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-54293: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "nltk: NLTK: Information Disclosure via Path Traversal in `nltk.data.load()`\n\nNLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path traversal via URL-encoded path separators and traversal segments when using the nltk: URL scheme. The unsafe-path regex check is performed before url2pathname() decodes the %xx sequences (a classic decode-after-check / TOCTOU-style flaw), allowing an attacker to by\n\nPackage: nltk\nInstalled: 3.9.1\nFixed in: 3.10.0\nSeverity: HIGH\nFix: Upgrade nltk to 3.10.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3ca02038d3122528", "name": "CVE-2026-33230: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-33230: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "nltk: NLTK: Script execution via reflected cross-site scripting in WordNet Browser\n\nNLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` contains a reflected cross-site scripting issue in the `lookup_...` route. A crafted `lookup_<payload>` URL can inject arbitrary HTML/JavaScript into the response page because attacker-controlled `word` data is reflected into HTML without escaping. This impacts users running the l\n\nPackage: nltk\nInstalled: 3.9.1\nFixed in: 3.9.4\nSeverity: MEDIUM\nFix: Upgrade nltk to 3.9.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e9f2e78f7aa53d61", "name": "GHSA-rf74-v2fm-23pw: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "GHSA-rf74-v2fm-23pw: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS\n\n### Summary\n`JSONTaggedDecoder.decode_obj()` in `nltk/jsontags.py` calls itself \nrecursively without any depth limit. A deeply nested JSON structure \nexceeding `sys.getrecursionlimit()` (default: 1000) will raise an \nunhandled `RecursionError`, crashing the Python process.\n\n### Affected code\nFile: `nltk/jsontags.py`, lines 47\u201352\n```python\n@classmethod\ndef decode_obj(cls, obj):\n    if isinstance(obj, dict):\n        obj = {key: cls.decode_obj(val) for (key, val) in obj.items()}\n    elif isinstance\n\nPackage: nltk\nInstalled: 3.9.1\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f766bf2c505b2f2b", "name": "CVE-2025-67221: orjson 3.10.16 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-67221: orjson 3.10.16 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "orjson: orjson: Denial of Service due to unbounded recursion with deeply nested JSON documents\n\nThe orjson.dumps function in orjson thru 3.11.4 does not limit recursion for deeply nested JSON documents.\n\nPackage: orjson\nInstalled: 3.10.16\nFixed in: 3.11.6\nSeverity: HIGH\nFix: Upgrade orjson to 3.11.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c1b769fd0c9d0c2d", "name": "CVE-2025-48379: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-48379: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-pillow: pillow: Pillow DDS Heap Buffer Overflow\n\nPillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without checking for available space. This only affects users who save untrusted data as a compressed DDS image. This issue has been patched in version 11.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 11.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 11.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-868629d4b617ce05", "name": "CVE-2026-25990: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-25990: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image\n\nPillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.1.1\nSeverity: HIGH\nFix: Upgrade pillow to 12.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-75fd122a4fb0b593", "name": "CVE-2026-40192: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-40192: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing\n\nPillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.2.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-85cb3b2ba8a4c9da", "name": "CVE-2026-42311: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-42311: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing\n\nPillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.2.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-86fa88d96844ec27", "name": "CVE-2026-54058: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-54058: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image\n\nPillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eee97bb5016a65fa", "name": "CVE-2026-54059: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-54059: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted PCF font data\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c8486c8694238962", "name": "CVE-2026-54060: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-54060: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(\"1\", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-63227222f2a507d8", "name": "CVE-2026-55379: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-55379: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted BDF font file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6e7e4917108edd6c", "name": "CVE-2026-55380: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-55380: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted GD 2.x image file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fbd870123e07a43f", "name": "CVE-2026-59197: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-59197: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Native heap out-of-bounds write\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1dc5b9862b69da4b", "name": "CVE-2026-59199: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-59199: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via out-of-bounds write in image processing\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-29ca42f167f97ac7", "name": "CVE-2026-59200: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-59200: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of service via crafted PDF stream\n\nPillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-775e13f760cf5079", "name": "CVE-2026-59204: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-59204: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via crafted JPEG2000 image\n\nPillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c5b79b9708c6de43", "name": "CVE-2026-59205: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-59205: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ff74de4af1b61344", "name": "CVE-2026-42308: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-42308: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "Pillow: python: Pillow: Denial of Service via integer overflow in font processing\n\nPillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9821e076016b442a", "name": "CVE-2026-42309: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-42309: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via specially crafted coordinate input\n\nPillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polygon and ImageDraw.ImageDraw.line could cause a heap buffer overflow, as nested lists were recursively unpacked beyond the allocated buffer. Coordinate lists are now validated to contain exactly two numeric coordinates. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-649990f9c6f33185", "name": "CVE-2026-42310: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-42310: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via malicious PDF processing\n\nPillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f9c83181e1630a86", "name": "CVE-2026-55798: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-55798: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Arbitrary command injection via shell metacharacters in file paths\n\nPillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4677c9e613c253bb", "name": "CVE-2026-59198: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-59198: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Information disclosure via TGA RLE encoder out-of-bounds read\n\nPillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-93902e96288aec4a", "name": "CVE-2025-4565: protobuf 6.30.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-4565: protobuf 6.30.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-protobuf: Unbounded recursion in Python Protobuf\n\nAny project that uses Protobuf Pure-Python backend\u00a0to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP\u00a0tags can be corrupted by exceeding the Python recursion limit. This can result in a Denial of service by crashing the application with a RecursionError. We recommend upgrading to version =>6.31.1 or beyond commit\u00a017838beda2943d08b8a9d4df5b68f5f04f26d901\n\nPackage: protobuf\nInstalled: 6.30.2\nFixed in: 4.25.8, 5.29.5, 6.31.1\nSeverity: HIGH\nFix: Upgrade protobuf to 4.25.8, 5.29.5, 6.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-89241c57518bf84c", "name": "CVE-2026-0994: protobuf 6.30.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-0994: protobuf 6.30.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python: protobuf: Protobuf: Denial of Service due to recursion depth bypass\n\nA denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages.\n\nDue to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python\u2019s recursion stack and causing a RecursionError.\n\nPackage: protobuf\nInstalled: 6.30.2\nFixed in: 6.33.5, 5.29.6\nSeverity: HIGH\nFix: Upgrade protobuf to 6.33.5, 5.29.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-af033e6895a0c43d", "name": "CVE-2026-23490: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-23490: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.2\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-42e80a6aa75f6458", "name": "CVE-2026-30922: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-30922: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with \"Indefinite Length\" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consu\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.3\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cdd8852fb0fa8505", "name": "CVE-2026-59885: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-59885: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values.\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.4\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-68aa894255d14e88", "name": "CVE-2026-59886: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-59886: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.4\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e49a0640168722d8", "name": "CVE-2026-28684: python-dotenv 1.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirement", "shortDescription": {"text": "CVE-2026-28684: python-dotenv 1.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following\n\npython-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when a cross-device rename fallback is triggered. Users should upgrade to v.1.2.2 or, as a workaround, apply the patch manually.\n\nPackage: python-dotenv\nInstalled: 1.1.0\nFixed in: 1.2.2\nSeverity: MEDIUM\nFix: Upgrade python-dotenv to 1.2.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9c0e85a77fc11b6d", "name": "CVE-2026-24486: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/require", "shortDescription": {"text": "CVE-2026-24486: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Arbitrary file write via path traversal vulnerability\n\nPython-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write uploaded files to arbitrary locations on the filesystem by crafting a malicious filename. Users should upgrade to version 0.0.22 to receive a patch or, as a workaround, avoid using `UPLOAD_KEEP_FILENAME=True` in project configurations.\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.22\nSeverity: HIGH\nFix: Upgrade python-multipart to 0.0.22"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-28b005542446d4bd", "name": "CVE-2026-42561: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/require", "shortDescription": {"text": "CVE-2026-42561: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-multipart: python-multipart: Denial of Service via excessive multipart part headers\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, MultipartParser previously had no limit on the number of part headers or the size of an individual part header. An attacker could send a request with either many repeated headers without terminating the header block or a single very large header value, causing excessive CPU work before request reje\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.27\nSeverity: HIGH\nFix: Upgrade python-multipart to 0.0.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ab30ae632c5554bf", "name": "CVE-2026-53539: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/require", "shortDescription": {"text": "CVE-2026-53539: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Denial of Service via crafted form-urlencoded bodies\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step lookup: it first scanned the entire remaining buffer for &, and only when no & existed anywhere ahead did it fall back to scanning for ;. For a body that uses ; as the separator and contains no &, every field iteration performed a full failed & scan over the entire remaining buffer before locating the ne\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.30\nSeverity: HIGH\nFix: Upgrade python-multipart to 0.0.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e14d3deacd4cc3a3", "name": "CVE-2026-40347: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/require", "shortDescription": {"text": "CVE-2026-40347: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Denial of Service via crafted multipart/form-data requests\n\nPython-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candidate when processing leading CR/LF data and immediately discards epilogue data after the closing boundary.\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.26\nSeverity: MEDIUM\nFix: Upgrade python-multipart to 0.0.26"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-45b455ce1f3b8347", "name": "CVE-2026-53537: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/require", "shortDescription": {"text": "CVE-2026-53537: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "multipart: Python-Multipart: Information disclosure via header parsing discrepancy\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message, which transparently applies RFC 2231/5987 decoding. The extended parameter syntax (filename*=charset'lang'value, name*=..., and the filename*0/filename*1 continuation form) is decoded and surfaced under the bare filename/name key, and overrides the plain parameter when both are present. RFC 7578 \u00a74.2 explicitly forbid\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.30\nSeverity: LOW\nFix: Upgrade python-multipart to 0.0.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-610dc7a83341787b", "name": "CVE-2026-53538: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/require", "shortDescription": {"text": "CVE-2026-53538: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Information disclosure due to parser differential in form data handling\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator. This creates a parser differential: the same bytes are tokenized into different fields than a WHATWG compliant intermediary would produce, allowing an attacker to smuggle extra form \n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.30\nSeverity: LOW\nFix: Upgrade python-multipart to 0.0.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ce5852c9e8b9b53b", "name": "CVE-2026-53540: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/require", "shortDescription": {"text": "CVE-2026-53540: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Negative Content-Length in parse_form buffers the entire body in memory\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned the bounded read into a read-until-EOF, so the entire body was loaded into memory in a single read instead of in fixed-size chunks. This vulnerability is fixed in 0.0.31.\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.31\nSeverity: LOW\nFix: Upgrade python-multipart to 0.0.31"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c4668254ddf73039", "name": "CVE-2024-47081: requests 2.32.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2024-47081: requests 2.32.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "requests: Requests vulnerable to .netrc credentials leak via malicious URLs\n\nRequests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.\n\nPackage: requests\nInstalled: 2.32.3\nFixed in: 2.32.4\nSeverity: MEDIUM\nFix: Upgrade requests to 2.32.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f17acefc3e1037a1", "name": "CVE-2026-25645: requests 2.32.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.tx", "shortDescription": {"text": "CVE-2026-25645: requests 2.32.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "requests: Requests: Security bypass due to predictable temporary file creation\n\nRequests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulner\n\nPackage: requests\nInstalled: 2.32.3\nFixed in: 2.33.0\nSeverity: MEDIUM\nFix: Upgrade requests to 2.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e03f26eecc749785", "name": "CVE-2026-49476: soupsieve 2.6 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-49476: soupsieve 2.6 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector string\n\nSoup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.\n\nPackage: soupsieve\nInstalled: 2.6\nFixed in: 2.8.4\nSeverity: HIGH\nFix: Upgrade soupsieve to 2.8.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f9319b5a1ff37e78", "name": "CVE-2026-49477: soupsieve 2.6 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-49477: soupsieve 2.6 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings\n\nSoup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beautiful Soup .select() / .select_one() to cause CPU exhaustion and denial of service. This issue is fi\n\nPackage: soupsieve\nInstalled: 2.6\nFixed in: 2.8.4\nSeverity: HIGH\nFix: Upgrade soupsieve to 2.8.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-821c4be6c60ebb65", "name": "CVE-2025-62727: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.t", "shortDescription": {"text": "CVE-2025-62727: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "starlette: Starlette DoS via Range header merging\n\nStarlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileResponse Range parsing/merging logic. This enables CPU exhaustion per request, causing denial\u2011of\u2011service for endpoints serving files (e.g., StaticFiles or any use of FileResponse). This vulnerability is fixed in 0.49.1.\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 0.49.1\nSeverity: HIGH\nFix: Upgrade starlette to 0.49.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5e7f3c744eb57071", "name": "CVE-2026-48818: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.t", "shortDescription": {"text": "CVE-2026-48818: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "starlette: Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows\n\nStarlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\\\attacker.com\\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account\u2019s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as Fas\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.1.0\nSeverity: HIGH\nFix: Upgrade starlette to 1.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e7453059c6f53505", "name": "CVE-2026-54283: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.t", "shortDescription": {"text": "CVE-2026-54283: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS\n\nStarlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, but silently ignored for application/x-www-form-urlencoded. An unauthenticated attacker can therefore send a urlencoded body with an arbitrarily large number of fields or an arbitrarily large field, even when the application configured limits it believed would apply.\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.3.1\nSeverity: HIGH\nFix: Upgrade starlette to 1.3.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-711590fc06028dfc", "name": "CVE-2025-54121: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.t", "shortDescription": {"text": "CVE-2025-54121: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "starlette: Starlette denial-of-service\n\nStarlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In versions 0.47.1 and below, when parsing a multi-part form with large files (greater than the default max spool size) starlette will block the main thread to roll the file over to disk. This blocks the event thread which means the application can't accept new connections. The UploadFile code has a minor bug where instead of just checking for self._in_me\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 0.47.2\nSeverity: MEDIUM\nFix: Upgrade starlette to 0.47.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6835ee5d538db915", "name": "CVE-2026-48710: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.t", "shortDescription": {"text": "CVE-2026-48710: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "starlette: Starlette: Security restriction bypass via malformed HTTP Host header\n\nStarlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) \n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.0.1\nSeverity: MEDIUM\nFix: Upgrade starlette to 1.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-97459d2b0f6f6f21", "name": "CVE-2026-48817: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.t", "shortDescription": {"text": "CVE-2026-48817: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "starlette: Starlette: Information disclosure and unintended method execution via non-standard HTTP methods\n\nStarlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs. When an HTTPEndpoint subclass is registered through Route(...) without an explicit methods= argument, the route does not constrain the method and every method reaches the endpoint. If a non-standard HTTP method whose lo\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.1.0\nSeverity: MEDIUM\nFix: Upgrade starlette to 1.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-85aecfbd41ece92b", "name": "CVE-2026-54282: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.t", "shortDescription": {"text": "CVE-2026-54282: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "starlette: Starlette: Information disclosure due to improper HTTP request path validation\n\nStarlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path} and re-parsing the result, a path that does not begin with / (for example @google.com) moves the authority boundary during re-parsing, so request.url.hostname and request.url.netloc become attacker-controlled. Code that reads request.url.hostname (rather than the Host header \n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.3.0\nSeverity: LOW\nFix: Upgrade starlette to 1.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f75384419f6763a", "name": "CVE-2025-32434: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-32434: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "PyTorch is a Python package that provides tensor computation with stro ...\n\nPyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue has been patched in version 2.6.0.\n\nPackage: torch\nInstalled: 2.2.2\nFixed in: 2.6.0\nSeverity: CRITICAL\nFix: Upgrade torch to 2.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-64e337c1a58db837", "name": "CVE-2025-2998: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-2998: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "A vulnerability was found in PyTorch 2.6.0. It has been declared as cr ...\n\nA vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.2.2\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a020b8d7c9c71073", "name": "CVE-2025-2999: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-2999: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "A vulnerability was found in PyTorch 2.6.0. It has been rated as criti ...\n\nA vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.2.2\nFixed in: 2.9.1\nSeverity: MEDIUM\nFix: Upgrade torch to 2.9.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2991a51995372545", "name": "CVE-2025-3730: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-3730: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "A vulnerability, which was classified as problematic, was found in PyT ...\n\nA vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The name of the patch is 46fc5d8e360127361211cb237d5f9eef0223e567. It is recommended to apply a pa\n\nPackage: torch\nInstalled: 2.2.2\nFixed in: 2.8.0\nSeverity: MEDIUM\nFix: Upgrade torch to 2.8.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4651de99293353ba", "name": "CVE-2025-2148: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-2148: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared ...\n\nA vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.\n\nPackage: torch\nInstalled: 2.2.2\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b561637a9fe3c34a", "name": "CVE-2025-2149: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-2149: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as ...\n\nA vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zero_point leads to improper initialization. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.2.2\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-536e958df6ece688", "name": "CVE-2025-2953: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-2953: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "torch: PyTorch torch.mkldnn_max_pool2d denial of service\n\nA vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects.\n\nPackage: torch\nInstalled: 2.2.2\nFixed in: 2.7.1-rc1\nSeverity: LOW\nFix: Upgrade torch to 2.7.1-rc1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dca48a65041f20e0", "name": "CVE-2025-3000: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-3000: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "A vulnerability classified as critical has been found in PyTorch 2.6.0 ...\n\nA vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.2.2\nFixed in: 2.13.0\nSeverity: LOW\nFix: Upgrade torch to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b7bdc2d4715e0f9e", "name": "CVE-2025-3001: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-3001: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "A vulnerability classified as critical was found in PyTorch 2.6.0. Thi ...\n\nA vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.2.2\nFixed in: 2.10.0\nSeverity: LOW\nFix: Upgrade torch to 2.10.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-649040017770a165", "name": "CVE-2026-4372: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements", "shortDescription": {"text": "CVE-2026-4372: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "HuggingFace transformers vulnerable to remote code execution\n\nA critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attacker-controlled HuggingFace Hub repository ID. When a victim loads this model using the standard `AutoModelForCausalLM.from_pretrained()` API, the library downloads and executes arbitrary Python code from the attacker's re\n\nPackage: transformers\nInstalled: 4.51.3\nFixed in: 5.3.0\nSeverity: HIGH\nFix: Upgrade transformers to 5.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e170dccdbfa32a27", "name": "CVE-2026-5241: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements", "shortDescription": {"text": "CVE-2026-5241: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting\n\nA vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, is overridden by untrusted serialized configuration data in a nested code path. Specifically, when loading a LightGlue model using `AutoModel.from_pretrained()` with `trust_remote_code=False`, the `Lig\n\nPackage: transformers\nInstalled: 4.51.3\nFixed in: 5.5.0\nSeverity: HIGH\nFix: Upgrade transformers to 5.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6a669b0ffe380ff0", "name": "CVE-2025-3933: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements", "shortDescription": {"text": "CVE-2025-3933: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers\n\nA Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability affects versions 4.50.3 and earlier, and is fixed in version 4.52.1. The issue arises from the regex pattern `<s_(.*?)>` which can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. This vulnerability can lead to service disruption,\n\nPackage: transformers\nInstalled: 4.51.3\nFixed in: 4.52.1\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.52.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-082df0a7738030b4", "name": "CVE-2025-5197: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements", "shortDescription": {"text": "CVE-2025-5197: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "transformers: Transformers ReDoS Vulnerability\n\nA Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically in the `convert_tf_weight_name_to_pt_weight_name()` function. This function, responsible for converting TensorFlow weight names to PyTorch format, uses a regex pattern `/[^/]*___([^/]*)/` that can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. The vulnerability affects versions up to 4.51.3 and is fixed in vers\n\nPackage: transformers\nInstalled: 4.51.3\nFixed in: 4.53.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.53.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-12759909e7b13e13", "name": "CVE-2025-6051: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements", "shortDescription": {"text": "CVE-2025-6051: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers\n\nA Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the `normalize_numbers()` method of the `EnglishNormalizer` class. This vulnerability affects versions up to 4.52.4 and is fixed in version 4.53.0. The issue arises from the method's handling of numeric strings, which can be exploited using crafted input strings containing long sequences of digits, leading to excessive CPU consumption. This vulnerability impac\n\nPackage: transformers\nInstalled: 4.51.3\nFixed in: 4.53.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.53.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-42b16f7009057df9", "name": "CVE-2025-6638: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements", "shortDescription": {"text": "CVE-2025-6638: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers\n\nA Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language_code()` method. This vulnerability is present in version 4.52.4 and has been fixed in version 4.53.0. The issue arises from inefficient regex processing, which can be exploited by crafted input strings containing malformed language code patterns, leading to excessive CPU consumption and potential denial of service.\n\nPackage: transformers\nInstalled: 4.51.3\nFixed in: 4.53.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.53.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d2192c9bbd6366d8", "name": "CVE-2025-6921: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements", "shortDescription": {"text": "CVE-2025-6921: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers\n\nThe huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer. The vulnerability arises from the _do_use_weight_decay method, which processes user-controlled regular expressions in the include_in_weight_decay and exclude_from_weight_decay lists. Malicious regular expressions can cause catastrophic backtracking during the re.search call, leading to 100% CPU utilization and a denial of service. This is\n\nPackage: transformers\nInstalled: 4.51.3\nFixed in: 4.53.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.53.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-513576f3f83ee355", "name": "CVE-2026-1839: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements", "shortDescription": {"text": "CVE-2026-1839: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "transformers: HuggingFace Transformers: Arbitrary code execution via malicious checkpoint file\n\nA vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This issue affects all versions of the library supporting `torch>=2.2` when used with PyTorch versions below 2.6, as the `safe_globals()` context manager provides no protection in these versions. An attacker can exploit this vul\n\nPackage: transformers\nInstalled: 4.51.3\nFixed in: 5.0.0rc3\nSeverity: MEDIUM\nFix: Upgrade transformers to 5.0.0rc3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dfb0688847655c9f", "name": "CVE-2025-3777: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements", "shortDescription": {"text": "CVE-2025-3777: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "transformers: Improper Input Validation in huggingface/transformers\n\nHugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL validation using the `startswith()` method, which can be bypassed through URL username injection. This allows attackers to craft URLs that appear to be from YouTube but resolve to malicious domains, potentially leading to phishing attacks, malware distribution, or data exfiltration. The issue is fixed in version 4.52.1\n\nPackage: transformers\nInstalled: 4.51.3\nFixed in: 4.52.1\nSeverity: LOW\nFix: Upgrade transformers to 4.52.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bdff4c39aa7b542e", "name": "CVE-2025-66418: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-66418: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.\n\nPackage: urllib3\nInstalled: 2.4.0\nFixed in: 2.6.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-772dea63be5596f6", "name": "CVE-2025-66471: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-66471: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "urllib3: urllib3 Streaming API improperly handles highly compressed data\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, b\n\nPackage: urllib3\nInstalled: 2.4.0\nFixed in: 2.6.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0f06340f58aad3a1", "name": "CVE-2026-21441: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-21441: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)\n\nurllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in ve\n\nPackage: urllib3\nInstalled: 2.4.0\nFixed in: 2.6.3\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6434fcc50febe87d", "name": "CVE-2026-44431: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2026-44431: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers\n\nurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.\n\nPackage: urllib3\nInstalled: 2.4.0\nFixed in: 2.7.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a00e0cf02c59cec1", "name": "CVE-2025-50181: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-50181: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation\n\nurllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.\n\nPackage: urllib3\nInstalled: 2.4.0\nFixed in: 2.5.0\nSeverity: MEDIUM\nFix: Upgrade urllib3 to 2.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f284203f7489f65d", "name": "CVE-2025-50182: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt", "shortDescription": {"text": "CVE-2025-50182: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "fullDescription": {"text": "urllib3: urllib3 does not control redirects in browsers and Node.js\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest. This means Python libraries can be used to make HTTP requests from a browser or Node.js. Additionally, urllib3 provides a mechanism to control redirects, but the retries and redirect parameters are ignored with Pyodi\n\nPackage: urllib3\nInstalled: 2.4.0\nFixed in: 2.5.0\nSeverity: MEDIUM\nFix: Upgrade urllib3 to 2.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-220df06f1f5f55d2", "name": "CVE-2026-31240: mem0ai 0.1.29 \u2014 advanced_ai_agents/single_agent_apps/ai_customer_support_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-31240: mem0ai 0.1.29 \u2014 advanced_ai_agents/single_agent_apps/ai_customer_support_agent/requirements.txt"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory management API endpoints\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0fc46f49469983ac", "name": "CVE-2026-31241: mem0ai 0.1.29 \u2014 advanced_ai_agents/single_agent_apps/ai_customer_support_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-31241: mem0ai 0.1.29 \u2014 advanced_ai_agents/single_agent_apps/ai_customer_support_agent/requirements.txt"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory deletion API endpoint\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c18f61ca17f45f1a", "name": "CVE-2026-31245: mem0ai 0.1.29 \u2014 advanced_ai_agents/single_agent_apps/ai_customer_support_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-31245: mem0ai 0.1.29 \u2014 advanced_ai_agents/single_agent_apps/ai_customer_support_agent/requirements.txt"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory creation API endpoint\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f875124eb8b678b9", "name": "CVE-2026-7597: mem0ai 0.1.29 \u2014 advanced_ai_agents/single_agent_apps/ai_customer_support_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-7597: mem0ai 0.1.29 \u2014 advanced_ai_agents/single_agent_apps/ai_customer_support_agent/requirements.txt"}, "fullDescription": {"text": "mem0ai mem0 has an Improper Input Validation Issue\n\nA vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: 2.0.0b2\nSeverity: LOW\nFix: Upgrade mem0ai to 2.0.0b2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d836defd2af2f7bc", "name": "CVE-2026-33682: streamlit 1.40.2 \u2014 advanced_ai_agents/single_agent_apps/ai_health_fitness_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.40.2 \u2014 advanced_ai_agents/single_agent_apps/ai_health_fitness_agent/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.40.2\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-18ffb810d8d50efb", "name": "CVE-2026-10804: streamlit 1.40.2 \u2014 advanced_ai_agents/single_agent_apps/ai_health_fitness_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.40.2 \u2014 advanced_ai_agents/single_agent_apps/ai_health_fitness_agent/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.40.2\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9402e870d5e74334", "name": "CVE-2025-69223: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-69223: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.13.3\nSeverity: HIGH\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6b46b3d9dad5ea81", "name": "CVE-2025-69227: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-69227: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via specially crafted POST request\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an infinite loop to occur when assert statements are bypassed, resulting in a DoS attack when processing a POST body. If optimizations are enabled (-O or PYTHONOPTIMIZE=1), and the application includes a handler that uses the Request.post() method, then an attacker may be able to execute a DoS attack with a specially crafted message. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.13.3\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-721b9ec9c985a7a0", "name": "CVE-2025-69228: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-69228: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an application includes a handler that uses the Request.post() method, an attacker may be able to freeze the server by exhausting the memory. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.13.3\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-79675ef3e3ba56ca", "name": "CVE-2025-69229: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-69229: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via excessive CPU usage in chunked message handling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usage when receiving a large number of chunks. If an application makes use of the request.read() method in an endpoint, it may be possible for an attacker to cause the server to spend a moderate amount of blocking CPU time (e.g. 1 second) while processing the request. This could potentially lead to DoS as the server would \n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.13.3\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6143d9b12ae4358b", "name": "CVE-2026-22815: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-22815: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via insufficient header/trailer handling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ac8d00b0f7c992b9", "name": "CVE-2026-34515: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-34515: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Information disclosure via static resource handler on Windows\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5bf48de2f19823ff", "name": "CVE-2026-34516: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-34516: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via excessive multipart headers\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multipart headers may be allowed to use more memory than intended, potentially allowing a DoS vulnerability. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-76178d4410c48ffd", "name": "CVE-2026-34525: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-34525: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Security bypass via multiple Host headers\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6fb848581cc81d47", "name": "CVE-2026-34993: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-34993: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load()\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.14.0\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dcc1adac586e1f06", "name": "CVE-2026-47265: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-47265: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "python-aiohttp: AIOHTTP: Information disclosure via improper handling of cookies during cross-origin redirects\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect. If a developer uses the `cookies` parameter on a per-request basis then sensitive data might be leaked to an attacker if they manage to control a redirect. Version 3.14.0 patches the issue. If unable to upgrade, using a `Cookie` header in the `headers` parameter is not vulnerable.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.14.0\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-19ad3dcb4dffcf1f", "name": "CVE-2026-54273: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-54273: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via excessive pipelined requests\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An attacker may be able to use pipelined requests to use excessive amounts of memory, potentially leading to DoS. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8a3dfed1576ddea2", "name": "CVE-2026-54274: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-54274: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via incomplete websocket frame payloads\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-01ca8a221f18161e", "name": "CVE-2026-54276: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-54276: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Information disclosure via DigestAuthMiddleware after cross-origin redirect\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vulnerability or similar on the target domain for an attacker to be able to execute. Further, the attacker is only receiving the digest, so should only be able to extract the user's credentials if the cryptography is weak or there is some kind of password reuse. This\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-32951b353791b75b", "name": "CVE-2026-54277: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-54277: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via oversized HTTP request lines bypassing max_line_size check\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in parts of an HTTP request in the C parser. If using the optimised C parser (the default in pre-built wheels), then an attacker may be able to send oversized lines through the HTTP parser and use an excessive amount of memory, potentially leading to DoS. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7f7bf5da41847c4d", "name": "CVE-2026-54278: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-54278: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service due to excessive memory consumption from compressed request body\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-89dbe9e452890258", "name": "CVE-2025-53643: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-53643: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP HTTP Request/Response Smuggling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request. If a pure Python version of aiohttp is installed (i.e. without the usual C extensions) or AIOHTTP_NO_EXTENSIONS is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections. Version 3.12.14 contains a p\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.12.14\nSeverity: LOW\nFix: Upgrade aiohttp to 3.12.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-02fe326588dbcab2", "name": "CVE-2025-69224: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-69224: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Request smuggling via non-ASCII characters in HTTP parser\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python HTTP parser may allow a request smuggling attack with the presence of non-ASCII characters. If a pure Python version of AIOHTTP is installed (i.e. without the usual C extensions) or AIOHTTP_NO_EXTENSIONS is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.13.3\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6ad504bbd8dc3fe2", "name": "CVE-2025-69225: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-69225: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Request smuggling vulnerability via non-ASCII decimals in Range header\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.13.3\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-88024ffbdd99c6ea", "name": "CVE-2025-69226: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-69226: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Information disclosure of path components via static file path normalization\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.13.3\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d0f127913e262833", "name": "CVE-2025-69230: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-69230: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via specially crafted invalid cookies\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is accessed in an application, then an attacker may be able to trigger a storm of warning-level logs using a specially crafted Cookie header. This issue is fixed in 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.13.3\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c2d3c9f07a15a300", "name": "CVE-2026-34513: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-34513: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service due to unbounded DNS cache\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2680dc97791c616a", "name": "CVE-2026-34514: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-34514: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Header Injection via content_type parameter manipulation\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5b15888a9122125a", "name": "CVE-2026-34517: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-34517: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via large multipart form fields\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multipart form fields, aiohttp read the entire field into memory before checking client_max_size. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b0ad098edb08a39b", "name": "CVE-2026-34518: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-34518: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Information disclosure via retained Cookie and Proxy-Authorization headers during redirects\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following redirects to a different origin, aiohttp drops the Authorization header, but retains the Cookie and Proxy-Authorization headers. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8eb981584f93a3c7", "name": "CVE-2026-34519: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-34519: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Header injection vulnerability via reason parameter\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the reason parameter when creating a Response may be able to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-894e65a41d29c69c", "name": "CVE-2026-34520: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-34520: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Header injection vulnerability due to improper character handling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c720d8ac9ffb0575", "name": "CVE-2026-50269: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-50269: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: CRLF injection in multipart headers\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar. In the unlikely situation that an application is passing user-controlled strings into MultipartWriter.append(headers=...) or Payload.headers, then an attacker may be able to modify the request to inject headers or change the contents of the request. This vulnerabi\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.14.0\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-04cbf53ec8088abb", "name": "CVE-2026-54275: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-54275: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: TLS SNI check bypass via connection reuse\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an application makes multiple requests to the same domain, but with different per-request server_hostname parameters, then the later calls may succeed by reusing the existing connection when they should have been rejected due to the TLS SNI check. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.14.1\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4dc122be14f7a7d1", "name": "CVE-2026-54279: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-54279: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Host-Only Cookies Become Domain Cookies After CookieJar Persistence\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.14.1\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ebc54ed8ee364e9", "name": "CVE-2026-54280: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-54280: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be able to cause resource starvation temporarily until garbage collection or similar closes the file. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.12.12\nFixed in: 3.14.1\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d651449de50155a7", "name": "CVE-2026-26007: cryptography 45.0.4 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-26007: cryptography 45.0.4 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves\n\ncryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead \n\nPackage: cryptography\nInstalled: 45.0.4\nFixed in: 46.0.5\nSeverity: HIGH\nFix: Upgrade cryptography to 46.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-aa8f829f9e66893b", "name": "GHSA-537c-gmf6-5ccf: cryptography 45.0.4 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "GHSA-537c-gmf6-5ccf: cryptography 45.0.4 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "Vulnerable OpenSSL included in cryptography wheels\n\npyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt.\n\nIf you are building cryptography source (\"sdist\") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on \n\nPackage: cryptography\nInstalled: 45.0.4\nFixed in: 48.0.1\nSeverity: HIGH\nFix: Upgrade cryptography to 48.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c2afdcbc969914e0", "name": "CVE-2026-39892: cryptography 45.0.4 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-39892: cryptography 45.0.4 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API\n\ncryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.\n\nPackage: cryptography\nInstalled: 45.0.4\nFixed in: 46.0.7\nSeverity: MEDIUM\nFix: Upgrade cryptography to 46.0.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-99d7b61abe628114", "name": "CVE-2026-34073: cryptography 45.0.4 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-34073: cryptography 45.0.4 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "python-cryptography: Cryptography: Security bypass due to improper DNS name constraint validation\n\ncryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the \"peer name\" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for b\n\nPackage: cryptography\nInstalled: 45.0.4\nFixed in: 46.0.6\nSeverity: LOW\nFix: Upgrade cryptography to 46.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e1e181c18fecc0a2", "name": "CVE-2026-45409: idna 3.10 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-45409: idna 3.10 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "python-idna: idna: Denial of Service via specially crafted long inputs\n\nInternationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fi\n\nPackage: idna\nInstalled: 3.10\nFixed in: 3.15\nSeverity: MEDIUM\nFix: Upgrade idna to 3.15"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ac30b86e638211f4", "name": "CVE-2026-45134: langchain 0.3.25 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-45134: langchain 0.3.25 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest\n\nPackage: langchain\nInstalled: 0.3.25\nFixed in: 0.3.30\nSeverity: HIGH\nFix: Upgrade langchain to 0.3.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9378ef0c5295354b", "name": "CVE-2026-55443: langchain 0.3.25 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-55443: langchain 0.3.25 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended root directory. Affected behaviors include: a file-search agent middleware that validates a starting directory but not the search pattern or the resolved target of matched files, so glob patterns and symlinks can reach files outside the configured root; prompt- \n\nPackage: langchain\nInstalled: 0.3.25\nFixed in: 1.3.9\nSeverity: MEDIUM\nFix: Upgrade langchain to 1.3.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e6d90b73c3797332", "name": "CVE-2025-6984: langchain-community 0.3.25 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-6984: langchain-community 0.3.25 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "langchain-community: Langchain-community insecure XML parsing\n\nThe langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.\n\nPackage: langchain-community\nInstalled: 0.3.25\nFixed in: 0.3.27\nSeverity: HIGH\nFix: Upgrade langchain-community to 0.3.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eac6b982f5ae6b5b", "name": "CVE-2025-68664: langchain-core 0.3.65 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-68664: langchain-core 0.3.65 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "langchain-core: LangChain: Arbitrary code execution via serialization injection\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd() functions. The functions do not escape dictionaries with 'lc' keys when serializing free-form dictionaries. The 'lc' key is used internally by LangChain to mark serialized objects. When user-controlled data contains this key structure, it is treated as a legitimate LangChain object during deserialization r\n\nPackage: langchain-core\nInstalled: 0.3.65\nFixed in: 1.2.5, 0.3.81\nSeverity: CRITICAL\nFix: Upgrade langchain-core to 1.2.5, 0.3.81"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-f1cb5aa94662b2f4", "name": "CVE-2025-65106: langchain-core 0.3.65 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-65106: langchain-core 0.3.65 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "langchain-core: LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates\n\nLangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template system that allows attackers to access Python object internals through template syntax. This vulnerability affects applications that accept untrusted template strings (not just template variables) in ChatPromptTemplate and related prompt template classes. This issue has been patched in versions 0.3.8\n\nPackage: langchain-core\nInstalled: 0.3.65\nFixed in: 1.0.7, 0.3.80\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.0.7, 0.3.80"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f70baea085964f2f", "name": "CVE-2026-34070: langchain-core 0.3.65 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-34070: langchain-core 0.3.65 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "langchain: path traversal in legacy load_prompt functions in langchain-core\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path injection. When an application passes user-influenced prompt configurations to load_prompt() or load_prompt_from_config(), an attacker can read arbitrary files on the host filesystem, constrained only by file-extension chec\n\nPackage: langchain-core\nInstalled: 0.3.65\nFixed in: 1.2.22\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.2.22"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8de8ea4ce1c378a8", "name": "CVE-2026-44843: langchain-core 0.3.65 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-44843: langchain-core 0.3.65 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call load() with allowed_objects=\"all\". This does not enable arbitrary Python object deserialization, but it does allow any trusted LangChain-serializable object to be revived, which is broader than these runtime path\n\nPackage: langchain-core\nInstalled: 0.3.65\nFixed in: 1.3.3, 0.3.85\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.3.3, 0.3.85"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-17cd2a9d20bdd87d", "name": "CVE-2026-40087: langchain-core 0.3.65 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-40087: langchain-core 0.3.65 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "langchain: incomplete f-string validation in prompt templates\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-string prompt-template validation was incomplete in two respects. First, some prompt template classes accepted f-string templates and formatted them without enforcing the same attribute-access validation as PromptTemplate. In particular, DictPromptTemplate and ImagePromptTemplate could accept templates containing attribute access or indexing expressions and subsequently evaluate t\n\nPackage: langchain-core\nInstalled: 0.3.65\nFixed in: 0.3.84, 1.2.28\nSeverity: MEDIUM\nFix: Upgrade langchain-core to 0.3.84, 1.2.28"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-43b1ccd08e3b2fcf", "name": "CVE-2026-26013: langchain-core 0.3.65 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-26013: langchain-core 0.3.65 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "langchain: SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side Request Forgery (SSRF) attacks by providing malicious image URLs in user input. This vulnerability is fixed in 1.2.11.\n\nPackage: langchain-core\nInstalled: 0.3.65\nFixed in: 1.2.11\nSeverity: LOW\nFix: Upgrade langchain-core to 1.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e76a524cc2268dcd", "name": "CVE-2025-6985: langchain-text-splitters 0.3.8 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.loc", "shortDescription": {"text": "CVE-2025-6985: langchain-text-splitters 0.3.8 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "langchain-text-splitters: XXE Vulnerability in langchain-text-splitters\n\nThe HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing. This vulnerability arises because the class allows the use of arbitrary XSLT stylesheets, which are parsed using lxml.etree.parse() and lxml.etree.XSLT() without any hardening measures. In lxml versions up to 4.9.x, external entities are resolved by default, allowing attackers to read arbitrary local files or perform outbound HTTP(S) fetches. In l\n\nPackage: langchain-text-splitters\nInstalled: 0.3.8\nFixed in: 0.3.9\nSeverity: HIGH\nFix: Upgrade langchain-text-splitters to 0.3.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-535a1e18437ec0da", "name": "CVE-2026-41481: langchain-text-splitters 0.3.8 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lo", "shortDescription": {"text": "CVE-2026-41481: langchain-text-splitters 0.3.8 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "langchain-text-splitters: LangChain: Information Disclosure via Server-Side Request Forgery (SSRF) Redirect Bypass\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters\n 1.1.2, HTMLHeaderTextSplitter.split_text_from_url() validated the initial URL using validate_safe_url() but then performed the fetch with requests.get() with redirects enabled (the default). Because redirect targets were not revalidated, a URL pointing to an attacker-controlled server could redirect to internal, localhost, or cloud metadata endpoints, bypassing SSRF protections. The resp\n\nPackage: langchain-text-splitters\nInstalled: 0.3.8\nFixed in: 1.1.2\nSeverity: MEDIUM\nFix: Upgrade langchain-text-splitters to 1.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f2b7a8513d8041ec", "name": "CVE-2026-45134: langsmith 0.3.45 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-45134: langsmith 0.3.45 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest\n\nPackage: langsmith\nInstalled: 0.3.45\nFixed in: 0.8.0\nSeverity: HIGH\nFix: Upgrade langsmith to 0.8.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d486ff8cd1c386a0", "name": "GHSA-f4xh-w4cj-qxq8: langsmith 0.3.45 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "GHSA-f4xh-w4cj-qxq8: langsmith 0.3.45 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "LangSmith SDK TracingMiddleware: Arbitrary server-side file read\n\n# Summary\n\nAn attacker who can send an HTTP request to a server running the LangSmith SDK's `TracingMiddleware` can cause that server to read an arbitrary file from its local filesystem and upload the contents to LangSmith as a trace attachment. Depending on how the distributed trace system is deployed, triggering a read may not require authentication. Retrieving the contents requires read access to the LangSmith workspace the traces are sent to. The net effect is a trust-boundary crossing: a pa\n\nPackage: langsmith\nInstalled: 0.3.45\nFixed in: 0.8.18\nSeverity: HIGH\nFix: Upgrade langsmith to 0.8.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d2375bc96957e1db", "name": "CVE-2026-41182: langsmith 0.3.45 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-41182: langsmith 0.3.45 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "LangSmith SDK: Streaming token events bypass output redaction\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces streaming output, each chunk is recorded as a new_token event containing the raw token value. These events bypass the redaction pipeline entirely \u2014 prepareRunCreateOrUpdateInputs (\n\nPackage: langsmith\nInstalled: 0.3.45\nFixed in: 0.7.31\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.7.31"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a9bbb088e9fdd17e", "name": "CVE-2025-68480: marshmallow 3.26.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-68480: marshmallow 3.26.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "github.com/marshmallow-code/marshmallow: Marshmallow: Denial of Service via crafted request to Schema.load function\n\nMarshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2, Schema.load(data, many=True) is vulnerable to denial of service attacks. A moderately sized request can consume a disproportionate amount of CPU time. This issue has been patched in version 3.26.2 and 4.1.2.\n\nPackage: marshmallow\nInstalled: 3.26.1\nFixed in: 3.26.2, 4.1.2\nSeverity: MEDIUM\nFix: Upgrade marshmallow to 3.26.2, 4.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5284baa3d495782e", "name": "CVE-2025-67221: orjson 3.10.18 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-67221: orjson 3.10.18 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "orjson: orjson: Denial of Service due to unbounded recursion with deeply nested JSON documents\n\nThe orjson.dumps function in orjson thru 3.11.4 does not limit recursion for deeply nested JSON documents.\n\nPackage: orjson\nInstalled: 3.10.18\nFixed in: 3.11.6\nSeverity: HIGH\nFix: Upgrade orjson to 3.11.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-16c67ceed08d35ac", "name": "CVE-2025-48379: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-48379: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "python-pillow: pillow: Pillow DDS Heap Buffer Overflow\n\nPillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without checking for available space. This only affects users who save untrusted data as a compressed DDS image. This issue has been patched in version 11.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 11.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 11.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a07baf260297ac45", "name": "CVE-2026-25990: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-25990: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image\n\nPillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.1.1\nSeverity: HIGH\nFix: Upgrade pillow to 12.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-64ca0fc86ede45ca", "name": "CVE-2026-40192: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-40192: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing\n\nPillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.2.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f6cdf54be3efd7a1", "name": "CVE-2026-42311: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-42311: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing\n\nPillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.2.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3e47c01a5018cb19", "name": "CVE-2026-54058: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-54058: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image\n\nPillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c368e1deecd66025", "name": "CVE-2026-54059: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-54059: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted PCF font data\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fdd258c512792d94", "name": "CVE-2026-54060: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-54060: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(\"1\", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-05baca043731dbf8", "name": "CVE-2026-55379: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-55379: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted BDF font file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-23d1a94f2aeda7f7", "name": "CVE-2026-55380: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-55380: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted GD 2.x image file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0365e8b39bd5cc6a", "name": "CVE-2026-59197: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-59197: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Native heap out-of-bounds write\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5e37fb82a7ef5936", "name": "CVE-2026-59199: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-59199: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via out-of-bounds write in image processing\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7ed704b482d1e181", "name": "CVE-2026-59200: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-59200: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of service via crafted PDF stream\n\nPillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8b5c300e3ae1a5a8", "name": "CVE-2026-59204: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-59204: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via crafted JPEG2000 image\n\nPillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-87c30b9be5567f61", "name": "CVE-2026-59205: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-59205: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ddc10cba293f1e6b", "name": "CVE-2026-42308: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-42308: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "Pillow: python: Pillow: Denial of Service via integer overflow in font processing\n\nPillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7ac8fc2a5be28ba2", "name": "CVE-2026-42309: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-42309: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via specially crafted coordinate input\n\nPillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polygon and ImageDraw.ImageDraw.line could cause a heap buffer overflow, as nested lists were recursively unpacked beyond the allocated buffer. Coordinate lists are now validated to contain exactly two numeric coordinates. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7380f6239aab4e47", "name": "CVE-2026-42310: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-42310: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via malicious PDF processing\n\nPillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-503866edce928c6a", "name": "CVE-2026-55798: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-55798: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Arbitrary command injection via shell metacharacters in file paths\n\nPillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-495281d30896d68d", "name": "CVE-2026-59198: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-59198: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Information disclosure via TGA RLE encoder out-of-bounds read\n\nPillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.2.1\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-df797bd94c0bf972", "name": "CVE-2026-4539: pygments 2.19.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-4539: pygments 2.19.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "pygments: Pygments: Denial of Service via inefficient regular expression processing in AdlLexer\n\nA security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.\n\nPackage: pygments\nInstalled: 2.19.1\nFixed in: 2.20.0\nSeverity: LOW\nFix: Upgrade pygments to 2.20.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7e36590035d25b51", "name": "CVE-2026-28684: python-dotenv 1.1.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-28684: python-dotenv 1.1.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following\n\npython-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when a cross-device rename fallback is triggered. Users should upgrade to v.1.2.2 or, as a workaround, apply the patch manually.\n\nPackage: python-dotenv\nInstalled: 1.1.0\nFixed in: 1.2.2\nSeverity: MEDIUM\nFix: Upgrade python-dotenv to 1.2.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7a86375de4b92d43", "name": "CVE-2026-25645: requests 2.32.4 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-25645: requests 2.32.4 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "requests: Requests: Security bypass due to predictable temporary file creation\n\nRequests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulner\n\nPackage: requests\nInstalled: 2.32.4\nFixed in: 2.33.0\nSeverity: MEDIUM\nFix: Upgrade requests to 2.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bd293b9b52b8a62c", "name": "CVE-2026-59890: setuptools 80.9.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-59890: setuptools 80.9.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD)\n\nsetuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.\n\nPackage: setuptools\nInstalled: 80.9.0\nFixed in: 83.0.0\nSeverity: MEDIUM\nFix: Upgrade setuptools to 83.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ed3705571cce3614", "name": "CVE-2026-49476: soupsieve 2.7 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-49476: soupsieve 2.7 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector string\n\nSoup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.\n\nPackage: soupsieve\nInstalled: 2.7\nFixed in: 2.8.4\nSeverity: HIGH\nFix: Upgrade soupsieve to 2.8.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3bab062028ca0037", "name": "CVE-2026-49477: soupsieve 2.7 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-49477: soupsieve 2.7 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings\n\nSoup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beautiful Soup .select() / .select_one() to cause CPU exhaustion and denial of service. This issue is fi\n\nPackage: soupsieve\nInstalled: 2.7\nFixed in: 2.8.4\nSeverity: HIGH\nFix: Upgrade soupsieve to 2.8.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4f09e3ee8884d88e", "name": "CVE-2025-66418: urllib3 2.4.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-66418: urllib3 2.4.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.\n\nPackage: urllib3\nInstalled: 2.4.0\nFixed in: 2.6.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5bb7f365e03e551e", "name": "CVE-2025-66471: urllib3 2.4.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-66471: urllib3 2.4.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3 Streaming API improperly handles highly compressed data\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, b\n\nPackage: urllib3\nInstalled: 2.4.0\nFixed in: 2.6.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0f4cdbf73f988dcf", "name": "CVE-2026-21441: urllib3 2.4.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-21441: urllib3 2.4.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)\n\nurllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in ve\n\nPackage: urllib3\nInstalled: 2.4.0\nFixed in: 2.6.3\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d06c67096bfd994d", "name": "CVE-2026-44431: urllib3 2.4.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2026-44431: urllib3 2.4.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers\n\nurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.\n\nPackage: urllib3\nInstalled: 2.4.0\nFixed in: 2.7.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cb626db39eb36222", "name": "CVE-2025-50181: urllib3 2.4.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-50181: urllib3 2.4.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation\n\nurllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.\n\nPackage: urllib3\nInstalled: 2.4.0\nFixed in: 2.5.0\nSeverity: MEDIUM\nFix: Upgrade urllib3 to 2.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-accc4e9114812943", "name": "CVE-2025-50182: urllib3 2.4.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock", "shortDescription": {"text": "CVE-2025-50182: urllib3 2.4.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3 does not control redirects in browsers and Node.js\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest. This means Python libraries can be used to make HTTP requests from a browser or Node.js. Additionally, urllib3 provides a mechanism to control redirects, but the retries and redirect parameters are ignored with Pyodi\n\nPackage: urllib3\nInstalled: 2.4.0\nFixed in: 2.5.0\nSeverity: MEDIUM\nFix: Upgrade urllib3 to 2.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2b556dbe3f0fc26f", "name": "CVE-2026-31240: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/ai_travel_agent_memory/requirements.txt", "shortDescription": {"text": "CVE-2026-31240: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/ai_travel_agent_memory/requirements.txt"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory management API endpoints\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4c0b0e7228dae96e", "name": "CVE-2026-31241: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/ai_travel_agent_memory/requirements.txt", "shortDescription": {"text": "CVE-2026-31241: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/ai_travel_agent_memory/requirements.txt"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory deletion API endpoint\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8436f2c64e092e75", "name": "CVE-2026-31245: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/ai_travel_agent_memory/requirements.txt", "shortDescription": {"text": "CVE-2026-31245: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/ai_travel_agent_memory/requirements.txt"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory creation API endpoint\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-72503a3e0b2c6082", "name": "CVE-2026-7597: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/ai_travel_agent_memory/requirements.txt", "shortDescription": {"text": "CVE-2026-7597: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/ai_travel_agent_memory/requirements.txt"}, "fullDescription": {"text": "mem0ai mem0 has an Improper Input Validation Issue\n\nA vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: 2.0.0b2\nSeverity: LOW\nFix: Upgrade mem0ai to 2.0.0b2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f8f7396dd61efb02", "name": "CVE-2026-31240: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/llm_app_personalized_memory/requirement", "shortDescription": {"text": "CVE-2026-31240: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/llm_app_personalized_memory/requirements.txt"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory management API endpoints\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e4073c9a19474c2b", "name": "CVE-2026-31241: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/llm_app_personalized_memory/requirement", "shortDescription": {"text": "CVE-2026-31241: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/llm_app_personalized_memory/requirements.txt"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory deletion API endpoint\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5080deef6205b91b", "name": "CVE-2026-31245: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/llm_app_personalized_memory/requirement", "shortDescription": {"text": "CVE-2026-31245: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/llm_app_personalized_memory/requirements.txt"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory creation API endpoint\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-17fad5649a68d9e4", "name": "CVE-2026-7597: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/llm_app_personalized_memory/requirements", "shortDescription": {"text": "CVE-2026-7597: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/llm_app_personalized_memory/requirements.txt"}, "fullDescription": {"text": "mem0ai mem0 has an Improper Input Validation Issue\n\nA vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: 2.0.0b2\nSeverity: LOW\nFix: Upgrade mem0ai to 2.0.0b2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-23811568eae1ff0f", "name": "CVE-2026-31240: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/local_chatgpt_with_memory/requirements.", "shortDescription": {"text": "CVE-2026-31240: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/local_chatgpt_with_memory/requirements.txt"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory management API endpoints\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-17ae306f9a6c1945", "name": "CVE-2026-31241: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/local_chatgpt_with_memory/requirements.", "shortDescription": {"text": "CVE-2026-31241: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/local_chatgpt_with_memory/requirements.txt"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory deletion API endpoint\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8345a2494a24f7cd", "name": "CVE-2026-31245: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/local_chatgpt_with_memory/requirements.", "shortDescription": {"text": "CVE-2026-31245: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/local_chatgpt_with_memory/requirements.txt"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory creation API endpoint\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8d6751bfe8d8e6ac", "name": "CVE-2026-7597: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/local_chatgpt_with_memory/requirements.t", "shortDescription": {"text": "CVE-2026-7597: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/local_chatgpt_with_memory/requirements.txt"}, "fullDescription": {"text": "mem0ai mem0 has an Improper Input Validation Issue\n\nA vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: 2.0.0b2\nSeverity: LOW\nFix: Upgrade mem0ai to 2.0.0b2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2e1076f99c8eeddf", "name": "CVE-2026-31240: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/multi_llm_memory/requirements.txt", "shortDescription": {"text": "CVE-2026-31240: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/multi_llm_memory/requirements.txt"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory management API endpoints\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the requester's identity or permissions. A remote attacker can exploit this by sending unauthenticated requests to modify, overwrite, or delete arbitrary memory records, leading to unauthorized data manipulation and potential data loss.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9d05b952d35b47f4", "name": "CVE-2026-31241: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/multi_llm_memory/requirements.txt", "shortDescription": {"text": "CVE-2026-31241: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/multi_llm_memory/requirements.txt"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory deletion API endpoint\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters. A remote attacker can exploit this by sending unauthenticated DELETE requests to erase memory data for any user, leading to unauthorized data loss and denial of service.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c2445bae45c78221", "name": "CVE-2026-31245: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/multi_llm_memory/requirements.txt", "shortDescription": {"text": "CVE-2026-31245: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/multi_llm_memory/requirements.txt"}, "fullDescription": {"text": "mem0 server lacks authentication and authorization controls for its memory creation API endpoint\n\nThe mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending unauthenticated POST requests to create malicious or spoofed memory entries in the database, leading to unauthorized data injection and potential data pollution.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-11e3f118ba82d34f", "name": "CVE-2026-7597: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/multi_llm_memory/requirements.txt", "shortDescription": {"text": "CVE-2026-7597: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/multi_llm_memory/requirements.txt"}, "fullDescription": {"text": "mem0ai mem0 has an Improper Input Validation Issue\n\nA vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 62dca096f9236010ca15fea9ba369ba740b86b7a. Applying a patch is the recommended action to fix this issue.\n\nPackage: mem0ai\nInstalled: 0.1.29\nFixed in: 2.0.0b2\nSeverity: LOW\nFix: Upgrade mem0ai to 2.0.0b2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8a11f90440ae2bbe", "name": "CVE-2026-44573: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44573: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed data route, allowing an attacker to retrieve SSR JSON for protected pages without passing the intende\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-864c94e0c162973c", "name": "CVE-2026-44574: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44574: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Authorization bypass via crafted query parameters\n\nNext.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check. This vulnerability is fixed in 1\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-23e834cb601b197d", "name": "CVE-2026-44575: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44575: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Unauthorized access to protected content via middleware bypass\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e6a68be8af210ae1", "name": "CVE-2026-44578: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44578: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests\n\nNext.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-da6bfa426e1d4c24", "name": "CVE-2026-44579: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44579: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service via crafted POST requests to server actions\n\nNext.js is a React framework for building full-stack web applications. From  to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open for an extended period, consuming file descriptors and server capacity until legitimate users are den\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5d357be8a71a3aa8", "name": "CVE-2026-45109: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-45109: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.18, 16.2.6\nSeverity: HIGH\nFix: Upgrade next to 15.5.18, 16.2.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-28dc9e364afe957f", "name": "CVE-2026-64641: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-64641: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Denial of Service in App Router using Server Actions\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.\n\n## Workarounds\n\nNo workaround exists besides upgrading. Applications using Pages Router or not using Server Actions are not vulnerable.\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-39f148ad58f13d79", "name": "CVE-2026-64642: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-64642: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router built with Turbopack and a **single** entry in `config.i18n.locales` can bypass middleware/proxy based authentication.\n\n## Workarounds\n\nIf you cannot upgrade immediately, enforce authorization in the page's server-side data path instead of relying solely on middleware.\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2bc820d50b4e0143", "name": "CVE-2026-64645: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-64645: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\n## Impact\n\nA `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's\u00a0hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect.\n\nThis affects any destination that puts a dynamic segmen\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4fca12546744e962", "name": "CVE-2026-64649: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-64649: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in Server Actions on custom servers\n\n## Impact\n\nWhen a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization.\n\nApplications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c9615fa6f8a15461", "name": "GHSA-8h8q-6873-q5fj: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "GHSA-8h8q-6873-q5fj: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js Vulnerable to Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh). \n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of \n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8b48486713516c3e", "name": "GHSA-q4gf-8mx6-v5v3: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "GHSA-q4gf-8mx6-v5v3: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js has a Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react/security/advisories/GHSA-479c-33wc-g2pg). You can read more about this advisory our [this changelog](https://vercel.com/changelog/summary-of-cve-2026-23869).\n\nA specially crafted HTTP request can be sent to any App Rout\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.15, 16.2.3\nSeverity: HIGH\nFix: Upgrade next to 15.5.15, 16.2.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0c14ce8b5b659d11", "name": "CVE-2026-27978: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-27978: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: null origin can bypass Server Actions CSRF checks\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, `origin: null` was treated as a \"missing\" origin during Server Action CSRF validation. As a result, requests from opaque contexts (such as sandboxed iframes) could bypass origin verification instead of being validated as cross-origin requests. An attacker could induce a victim browser to submit Server Actions from a sandboxed context, potentially executing state-changing\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 16.1.7\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7ef43a4b79e4c619", "name": "CVE-2026-27979: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-27979: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Unbounded postponed resume buffering can lead to DoS\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing the `next-resume: 1` header (corresponding with a PPR resume request) would buffer request bodies without consistently enforcing `maxPostponedStateSize` in certain setups. The previous mitigation protected minimal-mode deployments, but equivalent non-minimal deployments remained vulnerable to the same unbounded postponed resume-body buffering behavio\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 16.1.7\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1b6265aec4d3cf58", "name": "CVE-2026-27980: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-27980: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Unbounded next/image disk cache growth can exhaust storage\n\nNext.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unbounded cache growth. An attacker could generate many unique image-optimization variants and exhaust disk space, causing denial of service. This is fixed in version 16.1.7 by adding an LRU-backed disk cache with `images.maximumDiskCacheSize`, including e\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 16.1.7, 15.5.14\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d39f3e8b86d44266", "name": "CVE-2026-29057: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-29057: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: HTTP request smuggling in rewrites\n\nNext.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfer-Encoding: chunked` could trigger request boundary disagreement between the proxy and backend. This could allow request smuggling through rewritten routes. An attacker could smuggle a second request to unintended backend routes (for example, interna\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 16.1.7, 15.5.13\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-046872394d6e413a", "name": "CVE-2026-44576: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44576: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning vulnerability in React Server Components\n\nNext.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later visitors receive component payloads instead of the expected HTML. This vulnerability is fixed in 15.5\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-56f1bd6e0c7505e0", "name": "CVE-2026-44577: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44577: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Denial of Service via Image Optimization API\n\nNext.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the /_next/image endpoint that match the images.localPatterns configuration (by default, all patterns are allowed). This vulnerability\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b54af13d8c83e19a", "name": "CVE-2026-44580: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44580: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Cross-site scripting allows arbitrary code execution via untrusted script content\n\nNext.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to break out of the intended script context and execute arbitrary JavaScript in a visitor's browser. This vu\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-40e3628ab9a23dcc", "name": "CVE-2026-44581: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44581: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Stored Cross-Site Scripting via malformed nonce values in cached responses\n\nNext.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to poison cached responses and cause script execution for later visitors. This vulnerability is fixed i\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-46e413729a139427", "name": "CVE-2026-64643: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-64643: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Unauthenticated disclosure of internal Server Function endpoints\n\n## Impact\n\nIn Next.js applications using App Router, Server Actions (`use server`) or `use cache` endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used.\n\nServer Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references).\n\nAffected users are applications using App Router + Server Actions.  \n\nBy itself, this disclosure is typically a recon/enumeration primi\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-adfb9f95c5355e35", "name": "CVE-2026-64644: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-64644: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Denial of Service in the Image Optimization API using SVGs\n\n### Impact\n\nWhen self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in  `/_next/image` endpoints.\n\n- If you are using `config.images.remotePatterns`, only the patterns in that array are impacted.\n- If you are using `config.images.unoptimized: true`, you are NOT impacted.\n- If you are using `config.images.loader: 'custom'`\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a1f07d2f536e7c35", "name": "CVE-2026-64646: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-64646: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Unbounded Server Action payload in Edge runtime\n\n## Impact\n\nRequests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime\n\n## Workarounds\n\nIf you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should be allowed at max by your hosting provider.\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-76f99002cabed206", "name": "CVE-2026-64647: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-64647: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for `\uc083\uc083` and `\uc104\uc104` in the request body would share the same cache.\n\n##\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-882e13302b26c632", "name": "CVE-2026-64648: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-64648: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis only applies to `fetch` calls with a request that has a different init than the one passed to `fetch`.\nSafe: `fetch(new Request(init), init)`\nUnsafe: `fetch(new Request(init), aDifferentInit)`\n\n## Work\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c4f6e28fa224c593", "name": "CVE-2026-27977: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-27977: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: null origin can bypass dev HMR websocket CSRF checks\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in `next dev`, cross-site protection for internal websocket endpoints could treat `Origin: null` as a bypass case even if `allowedDevOrigins` is configured, allowing privacy-sensitive/opaque contexts (for example sandboxed documents) to connect unexpectedly. If a dev server is reachable from attacker-controlled content, an attacker may be able to connect to the HMR webso\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 16.1.7\nSeverity: LOW\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0dcd17bd64e5e46d", "name": "CVE-2026-44572: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44572: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service due to improper handling of x-nextjs-data header with redirects\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When that happened, the middleware/proxy could treat the request as a data request and replace the standard Location redirect header with the internal x-nextjs-redirect header. Browsers do not follow x-nextjs-redirect, so the response became an unusable red\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cfe2acbcefe904e7", "name": "CVE-2026-44582: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44582: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning allows incorrect response delivery\n\nNext.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL. This vulnerability is fixed in 15.5.16 and 16.2.5.\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ea6b3d387573cc3", "name": "CVE-2026-41305: postcss 8.4.31 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.4.31\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bb375e63f791024b", "name": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json", "shortDescription": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "fullDescription": {"text": "sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591\n\n### Impact\n\nA number of vulnerabilities, two rated as \"High\" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency.\n\nThose processing untrusted input with versions of sharp prior to 0.35.0 are affected.\n\n### Patches\n\n#### Using prebuilt binaries provided by sharp?\n\nMost people rely on the prebuilt binaries provided by sharp.\n\nPlease upgrade sharp to the latest version, currently 0.35.3, which provides libvips 8.18.3.\n\n#### Using a globally-installed libvips?\n\nP\n\nPackage: sharp\nInstalled: 0.34.5\nFixed in: 0.35.0\nSeverity: HIGH\nFix: Upgrade sharp to 0.35.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8357761e3aca4343", "name": "CVE-2025-58754: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2025-58754: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios DoS via lack of data size check\n\nAxios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP. Instead, its Node http adapter decodes the entire payload into memory (`Buffer`/`Blob`) and returns a synthetic 200 response. This path ignores `maxContentLength` / `maxBodyLength` (which only protect HTTP responses), so an attacker can supply a very large `data:` URI a\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.12.0, 0.30.2\nSeverity: HIGH\nFix: Upgrade axios to 1.12.0, 0.30.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-47856eb92b31756c", "name": "CVE-2026-25639: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-25639: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providing a malicious configuration object created via JSON.parse(), causing complete denial of service. This vulnerability is fixed in versions 0.30.3 and 1.13.5.\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.13.5, 0.30.3\nSeverity: HIGH\nFix: Upgrade axios to 1.13.5, 0.30.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0c66927718fb7d64", "name": "CVE-2026-42033: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-42033: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: HTTP Transport Hijacking via Prototype Pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify every JSON response before the application sees it, or (b) fully hijack the underlying HTTP transport, gaining access to request credentials, headers, and body. The precondition is prototype pollution from a separate source in the same \n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.15.1, 0.31.1\nSeverity: HIGH\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-75cef56f99b4558f", "name": "CVE-2026-42035: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-42035: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Arbitrary HTTP header injection via prototype pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP headers into outgoing requests. The vulnerability exploits duck-type checking of the data payload, where if Object.prototype is polluted with getHeaders, append, pipe, on, once, and Symbol.toStringTag, Axios misidentifies any plain object payload as a FormData instance an\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.15.1, 0.31.1\nSeverity: HIGH\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9361e36af728cf95", "name": "CVE-2026-42043: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-42043: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: NO_PROXY bypass via crafted URL\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. This vulnerability is due to an incomplete for CVE-2025-62718, This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.15.1, 0.31.1\nSeverity: HIGH\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ffa4e055143e0f10", "name": "CVE-2026-42264: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-42264: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Prototype pollution allows information disclosure and request manipulation\n\nAxios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype is polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request.\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.15.2\nSeverity: HIGH\nFix: Upgrade axios to 1.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-91faa7c3b4c6715d", "name": "CVE-2026-44486: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-44486: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure of proxy credentials via HTTP redirects\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios\u2019 Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorization header. If Axios then follows a redirect and the redirected request is no longer sent through that proxy, the stale Proxy-Authorization header can remain on the redirected request and be sent to the redirect target. T\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.16.0, 0.32.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-52d83060249ff34f", "name": "CVE-2026-44487: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-44487: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure of proxy credentials via redirect flows\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios\u2019s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial HTTP request is sent through an authenticated HTTP proxy, redirects are followed, and the redirected URL is no longer proxied. Under affected redirect shapes, the final origin can receive the proxy credential that was in\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.16.0, 0.32.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e5b20a6d125019a6", "name": "CVE-2026-44488: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-44488: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Denial of Service due to unenforced request and response size limits\n\nAxios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments where axios resolved to the fetch adapter, could receive or send bodies larger than maxContentLength or maxBodyLength despite those limits being explicitly configured. This can cause resource exhaustion in server-side usag\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.16.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-706538ce1cd45397", "name": "CVE-2026-44494: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-44494: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack \u2014 intercepting, reading, and modifying all HTTP traffic including authentication credentials. The HTTP adapter at lib/adapters/http.js:670 reads config.proxy via standard property access, whic\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.16.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7ff63965ea7f2876", "name": "CVE-2026-44495: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-44495: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure due to prototype pollution vulnerability\n\nAxios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions may treat that inherited value as request configuration or as an option validator. Axios does not itself create the prototype pollution. Exploitability requires a separate prototype-p\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.15.2, 0.31.1\nSeverity: HIGH\nFix: Upgrade axios to 1.15.2, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b71c8793b57e2583", "name": "CVE-2026-44496: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-44496: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name\n\nAxios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who can influence the cookie name passed to axios can cause expensive regex backtracking while axios reads document.cookie. The practical impact is client-side availability degradation, such as freezing the\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.16.0, 0.32.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-55d06ad407c1338f", "name": "CVE-2025-62718: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2025-62718: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the configured proxy. This goes against what developers expect and lets attackers force requests through a proxy, even if NO_PROXY is set up to protect loopback or internal services. This is\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.15.0, 0.31.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.0, 0.31.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-778fb3daf7e5b907", "name": "CVE-2026-40175: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-40175: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Remote Code Execution via Prototype Pollution escalation\n\nAxios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound requests. This vulnerability is fixed in 1.15.0 and 0.3.1.\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.15.0, 0.31.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.0, 0.31.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-35cd67467e3864be", "name": "CVE-2026-42034: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-42034: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Denial of Service via oversized streamed uploads bypassing body limits\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). Oversized streamed uploads are sent fully even when the caller sets strict body limits. This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9a77561fa1637d08", "name": "CVE-2026-42036: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-42036: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Denial of Service via unbounded stream consumption when 'responseType: 'stream'' is used\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLength. This bypasses configured response-size limits and allows unbounded downstream consumption. This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1ffa864e8f56590f", "name": "CVE-2026-42037: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-42037: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Node.js: Axios: Information disclosure via CRLF injection in multipart Content-Type header\n\nAxios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formDataToStream.js interpolates value.type directly into the Content-Type header of each multipart part without sanitizing CRLF (\\r\\n) sequences. An attacker who controls the .type property of a Blob/File-like object (e.g., via a user-uploaded file in a Node.js proxy service) can inject arbitrary MIME part headers into the multipart form-data body. This bypa\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.15.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d4a852ffd50d9b4f", "name": "CVE-2026-42038: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-42038: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure due to `no_proxy` bypass\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is incomplete. When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still route through the proxy instead of bypassing it. The shouldBypassProxy() function does pure string matching \u2014 it does not resolve IP aliases or loopback equivalents. This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0ebc2dce1af9d400", "name": "CVE-2026-42039: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-42039: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5e59c86be820a179", "name": "CVE-2026-42041: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-42041: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling. The root cause is that validateStatus is the only config property using the mergeDirectKeys\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8d2c19e5b4e77c23", "name": "CVE-2026-42042: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-42042: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: XSRF token bypass leading to information disclosure\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantics instead of strict boolean comparison for the withXSRFToken config property. When this property is set to any truthy non-boolean value (via prototype pollution or misconfiguration), the same-origin check (isURLSameOrigin) is short-circuited, causing XSRF tokens to be sent to all request targets including cross-origin s\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-97f95545c730c79d", "name": "CVE-2026-42044: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-42044: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget\n\nAxios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into surgical, invisible modification of all JSON API responses \u2014 including privilege escalation, balance manipulation, and authorization bypass. The default transformResponse function at lib/defaults/index.js:124 calls JSON.parse(data, \n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.15.2\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-edfa93a1f32d0375", "name": "CVE-2026-44490: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-44490: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure and denial of service due to prototype pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency in the same process (e.g. lodash _.merge / CVE-2018-16487), axios silently picks up the polluted values. (1) lib/utils.js line 406 builds merge()'s accumulator as result = {}, so result[targetKey] (line 414) walks Object.prototype and the polluted bucket's own keys are copied into the mer\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.16.0, 0.32.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a946177615e8a6d9", "name": "GHSA-42h9-826w-cgv3: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "GHSA-42h9-826w-cgv3: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "Axios: Excessive recursion in formDataToJSON can cause denial of service\n\n## Summary\nAxios versions `0.28.0` and later contain uncontrolled recursion in `formDataToJSON`, the helper behind the public `axios.formToJSON()` / named `formToJSON` API and the default request transform used when FormData is sent with an `application/json` content type.\n\nApplications are affected when they pass attacker-controlled `FormData` field names into this functionality. A field name with thousands of nested bracket segments can exhaust the JavaScript call stack and throw `RangeError: \n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ad6aa5d607304df5", "name": "GHSA-7q8q-rj6j-mhjq: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "GHSA-7q8q-rj6j-mhjq: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "Axios: Nested axios option objects can consume polluted prototype values\n\n## Summary\n\nAxios can consume inherited properties from nested request option objects when the JavaScript process already has a polluted `Object.prototype`.\n\nThe top-level merged config is protected with a null prototype, but nested plain objects such as `auth` and `paramsSerializer` are cloned into ordinary objects. If application code passes placeholders such as `auth: {}` or `paramsSerializer: {}`, inherited `username`, `password`, `encode`, or `serialize` properties can influence outbound re\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-033ad7cae7e63c84", "name": "GHSA-jqh4-m9w3-8hp9: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "GHSA-jqh4-m9w3-8hp9: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`\n\n## Summary\n\naxios\u2019 fetch adapter does not enforce `maxBodyLength` for live WHATWG `ReadableStream` request bodies whose size cannot be determined before dispatch. Applications that use `adapter: \"fetch\"` and rely on `maxBodyLength` to cap untrusted upload/proxy streams can send the full stream even when it exceeds the configured limit.\n\nThis affects fetch-adapter usage in edge runtimes where fetch is selected, and in Node.js or browser environments where the fetch adapter is explicitly selected.\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-42027386bfdd7ee6", "name": "GHSA-mmx7-hfxf-jppx: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "GHSA-mmx7-hfxf-jppx: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "Axios: Prototype pollution gadgets can alter axios request construction\n\n## Summary\n\naxios is vulnerable to read-side prototype-pollution gadgets when `Object.prototype` has already been polluted by another vulnerability or dependency. The most broadly reachable issue is in the bodyless method aliases: `axios.get()`, `axios.delete()`, `axios.head()`, and `axios.options()` read inherited `data` before config normalization, causing attacker-controlled body data to be sent on requests that did not explicitly set a body.\n\nAdditional low-level paths affect consumers that \n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.18.0, 0.33.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0, 0.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-daf0e90cf7e379b4", "name": "GHSA-pmv8-rq9r-6j72: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "GHSA-pmv8-rq9r-6j72: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "Axios: Deep formToJSON Key Recursion Can Cause Denial of Service\n\n## Summary\n\nAxios versions starting with `0.28.0` contain uncontrolled recursion in `formDataToJSON`, which is exposed as `axios.formToJSON()` and used internally when axios serialises `FormData` with `Content-Type: application/json`.\n\nIf an application passes attacker-controlled `FormData` field names to this functionality, a field name with thousands of nested bracket segments can exhaust the JavaScript call stack and cause denial of service for that request or, in applications without appropr\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1387e8bd61c1a79f", "name": "CVE-2026-42040: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-42040: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Incorrect null byte handling can lead to data integrity issues\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the encode() function in lib/helpers/AxiosURLSearchParams.js contains a character mapping (charMap) at line 21 that reverses the safe percent-encoding of null bytes. After encodeURIComponent('\\x00') correctly produces the safe sequence %00, the charMap entry '%00': '\\x00' converts it back to a raw null byte. Primary impact is limited because the standard axios request flow is not affected. This vulnerab\n\nPackage: axios\nInstalled: 1.11.0\nFixed in: 1.15.1, 0.31.1\nSeverity: LOW\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-968cdb29a8cc2611", "name": "CVE-2026-34769: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-34769: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "Electron: Electron: Arbitrary code execution and security bypass via undocumented command-line switches\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented commandLineSwitches webPreference allowed arbitrary switches to be appended to the renderer process command line. Apps that construct webPreferences by spreading untrusted configuration objects may inadvertently allow an attacker to inject switches that disable renderer sandboxing or web security controls. Apps are on\n\nPackage: electron\nInstalled: 37.2.6\nFixed in: 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8\nSeverity: HIGH\nFix: Upgrade electron to 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7b0df819631d02ef", "name": "CVE-2026-34770: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-34770: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "Electron: Use-after-free in PowerMonitor on Windows and macOS\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-free. After the native PowerMonitor object is garbage-collected, the associated OS-level resources (a message window on Windows, a shutdown handler on macOS) retain dangling references. A subsequent session-change event (Windows) or system shutdown (macOS) derefer\n\nPackage: electron\nInstalled: 37.2.6\nFixed in: 38.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8\nSeverity: HIGH\nFix: Upgrade electron to 38.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5c869c18e2580a27", "name": "CVE-2026-34771: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-34771: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "electron: Electron: Memory corruption or application crash via use-after-free in permission request handling\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that register an asynchronous session.setPermissionRequestHandler() may be vulnerable to a use-after-free when handling fullscreen, pointer-lock, or keyboard-lock permission requests. If the requesting frame navigates or the window closes while the permission handler is pending, invoking the stored callback dereferences freed me\n\nPackage: electron\nInstalled: 37.2.6\nFixed in: 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8\nSeverity: HIGH\nFix: Upgrade electron to 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f6827d8b25534c77", "name": "CVE-2026-34774: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-34774: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "Electron: Electron: Memory corruption and crash due to use-after-free in offscreen rendering\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0, apps that use offscreen rendering and allow child windows via window.open() may be vulnerable to a use-after-free. If the parent offscreen WebContents is destroyed while a child window remains open, subsequent paint frames on the child dereference freed memory, which may lead to a crash or memory corruption. Apps are only affected if they use offsc\n\nPackage: electron\nInstalled: 37.2.6\nFixed in: 39.8.1, 40.7.0, 41.0.0\nSeverity: HIGH\nFix: Upgrade electron to 39.8.1, 40.7.0, 41.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-082547f0c749b0ff", "name": "CVE-2025-55305: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2025-55305: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "electron: ASAR Integrity Bypass via resource modification\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impacts apps that have the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses enabled. Apps without these fuses enabled are not impacted. This issue is fixed in versions 35.7.5, 36.8.1, 37.3.1 and \n\nPackage: electron\nInstalled: 37.2.6\nFixed in: 35.7.5, 36.8.1, 37.3.1, 38.0.0-beta.6\nSeverity: MEDIUM\nFix: Upgrade electron to 35.7.5, 36.8.1, 37.3.1, 38.0.0-beta.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b0e58a3e96b3910c", "name": "CVE-2026-34765: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-34765: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "electron: Electron: Arbitrary code execution or information disclosure via incorrect window handling\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls window.open() with a target name, Electron did not correctly scope the named-window lookup to the opener's browsing context group. A renderer could navigate an existing child window that was opened by a different, unrelated renderer if both used the same target name. If that existing child was created with more permissi\n\nPackage: electron\nInstalled: 37.2.6\nFixed in: 39.8.5, 40.8.5, 41.1.0, 42.0.0-alpha.5\nSeverity: MEDIUM\nFix: Upgrade electron to 39.8.5, 40.8.5, 41.1.0, 42.0.0-alpha.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-56f313cc5a780094", "name": "CVE-2026-34767: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-34767: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "electron: Electron: HTTP Response Header Injection via attacker-controlled input\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.3, 40.8.3, and 41.0.3, apps that register custom protocol handlers via protocol.handle() / protocol.registerSchemesAsPrivileged() or modify response headers via webRequest.onHeadersReceived may be vulnerable to HTTP response header injection if attacker-controlled input is reflected into a response header name or value. An attacker who can influence a header valu\n\nPackage: electron\nInstalled: 37.2.6\nFixed in: 38.8.6, 39.8.3, 40.8.3, 41.0.3\nSeverity: MEDIUM\nFix: Upgrade electron to 38.8.6, 39.8.3, 40.8.3, 41.0.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e44d2960d6168ad4", "name": "CVE-2026-34772: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-34772: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "Electron: Electron: Use-after-free vulnerability leads to memory corruption or crash\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that allow downloads and programmatically destroy sessions may be vulnerable to a use-after-free. If a session is torn down while a native save-file dialog is open for a download, dismissing the dialog dereferences freed memory, which may lead to a crash or memory corruption. Apps that do not destroy sessions at runtime, or that\n\nPackage: electron\nInstalled: 37.2.6\nFixed in: 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.7\nSeverity: MEDIUM\nFix: Upgrade electron to 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5c0e5f52c7021461", "name": "CVE-2026-34773: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-34773: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "electron: Electron: Protocol handler hijacking via improper validation of protocol names\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on Windows, app.setAsDefaultProtocolClient(protocol) did not validate the protocol name before writing to the registry. Apps that pass untrusted input as the protocol name may allow an attacker to write to arbitrary subkeys under HKCU\\Software\\Classes\\, potentially hijacking existing protocol handlers. Apps are only affected if they call ap\n\nPackage: electron\nInstalled: 37.2.6\nFixed in: 38.8.6, 39.8.1, 40.8.1, 41.0.0\nSeverity: MEDIUM\nFix: Upgrade electron to 38.8.6, 39.8.1, 40.8.1, 41.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a3a4cd47183cc6a5", "name": "CVE-2026-34775: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-34775: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "Electron: Electron: Arbitrary code execution and information disclosure due to incorrect Node.js integration scoping\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0, the nodeIntegrationInWorker webPreference was not correctly scoped in all configurations. In certain process-sharing scenarios, workers spawned in frames configured with nodeIntegrationInWorker: false could still receive Node.js integration. Apps are only affected if they enable nodeIntegrationInWorker. Apps that do not use nodeIntegrationI\n\nPackage: electron\nInstalled: 37.2.6\nFixed in: 38.8.6, 39.8.4, 40.8.4, 41.0.0\nSeverity: MEDIUM\nFix: Upgrade electron to 38.8.6, 39.8.4, 40.8.4, 41.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5a5b01efc88e67fe", "name": "CVE-2026-34776: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-34776: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "Electron: Electron: Information disclosure via crafted second-instance message\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on macOS and Linux, apps that call app.requestSingleInstanceLock() were vulnerable to an out-of-bounds heap read when parsing a crafted second-instance message. Leaked memory could be delivered to the app's second-instance event handler. This issue is limited to processes running as the same user as the Electron app. Apps that do not call a\n\nPackage: electron\nInstalled: 37.2.6\nFixed in: 38.8.6, 39.8.1, 40.8.1, 41.0.0\nSeverity: MEDIUM\nFix: Upgrade electron to 38.8.6, 39.8.1, 40.8.1, 41.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b441347c52a5b873", "name": "CVE-2026-34777: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-34777: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "Electron: Electron: Unauthorized permission granting and information disclosure via incorrect iframe origin\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, when an iframe requests fullscreen, pointerLock, keyboardLock, openExternal, or media permissions, the origin passed to session.setPermissionRequestHandler() was the top-level page's origin rather than the requesting iframe's origin. Apps that grant permissions based on the origin parameter or webContents.getURL() may inadvertently grant pe\n\nPackage: electron\nInstalled: 37.2.6\nFixed in: 38.8.6, 39.8.1, 40.8.1, 41.0.0\nSeverity: MEDIUM\nFix: Upgrade electron to 38.8.6, 39.8.1, 40.8.1, 41.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ff8fc12f7c3c6a35", "name": "CVE-2026-34778: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-34778: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "Electron: Electron: Integrity issue due to IPC channel spoofing by a service worker\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, a service worker running in a session could spoof reply messages on the internal IPC channel used by webContents.executeJavaScript() and related methods, causing the main-process promise to resolve with attacker-controlled data. Apps are only affected if they have service workers registered and use the result of webContents.executeJavaScrip\n\nPackage: electron\nInstalled: 37.2.6\nFixed in: 38.8.6, 39.8.1, 40.8.1, 41.0.0\nSeverity: MEDIUM\nFix: Upgrade electron to 38.8.6, 39.8.1, 40.8.1, 41.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-82ad62f1ce4e0992", "name": "CVE-2026-34779: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-34779: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "Electron: AppleScript injection in app.moveToApplicationsFolder on macOS\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on macOS, app.moveToApplicationsFolder() used an AppleScript fallback path that did not properly handle certain characters in the application bundle path. Under specific conditions, a crafted launch path could lead to arbitrary AppleScript execution when the user accepted the move-to-Applications prompt. Apps are only affected if the\n\nPackage: electron\nInstalled: 37.2.6\nFixed in: 38.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8\nSeverity: MEDIUM\nFix: Upgrade electron to 38.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0878e27033ca0657", "name": "CVE-2026-34764: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-34764: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "Electron: Electron: Memory corruption or crash due to use-after-free in offscreen rendering with shared textures.\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alpha.1 to before 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that use offscreen rendering with GPU shared textures may be vulnerable to a use-after-free. Under certain conditions, the release() callback provided on a paint event texture can outlive its backing native state, and invoking it after that point dereferences freed memory in the main process, which may lead to a cra\n\nPackage: electron\nInstalled: 37.2.6\nFixed in: 39.8.5, 40.8.5, 41.1.0, 42.0.0-alpha.5\nSeverity: LOW\nFix: Upgrade electron to 39.8.5, 40.8.5, 41.1.0, 42.0.0-alpha.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7cfac469589af530", "name": "CVE-2026-34766: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-34766: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "Electron: Electron: Unauthorized USB device access via select-usb-device event callback validation bypass\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, the select-usb-device event callback did not validate the chosen device ID against the filtered list that was presented to the handler. An app whose handler could be influenced to select a device ID outside the filtered set would grant access to a device that did not match the renderer's requested filters or was listed in exclusionFi\n\nPackage: electron\nInstalled: 37.2.6\nFixed in: 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8\nSeverity: LOW\nFix: Upgrade electron to 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9206863f2f00d1ee", "name": "CVE-2026-34768: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-34768: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "electron: Electron: Arbitrary code execution via unquoted path in Run registry key\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Windows, app.setLoginItemSettings({openAtLogin: true}) wrote the executable path to the Run registry key without quoting. If the app is installed to a path containing spaces, an attacker with write access to an ancestor directory may be able to cause a different executable to run at login instead of the intended app. On a default \n\nPackage: electron\nInstalled: 37.2.6\nFixed in: 38.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8\nSeverity: LOW\nFix: Upgrade electron to 38.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-85e416eaee1dc78f", "name": "CVE-2026-34781: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-34781: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "Electron: Electron: Denial of Service via malformed clipboard image data\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that call clipboard.readImage() may be vulnerable to a denial of service. If the system clipboard contains image data that fails to decode, the resulting null bitmap is passed unchecked to image construction, triggering a controlled abort and crashing the process. Apps are only affected if they call clipboard.readImage(). Apps that do n\n\nPackage: electron\nInstalled: 37.2.6\nFixed in: 39.8.5, 40.8.5, 41.1.0, 42.0.0-alpha.5\nSeverity: LOW\nFix: Upgrade electron to 39.8.5, 40.8.5, 41.1.0, 42.0.0-alpha.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6e591b7093de27e6", "name": "GHSA-r4q5-vmmm-2653: follow-redirects 1.15.11 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "GHSA-r4q5-vmmm-2653: follow-redirects 1.15.11 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets\n\n## Summary\n\nWhen an HTTP request follows a cross-domain redirect (301/302/307/308), `follow-redirects` only strips `authorization`, `proxy-authorization`, and `cookie` headers (matched by regex at index.js:469-476). Any custom authentication header (e.g., `X-API-Key`, `X-Auth-Token`, `Api-Key`, `Token`) is forwarded verbatim to the redirect target.\n\nSince `follow-redirects` is the redirect-handling dependency for **axios** (105K+ stars), this vulnerability affects the entire axios ecosystem.\n\n##\n\nPackage: follow-redirects\nInstalled: 1.15.11\nFixed in: 1.16.0\nSeverity: MEDIUM\nFix: Upgrade follow-redirects to 1.16.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-69a6e1af278fdb2d", "name": "CVE-2026-12143: form-data 4.0.4 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json", "shortDescription": {"text": "CVE-2026-12143: form-data 4.0.4 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "fullDescription": {"text": "form-data: form-data: Form field override via CRLF injection\n\nform-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (\") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the atta\n\nPackage: form-data\nInstalled: 4.0.4\nFixed in: 2.5.6, 3.0.5, 4.0.6\nSeverity: HIGH\nFix: Upgrade form-data to 2.5.6, 3.0.5, 4.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7864497877991e7c", "name": "CVE-2026-24001: diff 7.0.0 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-24001: diff 7.0.0 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "jsdiff: denial of service vulnerability in parsePatch and applyPatch\n\njsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, 4.0.4, and 3.5.1, attempting to parse a patch whose filename headers contain the line break characters `\\r`, `\\u2028`, or `\\u2029` can cause the `parsePatch` method to enter an infinite loop. It then consumes memory without limit until the process crashes due to running out of memory. Applications are therefore likely to be vulnerable to a denial-of-service attack if they call `parsePatch` with a user-provid\n\nPackage: diff\nInstalled: 7.0.0\nFixed in: 8.0.3, 5.2.2, 4.0.4, 3.5.1\nSeverity: LOW\nFix: Upgrade diff to 8.0.3, 5.2.2, 4.0.4, 3.5.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0a1c915e7bbe7755", "name": "CVE-2026-44573: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44573: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed data route, allowing an attacker to retrieve SSR JSON for protected pages without passing the intende\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-72292f63b82277fa", "name": "CVE-2026-44574: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44574: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Authorization bypass via crafted query parameters\n\nNext.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check. This vulnerability is fixed in 1\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-80f0afbe2ff50cb1", "name": "CVE-2026-44575: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44575: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Unauthorized access to protected content via middleware bypass\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ceaa67fa8ab5ec1f", "name": "CVE-2026-44578: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44578: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests\n\nNext.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-15b79c877030b69d", "name": "CVE-2026-44579: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44579: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service via crafted POST requests to server actions\n\nNext.js is a React framework for building full-stack web applications. From  to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open for an extended period, consuming file descriptors and server capacity until legitimate users are den\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b66b1dbf7678f274", "name": "CVE-2026-45109: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-45109: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.18, 16.2.6\nSeverity: HIGH\nFix: Upgrade next to 15.5.18, 16.2.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-258b464419aa3041", "name": "CVE-2026-64641: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-64641: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Denial of Service in App Router using Server Actions\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.\n\n## Workarounds\n\nNo workaround exists besides upgrading. Applications using Pages Router or not using Server Actions are not vulnerable.\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b8abbcf6b1d4b7ed", "name": "CVE-2026-64645: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-64645: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\n## Impact\n\nA `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's\u00a0hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect.\n\nThis affects any destination that puts a dynamic segmen\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e55746e7fc7fac04", "name": "CVE-2026-64649: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-64649: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in Server Actions on custom servers\n\n## Impact\n\nWhen a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization.\n\nApplications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f3118ba41e6fd416", "name": "GHSA-8h8q-6873-q5fj: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "GHSA-8h8q-6873-q5fj: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js Vulnerable to Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh). \n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of \n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7781245eef7dc8d9", "name": "CVE-2026-44576: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44576: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning vulnerability in React Server Components\n\nNext.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later visitors receive component payloads instead of the expected HTML. This vulnerability is fixed in 15.5\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e6567ba27f70dba1", "name": "CVE-2026-44577: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44577: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Denial of Service via Image Optimization API\n\nNext.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the /_next/image endpoint that match the images.localPatterns configuration (by default, all patterns are allowed). This vulnerability\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b04e65e574c83faf", "name": "CVE-2026-44580: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44580: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Cross-site scripting allows arbitrary code execution via untrusted script content\n\nNext.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to break out of the intended script context and execute arbitrary JavaScript in a visitor's browser. This vu\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-76b0fdb43b419a09", "name": "CVE-2026-44581: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44581: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Stored Cross-Site Scripting via malformed nonce values in cached responses\n\nNext.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to poison cached responses and cause script execution for later visitors. This vulnerability is fixed i\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1c7c4f46d7e9ff57", "name": "CVE-2026-64643: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-64643: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Unauthenticated disclosure of internal Server Function endpoints\n\n## Impact\n\nIn Next.js applications using App Router, Server Actions (`use server`) or `use cache` endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used.\n\nServer Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references).\n\nAffected users are applications using App Router + Server Actions.  \n\nBy itself, this disclosure is typically a recon/enumeration primi\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b49d8564abe6e827", "name": "CVE-2026-64644: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-64644: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Denial of Service in the Image Optimization API using SVGs\n\n### Impact\n\nWhen self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in  `/_next/image` endpoints.\n\n- If you are using `config.images.remotePatterns`, only the patterns in that array are impacted.\n- If you are using `config.images.unoptimized: true`, you are NOT impacted.\n- If you are using `config.images.loader: 'custom'`\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6823ec5928c419de", "name": "CVE-2026-64646: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-64646: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Unbounded Server Action payload in Edge runtime\n\n## Impact\n\nRequests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime\n\n## Workarounds\n\nIf you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should be allowed at max by your hosting provider.\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-67bdd769ea873ab5", "name": "CVE-2026-64647: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-64647: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for `\uc083\uc083` and `\uc104\uc104` in the request body would share the same cache.\n\n##\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b08be22a49bb9196", "name": "CVE-2026-64648: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-64648: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis only applies to `fetch` calls with a request that has a different init than the one passed to `fetch`.\nSafe: `fetch(new Request(init), init)`\nUnsafe: `fetch(new Request(init), aDifferentInit)`\n\n## Work\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-582a26b2b7663ae4", "name": "CVE-2026-44572: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44572: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service due to improper handling of x-nextjs-data header with redirects\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When that happened, the middleware/proxy could treat the request as a data request and replace the standard Location redirect header with the internal x-nextjs-redirect header. Browsers do not follow x-nextjs-redirect, so the response became an unusable red\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7ea584b1a1ed64a6", "name": "CVE-2026-44582: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-44582: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning allows incorrect response delivery\n\nNext.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL. This vulnerability is fixed in 15.5.16 and 16.2.5.\n\nPackage: next\nInstalled: 15.5.15\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-70e63851895a24e4", "name": "CVE-2026-41305: postcss 8.4.31 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.4.31\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e5ca2da93c2facc6", "name": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json", "shortDescription": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "fullDescription": {"text": "sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591\n\n### Impact\n\nA number of vulnerabilities, two rated as \"High\" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency.\n\nThose processing untrusted input with versions of sharp prior to 0.35.0 are affected.\n\n### Patches\n\n#### Using prebuilt binaries provided by sharp?\n\nMost people rely on the prebuilt binaries provided by sharp.\n\nPlease upgrade sharp to the latest version, currently 0.35.3, which provides libvips 8.18.3.\n\n#### Using a globally-installed libvips?\n\nP\n\nPackage: sharp\nInstalled: 0.34.5\nFixed in: 0.35.0\nSeverity: HIGH\nFix: Upgrade sharp to 0.35.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b2532895b1591d7a", "name": "CVE-2026-4810: google-adk 1.9.0 \u2014 always_on_agents/release_radar_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-4810: google-adk 1.9.0 \u2014 always_on_agents/release_radar_agent/requirements.txt"}, "fullDescription": {"text": "Google Agent Development Kit (ADK) has a Code Injection and Missing Authentication vulnerability\n\nA Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an unauthenticated remote attacker to execute arbitrary code on the server hosting the ADK instance.\n\nThis vulnerability was patched in versions 1.28.1 and 2.0.0a2.\n\n\nCustomers need to redeploy the upgraded ADK to their production environments. In addition, if they are running ADK Web locally, they als\n\nPackage: google-adk\nInstalled: 1.9.0\nFixed in: 1.28.1, 2.0.0a2\nSeverity: CRITICAL\nFix: Upgrade google-adk to 1.28.1, 2.0.0a2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-eb02a5db04fe88b8", "name": "CVE-2026-8769: @ai-sdk/provider-utils 2.2.8 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 2.2.8 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue\n\nA vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.\n\nPackage: @ai-sdk/provider-utils\nInstalled: 2.2.8\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-320edb0e675558ed", "name": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.25 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.25 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue\n\nA vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.\n\nPackage: @ai-sdk/provider-utils\nInstalled: 3.0.25\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-692f580449fa2d2b", "name": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.14 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.14 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nThe same as the `hono` core [Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44).\n\n### Summary\n\nOn Windows hosts, an encoded backslash (`%5C`) in the request path decodes to `\\`, which the Windows path resolver treats as a separator. `serve-static` then resolves a single URL segment such as `admin\\secret.txt` into a nested file under the root and serves it, letting an attacker read static files meant t\n\nPackage: @hono/node-server\nInstalled: 1.19.14\nFixed in: 2.0.5\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 2.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b200a914b2a438b9", "name": "GHSA-6475-r3vj-m8vf: @smithy/config-resolver 4.2.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-6475-r3vj-m8vf: @smithy/config-resolver 4.2.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "AWS SDK for JavaScript v3 adopted defense in depth enhancement for region parameter value\n\nCVSSv3.1 Rating: 3.7 (LOW)\n\nSummary\n\nThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value.\n\nA defense-in-depth enhancement has been implemented in the AWS SDK for JavaScript v3 (versions 3.723.0 and later). This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was re\n\nPackage: @smithy/config-resolver\nInstalled: 4.2.2\nFixed in: 4.4.0\nSeverity: LOW\nFix: Upgrade @smithy/config-resolver to 4.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a6d3aa3763d7a401", "name": "CVE-2026-12590: body-parser 1.20.3 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-12590: body-parser 1.20.3 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 1.20.3\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-58c0f96f84d00e1a", "name": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 2.2.2\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-47af9952ee7d030d", "name": "CVE-2026-24001: diff 5.2.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-24001: diff 5.2.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "jsdiff: denial of service vulnerability in parsePatch and applyPatch\n\njsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, 4.0.4, and 3.5.1, attempting to parse a patch whose filename headers contain the line break characters `\\r`, `\\u2028`, or `\\u2029` can cause the `parsePatch` method to enter an infinite loop. It then consumes memory without limit until the process crashes due to running out of memory. Applications are therefore likely to be vulnerable to a denial-of-service attack if they call `parsePatch` with a user-provid\n\nPackage: diff\nInstalled: 5.2.0\nFixed in: 8.0.3, 5.2.2, 4.0.4, 3.5.1\nSeverity: LOW\nFix: Upgrade diff to 8.0.3, 5.2.2, 4.0.4, 3.5.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1d59f684575194de", "name": "GHSA-cmwh-pvxp-8882: dompurify 3.4.7 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.4.7 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)\n\n## Summary\n\nDOMPurify 3.4.7 shipped a security fix (\"permanent hook pollution\") that makes a registered `uponSanitizeAttribute` hook's mutation of `data.allowedAttributes` **non-persistent** \u2014 so allowing an attribute for one element does not leak into later `sanitize()` calls. The fix clones `ALLOWED_ATTR` inside `_parseConfig`.\n\nThat guard is **silently bypassed whenever the application uses the persistent-config API `DOMPurify.setConfig()`.** `setConfig()` sets the module flag `SET_CONFIG = t\n\nPackage: dompurify\nInstalled: 3.4.7\nFixed in: 3.4.11\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-85d232377cba56fc", "name": "GHSA-c2j3-45gr-mqc4: dompurify 3.4.7 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.4.7 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.\n\n## Summary\n\nThere is a possible hook-policy inconsistency in DOMPurify 3.4.11 involving `CUSTOM_ELEMENT_HANDLING`.\n\nWhen a custom element is allowed via `CUSTOM_ELEMENT_HANDLING.tagNameCheck`, it appears that the element does not go through `afterSanitizeElements` in the same way as a normal element. As a result, an application that relies on `afterSanitizeElements` as a security policy layer to strip sensitive attributes from all elements may see those attributes removed from normal elements bu\n\nPackage: dompurify\nInstalled: 3.4.7\nFixed in: 3.4.12\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-28f15a37dd5c1179", "name": "GHSA-gvmj-g25r-r7wr: dompurify 3.4.7 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.4.7 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes\n\n## Summary\n\nWhen DOMPurify is configured with both `SAFE_FOR_TEMPLATES: true` and `RETURN_DOM: true` (or `IN_PLACE: true`), an attacker can inject template expressions, such as `${evil}`, `{{evil}}`, or `<%evil%>`, that survive the sanitization pass inside `<template>` element content. This bypasses the explicit purpose of `SAFE_FOR_TEMPLATES`, which is to prevent template engine evaluation of user-supplied content.\n\n> **Note:** The string output path is **not** affected. Only the DOM return pat\n\nPackage: dompurify\nInstalled: 3.4.7\nFixed in: 3.4.8\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-290ae82ab5e1b76b", "name": "GHSA-vxr8-fq34-vvx9: dompurify 3.4.7 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.4.7 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output\n\n## Impact\n\nA DOMPurify instance that is reused across trust boundaries can stay bound to a previously supplied `TRUSTED_TYPES_POLICY` even after `clearConfig()` is called. A later caller that requests `RETURN_TRUSTED_TYPE` receives a `TrustedHTML` object created by the old policy, not by a clean default configuration.\n\nIf the old policy is unsafe or controlled by a less-trusted integration, this turns a later \"default\" sanitize call into script execution at a Trusted Types sink. `TRUSTED_TYPES_P\n\nPackage: dompurify\nInstalled: 3.4.7\nFixed in: 3.4.9\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f81574f9babff8df", "name": "CVE-2026-13676: fast-uri 3.1.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-13676: fast-uri 3.1.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization\n\nfast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo\n\nPackage: fast-uri\nInstalled: 3.1.2\nFixed in: 4.0.1, 3.1.3, 2.4.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 4.0.1, 3.1.3, 2.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-575cc651db0f6125", "name": "CVE-2026-16221: fast-uri 3.1.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-16221: fast-uri 3.1.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...\n\nImpact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f\n\nPackage: fast-uri\nInstalled: 3.1.2\nFixed in: 2.4.3, 3.1.4, 4.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 2.4.3, 3.1.4, 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5e5a80b52dd67a2a", "name": "CVE-2026-25896: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-25896: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling\n\nfast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&lt;, &gt;, &amp;, &quot;, &apos;) with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5.\n\nPackage: fast-xml-parser\nInstalled: 5.2.5\nFixed in: 5.3.5, 4.5.4\nSeverity: CRITICAL\nFix: Upgrade fast-xml-parser to 5.3.5, 4.5.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-6d66602a2d52d1b8", "name": "CVE-2026-25128: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-25128: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser has RangeError DoS Numeric Entities Bug\n\nfast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 5.0.9 through 5.3.3, a RangeError vulnerability exists in the numeric entity processing of fast-xml-parser when parsing XML with out-of-range entity code points (e.g., `&#9999999;` or `&#xFFFFFF;`). This causes the parser to throw an uncaught exception, crashing any application that processes untrusted XML input. Version 5.3.4 fixes the issu\n\nPackage: fast-xml-parser\nInstalled: 5.2.5\nFixed in: 5.3.4\nSeverity: HIGH\nFix: Upgrade fast-xml-parser to 5.3.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-69dcf0919bbb7984", "name": "CVE-2026-26278: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-26278: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion\n\nfast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it\u2019s possible to make the parser spend seconds or even minutes processing a single request, effectively freezing the application. Version 5.3.6 fixes the issue. As a workaround, avoid using DOCTYPE parsing by `process\n\nPackage: fast-xml-parser\nInstalled: 5.2.5\nFixed in: 4.5.4, 5.3.6\nSeverity: HIGH\nFix: Upgrade fast-xml-parser to 4.5.4, 5.3.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3a4efe2ab45ba289", "name": "CVE-2026-33036: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-33036: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass\n\nfast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerability where numeric character references (&#NNN;, &#xHH;) and standard XML entities completely evade the entity expansion limits (e.g., maxTotalExpansions, maxExpandedLength) added to fix CVE-2026-26278, enabling XML entity expansion Denial of Service. The root cause is that replaceEntitiesValue() in OrderedObjParser.js only enforces \n\nPackage: fast-xml-parser\nInstalled: 5.2.5\nFixed in: 5.5.6, 4.5.5\nSeverity: HIGH\nFix: Upgrade fast-xml-parser to 5.5.6, 4.5.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d1994eaab17762b7", "name": "CVE-2026-33349: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-33349: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Denial of Service via unbounded entity expansion due to incorrect configuration limit handling\n\nfast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.0-beta.3 to before version 5.5.7, the DocTypeReader in fast-xml-parser uses JavaScript truthy checks to evaluate maxEntityCount and maxEntitySize configuration limits. When a developer explicitly sets either limit to 0 \u2014 intending to disallow all entities or restrict entity size to zero bytes \u2014 the falsy nature of 0 in JavaScript causes the guard conditions to short-circuit, co\n\nPackage: fast-xml-parser\nInstalled: 5.2.5\nFixed in: 4.5.5, 5.5.7\nSeverity: MEDIUM\nFix: Upgrade fast-xml-parser to 4.5.5, 5.5.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c8c464f18fb72670", "name": "CVE-2026-41650: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41650: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: XML injection via improper escaping of comment and CDATA sequences\n\nfast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version 5.7.0, XMLBuilder does not escape the \"-->\" sequence in comment content or the \"]]>\" sequence in CDATA sections when building XML from JavaScript objects. This allows XML injection when user-controlled data flows into comments or CDATA elements, leading to XSS, SOAP injection, or data manipulation. This issue has been patched in version 5.7.0.\n\nPackage: fast-xml-parser\nInstalled: 5.2.5\nFixed in: 5.7.0\nSeverity: MEDIUM\nFix: Upgrade fast-xml-parser to 5.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-426271cd4374c404", "name": "CVE-2026-27942: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-27942: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service\n\nfast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with `preserveOrder:true`. Version 5.3.8 fixes the issue. As a workaround, use XML builder with `preserveOrder:false` or check the input data before passing to builder.\n\nPackage: fast-xml-parser\nInstalled: 5.2.5\nFixed in: 5.3.8, 4.5.4\nSeverity: LOW\nFix: Upgrade fast-xml-parser to 5.3.8, 4.5.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dd8f3438c20bd506", "name": "CVE-2026-12143: form-data 4.0.4 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-12143: form-data 4.0.4 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "form-data: form-data: Form field override via CRLF injection\n\nform-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (\") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the atta\n\nPackage: form-data\nInstalled: 4.0.4\nFixed in: 2.5.6, 3.0.5, 4.0.6\nSeverity: HIGH\nFix: Upgrade form-data to 2.5.6, 3.0.5, 4.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1348743695a4f817", "name": "CVE-2026-54290: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54290: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials: true and no explicit origin (the default wildcard), the CORS Middleware reflects the request's Origin and sends Access-Control-Allow-Credentials: true. Any site can then make credentialed cross-origin requests and read the responses, exposing cookie-authenticated endpoints to arbitrary origins. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.23\nFixed in: 4.12.25\nSeverity: HIGH\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e724397e7619c093", "name": "CVE-2026-54286: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54286: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \\, which the Windows path resolver treats as a separator. serve-static then resolves a single URL segment such as admin\\secret.txt into a nested file under the root and serves it, letting an attacker read static files meant to be protected behind prefix-mounted middleware. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.23\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a45e1883ae0b38f5", "name": "CVE-2026-54287: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54287: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, the ALB single-header response and the VPC Lattice v2 response join multiple Set-Cookie headers into one comma-separated value. Because commas also appear inside cookie attributes (for example Expires dates), clients cannot split the value back into individual cookies and silently drop or misparse them. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.23\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5b033b87654ac218", "name": "CVE-2026-54288: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54288: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit Middleware trusts the request's Content-Length header to decide whether a body is within the limit. On AWS Lambda (API Gateway v1/v2, ALB, VPC Lattice, and Lambda@Edge) the body is delivered fully buffered and the adapter builds the request with the client-declared Content-Length, which need not match the actual payload. A client can declare a tiny Content-Length while sending a\n\nPackage: hono\nInstalled: 4.12.23\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ae3d9613fc5dfb08", "name": "CVE-2026-54289: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54289: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Edge, CloudFront delivers a request header that appears more than once as several separate entries. The adapter writes each value with Headers.set instead of Headers.append, so every value overwrites the previous one and only the last reaches the application. Repeated request headers such as X-Forwarded-For, Forwarded, and Via are silently truncated to a single value. Request mid\n\nPackage: hono\nInstalled: 4.12.23\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-703ffa82637537b1", "name": "CVE-2026-59895: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59895: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.23\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2f59afe95a306581", "name": "CVE-2026-59896: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59896: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "hono/jsx does not isolate context per request, leading to cross-request data disclosure\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async component. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.23\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eb91f035a94808a3", "name": "CVE-2026-59897: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59897: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete X-Forwarded-For chain, rate limiting, audit logging, or proxy-chain validation can receive incomplete data. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.23\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-87ea3d009da07611", "name": "CVE-2025-65945: jws 4.0.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-65945: jws 4.0.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "node-jws: auth0/node-jws: Improper signature verification in HS256 algorithm\n\nauth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditions. Applications are affected when they use the jws.createVerify() function for HMAC algorithms and use user-provided data from the JSON Web Signature protected header or payload in HMAC secret lookup routines, which can allow attackers to bypass signature verif\n\nPackage: jws\nInstalled: 4.0.0\nFixed in: 3.2.3, 4.0.1\nSeverity: HIGH\nFix: Upgrade jws to 3.2.3, 4.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8e08a751d442493b", "name": "CVE-2026-4800: lodash 4.17.21 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-4800: lodash 4.17.21 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1571e2350db522e5", "name": "CVE-2025-13465: lodash 4.17.21 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-13465: lodash 4.17.21 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "lodash: prototype pollution in _.unset and _.omit functions\n\nLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset\u00a0and _.omit\u00a0functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.\n\nThe issue permits deletion of properties but does not allow overwriting their original behavior.\n\nThis issue is patched on 4.17.23\n\nPackage: lodash\nInstalled: 4.17.21\nFixed in: 4.17.23\nSeverity: MEDIUM\nFix: Upgrade lodash to 4.17.23"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ac6e43a07303587b", "name": "CVE-2026-2950: lodash 4.17.21 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-2950: lodash 4.17.21 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e801d7d0a06470bf", "name": "CVE-2025-66400: mdast-util-to-hast 13.2.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-66400: mdast-util-to-hast 13.2.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "mdast-util-to-hast: mdast-util-to-hast: Markdown code elements can appear as regular page content\n\nmdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdown source by using character references. This could make rendered user supplied markdown code elements appear like the rest of the page. This vulnerability is fixed in 13.2.1.\n\nPackage: mdast-util-to-hast\nInstalled: 13.2.0\nFixed in: 13.2.1\nSeverity: MEDIUM\nFix: Upgrade mdast-util-to-hast to 13.2.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0e2e5c4a92721740", "name": "CVE-2025-55182: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-55182: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "next: React Server Components: Pre-authentication remote code execution via unsafe deserialization\n\nA pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7\nSeverity: CRITICAL\nFix: Upgrade next to 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-2b68052ad2262eb5", "name": "CVE-2026-44573: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44573: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed data route, allowing an attacker to retrieve SSR JSON for protected pages without passing the intende\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d1ec40d9c1327ecd", "name": "CVE-2026-44575: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44575: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Unauthorized access to protected content via middleware bypass\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5f98a2d6dbe93b30", "name": "CVE-2026-44578: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44578: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests\n\nNext.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-95443fdb07394dfd", "name": "CVE-2026-44579: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44579: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service via crafted POST requests to server actions\n\nNext.js is a React framework for building full-stack web applications. From  to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open for an extended period, consuming file descriptors and server capacity until legitimate users are den\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-09e14aa25645a9f7", "name": "CVE-2026-45109: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-45109: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.18, 16.2.6\nSeverity: HIGH\nFix: Upgrade next to 15.5.18, 16.2.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3fc29af1c121a014", "name": "CVE-2026-64641: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64641: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Denial of Service in App Router using Server Actions\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.\n\n## Workarounds\n\nNo workaround exists besides upgrading. Applications using Pages Router or not using Server Actions are not vulnerable.\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b06fbbaa61ab0f35", "name": "CVE-2026-64645: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64645: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\n## Impact\n\nA `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's\u00a0hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect.\n\nThis affects any destination that puts a dynamic segmen\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d30a07bc2aa86069", "name": "CVE-2026-64649: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64649: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in Server Actions on custom servers\n\n## Impact\n\nWhen a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization.\n\nApplications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-de5bcc57d1406ee5", "name": "GHSA-8h8q-6873-q5fj: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-8h8q-6873-q5fj: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js Vulnerable to Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh). \n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of \n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8ba6970f814b9fef", "name": "GHSA-h25m-26qc-wcjf: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-h25m-26qc-wcjf: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.0.x, 19.1.x, and 19.2.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23864](https://github.com/facebook/react/security/advisories/GHSA-83fc-fqcc-2hmg).\n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage, out-of-m\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5\nSeverity: HIGH\nFix: Upgrade next to 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0459e427eb1a31ec", "name": "GHSA-mwv6-3258-q52c: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-mwv6-3258-q52c: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Next Vulnerable to Denial of Service with Server Components\n\nA vulnerability affects certain React packages for versions 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.1.2, 19.2.0, and 19.2.1 and frameworks that use the affected packages, including Next.js 15.x and 16.x using the App Router. The issue is tracked upstream as [CVE-2025-55184](https://www.cve.org/CVERecord?id=CVE-2025-55184).\n\nA malicious HTTP request can be crafted and sent to any App Router endpoint that, when deserialized, can cause the server process to hang and consume CPU. This can result in denia\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 14.2.34, 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 15.6.0-canary.59, 16.0.9, 16.1.0-canary.17\nSeverity: HIGH\nFix: Upgrade next to 14.2.34, 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 15.6.0-canary.59, 16.0.9, 16.1.0-canary.17"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f77430643d435c19", "name": "GHSA-q4gf-8mx6-v5v3: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-q4gf-8mx6-v5v3: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js has a Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react/security/advisories/GHSA-479c-33wc-g2pg). You can read more about this advisory our [this changelog](https://vercel.com/changelog/summary-of-cve-2026-23869).\n\nA specially crafted HTTP request can be sent to any App Rout\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.15, 16.2.3\nSeverity: HIGH\nFix: Upgrade next to 15.5.15, 16.2.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4997e740bdb621d2", "name": "CVE-2025-55173: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-55173: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "nextjs: Next.js Content Injection Vulnerability for Image Optimization\n\nNext.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Optimization is vulnerable to content injection. The issue allowed attacker-controlled external image sources to trigger file downloads with arbitrary content and filenames under specific configurations. This behavior could be abused for phishing or malicious file delivery. This vulnerability has been fixed in Next.js versions 14.2.31 and 15.4.5.\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 14.2.31, 15.4.5\nSeverity: MEDIUM\nFix: Upgrade next to 14.2.31, 15.4.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2819da1536e67317", "name": "CVE-2025-57752: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-57752: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "nextjs: Next.js Affected by Cache Key Confusion for Image Optimization API Routes\n\nNext.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Optimization API routes are affected by cache key confusion. When images returned from API routes vary based on request headers (such as Cookie or Authorization), these responses could be incorrectly cached and served to unauthorized users due to a cache key confusion bug. This vulnerability has been fixed in Next.js versions 14.2.31 and 15.4.5. All us\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 14.2.31, 15.4.5\nSeverity: MEDIUM\nFix: Upgrade next to 14.2.31, 15.4.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-29be2460875677fd", "name": "CVE-2025-57822: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-57822: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js Improper Middleware Redirect Handling Leads to SSRF\n\nNext.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly passing the request object, it could lead to SSRF in self-hosted applications that incorrectly forwarded user-supplied headers. This vulnerability has been fixed in Next.js versions 14.2.32 and 15.4.7. All users implementing custom middleware logic in self-hosted environments are strongly encouraged to upgrade and verify correct usage of the next() \n\nPackage: next\nInstalled: 15.3.2\nFixed in: 14.2.32, 15.4.7\nSeverity: MEDIUM\nFix: Upgrade next to 14.2.32, 15.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-65d34bd91059283b", "name": "CVE-2025-59471: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-59471: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "next: NextJS Denial of Service in Image Optimizer\n\nA denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing a maximum size limit, allowing an attacker to cause out-of-memory conditions by requesting optimization of arbitrarily large images. This vulnerability requires that `remotePatterns` is configured to allow image optimization from external domains and\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.10, 16.1.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.10, 16.1.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f7ede05bf0eda628", "name": "CVE-2026-27980: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-27980: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Unbounded next/image disk cache growth can exhaust storage\n\nNext.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unbounded cache growth. An attacker could generate many unique image-optimization variants and exhaust disk space, causing denial of service. This is fixed in version 16.1.7 by adding an LRU-backed disk cache with `images.maximumDiskCacheSize`, including e\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 16.1.7, 15.5.14\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-60ba2113c6312508", "name": "CVE-2026-29057: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-29057: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: HTTP request smuggling in rewrites\n\nNext.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfer-Encoding: chunked` could trigger request boundary disagreement between the proxy and backend. This could allow request smuggling through rewritten routes. An attacker could smuggle a second request to unintended backend routes (for example, interna\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 16.1.7, 15.5.13\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-db1e7c129fe2640a", "name": "CVE-2026-44576: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44576: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning vulnerability in React Server Components\n\nNext.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later visitors receive component payloads instead of the expected HTML. This vulnerability is fixed in 15.5\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d12b228b3d49a57", "name": "CVE-2026-44577: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44577: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Next.js: Denial of Service via Image Optimization API\n\nNext.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the /_next/image endpoint that match the images.localPatterns configuration (by default, all patterns are allowed). This vulnerability\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ace0fa1f6c7c35f0", "name": "CVE-2026-44580: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44580: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Cross-site scripting allows arbitrary code execution via untrusted script content\n\nNext.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to break out of the intended script context and execute arbitrary JavaScript in a visitor's browser. This vu\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b5a7ac3c4d0ca4cf", "name": "CVE-2026-44581: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44581: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Stored Cross-Site Scripting via malformed nonce values in cached responses\n\nNext.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to poison cached responses and cause script execution for later visitors. This vulnerability is fixed i\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d4821573718401c2", "name": "CVE-2026-64643: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64643: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Unauthenticated disclosure of internal Server Function endpoints\n\n## Impact\n\nIn Next.js applications using App Router, Server Actions (`use server`) or `use cache` endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used.\n\nServer Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references).\n\nAffected users are applications using App Router + Server Actions.  \n\nBy itself, this disclosure is typically a recon/enumeration primi\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1aac450d25d5e20d", "name": "CVE-2026-64646: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64646: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Unbounded Server Action payload in Edge runtime\n\n## Impact\n\nRequests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime\n\n## Workarounds\n\nIf you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should be allowed at max by your hosting provider.\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f26bb2b3ea61ff49", "name": "CVE-2026-64647: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64647: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for `\uc083\uc083` and `\uc104\uc104` in the request body would share the same cache.\n\n##\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-be3fe13aee44c504", "name": "CVE-2026-64648: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64648: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis only applies to `fetch` calls with a request that has a different init than the one passed to `fetch`.\nSafe: `fetch(new Request(init), init)`\nUnsafe: `fetch(new Request(init), aDifferentInit)`\n\n## Work\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2f0f3d1508d2355e", "name": "GHSA-w37m-7fhw-fmv9: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-w37m-7fhw-fmv9: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Next Server Actions Source Code Exposure \n\nA vulnerability affects certain React packages for versions 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.1.2, 19.2.0, and 19.2.1 and frameworks that use the affected packages, including Next.js 15.x and 16.x using the App Router. The issue is tracked upstream as [CVE-2025-55183](https://www.cve.org/CVERecord?id=CVE-2025-55183).\n\nA malicious HTTP request can be crafted and sent to any App Router endpoint that can return the compiled source code of [Server Functions](https://react.dev/reference/rsc/server-f\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 15.6.0-canary.59, 16.0.9, 16.1.0-canary.17\nSeverity: MEDIUM\nFix: Upgrade next to 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 15.6.0-canary.59, 16.0.9, 16.1.0-canary.17"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5cc3f463284ab389", "name": "CVE-2025-49005: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-49005: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "nextjs: Next.js cache poisoning\n\nNext.js is a React framework for building full-stack web applications. In Next.js App Router from 15.3.0 to before 15.3.3 and Vercel CLI from 41.4.1 to 42.2.0, a cache poisoning vulnerability was found. The issue allowed page requests for HTML content to return a React Server Component (RSC) payload instead under certain conditions. When deployed to Vercel, this would only impact the browser cache, and would not lead to the CDN being poisoned. When self-hosted and deployed externally, this could\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.3.3\nSeverity: LOW\nFix: Upgrade next to 15.3.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-58965e41acbac259", "name": "CVE-2026-44572: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44572: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service due to improper handling of x-nextjs-data header with redirects\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When that happened, the middleware/proxy could treat the request as a data request and replace the standard Location redirect header with the internal x-nextjs-redirect header. Browsers do not follow x-nextjs-redirect, so the response became an unusable red\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-276f7bfede241150", "name": "CVE-2026-44582: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44582: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning allows incorrect response delivery\n\nNext.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL. This vulnerability is fixed in 15.5.16 and 16.2.5.\n\nPackage: next\nInstalled: 15.3.2\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b3a1ea55eaf10bdb", "name": "CVE-2025-12816: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-12816: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications\n\nAn interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.\n\nPackage: node-forge\nInstalled: 1.3.1\nFixed in: 1.3.2\nSeverity: HIGH\nFix: Upgrade node-forge to 1.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-490eddd40d205a51", "name": "CVE-2025-66031: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-66031: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "node-forge: node-forge ASN.1 Unbounded Recursion\n\nForge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.\n\nPackage: node-forge\nInstalled: 1.3.1\nFixed in: 1.3.2\nSeverity: HIGH\nFix: Upgrade node-forge to 1.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-16f407b78644f9a3", "name": "CVE-2026-33891: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-33891: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "node-forge: node-forge: Denial of Service via infinite loop in BigInteger.modInverse()\n\nForge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn library). When modInverse() is called with a zero value as input, the internal Extended Euclidean Algorithm enters an unreachable exit condition, causing the process to hang indefinitely and consume 100%\n\nPackage: node-forge\nInstalled: 1.3.1\nFixed in: 1.4.0\nSeverity: HIGH\nFix: Upgrade node-forge to 1.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1b8a7d2951d9ca55", "name": "CVE-2026-33894: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-33894: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "node-forge: Forge: Signature Forgery via Weak RSASSA PKCS#1 v1.5 Verification\n\nForge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attackers can forge signatures by stuffing \u201cgarbage\u201d bytes within the ASN structure in order to construct a signature that passes verification, enabling Bleichenbacher style forgery. This issue is similar to CVE-2022-24771, but adds bytes in an addition field within th\n\nPackage: node-forge\nInstalled: 1.3.1\nFixed in: 1.4.0\nSeverity: HIGH\nFix: Upgrade node-forge to 1.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c80583477f50b6cc", "name": "CVE-2026-33895: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-33895: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "node-forge: Forge: Authentication bypass via forged Ed25519 cryptographic signatures\n\nForge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not reduced modulo the group order (`S >= L`). A valid signature and its `S + L` variant both verify in forge, while Node.js `crypto.verify` (OpenSSL-backed) rejects the `S + L` variant, as defined by the specification. This class of signature malleability has been exploited in p\n\nPackage: node-forge\nInstalled: 1.3.1\nFixed in: 1.4.0\nSeverity: HIGH\nFix: Upgrade node-forge to 1.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-789b452727ed01d3", "name": "CVE-2026-33896: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-33896: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "node-forge: Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance\n\nForge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` extensions. This allows any leaf certificate (without these extensions) to act as a CA and sign other certificates, which node-forge will accept as valid. Version 1.4.0 patches the issue.\n\nPackage: node-forge\nInstalled: 1.3.1\nFixed in: 1.4.0\nSeverity: HIGH\nFix: Upgrade node-forge to 1.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fb2675bd8204254d", "name": "CVE-2025-66030: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-66030: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "node-forge: node-forge: Integer Overflow allows OID-based security bypass\n\nForge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.\n\nPackage: node-forge\nInstalled: 1.3.1\nFixed in: 1.3.2\nSeverity: MEDIUM\nFix: Upgrade node-forge to 1.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f9699082ffa30cc2", "name": "CVE-2026-4867: path-to-regexp 0.1.12 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-4867: path-to-regexp 0.1.12 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters\n\nImpact:\n\nA bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c or /:a-:b-:c-:d. The backtrack protection added in path-to-regexp@0.1.12 only prevents ambiguity for two parameters. With three or more, the generated lookahead does not block single separator characters, so capture groups overlap and cause catastrophic backtracking.\n\nPatches:\n\nUpgrade to path-to-regexp@0.1.13\n\n\n\nPackage: path-to-regexp\nInstalled: 0.1.12\nFixed in: 0.1.13\nSeverity: HIGH\nFix: Upgrade path-to-regexp to 0.1.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f827b248f2f245ac", "name": "CVE-2025-59288: playwright 1.55.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-59288: playwright 1.55.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "playwright: Playwright Spoofing Vulnerability\n\nImproper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network.\n\nPackage: playwright\nInstalled: 1.55.0\nFixed in: 1.55.1\nSeverity: HIGH\nFix: Upgrade playwright to 1.55.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-76023393a287362b", "name": "CVE-2026-41305: postcss 8.4.31 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.4.31\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a1cc7072ab98a83e", "name": "CVE-2024-53382: prismjs 1.27.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2024-53382: prismjs 1.27.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "prismjs: DOM Clobbering vulnerability within the Prism library's prism-autoloader plugin\n\nPrism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.\n\nPackage: prismjs\nInstalled: 1.27.0\nFixed in: 1.30.0\nSeverity: MEDIUM\nFix: Upgrade prismjs to 1.30.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ad7c60b68832ed6f", "name": "CVE-2025-15284: qs 6.13.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-15284: qs 6.13.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "qs: qs: Denial of Service via improper input validation in array parsing\n\nImproper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1.\n\n\nSummary\n\nThe arrayLimit\u00a0option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLimit\u00a0should apply uniformly across all array notations.\n\nNote:\u00a0The default parameterLimit\u00a0of 1000 effectively mitigates the DoS scenario originally described. With default options, bracket notation cannot produce arrays la\n\nPackage: qs\nInstalled: 6.13.0\nFixed in: 6.14.1\nSeverity: MEDIUM\nFix: Upgrade qs to 6.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-61269bd3455dde98", "name": "CVE-2026-8723: qs 6.13.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-8723: qs 6.13.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "### Summary    `qs.stringify` throws `TypeError` when called with `arr ...\n\n### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti\n\nPackage: qs\nInstalled: 6.13.0\nFixed in: 6.15.2\nSeverity: MEDIUM\nFix: Upgrade qs to 6.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-51f507039a2eb2b7", "name": "CVE-2026-2391: qs 6.13.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-2391: qs 6.13.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "qs: qs's arrayLimit bypass in comma parsing allows denial of service\n\n### Summary\nThe `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).\n\n### Details\nWhen the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?\n\nPackage: qs\nInstalled: 6.13.0\nFixed in: 6.14.2\nSeverity: LOW\nFix: Upgrade qs to 6.14.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-67492b140d15e686", "name": "GHSA-f88m-g3jw-g9cj: sharp 0.34.4 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.4 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591\n\n### Impact\n\nA number of vulnerabilities, two rated as \"High\" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency.\n\nThose processing untrusted input with versions of sharp prior to 0.35.0 are affected.\n\n### Patches\n\n#### Using prebuilt binaries provided by sharp?\n\nMost people rely on the prebuilt binaries provided by sharp.\n\nPlease upgrade sharp to the latest version, currently 0.35.3, which provides libvips 8.18.3.\n\n#### Using a globally-installed libvips?\n\nP\n\nPackage: sharp\nInstalled: 0.34.4\nFixed in: 0.35.0\nSeverity: HIGH\nFix: Upgrade sharp to 0.35.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a54b8ecb28120903", "name": "CVE-2026-41907: uuid 10.0.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41907: uuid 10.0.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 10.0.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-74cd8f9fb45f438a", "name": "CVE-2026-41907: uuid 11.1.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 11.1.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-14dbcbd0d32cbcf6", "name": "CVE-2026-41907: uuid 9.0.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 9.0.1\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-14125201359a201d", "name": "CVE-2025-12758: validator 13.15.15 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-12758: validator 13.15.15 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements\n\nVersions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\\uFE0F, \\uFE0E) appearing in a sequence which lead to improper string length calculation. This can lead to an application using isLength for input validation accepting strings significantly longer than intended, resulting in issues like data truncation in databases, buffer over\n\nPackage: validator\nInstalled: 13.15.15\nFixed in: 13.15.22\nSeverity: HIGH\nFix: Upgrade validator to 13.15.22"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9214ad4fa98dab85", "name": "CVE-2025-56200: validator 13.15.15 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-56200: validator 13.15.15 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "validator.js has a URL validation bypass vulnerability in its isURL function\n\nA URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use ':' as the delimiter. This parsing difference allows attackers to bypass protocol and domain validation by crafting URLs leading to XSS and Open Redirect attacks.\n\nPackage: validator\nInstalled: 13.15.15\nFixed in: 13.15.20\nSeverity: MEDIUM\nFix: Upgrade validator to 13.15.20"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-76fdcb721fd038aa", "name": "CVE-2026-48779: ws 8.18.3 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-48779: ws 8.18.3 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments\n\nws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-si\n\nPackage: ws\nInstalled: 8.18.3\nFixed in: 5.2.5, 6.2.4, 7.5.11, 8.21.0\nSeverity: HIGH\nFix: Upgrade ws to 5.2.5, 6.2.4, 7.5.11, 8.21.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e19555eefdeda115", "name": "CVE-2026-45736: ws 8.18.3 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-45736: ws 8.18.3 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "fullDescription": {"text": "ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`\n\nws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.\n\nPackage: ws\nInstalled: 8.18.3\nFixed in: 8.20.1\nSeverity: MEDIUM\nFix: Upgrade ws to 8.20.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-db0e2b5c99e7b780", "name": "CVE-2026-45409: idna 3.11 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-45409: idna 3.11 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "python-idna: idna: Denial of Service via specially crafted long inputs\n\nInternationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fi\n\nPackage: idna\nInstalled: 3.11\nFixed in: 3.15\nSeverity: MEDIUM\nFix: Upgrade idna to 3.15"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-55297e5c4fbf16ad", "name": "CVE-2026-55443: langchain 1.2.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-55443: langchain 1.2.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended root directory. Affected behaviors include: a file-search agent middleware that validates a starting directory but not the search pattern or the resolved target of matched files, so glob patterns and symlinks can reach files outside the configured root; prompt- \n\nPackage: langchain\nInstalled: 1.2.7\nFixed in: 1.3.9\nSeverity: MEDIUM\nFix: Upgrade langchain to 1.3.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ae7351d9f2bdc3f2", "name": "CVE-2026-55443: langchain-anthropic 1.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-55443: langchain-anthropic 1.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended root directory. Affected behaviors include: a file-search agent middleware that validates a starting directory but not the search pattern or the resolved target of matched files, so glob patterns and symlinks can reach files outside the configured root; prompt- \n\nPackage: langchain-anthropic\nInstalled: 1.3.1\nFixed in: 1.4.6\nSeverity: MEDIUM\nFix: Upgrade langchain-anthropic to 1.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-57a27b91e04e9bcc", "name": "CVE-2026-34070: langchain-core 1.2.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-34070: langchain-core 1.2.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "langchain: path traversal in legacy load_prompt functions in langchain-core\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path injection. When an application passes user-influenced prompt configurations to load_prompt() or load_prompt_from_config(), an attacker can read arbitrary files on the host filesystem, constrained only by file-extension chec\n\nPackage: langchain-core\nInstalled: 1.2.7\nFixed in: 1.2.22\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.2.22"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c29b8b20edf7905d", "name": "CVE-2026-44843: langchain-core 1.2.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-44843: langchain-core 1.2.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call load() with allowed_objects=\"all\". This does not enable arbitrary Python object deserialization, but it does allow any trusted LangChain-serializable object to be revived, which is broader than these runtime path\n\nPackage: langchain-core\nInstalled: 1.2.7\nFixed in: 1.3.3, 0.3.85\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.3.3, 0.3.85"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b22b1ddfc3553ec7", "name": "CVE-2026-40087: langchain-core 1.2.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-40087: langchain-core 1.2.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "langchain: incomplete f-string validation in prompt templates\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-string prompt-template validation was incomplete in two respects. First, some prompt template classes accepted f-string templates and formatted them without enforcing the same attribute-access validation as PromptTemplate. In particular, DictPromptTemplate and ImagePromptTemplate could accept templates containing attribute access or indexing expressions and subsequently evaluate t\n\nPackage: langchain-core\nInstalled: 1.2.7\nFixed in: 0.3.84, 1.2.28\nSeverity: MEDIUM\nFix: Upgrade langchain-core to 0.3.84, 1.2.28"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-280fc04d59e0b028", "name": "CVE-2026-26013: langchain-core 1.2.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-26013: langchain-core 1.2.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "langchain: SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side Request Forgery (SSRF) attacks by providing malicious image URLs in user input. This vulnerability is fixed in 1.2.11.\n\nPackage: langchain-core\nInstalled: 1.2.7\nFixed in: 1.2.11\nSeverity: LOW\nFix: Upgrade langchain-core to 1.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f54918a39d9d76c6", "name": "CVE-2026-41488: langchain-openai 1.1.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-41488: langchain-openai 1.1.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "langchain-openai: Langchain-openai: Server-Side Request Forgery (SSRF) protection bypass via DNS rebinding\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size() helper (used by get_num_tokens_from_messages for image token counting) validated URLs for SSRF protection and then fetched them in a separate network operation with independent DNS resolution. This left a TOCTOU / DNS rebinding window: an attacker-controlled hostname could resolve to a public IP during validation and then to a private/localhost IP during the actual fetch.\n\nPackage: langchain-openai\nInstalled: 1.1.7\nFixed in: 1.1.14\nSeverity: LOW\nFix: Upgrade langchain-openai to 1.1.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c8289719fdf0643", "name": "CVE-2026-28277: langgraph 1.0.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-28277: langgraph 1.0.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "LangGraph checkpoint loading has unsafe msgpack deserialization\n\nLangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.0.9 and prior, LangGraph checkpointers can load msgpack-encoded checkpoints that reconstruct Python objects during deserialization. If an attacker can modify checkpoint data in the backing store (for example, after a database compromise or other privileged write access to the persistence layer), they can potentially supply a crafted payload that tri\n\nPackage: langgraph\nInstalled: 1.0.7\nFixed in: 1.0.10\nSeverity: MEDIUM\nFix: Upgrade langgraph to 1.0.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-423c335761052b47", "name": "CVE-2026-48775: langgraph-checkpoint 4.0.0 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48775: langgraph-checkpoint 4.0.0 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "langgraph: langgraph-checkpoint: LangGraph: Arbitrary code execution via insecure deserialization of modified checkpoint bytes\n\nLangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest in the backing store, the deserialization path could reconstruct objects beyond what the application expects, which could in turn result in code execution at checkpoint load time. T\n\nPackage: langgraph-checkpoint\nInstalled: 4.0.0\nFixed in: 4.1.1\nSeverity: MEDIUM\nFix: Upgrade langgraph-checkpoint to 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-04d1e74851653e18", "name": "CVE-2026-48776: langgraph-sdk 0.3.3 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48776: langgraph-sdk 0.3.3 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "langgraph: langgraph-sdk: LangGraph Python SDK: Unsafe URL path construction leads to unauthorized resource access\n\nLangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versions 0.3.14 and prior have unsafe URL path construction through unsanitized caller-supplied identifier values used in HTTP request paths for resource operations. Without sanitization of those values, identifiers that contain characters with special meaning in URL paths could cause the resulting request to address a different resource (and potentially \n\nPackage: langgraph-sdk\nInstalled: 0.3.3\nFixed in: 0.3.15\nSeverity: MEDIUM\nFix: Upgrade langgraph-sdk to 0.3.15"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d74a46da48ac588f", "name": "CVE-2026-45134: langsmith 0.6.4 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-45134: langsmith 0.6.4 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest\n\nPackage: langsmith\nInstalled: 0.6.4\nFixed in: 0.8.0\nSeverity: HIGH\nFix: Upgrade langsmith to 0.8.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-00761e873f86a423", "name": "GHSA-f4xh-w4cj-qxq8: langsmith 0.6.4 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "GHSA-f4xh-w4cj-qxq8: langsmith 0.6.4 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "LangSmith SDK TracingMiddleware: Arbitrary server-side file read\n\n# Summary\n\nAn attacker who can send an HTTP request to a server running the LangSmith SDK's `TracingMiddleware` can cause that server to read an arbitrary file from its local filesystem and upload the contents to LangSmith as a trace attachment. Depending on how the distributed trace system is deployed, triggering a read may not require authentication. Retrieving the contents requires read access to the LangSmith workspace the traces are sent to. The net effect is a trust-boundary crossing: a pa\n\nPackage: langsmith\nInstalled: 0.6.4\nFixed in: 0.8.18\nSeverity: HIGH\nFix: Upgrade langsmith to 0.8.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-00919a496da786ba", "name": "CVE-2026-41182: langsmith 0.6.4 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-41182: langsmith 0.6.4 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "LangSmith SDK: Streaming token events bypass output redaction\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces streaming output, each chunk is recorded as a new_token event containing the raw token value. These events bypass the redaction pipeline entirely \u2014 prepareRunCreateOrUpdateInputs (\n\nPackage: langsmith\nInstalled: 0.6.4\nFixed in: 0.7.31\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.7.31"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f1f24a788ce6ba88", "name": "CVE-2025-67221: orjson 3.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2025-67221: orjson 3.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "orjson: orjson: Denial of Service due to unbounded recursion with deeply nested JSON documents\n\nThe orjson.dumps function in orjson thru 3.11.4 does not limit recursion for deeply nested JSON documents.\n\nPackage: orjson\nInstalled: 3.11.5\nFixed in: 3.11.6\nSeverity: HIGH\nFix: Upgrade orjson to 3.11.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8aaaabd4b22515e4", "name": "CVE-2026-30922: pyasn1 0.6.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-30922: pyasn1 0.6.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with \"Indefinite Length\" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consu\n\nPackage: pyasn1\nInstalled: 0.6.2\nFixed in: 0.6.3\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0d7e720934582937", "name": "CVE-2026-59885: pyasn1 0.6.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-59885: pyasn1 0.6.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values.\n\nPackage: pyasn1\nInstalled: 0.6.2\nFixed in: 0.6.4\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-16499d8104b98e43", "name": "CVE-2026-59886: pyasn1 0.6.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-59886: pyasn1 0.6.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print\n\nPackage: pyasn1\nInstalled: 0.6.2\nFixed in: 0.6.4\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a93632f0556ac42b", "name": "CVE-2026-28684: python-dotenv 1.2.1 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-28684: python-dotenv 1.2.1 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following\n\npython-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when a cross-device rename fallback is triggered. Users should upgrade to v.1.2.2 or, as a workaround, apply the patch manually.\n\nPackage: python-dotenv\nInstalled: 1.2.1\nFixed in: 1.2.2\nSeverity: MEDIUM\nFix: Upgrade python-dotenv to 1.2.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-803bd69be705b713", "name": "CVE-2026-25645: requests 2.32.5 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-25645: requests 2.32.5 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "requests: Requests: Security bypass due to predictable temporary file creation\n\nRequests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulner\n\nPackage: requests\nInstalled: 2.32.5\nFixed in: 2.33.0\nSeverity: MEDIUM\nFix: Upgrade requests to 2.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8ab9a3f6e485c581", "name": "CVE-2025-62727: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2025-62727: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette DoS via Range header merging\n\nStarlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileResponse Range parsing/merging logic. This enables CPU exhaustion per request, causing denial\u2011of\u2011service for endpoints serving files (e.g., StaticFiles or any use of FileResponse). This vulnerability is fixed in 0.49.1.\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 0.49.1\nSeverity: HIGH\nFix: Upgrade starlette to 0.49.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-aa188a704d6c73d1", "name": "CVE-2026-48818: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48818: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows\n\nStarlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\\\attacker.com\\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account\u2019s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as Fas\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.1.0\nSeverity: HIGH\nFix: Upgrade starlette to 1.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-49fb83b93968790c", "name": "CVE-2026-54283: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-54283: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS\n\nStarlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, but silently ignored for application/x-www-form-urlencoded. An unauthenticated attacker can therefore send a urlencoded body with an arbitrarily large number of fields or an arbitrarily large field, even when the application configured limits it believed would apply.\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.3.1\nSeverity: HIGH\nFix: Upgrade starlette to 1.3.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-07156a5dfe5f2eae", "name": "CVE-2025-54121: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2025-54121: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette denial-of-service\n\nStarlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In versions 0.47.1 and below, when parsing a multi-part form with large files (greater than the default max spool size) starlette will block the main thread to roll the file over to disk. This blocks the event thread which means the application can't accept new connections. The UploadFile code has a minor bug where instead of just checking for self._in_me\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 0.47.2\nSeverity: MEDIUM\nFix: Upgrade starlette to 0.47.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e8f50909584579a", "name": "CVE-2026-48710: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48710: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Security restriction bypass via malformed HTTP Host header\n\nStarlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) \n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.0.1\nSeverity: MEDIUM\nFix: Upgrade starlette to 1.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dc1d95a21421b23e", "name": "CVE-2026-48817: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48817: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Information disclosure and unintended method execution via non-standard HTTP methods\n\nStarlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs. When an HTTPEndpoint subclass is registered through Route(...) without an explicit methods= argument, the route does not constrain the method and every method reaches the endpoint. If a non-standard HTTP method whose lo\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.1.0\nSeverity: MEDIUM\nFix: Upgrade starlette to 1.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a05cd3c02439e681", "name": "CVE-2026-54282: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-54282: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Information disclosure due to improper HTTP request path validation\n\nStarlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path} and re-parsing the result, a path that does not begin with / (for example @google.com) moves the authority boundary during re-parsing, so request.url.hostname and request.url.netloc become attacker-controlled. Code that reads request.url.hostname (rather than the Host header \n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.3.0\nSeverity: LOW\nFix: Upgrade starlette to 1.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-995c89fa3bb1a94f", "name": "CVE-2026-44431: urllib3 2.6.3 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-44431: urllib3 2.6.3 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers\n\nurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.\n\nPackage: urllib3\nInstalled: 2.6.3\nFixed in: 2.7.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-181cad0b9956ed6f", "name": "CVE-2026-44432: urllib3 2.6.3 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-44432: urllib3 2.6.3 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3: Denial of Service due to excessive HTTP response decompression\n\nurllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly \n\nPackage: urllib3\nInstalled: 2.6.3\nFixed in: 2.7.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fb39ed58889cc9f6", "name": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.17 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.17 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue\n\nA vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.\n\nPackage: @ai-sdk/provider-utils\nInstalled: 3.0.17\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-59b1231e478aeb9e", "name": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.20 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.20 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue\n\nA vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.\n\nPackage: @ai-sdk/provider-utils\nInstalled: 3.0.20\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-12bc393a5a83ef40", "name": "CVE-2026-29087: @hono/node-server 1.19.9 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-29087: @hono/node-server 1.19.9 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware\n\n@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting /admin/*), inconsistent URL decoding can allow protected static resources to be accessed without authorization. In particular, paths containing encoded slashes (%2F) may be evaluated differently by routing/middleware matching versus static file path resolution, enabling a bypass where middl\n\nPackage: @hono/node-server\nInstalled: 1.19.9\nFixed in: 1.19.10\nSeverity: HIGH\nFix: Upgrade @hono/node-server to 1.19.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1ab98012bb16aae9", "name": "CVE-2026-39406: @hono/node-server 1.19.9 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-39406: @hono/node-server 1.19.9 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "@hono/node-server: Middleware bypass via repeated slashes in serveStatic\n\n@hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware (e.g., /admin/*) is used for authorization, the router may not match paths containing repeated slashes, while serveStatic resolves them as normalized paths. This can lead to a middleware bypass. This vulnerability is fixed in 1.19.13.\n\nPackage: @hono/node-server\nInstalled: 1.19.9\nFixed in: 1.19.13\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 1.19.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-45f62cb86a07b2ce", "name": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.9 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.9 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nThe same as the `hono` core [Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44).\n\n### Summary\n\nOn Windows hosts, an encoded backslash (`%5C`) in the request path decodes to `\\`, which the Windows path resolver treats as a separator. `serve-static` then resolves a single URL segment such as `admin\\secret.txt` into a nested file under the root and serves it, letting an attacker read static files meant t\n\nPackage: @hono/node-server\nInstalled: 1.19.9\nFixed in: 2.0.5\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 2.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-293ba1a70b672312", "name": "CVE-2026-25536: @modelcontextprotocol/sdk 1.25.3 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-25536: @modelcontextprotocol/sdk 1.25.3 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "@modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leak\n\nMCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport deployments. This issue has been patched in version 1.26.0.\n\nPackage: @modelcontextprotocol/sdk\nInstalled: 1.25.3\nFixed in: 1.26.0\nSeverity: HIGH\nFix: Upgrade @modelcontextprotocol/sdk to 1.26.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fe8acd55462fef0d", "name": "CVE-2025-69873: ajv 8.17.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2025-69873: ajv 8.17.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "ajv: ReDoS via $data reference\n\najv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., \"^(a|a)*$\") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds\n\nPackage: ajv\nInstalled: 8.17.1\nFixed in: 8.18.0, 6.14.0\nSeverity: MEDIUM\nFix: Upgrade ajv to 8.18.0, 6.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dc1618aeb55bfecd", "name": "CVE-2026-12590: body-parser 1.20.4 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-12590: body-parser 1.20.4 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 1.20.4\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-190e23af524f66d6", "name": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 2.2.2\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-913c8a5dd55c2c7f", "name": "CVE-2026-0540: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-0540: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify: DOMPurify: Cross-site scripting vulnerability\n\nDOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like </noscript><img src=x onerror=alert(1)> in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2, 2.5.9\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2, 2.5.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-52fc7a4477aa73c4", "name": "CVE-2026-41238: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41238: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify: DOMPurify: Cross-Site Scripting bypass via prototype pollution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (no `CUSTOM_ELEMENT_HANDLING` option), a prior prototype pollution gadget can inject permissive `tagNameCheck` and `attributeNameCheck` regex values into `Object.prototype`, causing DOMPurify to allow arbitrary custom elements with arbitrary attributes\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f5fe58347f9978d8", "name": "CVE-2026-41239: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41239: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Vue 2: DOMPurify: Cross-site scripting due to incomplete sanitization of template expressions\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS via template-evaluating frameworks like Vue 2. Version 3.4.0 patches the issue.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-017e5bd64d4ccc26", "name": "CVE-2026-41240: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41240: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TAGS is used. Commit c361baa added an early exit for FORBID_ATTR at line 1214. The same fix was not applied to FORBID_TAGS. At line 1118-1123, when EXTRA_ELEMENT_HANDLING.tagCheck returns true, the short-circuit evaluation skips the FORBID_TAGS check entirely. This allows forbidden elements to survive \n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-95f8d0d3fd15dff0", "name": "CVE-2026-49458: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-49458: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting due to improper sanitization of DOM nodes\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks used parent-realm constructors, causing instanceof checks for forms, named node maps, document fragments, and elements to fail and skip clobber, template-content, and shadow-DOM sanitization branches so executable markup could survive. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0d85e0f237aea9e6", "name": "CVE-2026-49459: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-49459: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting bypass allows arbitrary script execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e405c9188b24d78b", "name": "CVE-2026-49978: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-49978: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4a23a28c7146702a", "name": "GHSA-39q2-94rc-95cp: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "GHSA-39q2-94rc-95cp: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation\n\n## Summary\nIn `src/purify.ts:1117-1123`, `ADD_TAGS` as a function (via `EXTRA_ELEMENT_HANDLING.tagCheck`) bypasses `FORBID_TAGS` due to short-circuit evaluation.\n\nThe condition:\n```\n!(tagCheck(tagName)) && (!ALLOWED_TAGS[tagName] || FORBID_TAGS[tagName])\n```\nWhen `tagCheck(tagName)` returns `true`, the entire condition is `false` and the element is kept \u2014 `FORBID_TAGS[tagName]` is never evaluated.\n\n## Inconsistency\nThis contradicts the attribute-side pattern at line 1214 where `FORBID_ATTR` expl\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-17f3bb1be445db6f", "name": "GHSA-76mc-f452-cxcm: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "GHSA-76mc-f452-cxcm: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\n# Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\n**CWE**: CWE-501 (Trust Boundary Violation \u2014 hook-scoped mutation leaks to global default sets) via CWE-693 (Protection Mechanism Failure \u2014 the default allow-list is silently widened for all subsequent sanitize calls)\n\n## Summary\n\nThe `data.allowedTags` and `data.allowedAttributes` fields passed to `uponSanitizeElement` and `uponSanitizeAttribute` hooks are **dir\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ddb7382b5c810631", "name": "GHSA-cj63-jhhr-wcxv: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "GHSA-cj63-jhhr-wcxv: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify USE_PROFILES prototype pollution allows event handlers\n\n## Summary\nWhen `USE_PROFILES` is enabled, DOMPurify rebuilds `ALLOWED_ATTR` as a plain array before populating it with the requested allowlists. Because the sanitizer still looks up attributes via `ALLOWED_ATTR[lcName]`, any `Array.prototype` property that is polluted also counts as an allowlisted attribute. An attacker who can set `Array.prototype.onclick = true` (or a runtime already subject to prototype pollution) can thus force DOMPurify to keep event handlers such as `onclick` even when th\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-00b1254f03f8ee62", "name": "GHSA-cjmm-f4jc-qw8r: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "GHSA-cjmm-f4jc-qw8r: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify ADD_ATTR predicate skips URI validation\n\n## Summary\nDOMPurify allows `ADD_ATTR` to be provided as a predicate function via `EXTRA_ELEMENT_HANDLING.attributeCheck`. When the predicate returns `true`, `_isValidAttribute` short-circuits the attribute check before URI-safe validation runs. An attacker who supplies a predicate that accepts specific attribute/tag combinations can then sanitize input such as `<a href=\"javascript:alert(document.domain)\">` and have the `javascript:` URL survive, because URI validation is skipped for that attrib\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c2e0fd8957d2a221", "name": "GHSA-cmwh-pvxp-8882: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)\n\n## Summary\n\nDOMPurify 3.4.7 shipped a security fix (\"permanent hook pollution\") that makes a registered `uponSanitizeAttribute` hook's mutation of `data.allowedAttributes` **non-persistent** \u2014 so allowing an attribute for one element does not leak into later `sanitize()` calls. The fix clones `ALLOWED_ATTR` inside `_parseConfig`.\n\nThat guard is **silently bypassed whenever the application uses the persistent-config API `DOMPurify.setConfig()`.** `setConfig()` sets the module flag `SET_CONFIG = t\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.11\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6a059b695b102e8e", "name": "GHSA-h8r8-wccr-v5f2: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "GHSA-h8r8-wccr-v5f2: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify is vulnerable to mutation-XSS via Re-Contextualization \n\n## Description\n\nA mutation-XSS (mXSS) condition was confirmed when sanitized HTML is reinserted into a new parsing context using `innerHTML` and special wrappers. The vulnerable wrappers confirmed in browser behavior are `script`, `xmp`, `iframe`, `noembed`, `noframes`, and `noscript`. The payload remains seemingly benign after `DOMPurify.sanitize()`, but mutates during the second parse into executable markup with an event handler, enabling JavaScript execution in the client (`alert(1)` in the P\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7bb7d1617d2c9ac0", "name": "GHSA-c2j3-45gr-mqc4: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.\n\n## Summary\n\nThere is a possible hook-policy inconsistency in DOMPurify 3.4.11 involving `CUSTOM_ELEMENT_HANDLING`.\n\nWhen a custom element is allowed via `CUSTOM_ELEMENT_HANDLING.tagNameCheck`, it appears that the element does not go through `afterSanitizeElements` in the same way as a normal element. As a result, an application that relies on `afterSanitizeElements` as a security policy layer to strip sensitive attributes from all elements may see those attributes removed from normal elements bu\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.12\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9094ad9425a3e5dd", "name": "GHSA-gvmj-g25r-r7wr: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes\n\n## Summary\n\nWhen DOMPurify is configured with both `SAFE_FOR_TEMPLATES: true` and `RETURN_DOM: true` (or `IN_PLACE: true`), an attacker can inject template expressions, such as `${evil}`, `{{evil}}`, or `<%evil%>`, that survive the sanitization pass inside `<template>` element content. This bypasses the explicit purpose of `SAFE_FOR_TEMPLATES`, which is to prevent template engine evaluation of user-supplied content.\n\n> **Note:** The string output path is **not** affected. Only the DOM return pat\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.8\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-77fc48313943c59f", "name": "GHSA-vxr8-fq34-vvx9: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output\n\n## Impact\n\nA DOMPurify instance that is reused across trust boundaries can stay bound to a previously supplied `TRUSTED_TYPES_POLICY` even after `clearConfig()` is called. A later caller that requests `RETURN_TRUSTED_TYPE` receives a `TrustedHTML` object created by the old policy, not by a clean default configuration.\n\nIf the old policy is unsafe or controlled by a less-trusted integration, this turns a later \"default\" sanitize call into script execution at a Trusted Types sink. `TRUSTED_TYPES_P\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.9\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-582324f40b486b59", "name": "GHSA-x4vx-rjvf-j5p4: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "GHSA-x4vx-rjvf-j5p4: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects\n\n## Summary\n\nWhen `DOMPurify.sanitize(root, { IN_PLACE: true })` is called on an attacker-supplied live DOM node, `DOMPurify` still trusts `currentNode.nodeName` for non-`form` nodes in the main `_sanitizeElements` pipeline. A real `<script>` child node whose observable `nodeName` is attacker-controlled can therefore be misclassified as an allowed element and retained. When the sanitized tree is inserted into a live document, the script executes.\n\nThis affects current `3.4.6`. The recent `IN_PLAC\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f338522e7d404ad1", "name": "CVE-2026-13676: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization\n\nfast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 4.0.1, 3.1.3, 2.4.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 4.0.1, 3.1.3, 2.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-43ca655ed127876d", "name": "CVE-2026-16221: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...\n\nImpact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 2.4.3, 3.1.4, 4.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 2.4.3, 3.1.4, 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-79cfe6b5d4570979", "name": "CVE-2026-6321: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies\n\nfast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Version\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-27538b0f067bb443", "name": "CVE-2026-6322: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: URI authority bypass due to improper delimiter handling\n\nfast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a differ\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f7fe6a18f9ea9231", "name": "CVE-2026-12143: form-data 4.0.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-12143: form-data 4.0.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "form-data: form-data: Form field override via CRLF injection\n\nform-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (\") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the atta\n\nPackage: form-data\nInstalled: 4.0.5\nFixed in: 2.5.6, 3.0.5, 4.0.6\nSeverity: HIGH\nFix: Upgrade form-data to 2.5.6, 3.0.5, 4.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b060b3345fb03f59", "name": "CVE-2026-29045: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-29045: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono vulnerable to arbitrary file access via serveStatic vulnerability \n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/admin/*', ...)), inconsistent URL decoding allowed protected static resources to be accessed without authorization. The router used decodeURI, while serveStatic used decodeURIComponent. This mismatch allowed paths containing encoded slashes (%2F) to bypass middleware protections while still resolving\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.4\nSeverity: HIGH\nFix: Upgrade hono to 4.12.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a4142f549dca8e42", "name": "CVE-2026-54290: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-54290: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials: true and no explicit origin (the default wildcard), the CORS Middleware reflects the request's Origin and sends Access-Control-Allow-Credentials: true. Any site can then make credentialed cross-origin requests and read the responses, exposing cookie-authenticated endpoints to arbitrary origins. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.25\nSeverity: HIGH\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7d2230078ad0fe75", "name": "CVE-2026-24398: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-24398: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, IP Restriction Middleware in Hono is vulnerable to an IP address validation bypass. The `IPV4_REGEX` pattern and `convertIPv4ToBinary` function in `src/utils/ipaddr.ts` do not properly validate that IPv4 octet values are within the valid range of 0-255, allowing attackers to craft malformed IP addresses that bypass IP-based access controls. Version 4.11.7 contains a patch for the issue.\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.11.7\nSeverity: MEDIUM\nFix: Upgrade hono to 4.11.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3190b383c0bfc454", "name": "CVE-2026-24472: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-24472: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono cache middleware ignores \"Cache-Control: private\" leading to Web Cache Deception\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Cache Middleware contains an information disclosure vulnerability caused by improper handling of HTTP cache control directives. The middleware does not respect standard cache control headers such as `Cache-Control: private` or `Cache-Control: no-store`, which may result in private or authenticated responses being cached and subsequently exposed to unauthorized users. Version 4.11.7 has \n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.11.7\nSeverity: MEDIUM\nFix: Upgrade hono to 4.11.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-df0ab16938228f95", "name": "CVE-2026-24473: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-24473: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Serve static Middleware for the Cloudflare Workers adapter contains an information disclosure vulnerability that may allow attackers to read arbitrary keys from the Workers environment. Improper validation of user-controlled paths can result in unintended access to internal asset keys. Version 4.11.7 contains a patch for the issue.\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.11.7\nSeverity: MEDIUM\nFix: Upgrade hono to 4.11.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e09a404b949fa2cc", "name": "CVE-2026-24771: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-24771: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono vulnerable to XSS through ErrorBoundary component \n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, a Cross-Site Scripting (XSS) vulnerability exists in the `ErrorBoundary` component of the hono/jsx library. Under certain usage patterns, untrusted user-controlled strings may be rendered as raw HTML, allowing arbitrary script execution in the victim's browser. Version 4.11.7 patches the issue.\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.11.7\nSeverity: MEDIUM\nFix: Upgrade hono to 4.11.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-20a8e19c0a288235", "name": "CVE-2026-29085: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-29085: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming Helper, the event, id, and retry fields were not validated for carriage return (\\r) or newline (\\n) characters. Because the SSE protocol uses line breaks as field delimiters, this could allow injection of additional SSE fields within the same event frame if untrusted input was passed into these fields. This issue has been patched in version 4.12.4.\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.4\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-86ee471158bf3623", "name": "CVE-2026-29086: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-29086: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, the setCookie() utility did not validate semicolons (;), carriage returns (\\r), or newline characters (\\n) in the domain and path options when constructing the Set-Cookie header. Because cookie attributes are delimited by semicolons, this could allow injection of additional cookie attributes if untrusted input was passed into these fields. This issue has been patched in version 4.12.4.\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.4\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d57022f0e8e3f390", "name": "CVE-2026-39407: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-39407: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono: Middleware bypass via repeated slashes in serveStatic\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware (e.g., /admin/*) is used for authorization, the router may not match paths containing repeated slashes, while serveStatic resolves them as normalized paths. This can lead to a middleware bypass. This vulnerability is fixed in \n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-584f573cacd15d47", "name": "CVE-2026-39408: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-39408: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono: Path traversal in toSSG() allows writing files outside the output directory\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to be written outside the configured output directory during static site generation. When using dynamic route parameters via ssgParams, specially crafted values can cause generated file paths to escape the intended output directory. This vulnerability is fixed in 4.12.12.\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f678a9582ccf30e7", "name": "CVE-2026-39409: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-39409: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-mapped IPv6 client addresses (e.g. ::ffff:127.0.0.1) before applying IPv4 allow or deny rules. In environments such as Node.js dual-stack, this can cause IPv4 rules to fail to match, leading to unintended authorization behavior. This vulnerability is fixed in 4.12.12.\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ab34a189b3e03a21", "name": "CVE-2026-39410: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-39410: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono: Non-breaking space prefix bypass in cookie name handling in getCookie()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy between browser cookie parsing and parse() handling allows cookie prefix protections to be bypassed. Cookie names that are treated as distinct by the browser may be normalized to the same key by parse(), allowing attacker-controlled cookies to override legitimate ones. This vulnerability is fixed in 4.12.12.\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-57bf89c16ed55d47", "name": "CVE-2026-44455: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44455: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handling of JSX element tag names in hono/jsx allowed unvalidated tag names to be directly inserted into the generated HTML output. When untrusted input is used as a tag name via the programmatic jsx() or createElement() APIs during server-side rendering, specially crafted values may break out of the intended element context and inject unintended HTML. This vulnerability is fixed in 4\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.16\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7053e25698b6f5e7", "name": "CVE-2026-44456: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44456: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono: bodyLimit() can be bypassed for chunked / unknown-length requests\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize for requests without a usable Content-Length (e.g. Transfer-Encoding: chunked). Oversized requests can reach handlers and return 200 instead of 413. This vulnerability is fixed in 4.12.16.\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.16\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c7977e41190df073", "name": "CVE-2026-44457: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44457: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for responses that declare per-user variance via Vary: Authorization or Vary: Cookie. As a result, a response cached for one authenticated user may be served to subsequent requests from different users. This vulnerability is fixed in 4.12.18.\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.18\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a38e2c44f914fb65", "name": "CVE-2026-44458: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44458: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono has CSS Declaration Injection via Style Object Values in JSX SSR\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer escapes style attribute object values for HTML but not for CSS. Untrusted input in a style object value or property name can therefore inject additional CSS declarations into the rendered style attribute. The impact is limited to CSS and does not allow JavaScript execution or HTML attribute breakout. This vulnerability is fixed in 4.12.18.\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.18\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-565870d2fc81539b", "name": "CVE-2026-47673: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-47673: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono: JWT middleware accepts any Authorization scheme, not only Bearer\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that the Authorization header value uses theBearer scheme. Any two-part header value \u2014 regardless of the scheme name in the first position \u2014 proceeds to JWT verification. A request presenting a valid JWT under a non-Bearer scheme identifier (such as Basic or Token) is authenticated identically to a correctly formed Bearer request. This vulnerability is\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3fa2ffc76867e25b", "name": "CVE-2026-47674: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-47674: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 \n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against configured deny and allow rules using string equality after partial normalization. Non-canonical IPv6 representations of an address already listed in a static rule \u2014 such as compressed forms, explicit-zero forms, or hex-notation IPv4-mapped addresses \u2014 do not match the normalized rule entry, causing the \n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-693f69c730a233dc", "name": "CVE-2026-47675: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-47675: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters that corrupt Set-Cookie header syntax (;, \\r, \\n), but does not apply the same validation to sameSite and priority. An application that passes user-controlled input into either option may produce a Set-Cookie response header containing attacker-chosen additional attributes. This vulnerability is fixed \n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-13df844911bab1d5", "name": "CVE-2026-47676: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-47676: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request path using the raw URL pathname, while route matching is performed against the percent-decoded path. This inconsistency causes the prefix to be stripped at the wrong position when the path contains percent-encoded multi-byte characters, resulting in the mounted sub-application receiving an incorrect path. This vulnerability is fixed\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5b0fc537468cf4c3", "name": "CVE-2026-54286: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-54286: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \\, which the Windows path resolver treats as a separator. serve-static then resolves a single URL segment such as admin\\secret.txt into a nested file under the root and serves it, letting an attacker read static files meant to be protected behind prefix-mounted middleware. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f6dd9024ec5017d0", "name": "CVE-2026-54287: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-54287: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, the ALB single-header response and the VPC Lattice v2 response join multiple Set-Cookie headers into one comma-separated value. Because commas also appear inside cookie attributes (for example Expires dates), clients cannot split the value back into individual cookies and silently drop or misparse them. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c04c0da1e0cdc07c", "name": "CVE-2026-54288: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-54288: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit Middleware trusts the request's Content-Length header to decide whether a body is within the limit. On AWS Lambda (API Gateway v1/v2, ALB, VPC Lattice, and Lambda@Edge) the body is delivered fully buffered and the adapter builds the request with the client-declared Content-Length, which need not match the actual payload. A client can declare a tiny Content-Length while sending a\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-002cc9a1cb95ebdf", "name": "CVE-2026-54289: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-54289: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Edge, CloudFront delivers a request header that appears more than once as several separate entries. The adapter writes each value with Headers.set instead of Headers.append, so every value overwrites the previous one and only the last reaches the application. Repeated request headers such as X-Forwarded-For, Forwarded, and Via are silently truncated to a single value. Request mid\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-498dd78298655aea", "name": "CVE-2026-56761: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-56761: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR\n\nhono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers can craft specially crafted attribute keys containing characters like quotes or angle brackets to break html tag boundaries and inject arbitrary attributes or elements.\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.14\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-20c57777f5bd0db3", "name": "CVE-2026-59895: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-59895: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-83efb7fdba07b4c8", "name": "CVE-2026-59897: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-59897: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete X-Forwarded-For chain, rate limiting, audit logging, or proxy-chain validation can receive incomplete data. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1216ba17dd8af3e9", "name": "GHSA-26pp-8wgv-hjvm: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "GHSA-26pp-8wgv-hjvm: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono missing validation of cookie name on write path in setCookie()\n\n## Summary\n\nCookie names are not validated on the write path when using `setCookie()`, `serialize()`, or `serializeSigned()` to generate Set-Cookie headers.\n\nWhile certain cookie attributes such as domain and path are validated, the cookie name itself may contain invalid characters.\n\nThis results in inconsistent handling of cookie names between parsing (read path) and serialization (write path).\n\n## Details\n\nWhen applications use `setCookie()`, `serialize()`, or `serializeSigned()` with a user-c\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9bef7bf5440c265c", "name": "GHSA-v8w9-8mx6-g223: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "GHSA-v8w9-8mx6-g223: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })\n\n## Summary\n\nWhen using `parseBody({ dot: true })` in HonoRequest, specially crafted form field names such as `__proto__.x` could create objects containing a `__proto__` property.\n\nIf the parsed result is later merged into regular JavaScript objects using unsafe merge patterns, this may lead to prototype pollution in the target object.\n\n## Details\n\nThe `parseBody({ dot: true })` feature supports dot notation to construct nested objects from form field names.\n\nIn previous versions, the `__proto__`\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.7\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-86ef819bf34c42b0", "name": "CVE-2026-44459: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44459: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validation of the JWT NumericDate claims exp, nbf, and iat in hono/utils/jwt allows tokens with non-spec-compliant claim values to silently bypass time-based checks. This issue is not exploitable by an anonymous attacker; it only manifests when a malformed claim value reaches verify() \u2014 typically when the application itself issues such tokens, or when the signing key is otherwise unde\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.12.18\nSeverity: LOW\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-48c7485302317618", "name": "GHSA-gq3j-xvxp-8hrf: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "GHSA-gq3j-xvxp-8hrf: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Hono added timing comparison hardening in basicAuth and bearerAuth\n\n## Summary\n\nThe `basicAuth` and `bearerAuth` middlewares previously used a comparison that was not fully timing-safe.\n\nThe `timingSafeEqual` function used normal string equality (`===`) when comparing hash values. This comparison may stop early if values differ, which can theoretically cause small timing differences.\n\nThe implementation has been updated to use a safer comparison method.\n\n\n## Details\n\nThe issue was caused by the use of normal string equality (`===`) when comparing hash values ins\n\nPackage: hono\nInstalled: 4.11.5\nFixed in: 4.11.10\nSeverity: LOW\nFix: Upgrade hono to 4.11.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f8c0cf7ddb3f78b4", "name": "CVE-2026-45134: langsmith 0.3.87 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-45134: langsmith 0.3.87 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest\n\nPackage: langsmith\nInstalled: 0.3.87\nFixed in: 0.6.0\nSeverity: HIGH\nFix: Upgrade langsmith to 0.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6c3a5a3dfbf40c67", "name": "CVE-2026-25528: langsmith 0.3.87 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-25528: langsmith 0.3.87 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing feature is vulnerable to Server-Side Request Forgery via malicious HTTP headers. An attacker can inject arbitrary api_url values through the baggage header, causing the SDK to exfiltrate sensitive trace data to attacker-controlled endpoints. When using distributed tracing, the SDK parses incoming HTTP headers via RunTree.from_headers() in Python or RunTree.fromHeaders() in Typ\n\nPackage: langsmith\nInstalled: 0.3.87\nFixed in: 0.4.6\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3e7bd6fecb5a52a8", "name": "CVE-2026-40190: langsmith 0.3.87 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-40190: langsmith 0.3.87 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() utility. The baseAssignValue() function only guards against the __proto__ key, but fails to prevent traversal via constructor.prototype. This allows an attacker who controls keys in data processed by the createAnonymizer() API to pollute Object.prototype, affecti\n\nPackage: langsmith\nInstalled: 0.3.87\nFixed in: 0.5.18\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.5.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-35e857ca7f1ac496", "name": "CVE-2026-41182: langsmith 0.3.87 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41182: langsmith 0.3.87 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "LangSmith SDK: Streaming token events bypass output redaction\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces streaming output, each chunk is recorded as a new_token event containing the raw token value. These events bypass the redaction pipeline entirely \u2014 prepareRunCreateOrUpdateInputs (\n\nPackage: langsmith\nInstalled: 0.3.87\nFixed in: 0.5.19\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.5.19"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fae51b633a002ba8", "name": "CVE-2026-45134: langsmith 0.4.8 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-45134: langsmith 0.4.8 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest\n\nPackage: langsmith\nInstalled: 0.4.8\nFixed in: 0.6.0\nSeverity: HIGH\nFix: Upgrade langsmith to 0.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-737917931f74bb36", "name": "CVE-2026-40190: langsmith 0.4.8 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-40190: langsmith 0.4.8 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() utility. The baseAssignValue() function only guards against the __proto__ key, but fails to prevent traversal via constructor.prototype. This allows an attacker who controls keys in data processed by the createAnonymizer() API to pollute Object.prototype, affecti\n\nPackage: langsmith\nInstalled: 0.4.8\nFixed in: 0.5.18\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.5.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7f1b7853209aa4d6", "name": "CVE-2026-41182: langsmith 0.4.8 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41182: langsmith 0.4.8 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "LangSmith SDK: Streaming token events bypass output redaction\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces streaming output, each chunk is recorded as a new_token event containing the raw token value. These events bypass the redaction pipeline entirely \u2014 prepareRunCreateOrUpdateInputs (\n\nPackage: langsmith\nInstalled: 0.4.8\nFixed in: 0.5.19\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.5.19"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-be6154a7d56c0119", "name": "CVE-2026-4800: lodash-es 4.17.21 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-4800: lodash-es 4.17.21 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d60c591788e5fde2", "name": "CVE-2025-13465: lodash-es 4.17.21 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2025-13465: lodash-es 4.17.21 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "lodash: prototype pollution in _.unset and _.omit functions\n\nLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset\u00a0and _.omit\u00a0functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.\n\nThe issue permits deletion of properties but does not allow overwriting their original behavior.\n\nThis issue is patched on 4.17.23\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.17.23\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.17.23"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-057c64b00d2db54e", "name": "CVE-2026-2950: lodash-es 4.17.21 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-2950: lodash-es 4.17.21 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5ee25e73f85672ce", "name": "CVE-2026-4800: lodash-es 4.17.23 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-4800: lodash-es 4.17.23 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash-es\nInstalled: 4.17.23\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f17ba385b405e7fc", "name": "CVE-2026-2950: lodash-es 4.17.23 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-2950: lodash-es 4.17.23 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash-es\nInstalled: 4.17.23\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fe8275cb340c2dc1", "name": "CVE-2026-41148: mermaid 11.12.2 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41148: mermaid 11.12.2 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: CSS injection vulnerability allows page defacement and information disclosure\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS injection through improper sanitization. The state diagram (and any other diagram type that routes user-controlled style strings through the createCssStyles parser) captures classDef values using an unrestricted regex that matches everything up to a newline. That value then flows unsanitized through \n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f7ef8cb1c948b4ab", "name": "CVE-2026-41149: mermaid 11.12.2 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41149: mermaid 11.12.2 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: HTML injection via classDef directive in state diagrams\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configuration. Specifically, the classDef directive in Mermaid state diagrams permits DOM injection that escapes the SVG context. However, <script> tags are stripped, which prevents cross-site scripting (XSS). This issue has been fixed in versions 10.9.6 and 11.15.0. If de\n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fe79823ba0d4a41f", "name": "CVE-2026-41150: mermaid 11.12.2 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41150: mermaid 11.12.2 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: Denial of Service via specially crafted gantt charts\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates. mermaid.parse is unaffected, unless you then call the ganttDb.getTasks() (which is called when rendering a diagram). This vulnerability is fixed in 10.9.6 and 11.15.0.\n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3b37e222a9c60eeb", "name": "CVE-2026-41159: mermaid 11.12.2 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41159: mermaid 11.12.2 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: Information disclosure and page defacement via CSS injection\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0,  Mermaid's default configuration allows injecting CSS that applies outside of the Mermaid diagram via the fontFamily, themeCSS, and altFontFamily configuration options. The injected CSS exploits stylis's & (scope reference) handling. :not(&) escapes the #mermaid-xxx automatic scoping, applying styles to all page elements. Global at-rules (@font-face, @keyframes, @c\n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eb352fed06fe5fd4", "name": "CVE-2026-44573: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44573: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed data route, allowing an attacker to retrieve SSR JSON for protected pages without passing the intende\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9fa7a25c11c6aee6", "name": "CVE-2026-44574: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44574: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Authorization bypass via crafted query parameters\n\nNext.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check. This vulnerability is fixed in 1\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7ea657c7a602700d", "name": "CVE-2026-44575: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44575: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Unauthorized access to protected content via middleware bypass\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a77d13049f721c39", "name": "CVE-2026-44578: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44578: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests\n\nNext.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6ff613b2e3ee5593", "name": "CVE-2026-44579: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44579: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service via crafted POST requests to server actions\n\nNext.js is a React framework for building full-stack web applications. From  to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open for an extended period, consuming file descriptors and server capacity until legitimate users are den\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0772cc31a72770d7", "name": "CVE-2026-45109: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-45109: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.18, 16.2.6\nSeverity: HIGH\nFix: Upgrade next to 15.5.18, 16.2.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0b790afb5fe75c8f", "name": "CVE-2026-64641: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-64641: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Denial of Service in App Router using Server Actions\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.\n\n## Workarounds\n\nNo workaround exists besides upgrading. Applications using Pages Router or not using Server Actions are not vulnerable.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-533b86fd1bbd1556", "name": "CVE-2026-64642: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-64642: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router built with Turbopack and a **single** entry in `config.i18n.locales` can bypass middleware/proxy based authentication.\n\n## Workarounds\n\nIf you cannot upgrade immediately, enforce authorization in the page's server-side data path instead of relying solely on middleware.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bce81a8fc51d6c73", "name": "CVE-2026-64645: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-64645: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\n## Impact\n\nA `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's\u00a0hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect.\n\nThis affects any destination that puts a dynamic segmen\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-beb9d069a4759d28", "name": "CVE-2026-64649: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-64649: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in Server Actions on custom servers\n\n## Impact\n\nWhen a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization.\n\nApplications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6ad57425320969a8", "name": "GHSA-8h8q-6873-q5fj: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "GHSA-8h8q-6873-q5fj: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Next.js Vulnerable to Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh). \n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of \n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7a98b5ea98d7553e", "name": "GHSA-h25m-26qc-wcjf: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "GHSA-h25m-26qc-wcjf: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.0.x, 19.1.x, and 19.2.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23864](https://github.com/facebook/react/security/advisories/GHSA-83fc-fqcc-2hmg).\n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage, out-of-m\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5\nSeverity: HIGH\nFix: Upgrade next to 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b632929b6d45ed49", "name": "GHSA-q4gf-8mx6-v5v3: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "GHSA-q4gf-8mx6-v5v3: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Next.js has a Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react/security/advisories/GHSA-479c-33wc-g2pg). You can read more about this advisory our [this changelog](https://vercel.com/changelog/summary-of-cve-2026-23869).\n\nA specially crafted HTTP request can be sent to any App Rout\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.15, 16.2.3\nSeverity: HIGH\nFix: Upgrade next to 15.5.15, 16.2.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2ff184872bbfcb6e", "name": "CVE-2025-59471: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2025-59471: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "next: NextJS Denial of Service in Image Optimizer\n\nA denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing a maximum size limit, allowing an attacker to cause out-of-memory conditions by requesting optimization of arbitrarily large images. This vulnerability requires that `remotePatterns` is configured to allow image optimization from external domains and\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.10, 16.1.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.10, 16.1.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2dba7962dccae992", "name": "CVE-2025-59472: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2025-59472: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "next: NextJS Denial of Service in Partial Pre Rendering\n\nA denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests with the `Next-Resume: 1` header and processes attacker-controlled postponed state data. Two closely related vulnerabilities allow an attacker to crash the server process through memory exhaustion:\n\n1. **Unbounded request body buffering**: The server buffers the entire POST request body into memory using `\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.5, 15.6.0-canary.61\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.5, 15.6.0-canary.61"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9c6eb4a4f4a62dc4", "name": "CVE-2026-27978: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-27978: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: null origin can bypass Server Actions CSRF checks\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, `origin: null` was treated as a \"missing\" origin during Server Action CSRF validation. As a result, requests from opaque contexts (such as sandboxed iframes) could bypass origin verification instead of being validated as cross-origin requests. An attacker could induce a victim browser to submit Server Actions from a sandboxed context, potentially executing state-changing\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-497349c8d3b6fceb", "name": "CVE-2026-27979: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-27979: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Unbounded postponed resume buffering can lead to DoS\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing the `next-resume: 1` header (corresponding with a PPR resume request) would buffer request bodies without consistently enforcing `maxPostponedStateSize` in certain setups. The previous mitigation protected minimal-mode deployments, but equivalent non-minimal deployments remained vulnerable to the same unbounded postponed resume-body buffering behavio\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e446540fbfb35256", "name": "CVE-2026-27980: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-27980: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Unbounded next/image disk cache growth can exhaust storage\n\nNext.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unbounded cache growth. An attacker could generate many unique image-optimization variants and exhaust disk space, causing denial of service. This is fixed in version 16.1.7 by adding an LRU-backed disk cache with `images.maximumDiskCacheSize`, including e\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7, 15.5.14\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9790b10edde7fa88", "name": "CVE-2026-29057: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-29057: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: HTTP request smuggling in rewrites\n\nNext.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfer-Encoding: chunked` could trigger request boundary disagreement between the proxy and backend. This could allow request smuggling through rewritten routes. An attacker could smuggle a second request to unintended backend routes (for example, interna\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7, 15.5.13\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8baa115b0e32695b", "name": "CVE-2026-44576: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44576: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning vulnerability in React Server Components\n\nNext.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later visitors receive component payloads instead of the expected HTML. This vulnerability is fixed in 15.5\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e4f2a9ca59020181", "name": "CVE-2026-44577: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44577: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Denial of Service via Image Optimization API\n\nNext.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the /_next/image endpoint that match the images.localPatterns configuration (by default, all patterns are allowed). This vulnerability\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2fea8ff19f93297d", "name": "CVE-2026-44580: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44580: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Cross-site scripting allows arbitrary code execution via untrusted script content\n\nNext.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to break out of the intended script context and execute arbitrary JavaScript in a visitor's browser. This vu\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e91cbb00f520e9b6", "name": "CVE-2026-44581: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44581: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Stored Cross-Site Scripting via malformed nonce values in cached responses\n\nNext.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to poison cached responses and cause script execution for later visitors. This vulnerability is fixed i\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-94428a222ad949c4", "name": "CVE-2026-64643: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-64643: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Unauthenticated disclosure of internal Server Function endpoints\n\n## Impact\n\nIn Next.js applications using App Router, Server Actions (`use server`) or `use cache` endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used.\n\nServer Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references).\n\nAffected users are applications using App Router + Server Actions.  \n\nBy itself, this disclosure is typically a recon/enumeration primi\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-167334b14655683d", "name": "CVE-2026-64644: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-64644: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Denial of Service in the Image Optimization API using SVGs\n\n### Impact\n\nWhen self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in  `/_next/image` endpoints.\n\n- If you are using `config.images.remotePatterns`, only the patterns in that array are impacted.\n- If you are using `config.images.unoptimized: true`, you are NOT impacted.\n- If you are using `config.images.loader: 'custom'`\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6b1b94ee9d94272b", "name": "CVE-2026-64646: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-64646: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Unbounded Server Action payload in Edge runtime\n\n## Impact\n\nRequests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime\n\n## Workarounds\n\nIf you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should be allowed at max by your hosting provider.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-81cbd2b686a8c515", "name": "CVE-2026-64647: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-64647: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for `\uc083\uc083` and `\uc104\uc104` in the request body would share the same cache.\n\n##\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e59f915ed9ec917f", "name": "CVE-2026-64648: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-64648: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis only applies to `fetch` calls with a request that has a different init than the one passed to `fetch`.\nSafe: `fetch(new Request(init), init)`\nUnsafe: `fetch(new Request(init), aDifferentInit)`\n\n## Work\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9924e36f4ffd8102", "name": "CVE-2026-27977: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-27977: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: null origin can bypass dev HMR websocket CSRF checks\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in `next dev`, cross-site protection for internal websocket endpoints could treat `Origin: null` as a bypass case even if `allowedDevOrigins` is configured, allowing privacy-sensitive/opaque contexts (for example sandboxed documents) to connect unexpectedly. If a dev server is reachable from attacker-controlled content, an attacker may be able to connect to the HMR webso\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7\nSeverity: LOW\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e3a8b0dee9955c3c", "name": "CVE-2026-44572: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44572: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service due to improper handling of x-nextjs-data header with redirects\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When that happened, the middleware/proxy could treat the request as a data request and replace the standard Location redirect header with the internal x-nextjs-redirect header. Browsers do not follow x-nextjs-redirect, so the response became an unusable red\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-30a81cf66ca57f16", "name": "CVE-2026-44582: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44582: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning allows incorrect response delivery\n\nNext.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL. This vulnerability is fixed in 15.5.16 and 16.2.5.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-86ce9b8335dcca0b", "name": "CVE-2026-4867: path-to-regexp 0.1.12 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-4867: path-to-regexp 0.1.12 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters\n\nImpact:\n\nA bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c or /:a-:b-:c-:d. The backtrack protection added in path-to-regexp@0.1.12 only prevents ambiguity for two parameters. With three or more, the generated lookahead does not block single separator characters, so capture groups overlap and cause catastrophic backtracking.\n\nPatches:\n\nUpgrade to path-to-regexp@0.1.13\n\n\n\nPackage: path-to-regexp\nInstalled: 0.1.12\nFixed in: 0.1.13\nSeverity: HIGH\nFix: Upgrade path-to-regexp to 0.1.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0222fb556c7a5eff", "name": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions\n\nImpact:\n\nA bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service.\n\nPatches:\n\nFixed in version 8.4.0.\n\nWorkarounds:\n\nLimit the number of sequential optional groups in route patterns. Avoid passing user-controlled input as route patterns.\n\nPackage: path-to-regexp\nInstalled: 8.3.0\nFixed in: 8.4.0\nSeverity: HIGH\nFix: Upgrade path-to-regexp to 8.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d4693592e282dc82", "name": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via specially crafted paths with multiple wildcards\n\nImpact:\n\nWhen using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path.\n\nUnsafe examples:\n\n/*foo-*bar-:baz\n/*a-:b-*c-:d\n/x/*a-:b/*c/y\n\nSafe examples:\n\n/*foo-:bar\n/*foo-:bar-*baz\n\nPatches:\n\nUpgrade to version 8.4.0.\n\nWorkarounds:\n\nIf you are using multiple wildcard parameters, you can check the regex output with a too\n\nPackage: path-to-regexp\nInstalled: 8.3.0\nFixed in: 8.4.0\nSeverity: MEDIUM\nFix: Upgrade path-to-regexp to 8.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-74aa28e1e13081d3", "name": "CVE-2026-41305: postcss 8.4.31 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.4.31\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-af93b96c688d36ed", "name": "CVE-2024-53382: prismjs 1.27.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2024-53382: prismjs 1.27.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "prismjs: DOM Clobbering vulnerability within the Prism library's prism-autoloader plugin\n\nPrism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.\n\nPackage: prismjs\nInstalled: 1.27.0\nFixed in: 1.30.0\nSeverity: MEDIUM\nFix: Upgrade prismjs to 1.30.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9fe2f0f13568b9dc", "name": "CVE-2026-8723: qs 6.14.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-8723: qs 6.14.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "### Summary    `qs.stringify` throws `TypeError` when called with `arr ...\n\n### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti\n\nPackage: qs\nInstalled: 6.14.1\nFixed in: 6.15.2\nSeverity: MEDIUM\nFix: Upgrade qs to 6.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-93eb7cd8ac983eb8", "name": "CVE-2026-2391: qs 6.14.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-2391: qs 6.14.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "qs: qs's arrayLimit bypass in comma parsing allows denial of service\n\n### Summary\nThe `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).\n\n### Details\nWhen the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?\n\nPackage: qs\nInstalled: 6.14.1\nFixed in: 6.14.2\nSeverity: LOW\nFix: Upgrade qs to 6.14.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4229af95ba177569", "name": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591\n\n### Impact\n\nA number of vulnerabilities, two rated as \"High\" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency.\n\nThose processing untrusted input with versions of sharp prior to 0.35.0 are affected.\n\n### Patches\n\n#### Using prebuilt binaries provided by sharp?\n\nMost people rely on the prebuilt binaries provided by sharp.\n\nPlease upgrade sharp to the latest version, currently 0.35.3, which provides libvips 8.18.3.\n\n#### Using a globally-installed libvips?\n\nP\n\nPackage: sharp\nInstalled: 0.34.5\nFixed in: 0.35.0\nSeverity: HIGH\nFix: Upgrade sharp to 0.35.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e3644a2a1d4665d9", "name": "CVE-2026-12644: ts-deepmerge 7.0.3 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-12644: ts-deepmerge 7.0.3 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "ts-deepmerge: Prototype Method Override leads to DoS\n\nVersions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of built-in Object.prototype methods (such as toString, valueOf). When user-controlled input contains these keys with non-function values, the resulting merged object becomes broken \u2014 any string context operation throws a TypeError, crashing the application.\n\nPackage: ts-deepmerge\nInstalled: 7.0.3\nFixed in: 8.0.0\nSeverity: MEDIUM\nFix: Upgrade ts-deepmerge to 8.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d482ea60f435961", "name": "CVE-2026-41907: uuid 10.0.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 10.0.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 10.0.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-70b73452b5db073a", "name": "CVE-2026-41907: uuid 11.1.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 11.1.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4081e2c7d8d1cfe7", "name": "CVE-2026-41907: uuid 9.0.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 9.0.1\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-467afb15139b2922", "name": "CVE-2026-22815: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-22815: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via insufficient header/trailer handling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-73aee9721dd8e858", "name": "CVE-2026-34515: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-34515: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Information disclosure via static resource handler on Windows\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9ff770951e26e110", "name": "CVE-2026-34516: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-34516: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via excessive multipart headers\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multipart headers may be allowed to use more memory than intended, potentially allowing a DoS vulnerability. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-54f96c902de16125", "name": "CVE-2026-34525: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-34525: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Security bypass via multiple Host headers\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d5d8618477b6d126", "name": "CVE-2026-34993: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-34993: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load()\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.0\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-703fd3ac5e4c0be6", "name": "CVE-2026-47265: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-47265: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "python-aiohttp: AIOHTTP: Information disclosure via improper handling of cookies during cross-origin redirects\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect. If a developer uses the `cookies` parameter on a per-request basis then sensitive data might be leaked to an attacker if they manage to control a redirect. Version 3.14.0 patches the issue. If unable to upgrade, using a `Cookie` header in the `headers` parameter is not vulnerable.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.0\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-01c27e0a5aee4775", "name": "CVE-2026-54273: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-54273: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via excessive pipelined requests\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An attacker may be able to use pipelined requests to use excessive amounts of memory, potentially leading to DoS. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ee6d2516cbb15479", "name": "CVE-2026-54274: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-54274: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via incomplete websocket frame payloads\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b03a654563be231e", "name": "CVE-2026-54276: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-54276: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Information disclosure via DigestAuthMiddleware after cross-origin redirect\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vulnerability or similar on the target domain for an attacker to be able to execute. Further, the attacker is only receiving the digest, so should only be able to extract the user's credentials if the cryptography is weak or there is some kind of password reuse. This\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f16b06cc82ae3586", "name": "CVE-2026-54277: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-54277: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via oversized HTTP request lines bypassing max_line_size check\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in parts of an HTTP request in the C parser. If using the optimised C parser (the default in pre-built wheels), then an attacker may be able to send oversized lines through the HTTP parser and use an excessive amount of memory, potentially leading to DoS. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0cb5d9b38ecbb0bc", "name": "CVE-2026-54278: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-54278: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service due to excessive memory consumption from compressed request body\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-015253882b0c945a", "name": "CVE-2026-34513: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-34513: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service due to unbounded DNS cache\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-caa08e021651a373", "name": "CVE-2026-34514: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-34514: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Header Injection via content_type parameter manipulation\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f8dd7f2505b701f4", "name": "CVE-2026-34517: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-34517: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via large multipart form fields\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multipart form fields, aiohttp read the entire field into memory before checking client_max_size. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9a65e3e6b727712c", "name": "CVE-2026-34518: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-34518: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Information disclosure via retained Cookie and Proxy-Authorization headers during redirects\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following redirects to a different origin, aiohttp drops the Authorization header, but retains the Cookie and Proxy-Authorization headers. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-73564f53c5bad19c", "name": "CVE-2026-34519: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-34519: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Header injection vulnerability via reason parameter\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the reason parameter when creating a Response may be able to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-89f4c3ddbc01e51f", "name": "CVE-2026-34520: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-34520: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Header injection vulnerability due to improper character handling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-69cb7214e0b39e47", "name": "CVE-2026-50269: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-50269: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: CRLF injection in multipart headers\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar. In the unlikely situation that an application is passing user-controlled strings into MultipartWriter.append(headers=...) or Payload.headers, then an attacker may be able to modify the request to inject headers or change the contents of the request. This vulnerabi\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.0\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-df40681f5bd4b674", "name": "CVE-2026-54275: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-54275: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: TLS SNI check bypass via connection reuse\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an application makes multiple requests to the same domain, but with different per-request server_hostname parameters, then the later calls may succeed by reusing the existing connection when they should have been rejected due to the TLS SNI check. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.1\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-79800e06701f2784", "name": "CVE-2026-54279: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-54279: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Host-Only Cookies Become Domain Cookies After CookieJar Persistence\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.1\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8b438f87801fda4d", "name": "CVE-2026-54280: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-54280: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be able to cause resource starvation temporarily until garbage collection or similar closes the file. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.1\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ee6398a00b92ca86", "name": "CVE-2026-41425: authlib 1.6.9 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-41425: authlib 1.6.9 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "authlib: Authlib: Cross-Site Request Forgery (CSRF) vulnerability in OAuth cache feature\n\nAuthlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth.  This vulnerability is fixed in 1.6.11.\n\nPackage: authlib\nInstalled: 1.6.9\nFixed in: 1.6.11\nSeverity: MEDIUM\nFix: Upgrade authlib to 1.6.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-51c09d5b24bd2ac9", "name": "CVE-2026-41479: authlib 1.6.9 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-41479: authlib 1.6.9 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "Authlib is a Python library which builds OAuth and OpenID Connect serv ...\n\nAuthlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an unsupported response_type and supplies an attacker-controlled redirect_uri. The vulnerable behavior happens before client lookup and before any redirect URI validation. As a result, an attacker does not need a valid client registration, an authenticated user, or any prior state. \n\nPackage: authlib\nInstalled: 1.6.9\nFixed in: 1.6.10, 1.7.1\nSeverity: MEDIUM\nFix: Upgrade authlib to 1.6.10, 1.7.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-912eef5d8d665524", "name": "CVE-2026-44681: authlib 1.6.9 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-44681: authlib 1.6.9 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "Authlib is a Python library which builds OAuth and OpenID Connect serv ...\n\nAuthlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authorization endpoint lets a remote attacker cause the authorization server to issue an HTTP 302 to an attacker-chosen URL by submitting an authorization request that omits the openid scope. This vulnerability is fixed in 1.6.12 and 1.7.1.\n\nPackage: authlib\nInstalled: 1.6.9\nFixed in: 1.7.1, 1.6.12\nSeverity: MEDIUM\nFix: Upgrade authlib to 1.7.1, 1.6.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-71254bab4f0165c1", "name": "GHSA-537c-gmf6-5ccf: cryptography 46.0.5 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "GHSA-537c-gmf6-5ccf: cryptography 46.0.5 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "Vulnerable OpenSSL included in cryptography wheels\n\npyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt.\n\nIf you are building cryptography source (\"sdist\") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on \n\nPackage: cryptography\nInstalled: 46.0.5\nFixed in: 48.0.1\nSeverity: HIGH\nFix: Upgrade cryptography to 48.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-38f3d788f84ad7a5", "name": "CVE-2026-39892: cryptography 46.0.5 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-39892: cryptography 46.0.5 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API\n\ncryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.\n\nPackage: cryptography\nInstalled: 46.0.5\nFixed in: 46.0.7\nSeverity: MEDIUM\nFix: Upgrade cryptography to 46.0.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-688ea7ea06a63b5a", "name": "CVE-2026-34073: cryptography 46.0.5 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-34073: cryptography 46.0.5 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "python-cryptography: Cryptography: Security bypass due to improper DNS name constraint validation\n\ncryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the \"peer name\" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for b\n\nPackage: cryptography\nInstalled: 46.0.5\nFixed in: 46.0.6\nSeverity: LOW\nFix: Upgrade cryptography to 46.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f321dd7385d5bdee", "name": "CVE-2026-4810: google-adk 1.26.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-4810: google-adk 1.26.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "Google Agent Development Kit (ADK) has a Code Injection and Missing Authentication vulnerability\n\nA Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an unauthenticated remote attacker to execute arbitrary code on the server hosting the ADK instance.\n\nThis vulnerability was patched in versions 1.28.1 and 2.0.0a2.\n\n\nCustomers need to redeploy the upgraded ADK to their production environments. In addition, if they are running ADK Web locally, they als\n\nPackage: google-adk\nInstalled: 1.26.0\nFixed in: 1.28.1, 2.0.0a2\nSeverity: CRITICAL\nFix: Upgrade google-adk to 1.28.1, 2.0.0a2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-4c0aa1b520ac5f65", "name": "CVE-2026-45409: idna 3.11 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-45409: idna 3.11 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "python-idna: idna: Denial of Service via specially crafted long inputs\n\nInternationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fi\n\nPackage: idna\nInstalled: 3.11\nFixed in: 3.15\nSeverity: MEDIUM\nFix: Upgrade idna to 3.15"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c8d911b388ab2c8f", "name": "CVE-2026-41205: mako 1.3.10 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-41205: mako 1.3.10 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "mako: Mako: Information disclosure via path traversal vulnerability\n\nMako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with // (e.g., //../../../secret.txt). The root cause is an inconsistency between two slash-stripping implementations. Any file readable by the process can be returned as rendered template content when an application passes untrusted input directly to TemplateLookup.get_template(). This vulnerability is fixed in 1.3.11.\n\nPackage: mako\nInstalled: 1.3.10\nFixed in: 1.3.11\nSeverity: HIGH\nFix: Upgrade mako to 1.3.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3cc5ff059554142f", "name": "CVE-2026-44307: mako 1.3.10 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-44307: mako 1.3.10 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "mako: Mako: Information disclosure via directory traversal\n\nMako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \\..\\..\\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12.\n\nPackage: mako\nInstalled: 1.3.10\nFixed in: 1.3.12\nSeverity: HIGH\nFix: Upgrade mako to 1.3.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e3e11053302e5cd1", "name": "CVE-2026-52869: mcp 1.26.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-52869: mcp 1.26.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal\n\nThe MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route requests to existing sessions using only the session_id query parameter or Mcp-Session-Id header without verifying the authenticated principal that created the session, allowing a different bearer-token-authenticated client\n\nPackage: mcp\nInstalled: 1.26.0\nFixed in: 1.27.2\nSeverity: HIGH\nFix: Upgrade mcp to 1.27.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5b86fa422a690b0b", "name": "CVE-2026-52870: mcp 1.26.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-52870: mcp 1.26.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks\n\nThe MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results from, consume messages for, or cancel other clients' tasks. This issue is fixed in version 1.27.2.\n\nPackage: mcp\nInstalled: 1.26.0\nFixed in: 1.27.2\nSeverity: HIGH\nFix: Upgrade mcp to 1.27.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7149da2b21257860", "name": "CVE-2026-59950: mcp 1.26.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-59950: mcp 1.26.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "MCP Python SDK: WebSocket server transport does not support Host/Origin validation\n\nThe MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1.\n\nPackage: mcp\nInstalled: 1.26.0\nFixed in: 1.28.1\nSeverity: HIGH\nFix: Upgrade mcp to 1.28.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5ecefc57ae9cf626", "name": "CVE-2026-30922: pyasn1 0.6.2 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-30922: pyasn1 0.6.2 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with \"Indefinite Length\" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consu\n\nPackage: pyasn1\nInstalled: 0.6.2\nFixed in: 0.6.3\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-191addef057ac181", "name": "CVE-2026-59885: pyasn1 0.6.2 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-59885: pyasn1 0.6.2 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values.\n\nPackage: pyasn1\nInstalled: 0.6.2\nFixed in: 0.6.4\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b908577be6148f12", "name": "CVE-2026-59886: pyasn1 0.6.2 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-59886: pyasn1 0.6.2 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print\n\nPackage: pyasn1\nInstalled: 0.6.2\nFixed in: 0.6.4\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8cda57397929680c", "name": "GHSA-4xgf-cpjx-pc3j: pydantic-settings 2.13.1 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "GHSA-4xgf-cpjx-pc3j: pydantic-settings 2.13.1 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size\n\n### Summary\n\n`NestedSecretsSettingsSource` reads secret values from files in a configured `secrets_dir`. When `secrets_nested_subdir=True`, a directory entry inside `secrets_dir` that is a symbolic link pointing **outside** `secrets_dir` is followed, so files outside the configured directory are read into settings values. The same code path bypasses the documented `secrets_dir_max_size` protection. An attacker or lower-privileged component able to influence entries in the configured secrets dire\n\nPackage: pydantic-settings\nInstalled: 2.13.1\nFixed in: 2.14.2\nSeverity: MEDIUM\nFix: Upgrade pydantic-settings to 2.14.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a3e00ecc5e9b4b5d", "name": "CVE-2026-32597: pyjwt 2.11.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-32597: pyjwt 2.11.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 \u00a74.1.11 MUST violation)\n\nPyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 \u00a74.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.\n\nPackage: pyjwt\nInstalled: 2.11.0\nFixed in: 2.12.0\nSeverity: HIGH\nFix: Upgrade pyjwt to 2.12.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ac1868d6eb97fffc", "name": "CVE-2026-48526: pyjwt 2.11.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48526: pyjwt 2.11.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens\n\nPyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.\n\nPackage: pyjwt\nInstalled: 2.11.0\nFixed in: 2.13.0\nSeverity: HIGH\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-39e1f46ae7c8d96a", "name": "CVE-2026-48522: pyjwt 2.11.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48522: pyjwt 2.11.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Server-Side Request Forgery (SSRF) via uncontrolled URL fetching in PyJWKClient\n\nPyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registering HTTPHandler, HTTPSHandler, FTPHandler, FileHandler, and DataHandler. There is currently no documented option to restrict which schemes PyJWKClient will fetch. If an application's jku URL ingestion path accepts attacker-influenced URLs (e.g., from JWT header, configuration file, OAuth flow parame\n\nPackage: pyjwt\nInstalled: 2.11.0\nFixed in: 2.13.0\nSeverity: MEDIUM\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-581bfb436edf9657", "name": "CVE-2026-48523: pyjwt 2.11.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48523: pyjwt 2.11.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Verifier-side algorithm bypass leads to unauthorized information access\n\nPyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-supplied algorithms allow-list, but signature verification is performed with the algorithm bound to the PyJWK object instead of the header algorithm. An attacker who controls a registered JWK/JWKS private key can sign with a disallowed algorithm, adv\n\nPackage: pyjwt\nInstalled: 2.11.0\nFixed in: 2.13.0\nSeverity: MEDIUM\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-01579caf25951d94", "name": "CVE-2026-48525: pyjwt 2.11.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48525: pyjwt 2.11.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Denial of Service via processing of crafted detached JWS tokens\n\nPyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option (\"b64\": false, RFC 7797), PyJWT performs Base64URL decoding of the compact-serialization payload segment before enforcing the detached-payload rules. For b64=false, PyJWT later discards that decoded payload and replaces it with the caller-provided detached_payload. In practice, this turns the middle segment into an attacker-controlled \u201cwork amplifier\u201d: a\n\nPackage: pyjwt\nInstalled: 2.11.0\nFixed in: 2.13.0\nSeverity: MEDIUM\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ed29724b4ca6f40c", "name": "CVE-2026-48524: pyjwt 2.11.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48524: pyjwt 2.11.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Denial of Service via unverified JSON Web Token key IDs\n\nPyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no rate limiting. Since kid comes from the unverified token header, an attacker can trigger unlimited outbound requests. The vulnerability surfaces only when a JWKS fetch fails; an attacker can attempt to provoke that with sustained unknown-kid traffic, but the outcome depends on upstream JWKS-endpoint be\n\nPackage: pyjwt\nInstalled: 2.11.0\nFixed in: 2.13.0\nSeverity: LOW\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50b5a0c50a4c4ac0", "name": "CVE-2026-27459: pyopenssl 25.3.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-27459: pyopenssl 25.3.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "pyOpenSSL: DTLS cookie callback buffer overflow\n\npyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.\n\nPackage: pyopenssl\nInstalled: 25.3.0\nFixed in: 26.0.0\nSeverity: HIGH\nFix: Upgrade pyopenssl to 26.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-29ae7ea06dc4e1d3", "name": "CVE-2026-27448: pyopenssl 25.3.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-27448: pyopenssl 25.3.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "pyOpenSSL: TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback\n\npyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.\n\nPackage: pyopenssl\nInstalled: 25.3.0\nFixed in: 26.0.0\nSeverity: LOW\nFix: Upgrade pyopenssl to 26.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eb75742e82e43f15", "name": "CVE-2026-42561: python-multipart 0.0.22 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-42561: python-multipart 0.0.22 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "python-multipart: python-multipart: Denial of Service via excessive multipart part headers\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, MultipartParser previously had no limit on the number of part headers or the size of an individual part header. An attacker could send a request with either many repeated headers without terminating the header block or a single very large header value, causing excessive CPU work before request reje\n\nPackage: python-multipart\nInstalled: 0.0.22\nFixed in: 0.0.27\nSeverity: HIGH\nFix: Upgrade python-multipart to 0.0.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-95b52dc839cb081b", "name": "CVE-2026-53539: python-multipart 0.0.22 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-53539: python-multipart 0.0.22 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Denial of Service via crafted form-urlencoded bodies\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step lookup: it first scanned the entire remaining buffer for &, and only when no & existed anywhere ahead did it fall back to scanning for ;. For a body that uses ; as the separator and contains no &, every field iteration performed a full failed & scan over the entire remaining buffer before locating the ne\n\nPackage: python-multipart\nInstalled: 0.0.22\nFixed in: 0.0.30\nSeverity: HIGH\nFix: Upgrade python-multipart to 0.0.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c4b71473cd8d0218", "name": "CVE-2026-40347: python-multipart 0.0.22 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-40347: python-multipart 0.0.22 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Denial of Service via crafted multipart/form-data requests\n\nPython-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candidate when processing leading CR/LF data and immediately discards epilogue data after the closing boundary.\n\nPackage: python-multipart\nInstalled: 0.0.22\nFixed in: 0.0.26\nSeverity: MEDIUM\nFix: Upgrade python-multipart to 0.0.26"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-050c28636ca13807", "name": "CVE-2026-53537: python-multipart 0.0.22 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-53537: python-multipart 0.0.22 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "multipart: Python-Multipart: Information disclosure via header parsing discrepancy\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message, which transparently applies RFC 2231/5987 decoding. The extended parameter syntax (filename*=charset'lang'value, name*=..., and the filename*0/filename*1 continuation form) is decoded and surfaced under the bare filename/name key, and overrides the plain parameter when both are present. RFC 7578 \u00a74.2 explicitly forbid\n\nPackage: python-multipart\nInstalled: 0.0.22\nFixed in: 0.0.30\nSeverity: LOW\nFix: Upgrade python-multipart to 0.0.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d1957ee7066c4377", "name": "CVE-2026-53538: python-multipart 0.0.22 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-53538: python-multipart 0.0.22 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Information disclosure due to parser differential in form data handling\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator. This creates a parser differential: the same bytes are tokenized into different fields than a WHATWG compliant intermediary would produce, allowing an attacker to smuggle extra form \n\nPackage: python-multipart\nInstalled: 0.0.22\nFixed in: 0.0.30\nSeverity: LOW\nFix: Upgrade python-multipart to 0.0.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f2e23bdcf513e9fa", "name": "CVE-2026-53540: python-multipart 0.0.22 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-53540: python-multipart 0.0.22 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Negative Content-Length in parse_form buffers the entire body in memory\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned the bounded read into a read-until-EOF, so the entire body was loaded into memory in a single read instead of in fixed-size chunks. This vulnerability is fixed in 0.0.31.\n\nPackage: python-multipart\nInstalled: 0.0.22\nFixed in: 0.0.31\nSeverity: LOW\nFix: Upgrade python-multipart to 0.0.31"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c3333920eeff3ae8", "name": "CVE-2026-25645: requests 2.32.5 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-25645: requests 2.32.5 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "requests: Requests: Security bypass due to predictable temporary file creation\n\nRequests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulner\n\nPackage: requests\nInstalled: 2.32.5\nFixed in: 2.33.0\nSeverity: MEDIUM\nFix: Upgrade requests to 2.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d2c53a9f29442fb4", "name": "CVE-2026-48818: starlette 0.52.1 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48818: starlette 0.52.1 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows\n\nStarlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\\\attacker.com\\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account\u2019s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as Fas\n\nPackage: starlette\nInstalled: 0.52.1\nFixed in: 1.1.0\nSeverity: HIGH\nFix: Upgrade starlette to 1.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d42c60b1b9b0fb4f", "name": "CVE-2026-54283: starlette 0.52.1 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-54283: starlette 0.52.1 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS\n\nStarlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, but silently ignored for application/x-www-form-urlencoded. An unauthenticated attacker can therefore send a urlencoded body with an arbitrarily large number of fields or an arbitrarily large field, even when the application configured limits it believed would apply.\n\nPackage: starlette\nInstalled: 0.52.1\nFixed in: 1.3.1\nSeverity: HIGH\nFix: Upgrade starlette to 1.3.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2a4328f08d420670", "name": "CVE-2026-48710: starlette 0.52.1 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48710: starlette 0.52.1 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Security restriction bypass via malformed HTTP Host header\n\nStarlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) \n\nPackage: starlette\nInstalled: 0.52.1\nFixed in: 1.0.1\nSeverity: MEDIUM\nFix: Upgrade starlette to 1.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8bb7a580295c15a9", "name": "CVE-2026-48817: starlette 0.52.1 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48817: starlette 0.52.1 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Information disclosure and unintended method execution via non-standard HTTP methods\n\nStarlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs. When an HTTPEndpoint subclass is registered through Route(...) without an explicit methods= argument, the route does not constrain the method and every method reaches the endpoint. If a non-standard HTTP method whose lo\n\nPackage: starlette\nInstalled: 0.52.1\nFixed in: 1.1.0\nSeverity: MEDIUM\nFix: Upgrade starlette to 1.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f746d08463abe509", "name": "CVE-2026-54282: starlette 0.52.1 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-54282: starlette 0.52.1 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Information disclosure due to improper HTTP request path validation\n\nStarlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path} and re-parsing the result, a path that does not begin with / (for example @google.com) moves the authority boundary during re-parsing, so request.url.hostname and request.url.netloc become attacker-controlled. Code that reads request.url.hostname (rather than the Host header \n\nPackage: starlette\nInstalled: 0.52.1\nFixed in: 1.3.0\nSeverity: LOW\nFix: Upgrade starlette to 1.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a52dac1c27c03863", "name": "CVE-2026-44431: urllib3 2.6.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-44431: urllib3 2.6.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers\n\nurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.\n\nPackage: urllib3\nInstalled: 2.6.3\nFixed in: 2.7.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ce0f6135696cb41a", "name": "CVE-2026-44432: urllib3 2.6.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock", "shortDescription": {"text": "CVE-2026-44432: urllib3 2.6.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3: Denial of Service due to excessive HTTP response decompression\n\nurllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly \n\nPackage: urllib3\nInstalled: 2.6.3\nFixed in: 2.7.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9ceb1a889a7aee5d", "name": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.23 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.23 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue\n\nA vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.\n\nPackage: @ai-sdk/provider-utils\nInstalled: 3.0.23\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2034fdeab49de2a5", "name": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.14 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.14 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nThe same as the `hono` core [Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44).\n\n### Summary\n\nOn Windows hosts, an encoded backslash (`%5C`) in the request path decodes to `\\`, which the Windows path resolver treats as a separator. `serve-static` then resolves a single URL segment such as `admin\\secret.txt` into a nested file under the root and serves it, letting an attacker read static files meant t\n\nPackage: @hono/node-server\nInstalled: 1.19.14\nFixed in: 2.0.5\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 2.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-98b9a7753d37eebf", "name": "CVE-2026-12590: body-parser 1.20.4 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-12590: body-parser 1.20.4 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 1.20.4\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1ba0e4c0a4c40f98", "name": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 2.2.2\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e3afe13db581902c", "name": "CVE-2026-49458: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-49458: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting due to improper sanitization of DOM nodes\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks used parent-realm constructors, causing instanceof checks for forms, named node maps, document fragments, and elements to fail and skip clobber, template-content, and shadow-DOM sanitization branches so executable markup could survive. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.4.1\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e3903fd46c82430a", "name": "CVE-2026-49459: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-49459: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting bypass allows arbitrary script execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.4.1\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cee95b06006c6b0b", "name": "CVE-2026-49978: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-49978: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.\n\nPackage: dompurify\nInstalled: 3.4.1\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-68ae8541ddab24ad", "name": "GHSA-76mc-f452-cxcm: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "GHSA-76mc-f452-cxcm: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\n# Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\n**CWE**: CWE-501 (Trust Boundary Violation \u2014 hook-scoped mutation leaks to global default sets) via CWE-693 (Protection Mechanism Failure \u2014 the default allow-list is silently widened for all subsequent sanitize calls)\n\n## Summary\n\nThe `data.allowedTags` and `data.allowedAttributes` fields passed to `uponSanitizeElement` and `uponSanitizeAttribute` hooks are **dir\n\nPackage: dompurify\nInstalled: 3.4.1\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cb00491cb6423447", "name": "GHSA-cmwh-pvxp-8882: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)\n\n## Summary\n\nDOMPurify 3.4.7 shipped a security fix (\"permanent hook pollution\") that makes a registered `uponSanitizeAttribute` hook's mutation of `data.allowedAttributes` **non-persistent** \u2014 so allowing an attribute for one element does not leak into later `sanitize()` calls. The fix clones `ALLOWED_ATTR` inside `_parseConfig`.\n\nThat guard is **silently bypassed whenever the application uses the persistent-config API `DOMPurify.setConfig()`.** `setConfig()` sets the module flag `SET_CONFIG = t\n\nPackage: dompurify\nInstalled: 3.4.1\nFixed in: 3.4.11\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ef44d9d2bb9c45de", "name": "GHSA-c2j3-45gr-mqc4: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.\n\n## Summary\n\nThere is a possible hook-policy inconsistency in DOMPurify 3.4.11 involving `CUSTOM_ELEMENT_HANDLING`.\n\nWhen a custom element is allowed via `CUSTOM_ELEMENT_HANDLING.tagNameCheck`, it appears that the element does not go through `afterSanitizeElements` in the same way as a normal element. As a result, an application that relies on `afterSanitizeElements` as a security policy layer to strip sensitive attributes from all elements may see those attributes removed from normal elements bu\n\nPackage: dompurify\nInstalled: 3.4.1\nFixed in: 3.4.12\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bb419ba562d55659", "name": "GHSA-gvmj-g25r-r7wr: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes\n\n## Summary\n\nWhen DOMPurify is configured with both `SAFE_FOR_TEMPLATES: true` and `RETURN_DOM: true` (or `IN_PLACE: true`), an attacker can inject template expressions, such as `${evil}`, `{{evil}}`, or `<%evil%>`, that survive the sanitization pass inside `<template>` element content. This bypasses the explicit purpose of `SAFE_FOR_TEMPLATES`, which is to prevent template engine evaluation of user-supplied content.\n\n> **Note:** The string output path is **not** affected. Only the DOM return pat\n\nPackage: dompurify\nInstalled: 3.4.1\nFixed in: 3.4.8\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f3e80c87133493be", "name": "GHSA-vxr8-fq34-vvx9: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output\n\n## Impact\n\nA DOMPurify instance that is reused across trust boundaries can stay bound to a previously supplied `TRUSTED_TYPES_POLICY` even after `clearConfig()` is called. A later caller that requests `RETURN_TRUSTED_TYPE` receives a `TrustedHTML` object created by the old policy, not by a clean default configuration.\n\nIf the old policy is unsafe or controlled by a less-trusted integration, this turns a later \"default\" sanitize call into script execution at a Trusted Types sink. `TRUSTED_TYPES_P\n\nPackage: dompurify\nInstalled: 3.4.1\nFixed in: 3.4.9\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d958878f35cec63a", "name": "GHSA-x4vx-rjvf-j5p4: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "GHSA-x4vx-rjvf-j5p4: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects\n\n## Summary\n\nWhen `DOMPurify.sanitize(root, { IN_PLACE: true })` is called on an attacker-supplied live DOM node, `DOMPurify` still trusts `currentNode.nodeName` for non-`form` nodes in the main `_sanitizeElements` pipeline. A real `<script>` child node whose observable `nodeName` is attacker-controlled can therefore be misclassified as an allowed element and retained. When the sanitized tree is inserted into a live document, the script executes.\n\nThis affects current `3.4.6`. The recent `IN_PLAC\n\nPackage: dompurify\nInstalled: 3.4.1\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1640ebac96888741", "name": "CVE-2026-13676: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization\n\nfast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 4.0.1, 3.1.3, 2.4.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 4.0.1, 3.1.3, 2.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-84659a08492ea51c", "name": "CVE-2026-16221: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...\n\nImpact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 2.4.3, 3.1.4, 4.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 2.4.3, 3.1.4, 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9a64bec523f5a5cc", "name": "CVE-2026-6321: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies\n\nfast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Version\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b8c9b3b3d88ceecb", "name": "CVE-2026-6322: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: URI authority bypass due to improper delimiter handling\n\nfast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a differ\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ff2d0668f040fc89", "name": "CVE-2026-54290: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-54290: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials: true and no explicit origin (the default wildcard), the CORS Middleware reflects the request's Origin and sends Access-Control-Allow-Credentials: true. Any site can then make credentialed cross-origin requests and read the responses, exposing cookie-authenticated endpoints to arbitrary origins. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.15\nFixed in: 4.12.25\nSeverity: HIGH\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-014f7155fa09511c", "name": "CVE-2026-44455: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44455: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handling of JSX element tag names in hono/jsx allowed unvalidated tag names to be directly inserted into the generated HTML output. When untrusted input is used as a tag name via the programmatic jsx() or createElement() APIs during server-side rendering, specially crafted values may break out of the intended element context and inject unintended HTML. This vulnerability is fixed in 4\n\nPackage: hono\nInstalled: 4.12.15\nFixed in: 4.12.16\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d3811ba66a7224d4", "name": "CVE-2026-44456: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44456: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Hono: bodyLimit() can be bypassed for chunked / unknown-length requests\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize for requests without a usable Content-Length (e.g. Transfer-Encoding: chunked). Oversized requests can reach handlers and return 200 instead of 413. This vulnerability is fixed in 4.12.16.\n\nPackage: hono\nInstalled: 4.12.15\nFixed in: 4.12.16\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-961b514163af9cc8", "name": "CVE-2026-44457: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44457: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for responses that declare per-user variance via Vary: Authorization or Vary: Cookie. As a result, a response cached for one authenticated user may be served to subsequent requests from different users. This vulnerability is fixed in 4.12.18.\n\nPackage: hono\nInstalled: 4.12.15\nFixed in: 4.12.18\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f08124d733ccc2dc", "name": "CVE-2026-44458: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44458: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Hono has CSS Declaration Injection via Style Object Values in JSX SSR\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer escapes style attribute object values for HTML but not for CSS. Untrusted input in a style object value or property name can therefore inject additional CSS declarations into the rendered style attribute. The impact is limited to CSS and does not allow JavaScript execution or HTML attribute breakout. This vulnerability is fixed in 4.12.18.\n\nPackage: hono\nInstalled: 4.12.15\nFixed in: 4.12.18\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7f34323f4f697eb3", "name": "CVE-2026-47673: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-47673: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Hono: JWT middleware accepts any Authorization scheme, not only Bearer\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that the Authorization header value uses theBearer scheme. Any two-part header value \u2014 regardless of the scheme name in the first position \u2014 proceeds to JWT verification. A request presenting a valid JWT under a non-Bearer scheme identifier (such as Basic or Token) is authenticated identically to a correctly formed Bearer request. This vulnerability is\n\nPackage: hono\nInstalled: 4.12.15\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-461c4c2ac3ade471", "name": "CVE-2026-47674: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-47674: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 \n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against configured deny and allow rules using string equality after partial normalization. Non-canonical IPv6 representations of an address already listed in a static rule \u2014 such as compressed forms, explicit-zero forms, or hex-notation IPv4-mapped addresses \u2014 do not match the normalized rule entry, causing the \n\nPackage: hono\nInstalled: 4.12.15\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5ac2560617d0289c", "name": "CVE-2026-47675: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-47675: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters that corrupt Set-Cookie header syntax (;, \\r, \\n), but does not apply the same validation to sameSite and priority. An application that passes user-controlled input into either option may produce a Set-Cookie response header containing attacker-chosen additional attributes. This vulnerability is fixed \n\nPackage: hono\nInstalled: 4.12.15\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4279f8d130e7b263", "name": "CVE-2026-47676: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-47676: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request path using the raw URL pathname, while route matching is performed against the percent-decoded path. This inconsistency causes the prefix to be stripped at the wrong position when the path contains percent-encoded multi-byte characters, resulting in the mounted sub-application receiving an incorrect path. This vulnerability is fixed\n\nPackage: hono\nInstalled: 4.12.15\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-913fb208e20dcf48", "name": "CVE-2026-54286: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-54286: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \\, which the Windows path resolver treats as a separator. serve-static then resolves a single URL segment such as admin\\secret.txt into a nested file under the root and serves it, letting an attacker read static files meant to be protected behind prefix-mounted middleware. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.15\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2cc0e1f5b08b9fe1", "name": "CVE-2026-54287: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-54287: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, the ALB single-header response and the VPC Lattice v2 response join multiple Set-Cookie headers into one comma-separated value. Because commas also appear inside cookie attributes (for example Expires dates), clients cannot split the value back into individual cookies and silently drop or misparse them. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.15\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-827fb8d4ffd4bc55", "name": "CVE-2026-54288: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-54288: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit Middleware trusts the request's Content-Length header to decide whether a body is within the limit. On AWS Lambda (API Gateway v1/v2, ALB, VPC Lattice, and Lambda@Edge) the body is delivered fully buffered and the adapter builds the request with the client-declared Content-Length, which need not match the actual payload. A client can declare a tiny Content-Length while sending a\n\nPackage: hono\nInstalled: 4.12.15\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bb1f23c66f5a0955", "name": "CVE-2026-54289: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-54289: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Edge, CloudFront delivers a request header that appears more than once as several separate entries. The adapter writes each value with Headers.set instead of Headers.append, so every value overwrites the previous one and only the last reaches the application. Repeated request headers such as X-Forwarded-For, Forwarded, and Via are silently truncated to a single value. Request mid\n\nPackage: hono\nInstalled: 4.12.15\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a00f456a8a21bd00", "name": "CVE-2026-59895: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-59895: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.15\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2671460d16907554", "name": "CVE-2026-59896: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-59896: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "hono/jsx does not isolate context per request, leading to cross-request data disclosure\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async component. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.15\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-250d26bf6bcca5de", "name": "CVE-2026-59897: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-59897: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete X-Forwarded-For chain, rate limiting, audit logging, or proxy-chain validation can receive incomplete data. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.15\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3e05adb62e2541d1", "name": "CVE-2026-44459: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44459: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validation of the JWT NumericDate claims exp, nbf, and iat in hono/utils/jwt allows tokens with non-spec-compliant claim values to silently bypass time-based checks. This issue is not exploitable by an anonymous attacker; it only manifests when a malformed claim value reaches verify() \u2014 typically when the application itself issues such tokens, or when the signing key is otherwise unde\n\nPackage: hono\nInstalled: 4.12.15\nFixed in: 4.12.18\nSeverity: LOW\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1951324b06e8b398", "name": "CVE-2026-42338: ip-address 10.1.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-42338: ip-address 10.1.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input\n\nip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods,\n\nPackage: ip-address\nInstalled: 10.1.0\nFixed in: 10.1.1\nSeverity: MEDIUM\nFix: Upgrade ip-address to 10.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aeffec36fa8778fd", "name": "CVE-2026-45134: langsmith 0.5.25 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-45134: langsmith 0.5.25 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest\n\nPackage: langsmith\nInstalled: 0.5.25\nFixed in: 0.6.0\nSeverity: HIGH\nFix: Upgrade langsmith to 0.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9e8229c2083c89f8", "name": "CVE-2026-41148: mermaid 11.14.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41148: mermaid 11.14.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: CSS injection vulnerability allows page defacement and information disclosure\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS injection through improper sanitization. The state diagram (and any other diagram type that routes user-controlled style strings through the createCssStyles parser) captures classDef values using an unrestricted regex that matches everything up to a newline. That value then flows unsanitized through \n\nPackage: mermaid\nInstalled: 11.14.0\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ac14fb6e780d639b", "name": "CVE-2026-41149: mermaid 11.14.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41149: mermaid 11.14.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: HTML injection via classDef directive in state diagrams\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configuration. Specifically, the classDef directive in Mermaid state diagrams permits DOM injection that escapes the SVG context. However, <script> tags are stripped, which prevents cross-site scripting (XSS). This issue has been fixed in versions 10.9.6 and 11.15.0. If de\n\nPackage: mermaid\nInstalled: 11.14.0\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2dae155444cc52e9", "name": "CVE-2026-41150: mermaid 11.14.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41150: mermaid 11.14.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: Denial of Service via specially crafted gantt charts\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates. mermaid.parse is unaffected, unless you then call the ganttDb.getTasks() (which is called when rendering a diagram). This vulnerability is fixed in 10.9.6 and 11.15.0.\n\nPackage: mermaid\nInstalled: 11.14.0\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-32d9a7e9d2a1a0ea", "name": "CVE-2026-41159: mermaid 11.14.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41159: mermaid 11.14.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: Information disclosure and page defacement via CSS injection\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0,  Mermaid's default configuration allows injecting CSS that applies outside of the Mermaid diagram via the fontFamily, themeCSS, and altFontFamily configuration options. The injected CSS exploits stylis's & (scope reference) handling. :not(&) escapes the #mermaid-xxx automatic scoping, applying styles to all page elements. Global at-rules (@font-face, @keyframes, @c\n\nPackage: mermaid\nInstalled: 11.14.0\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-003f4239fdf88f3a", "name": "CVE-2026-44573: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44573: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed data route, allowing an attacker to retrieve SSR JSON for protected pages without passing the intende\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ae4891b41312c3b0", "name": "CVE-2026-44574: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44574: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Authorization bypass via crafted query parameters\n\nNext.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check. This vulnerability is fixed in 1\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d050fac239020078", "name": "CVE-2026-44575: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44575: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Unauthorized access to protected content via middleware bypass\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c2df79a9e636ca9b", "name": "CVE-2026-44578: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44578: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests\n\nNext.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6248daf72b9d0e52", "name": "CVE-2026-44579: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44579: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service via crafted POST requests to server actions\n\nNext.js is a React framework for building full-stack web applications. From  to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open for an extended period, consuming file descriptors and server capacity until legitimate users are den\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-701b5b14ebe31d3f", "name": "CVE-2026-45109: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-45109: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.18, 16.2.6\nSeverity: HIGH\nFix: Upgrade next to 15.5.18, 16.2.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d7eb7dd002e60e49", "name": "CVE-2026-64641: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-64641: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Denial of Service in App Router using Server Actions\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.\n\n## Workarounds\n\nNo workaround exists besides upgrading. Applications using Pages Router or not using Server Actions are not vulnerable.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2581afa48c4e4491", "name": "CVE-2026-64642: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-64642: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router built with Turbopack and a **single** entry in `config.i18n.locales` can bypass middleware/proxy based authentication.\n\n## Workarounds\n\nIf you cannot upgrade immediately, enforce authorization in the page's server-side data path instead of relying solely on middleware.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-88f5df084a036f0c", "name": "CVE-2026-64645: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-64645: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\n## Impact\n\nA `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's\u00a0hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect.\n\nThis affects any destination that puts a dynamic segmen\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9ed650eb9c2e99bd", "name": "CVE-2026-64649: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-64649: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in Server Actions on custom servers\n\n## Impact\n\nWhen a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization.\n\nApplications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3b5ea31cc0821a05", "name": "GHSA-8h8q-6873-q5fj: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "GHSA-8h8q-6873-q5fj: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Next.js Vulnerable to Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh). \n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of \n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-15041d8034ad7545", "name": "GHSA-h25m-26qc-wcjf: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "GHSA-h25m-26qc-wcjf: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.0.x, 19.1.x, and 19.2.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23864](https://github.com/facebook/react/security/advisories/GHSA-83fc-fqcc-2hmg).\n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage, out-of-m\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5\nSeverity: HIGH\nFix: Upgrade next to 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-56ae987fed3e992a", "name": "GHSA-q4gf-8mx6-v5v3: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "GHSA-q4gf-8mx6-v5v3: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Next.js has a Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react/security/advisories/GHSA-479c-33wc-g2pg). You can read more about this advisory our [this changelog](https://vercel.com/changelog/summary-of-cve-2026-23869).\n\nA specially crafted HTTP request can be sent to any App Rout\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.15, 16.2.3\nSeverity: HIGH\nFix: Upgrade next to 15.5.15, 16.2.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4c20be9ba942ae50", "name": "CVE-2025-59471: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2025-59471: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "next: NextJS Denial of Service in Image Optimizer\n\nA denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing a maximum size limit, allowing an attacker to cause out-of-memory conditions by requesting optimization of arbitrarily large images. This vulnerability requires that `remotePatterns` is configured to allow image optimization from external domains and\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.10, 16.1.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.10, 16.1.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1688914e8f79cf93", "name": "CVE-2025-59472: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2025-59472: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "next: NextJS Denial of Service in Partial Pre Rendering\n\nA denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests with the `Next-Resume: 1` header and processes attacker-controlled postponed state data. Two closely related vulnerabilities allow an attacker to crash the server process through memory exhaustion:\n\n1. **Unbounded request body buffering**: The server buffers the entire POST request body into memory using `\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.5, 15.6.0-canary.61\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.5, 15.6.0-canary.61"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dc2303e8797c40d5", "name": "CVE-2026-27978: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-27978: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: null origin can bypass Server Actions CSRF checks\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, `origin: null` was treated as a \"missing\" origin during Server Action CSRF validation. As a result, requests from opaque contexts (such as sandboxed iframes) could bypass origin verification instead of being validated as cross-origin requests. An attacker could induce a victim browser to submit Server Actions from a sandboxed context, potentially executing state-changing\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-95d0ea88d45ddf26", "name": "CVE-2026-27979: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-27979: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Unbounded postponed resume buffering can lead to DoS\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing the `next-resume: 1` header (corresponding with a PPR resume request) would buffer request bodies without consistently enforcing `maxPostponedStateSize` in certain setups. The previous mitigation protected minimal-mode deployments, but equivalent non-minimal deployments remained vulnerable to the same unbounded postponed resume-body buffering behavio\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bce5b9ddef87e8a6", "name": "CVE-2026-27980: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-27980: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Unbounded next/image disk cache growth can exhaust storage\n\nNext.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unbounded cache growth. An attacker could generate many unique image-optimization variants and exhaust disk space, causing denial of service. This is fixed in version 16.1.7 by adding an LRU-backed disk cache with `images.maximumDiskCacheSize`, including e\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7, 15.5.14\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7bcbd29607e37893", "name": "CVE-2026-29057: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-29057: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: HTTP request smuggling in rewrites\n\nNext.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfer-Encoding: chunked` could trigger request boundary disagreement between the proxy and backend. This could allow request smuggling through rewritten routes. An attacker could smuggle a second request to unintended backend routes (for example, interna\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7, 15.5.13\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28efc85238389836", "name": "CVE-2026-44576: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44576: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning vulnerability in React Server Components\n\nNext.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later visitors receive component payloads instead of the expected HTML. This vulnerability is fixed in 15.5\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c408a2fc5bcfea00", "name": "CVE-2026-44577: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44577: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Denial of Service via Image Optimization API\n\nNext.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the /_next/image endpoint that match the images.localPatterns configuration (by default, all patterns are allowed). This vulnerability\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-37d78b5b7901a9be", "name": "CVE-2026-44580: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44580: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Cross-site scripting allows arbitrary code execution via untrusted script content\n\nNext.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to break out of the intended script context and execute arbitrary JavaScript in a visitor's browser. This vu\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bd4c241258782f49", "name": "CVE-2026-44581: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44581: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Stored Cross-Site Scripting via malformed nonce values in cached responses\n\nNext.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to poison cached responses and cause script execution for later visitors. This vulnerability is fixed i\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3344eb18acd02488", "name": "CVE-2026-64643: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-64643: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Unauthenticated disclosure of internal Server Function endpoints\n\n## Impact\n\nIn Next.js applications using App Router, Server Actions (`use server`) or `use cache` endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used.\n\nServer Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references).\n\nAffected users are applications using App Router + Server Actions.  \n\nBy itself, this disclosure is typically a recon/enumeration primi\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-73d7bc237c97635f", "name": "CVE-2026-64644: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-64644: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Denial of Service in the Image Optimization API using SVGs\n\n### Impact\n\nWhen self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in  `/_next/image` endpoints.\n\n- If you are using `config.images.remotePatterns`, only the patterns in that array are impacted.\n- If you are using `config.images.unoptimized: true`, you are NOT impacted.\n- If you are using `config.images.loader: 'custom'`\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-19ad8290ee9fa2e9", "name": "CVE-2026-64646: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-64646: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Unbounded Server Action payload in Edge runtime\n\n## Impact\n\nRequests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime\n\n## Workarounds\n\nIf you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should be allowed at max by your hosting provider.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-01b64404c49b0e02", "name": "CVE-2026-64647: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-64647: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for `\uc083\uc083` and `\uc104\uc104` in the request body would share the same cache.\n\n##\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7c963f5e5d9abfb4", "name": "CVE-2026-64648: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-64648: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis only applies to `fetch` calls with a request that has a different init than the one passed to `fetch`.\nSafe: `fetch(new Request(init), init)`\nUnsafe: `fetch(new Request(init), aDifferentInit)`\n\n## Work\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-356c4fd35fc77d23", "name": "CVE-2026-27977: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-27977: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: null origin can bypass dev HMR websocket CSRF checks\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in `next dev`, cross-site protection for internal websocket endpoints could treat `Origin: null` as a bypass case even if `allowedDevOrigins` is configured, allowing privacy-sensitive/opaque contexts (for example sandboxed documents) to connect unexpectedly. If a dev server is reachable from attacker-controlled content, an attacker may be able to connect to the HMR webso\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7\nSeverity: LOW\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-319719615df1944c", "name": "CVE-2026-44572: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44572: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service due to improper handling of x-nextjs-data header with redirects\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When that happened, the middleware/proxy could treat the request as a data request and replace the standard Location redirect header with the internal x-nextjs-redirect header. Browsers do not follow x-nextjs-redirect, so the response became an unusable red\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d71fc9d8bde3199d", "name": "CVE-2026-44582: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-44582: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning allows incorrect response delivery\n\nNext.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL. This vulnerability is fixed in 15.5.16 and 16.2.5.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eda3b07955dd098b", "name": "CVE-2026-41305: postcss 8.4.31 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.4.31\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b7d8afed0482b4f2", "name": "CVE-2024-53382: prismjs 1.27.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2024-53382: prismjs 1.27.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "prismjs: DOM Clobbering vulnerability within the Prism library's prism-autoloader plugin\n\nPrism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.\n\nPackage: prismjs\nInstalled: 1.27.0\nFixed in: 1.30.0\nSeverity: MEDIUM\nFix: Upgrade prismjs to 1.30.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cf8ea94e32587cd6", "name": "CVE-2026-8723: qs 6.14.2 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-8723: qs 6.14.2 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "### Summary    `qs.stringify` throws `TypeError` when called with `arr ...\n\n### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti\n\nPackage: qs\nInstalled: 6.14.2\nFixed in: 6.15.2\nSeverity: MEDIUM\nFix: Upgrade qs to 6.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7ac71c3dbb5d915f", "name": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591\n\n### Impact\n\nA number of vulnerabilities, two rated as \"High\" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency.\n\nThose processing untrusted input with versions of sharp prior to 0.35.0 are affected.\n\n### Patches\n\n#### Using prebuilt binaries provided by sharp?\n\nMost people rely on the prebuilt binaries provided by sharp.\n\nPlease upgrade sharp to the latest version, currently 0.35.3, which provides libvips 8.18.3.\n\n#### Using a globally-installed libvips?\n\nP\n\nPackage: sharp\nInstalled: 0.34.5\nFixed in: 0.35.0\nSeverity: HIGH\nFix: Upgrade sharp to 0.35.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a28047ca3be9a5c3", "name": "CVE-2026-41907: uuid 10.0.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 10.0.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 10.0.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-419cbbf214eb69af", "name": "CVE-2026-41907: uuid 11.1.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 11.1.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-436066a6315d64f1", "name": "CVE-2026-41907: uuid 13.0.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 13.0.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 13.0.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b1e068c6fe591eb5", "name": "CVE-2026-48779: ws 8.20.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-48779: ws 8.20.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments\n\nws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-si\n\nPackage: ws\nInstalled: 8.20.0\nFixed in: 5.2.5, 6.2.4, 7.5.11, 8.21.0\nSeverity: HIGH\nFix: Upgrade ws to 5.2.5, 6.2.4, 7.5.11, 8.21.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8f11b15288db8850", "name": "CVE-2026-45736: ws 8.20.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json", "shortDescription": {"text": "CVE-2026-45736: ws 8.20.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "fullDescription": {"text": "ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`\n\nws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.\n\nPackage: ws\nInstalled: 8.20.0\nFixed in: 8.20.1\nSeverity: MEDIUM\nFix: Upgrade ws to 8.20.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e740376317b7677c", "name": "CVE-2026-8769: @ai-sdk/provider-utils 2.2.8 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 2.2.8 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue\n\nA vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.\n\nPackage: @ai-sdk/provider-utils\nInstalled: 2.2.8\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4779db578cbc8851", "name": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.22 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.22 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue\n\nA vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.\n\nPackage: @ai-sdk/provider-utils\nInstalled: 3.0.22\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-165b809d490257c4", "name": "CVE-2026-39406: @hono/node-server 1.19.12 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-39406: @hono/node-server 1.19.12 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "@hono/node-server: Middleware bypass via repeated slashes in serveStatic\n\n@hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware (e.g., /admin/*) is used for authorization, the router may not match paths containing repeated slashes, while serveStatic resolves them as normalized paths. This can lead to a middleware bypass. This vulnerability is fixed in 1.19.13.\n\nPackage: @hono/node-server\nInstalled: 1.19.12\nFixed in: 1.19.13\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 1.19.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4282bcd1f6487e80", "name": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.12 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.12 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nThe same as the `hono` core [Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44).\n\n### Summary\n\nOn Windows hosts, an encoded backslash (`%5C`) in the request path decodes to `\\`, which the Windows path resolver treats as a separator. `serve-static` then resolves a single URL segment such as `admin\\secret.txt` into a nested file under the root and serves it, letting an attacker read static files meant t\n\nPackage: @hono/node-server\nInstalled: 1.19.12\nFixed in: 2.0.5\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 2.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-29c7df28751c5304", "name": "CVE-2026-54285: @opentelemetry/core 2.2.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54285: @opentelemetry/core 2.2.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "@opentelemetry/core: opentelemetry-js: @opentelemetry/core: Denial of Service via oversized baggage HTTP headers\n\nopentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8.0, W3CBaggagePropagator.extract() in @opentelemetry/core does not enforce size limits when parsing inbound baggage HTTP headers. The W3C Baggage specification recommends a maximum of 8,192 bytes and 180 entries; these limits were only enforced on the outbound (inject()) path, not on the inbound (extract()) path. Parsing oversized baggage causes memory allocation proportional to the header size without any cap. This vulnerabili\n\nPackage: @opentelemetry/core\nInstalled: 2.2.0\nFixed in: 2.8.0\nSeverity: MEDIUM\nFix: Upgrade @opentelemetry/core to 2.8.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-746c95293a54c3d6", "name": "CVE-2026-54285: @opentelemetry/core 2.6.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54285: @opentelemetry/core 2.6.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "@opentelemetry/core: opentelemetry-js: @opentelemetry/core: Denial of Service via oversized baggage HTTP headers\n\nopentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8.0, W3CBaggagePropagator.extract() in @opentelemetry/core does not enforce size limits when parsing inbound baggage HTTP headers. The W3C Baggage specification recommends a maximum of 8,192 bytes and 180 entries; these limits were only enforced on the outbound (inject()) path, not on the inbound (extract()) path. Parsing oversized baggage causes memory allocation proportional to the header size without any cap. This vulnerabili\n\nPackage: @opentelemetry/core\nInstalled: 2.6.1\nFixed in: 2.8.0\nSeverity: MEDIUM\nFix: Upgrade @opentelemetry/core to 2.8.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e36bcb26e6c2a93", "name": "CVE-2026-44288: @protobufjs/utf8 1.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44288: @protobufjs/utf8 1.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs: Security control bypass due to improper handling of overlong UTF-8 sequences\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them. An attacker who can provide protobuf binary data decoded through the affected UTF-8 path may be able to bypass application-level checks that inspect raw bytes before protobuf string decoding. For example, bytes that do not contain certain \n\nPackage: @protobufjs/utf8\nInstalled: 1.1.0\nFixed in: 1.1.1\nSeverity: MEDIUM\nFix: Upgrade @protobufjs/utf8 to 1.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-37f116b89eebcca7", "name": "CVE-2026-12590: body-parser 1.20.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-12590: body-parser 1.20.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 1.20.4\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f9bf6b5a86b77e62", "name": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 2.2.2\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9cb5f4c20004df35", "name": "CVE-2026-13149: brace-expansion 5.0.5 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-13149: brace-expansion 5.0.5 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity\n\nbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.\n\nPackage: brace-expansion\nInstalled: 5.0.5\nFixed in: 5.0.7, 1.1.16, 2.1.2\nSeverity: HIGH\nFix: Upgrade brace-expansion to 5.0.7, 1.1.16, 2.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b8ea256807ca7e28", "name": "CVE-2026-45149: brace-expansion 5.0.5 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-45149: brace-expansion 5.0.5 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges\n\nThe brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large numeric range like {1..10000000}, the sequence generation loop generates all 10 million intermediate elements before the max limit is applied With max=10, the output is correctly limited to 10 items, but the process still allocates ~505 MB and spends ~800ms building the full intermediate array. This vul\n\nPackage: brace-expansion\nInstalled: 5.0.5\nFixed in: 5.0.6\nSeverity: MEDIUM\nFix: Upgrade brace-expansion to 5.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9c3e2fd46b03c46", "name": "CVE-2026-41238: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41238: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: DOMPurify: Cross-Site Scripting bypass via prototype pollution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (no `CUSTOM_ELEMENT_HANDLING` option), a prior prototype pollution gadget can inject permissive `tagNameCheck` and `attributeNameCheck` regex values into `Object.prototype`, causing DOMPurify to allow arbitrary custom elements with arbitrary attributes\n\nPackage: dompurify\nInstalled: 3.3.3\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c9f195da9eb845a4", "name": "CVE-2026-41239: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41239: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: Vue 2: DOMPurify: Cross-site scripting due to incomplete sanitization of template expressions\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS via template-evaluating frameworks like Vue 2. Version 3.4.0 patches the issue.\n\nPackage: dompurify\nInstalled: 3.3.3\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e34fa2d41c9872de", "name": "CVE-2026-41240: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41240: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TAGS is used. Commit c361baa added an early exit for FORBID_ATTR at line 1214. The same fix was not applied to FORBID_TAGS. At line 1118-1123, when EXTRA_ELEMENT_HANDLING.tagCheck returns true, the short-circuit evaluation skips the FORBID_TAGS check entirely. This allows forbidden elements to survive \n\nPackage: dompurify\nInstalled: 3.3.3\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b4ea8d621c636357", "name": "CVE-2026-49458: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-49458: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting due to improper sanitization of DOM nodes\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks used parent-realm constructors, causing instanceof checks for forms, named node maps, document fragments, and elements to fail and skip clobber, template-content, and shadow-DOM sanitization branches so executable markup could survive. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.3.3\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-49a81e5ac3b913c9", "name": "CVE-2026-49459: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-49459: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting bypass allows arbitrary script execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.3.3\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ece7bb79ccac969c", "name": "CVE-2026-49978: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-49978: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.\n\nPackage: dompurify\nInstalled: 3.3.3\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b361b86e839e1aa3", "name": "GHSA-39q2-94rc-95cp: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-39q2-94rc-95cp: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation\n\n## Summary\nIn `src/purify.ts:1117-1123`, `ADD_TAGS` as a function (via `EXTRA_ELEMENT_HANDLING.tagCheck`) bypasses `FORBID_TAGS` due to short-circuit evaluation.\n\nThe condition:\n```\n!(tagCheck(tagName)) && (!ALLOWED_TAGS[tagName] || FORBID_TAGS[tagName])\n```\nWhen `tagCheck(tagName)` returns `true`, the entire condition is `false` and the element is kept \u2014 `FORBID_TAGS[tagName]` is never evaluated.\n\n## Inconsistency\nThis contradicts the attribute-side pattern at line 1214 where `FORBID_ATTR` expl\n\nPackage: dompurify\nInstalled: 3.3.3\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2564d77525aefeea", "name": "GHSA-76mc-f452-cxcm: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-76mc-f452-cxcm: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\n# Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\n**CWE**: CWE-501 (Trust Boundary Violation \u2014 hook-scoped mutation leaks to global default sets) via CWE-693 (Protection Mechanism Failure \u2014 the default allow-list is silently widened for all subsequent sanitize calls)\n\n## Summary\n\nThe `data.allowedTags` and `data.allowedAttributes` fields passed to `uponSanitizeElement` and `uponSanitizeAttribute` hooks are **dir\n\nPackage: dompurify\nInstalled: 3.3.3\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-29fba25a03d2c12b", "name": "GHSA-cmwh-pvxp-8882: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)\n\n## Summary\n\nDOMPurify 3.4.7 shipped a security fix (\"permanent hook pollution\") that makes a registered `uponSanitizeAttribute` hook's mutation of `data.allowedAttributes` **non-persistent** \u2014 so allowing an attribute for one element does not leak into later `sanitize()` calls. The fix clones `ALLOWED_ATTR` inside `_parseConfig`.\n\nThat guard is **silently bypassed whenever the application uses the persistent-config API `DOMPurify.setConfig()`.** `setConfig()` sets the module flag `SET_CONFIG = t\n\nPackage: dompurify\nInstalled: 3.3.3\nFixed in: 3.4.11\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ab35c956a2b1c12f", "name": "GHSA-c2j3-45gr-mqc4: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.\n\n## Summary\n\nThere is a possible hook-policy inconsistency in DOMPurify 3.4.11 involving `CUSTOM_ELEMENT_HANDLING`.\n\nWhen a custom element is allowed via `CUSTOM_ELEMENT_HANDLING.tagNameCheck`, it appears that the element does not go through `afterSanitizeElements` in the same way as a normal element. As a result, an application that relies on `afterSanitizeElements` as a security policy layer to strip sensitive attributes from all elements may see those attributes removed from normal elements bu\n\nPackage: dompurify\nInstalled: 3.3.3\nFixed in: 3.4.12\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-86ee908deba78d3e", "name": "GHSA-gvmj-g25r-r7wr: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes\n\n## Summary\n\nWhen DOMPurify is configured with both `SAFE_FOR_TEMPLATES: true` and `RETURN_DOM: true` (or `IN_PLACE: true`), an attacker can inject template expressions, such as `${evil}`, `{{evil}}`, or `<%evil%>`, that survive the sanitization pass inside `<template>` element content. This bypasses the explicit purpose of `SAFE_FOR_TEMPLATES`, which is to prevent template engine evaluation of user-supplied content.\n\n> **Note:** The string output path is **not** affected. Only the DOM return pat\n\nPackage: dompurify\nInstalled: 3.3.3\nFixed in: 3.4.8\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-24e85ae7b0e5ad8b", "name": "GHSA-vxr8-fq34-vvx9: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output\n\n## Impact\n\nA DOMPurify instance that is reused across trust boundaries can stay bound to a previously supplied `TRUSTED_TYPES_POLICY` even after `clearConfig()` is called. A later caller that requests `RETURN_TRUSTED_TYPE` receives a `TrustedHTML` object created by the old policy, not by a clean default configuration.\n\nIf the old policy is unsafe or controlled by a less-trusted integration, this turns a later \"default\" sanitize call into script execution at a Trusted Types sink. `TRUSTED_TYPES_P\n\nPackage: dompurify\nInstalled: 3.3.3\nFixed in: 3.4.9\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e8898a0dfa2bba6f", "name": "GHSA-x4vx-rjvf-j5p4: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-x4vx-rjvf-j5p4: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects\n\n## Summary\n\nWhen `DOMPurify.sanitize(root, { IN_PLACE: true })` is called on an attacker-supplied live DOM node, `DOMPurify` still trusts `currentNode.nodeName` for non-`form` nodes in the main `_sanitizeElements` pipeline. A real `<script>` child node whose observable `nodeName` is attacker-controlled can therefore be misclassified as an allowed element and retained. When the sanitized tree is inserted into a live document, the script executes.\n\nThis affects current `3.4.6`. The recent `IN_PLAC\n\nPackage: dompurify\nInstalled: 3.3.3\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d8d99547efd8f37d", "name": "GHSA-g7r4-m6w7-qqqr: esbuild 0.27.5 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-g7r4-m6w7-qqqr: esbuild 0.27.5 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "esbuild allows arbitrary file read when running the development server on Windows\n\n### Summary\n\nThe development server contains a path traversal vulnerability on Windows when serving files from `servedir`.\n\nDue to the use of `path.Clean()` (which only normalizes forward-slash `/` separators) instead of a Windows-aware path normalization function, it is possible to craft requests using backslashes (`\\`) that bypass the intended directory containment logic. An attacker can escape the configured `servedir` root and access arbitrary files on the filesystem.\nThis issue affects Wind\n\nPackage: esbuild\nInstalled: 0.27.5\nFixed in: 0.28.1\nSeverity: LOW\nFix: Upgrade esbuild to 0.28.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be9deb89e4605da6", "name": "CVE-2026-13676: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization\n\nfast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 4.0.1, 3.1.3, 2.4.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 4.0.1, 3.1.3, 2.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-40445d8139c47348", "name": "CVE-2026-16221: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...\n\nImpact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 2.4.3, 3.1.4, 4.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 2.4.3, 3.1.4, 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-db0571e3db52f310", "name": "CVE-2026-6321: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies\n\nfast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Version\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-93cf54db1d01bd9f", "name": "CVE-2026-6322: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-uri: fast-uri: URI authority bypass due to improper delimiter handling\n\nfast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a differ\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c066bf2c45b1c9fd", "name": "CVE-2026-12143: form-data 4.0.5 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-12143: form-data 4.0.5 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "form-data: form-data: Form field override via CRLF injection\n\nform-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (\") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the atta\n\nPackage: form-data\nInstalled: 4.0.5\nFixed in: 2.5.6, 3.0.5, 4.0.6\nSeverity: HIGH\nFix: Upgrade form-data to 2.5.6, 3.0.5, 4.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-260c7563bccdf897", "name": "CVE-2026-54290: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54290: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials: true and no explicit origin (the default wildcard), the CORS Middleware reflects the request's Origin and sends Access-Control-Allow-Credentials: true. Any site can then make credentialed cross-origin requests and read the responses, exposing cookie-authenticated endpoints to arbitrary origins. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.25\nSeverity: HIGH\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7f6e18e11c43737e", "name": "CVE-2026-39407: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-39407: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono: Middleware bypass via repeated slashes in serveStatic\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware (e.g., /admin/*) is used for authorization, the router may not match paths containing repeated slashes, while serveStatic resolves them as normalized paths. This can lead to a middleware bypass. This vulnerability is fixed in \n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d11076d2d263cb3e", "name": "CVE-2026-39408: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-39408: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono: Path traversal in toSSG() allows writing files outside the output directory\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to be written outside the configured output directory during static site generation. When using dynamic route parameters via ssgParams, specially crafted values can cause generated file paths to escape the intended output directory. This vulnerability is fixed in 4.12.12.\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d0a91d8127cd45bb", "name": "CVE-2026-39409: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-39409: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-mapped IPv6 client addresses (e.g. ::ffff:127.0.0.1) before applying IPv4 allow or deny rules. In environments such as Node.js dual-stack, this can cause IPv4 rules to fail to match, leading to unintended authorization behavior. This vulnerability is fixed in 4.12.12.\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8b91ac1042cef62f", "name": "CVE-2026-39410: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-39410: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono: Non-breaking space prefix bypass in cookie name handling in getCookie()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy between browser cookie parsing and parse() handling allows cookie prefix protections to be bypassed. Cookie names that are treated as distinct by the browser may be normalized to the same key by parse(), allowing attacker-controlled cookies to override legitimate ones. This vulnerability is fixed in 4.12.12.\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3839496490d17cc8", "name": "CVE-2026-44455: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44455: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handling of JSX element tag names in hono/jsx allowed unvalidated tag names to be directly inserted into the generated HTML output. When untrusted input is used as a tag name via the programmatic jsx() or createElement() APIs during server-side rendering, specially crafted values may break out of the intended element context and inject unintended HTML. This vulnerability is fixed in 4\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.16\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-35bd0ca22a9e704c", "name": "CVE-2026-44456: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44456: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono: bodyLimit() can be bypassed for chunked / unknown-length requests\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize for requests without a usable Content-Length (e.g. Transfer-Encoding: chunked). Oversized requests can reach handlers and return 200 instead of 413. This vulnerability is fixed in 4.12.16.\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.16\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e574752fda402774", "name": "CVE-2026-44457: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44457: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for responses that declare per-user variance via Vary: Authorization or Vary: Cookie. As a result, a response cached for one authenticated user may be served to subsequent requests from different users. This vulnerability is fixed in 4.12.18.\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.18\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-41a04ca764f69756", "name": "CVE-2026-44458: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44458: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono has CSS Declaration Injection via Style Object Values in JSX SSR\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer escapes style attribute object values for HTML but not for CSS. Untrusted input in a style object value or property name can therefore inject additional CSS declarations into the rendered style attribute. The impact is limited to CSS and does not allow JavaScript execution or HTML attribute breakout. This vulnerability is fixed in 4.12.18.\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.18\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-45aa1e13ad161248", "name": "CVE-2026-47673: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-47673: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono: JWT middleware accepts any Authorization scheme, not only Bearer\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that the Authorization header value uses theBearer scheme. Any two-part header value \u2014 regardless of the scheme name in the first position \u2014 proceeds to JWT verification. A request presenting a valid JWT under a non-Bearer scheme identifier (such as Basic or Token) is authenticated identically to a correctly formed Bearer request. This vulnerability is\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2de6385625ef116c", "name": "CVE-2026-47674: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-47674: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 \n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against configured deny and allow rules using string equality after partial normalization. Non-canonical IPv6 representations of an address already listed in a static rule \u2014 such as compressed forms, explicit-zero forms, or hex-notation IPv4-mapped addresses \u2014 do not match the normalized rule entry, causing the \n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-db37e7e151b30490", "name": "CVE-2026-47675: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-47675: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters that corrupt Set-Cookie header syntax (;, \\r, \\n), but does not apply the same validation to sameSite and priority. An application that passes user-controlled input into either option may produce a Set-Cookie response header containing attacker-chosen additional attributes. This vulnerability is fixed \n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-80aac3b7ef660f7d", "name": "CVE-2026-47676: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-47676: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request path using the raw URL pathname, while route matching is performed against the percent-decoded path. This inconsistency causes the prefix to be stripped at the wrong position when the path contains percent-encoded multi-byte characters, resulting in the mounted sub-application receiving an incorrect path. This vulnerability is fixed\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4b19225b7c481f5c", "name": "CVE-2026-54286: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54286: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \\, which the Windows path resolver treats as a separator. serve-static then resolves a single URL segment such as admin\\secret.txt into a nested file under the root and serves it, letting an attacker read static files meant to be protected behind prefix-mounted middleware. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-14c0e3765e0610b1", "name": "CVE-2026-54287: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54287: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, the ALB single-header response and the VPC Lattice v2 response join multiple Set-Cookie headers into one comma-separated value. Because commas also appear inside cookie attributes (for example Expires dates), clients cannot split the value back into individual cookies and silently drop or misparse them. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-922db8ff46ed53f4", "name": "CVE-2026-54288: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54288: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit Middleware trusts the request's Content-Length header to decide whether a body is within the limit. On AWS Lambda (API Gateway v1/v2, ALB, VPC Lattice, and Lambda@Edge) the body is delivered fully buffered and the adapter builds the request with the client-declared Content-Length, which need not match the actual payload. A client can declare a tiny Content-Length while sending a\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b88cb966fd3b6c3c", "name": "CVE-2026-54289: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54289: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Edge, CloudFront delivers a request header that appears more than once as several separate entries. The adapter writes each value with Headers.set instead of Headers.append, so every value overwrites the previous one and only the last reaches the application. Repeated request headers such as X-Forwarded-For, Forwarded, and Via are silently truncated to a single value. Request mid\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-58d187d68030830c", "name": "CVE-2026-56761: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-56761: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR\n\nhono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers can craft specially crafted attribute keys containing characters like quotes or angle brackets to break html tag boundaries and inject arbitrary attributes or elements.\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.14\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fa5567229be0c1ba", "name": "CVE-2026-59895: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59895: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-95429fc107c0f8c9", "name": "CVE-2026-59896: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59896: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "hono/jsx does not isolate context per request, leading to cross-request data disclosure\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async component. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-253ff8f6c8e71e63", "name": "CVE-2026-59897: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59897: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete X-Forwarded-For chain, rate limiting, audit logging, or proxy-chain validation can receive incomplete data. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cea84fab78aaa0f6", "name": "GHSA-26pp-8wgv-hjvm: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-26pp-8wgv-hjvm: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono missing validation of cookie name on write path in setCookie()\n\n## Summary\n\nCookie names are not validated on the write path when using `setCookie()`, `serialize()`, or `serializeSigned()` to generate Set-Cookie headers.\n\nWhile certain cookie attributes such as domain and path are validated, the cookie name itself may contain invalid characters.\n\nThis results in inconsistent handling of cookie names between parsing (read path) and serialization (write path).\n\n## Details\n\nWhen applications use `setCookie()`, `serialize()`, or `serializeSigned()` with a user-c\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d413679b10876f9", "name": "CVE-2026-44459: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44459: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validation of the JWT NumericDate claims exp, nbf, and iat in hono/utils/jwt allows tokens with non-spec-compliant claim values to silently bypass time-based checks. This issue is not exploitable by an anonymous attacker; it only manifests when a malformed claim value reaches verify() \u2014 typically when the application itself issues such tokens, or when the signing key is otherwise unde\n\nPackage: hono\nInstalled: 4.12.10\nFixed in: 4.12.18\nSeverity: LOW\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c5a3456e11ecbf55", "name": "CVE-2026-42338: ip-address 10.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-42338: ip-address 10.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input\n\nip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods,\n\nPackage: ip-address\nInstalled: 10.1.0\nFixed in: 10.1.1\nSeverity: MEDIUM\nFix: Upgrade ip-address to 10.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-71d5ae1338762ea0", "name": "CVE-2026-59869: js-yaml 3.14.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59869: js-yaml 3.14.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML documents\n\njs-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.\n\nPackage: js-yaml\nInstalled: 3.14.2\nFixed in: 3.15.0, 4.3.0\nSeverity: HIGH\nFix: Upgrade js-yaml to 3.15.0, 4.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bd0c00dd8d244051", "name": "CVE-2026-53550: js-yaml 3.14.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-53550: js-yaml 3.14.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML merge keys\n\njs-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerabil\n\nPackage: js-yaml\nInstalled: 3.14.2\nFixed in: 4.2.0, 3.15.0\nSeverity: MEDIUM\nFix: Upgrade js-yaml to 4.2.0, 3.15.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1a2d50b9e026e90d", "name": "CVE-2026-59869: js-yaml 4.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59869: js-yaml 4.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML documents\n\njs-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.\n\nPackage: js-yaml\nInstalled: 4.1.1\nFixed in: 3.15.0, 4.3.0\nSeverity: HIGH\nFix: Upgrade js-yaml to 3.15.0, 4.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-de0ee7e12c7ce037", "name": "CVE-2026-53550: js-yaml 4.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-53550: js-yaml 4.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML merge keys\n\njs-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerabil\n\nPackage: js-yaml\nInstalled: 4.1.1\nFixed in: 4.2.0, 3.15.0\nSeverity: MEDIUM\nFix: Upgrade js-yaml to 4.2.0, 3.15.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2e6957225ac9d682", "name": "CVE-2026-45134: langsmith 0.3.87 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-45134: langsmith 0.3.87 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest\n\nPackage: langsmith\nInstalled: 0.3.87\nFixed in: 0.6.0\nSeverity: HIGH\nFix: Upgrade langsmith to 0.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d151a813e5dca388", "name": "CVE-2026-25528: langsmith 0.3.87 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-25528: langsmith 0.3.87 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing feature is vulnerable to Server-Side Request Forgery via malicious HTTP headers. An attacker can inject arbitrary api_url values through the baggage header, causing the SDK to exfiltrate sensitive trace data to attacker-controlled endpoints. When using distributed tracing, the SDK parses incoming HTTP headers via RunTree.from_headers() in Python or RunTree.fromHeaders() in Typ\n\nPackage: langsmith\nInstalled: 0.3.87\nFixed in: 0.4.6\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7d9005d2bbbff8fb", "name": "CVE-2026-40190: langsmith 0.3.87 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-40190: langsmith 0.3.87 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() utility. The baseAssignValue() function only guards against the __proto__ key, but fails to prevent traversal via constructor.prototype. This allows an attacker who controls keys in data processed by the createAnonymizer() API to pollute Object.prototype, affecti\n\nPackage: langsmith\nInstalled: 0.3.87\nFixed in: 0.5.18\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.5.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3e36a629f6b85e21", "name": "CVE-2026-41182: langsmith 0.3.87 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41182: langsmith 0.3.87 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "LangSmith SDK: Streaming token events bypass output redaction\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces streaming output, each chunk is recorded as a new_token event containing the raw token value. These events bypass the redaction pipeline entirely \u2014 prepareRunCreateOrUpdateInputs (\n\nPackage: langsmith\nInstalled: 0.3.87\nFixed in: 0.5.19\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.5.19"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e034d1ec33de71cf", "name": "CVE-2026-45134: langsmith 0.5.16 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-45134: langsmith 0.5.16 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest\n\nPackage: langsmith\nInstalled: 0.5.16\nFixed in: 0.6.0\nSeverity: HIGH\nFix: Upgrade langsmith to 0.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7a6acbdf2653b7ce", "name": "CVE-2026-40190: langsmith 0.5.16 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-40190: langsmith 0.5.16 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() utility. The baseAssignValue() function only guards against the __proto__ key, but fails to prevent traversal via constructor.prototype. This allows an attacker who controls keys in data processed by the createAnonymizer() API to pollute Object.prototype, affecti\n\nPackage: langsmith\nInstalled: 0.5.16\nFixed in: 0.5.18\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.5.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4eed585e2b7fb808", "name": "CVE-2026-41182: langsmith 0.5.16 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41182: langsmith 0.5.16 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "LangSmith SDK: Streaming token events bypass output redaction\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces streaming output, each chunk is recorded as a new_token event containing the raw token value. These events bypass the redaction pipeline entirely \u2014 prepareRunCreateOrUpdateInputs (\n\nPackage: langsmith\nInstalled: 0.5.16\nFixed in: 0.5.19\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.5.19"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3b2af901bd388b18", "name": "CVE-2026-48801: linkify-it 5.0.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-48801: linkify-it 5.0.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability\n\nlinkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N\u00b2) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service tr\n\nPackage: linkify-it\nInstalled: 5.0.0\nFixed in: 5.0.1\nSeverity: HIGH\nFix: Upgrade linkify-it to 5.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eadf681250669e67", "name": "CVE-2026-59887: linkify-it 5.0.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59887: linkify-it 5.0.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text\n\nlinkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. This issue is fixed in version 5.0.2.\n\nPackage: linkify-it\nInstalled: 5.0.0\nFixed in: 5.0.2\nSeverity: HIGH\nFix: Upgrade linkify-it to 5.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b13c87f5369ef792", "name": "CVE-2026-4800: lodash 4.17.21 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-4800: lodash 4.17.21 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7e616d77a8446b57", "name": "CVE-2025-13465: lodash 4.17.21 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-13465: lodash 4.17.21 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "lodash: prototype pollution in _.unset and _.omit functions\n\nLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset\u00a0and _.omit\u00a0functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.\n\nThe issue permits deletion of properties but does not allow overwriting their original behavior.\n\nThis issue is patched on 4.17.23\n\nPackage: lodash\nInstalled: 4.17.21\nFixed in: 4.17.23\nSeverity: MEDIUM\nFix: Upgrade lodash to 4.17.23"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d566ab4f53a5bbef", "name": "CVE-2026-2950: lodash 4.17.21 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-2950: lodash 4.17.21 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-409e0cc56707168e", "name": "CVE-2026-4800: lodash-es 4.17.23 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-4800: lodash-es 4.17.23 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash-es\nInstalled: 4.17.23\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-03710688818e18cf", "name": "CVE-2026-2950: lodash-es 4.17.23 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-2950: lodash-es 4.17.23 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash-es\nInstalled: 4.17.23\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28de748363c9dec3", "name": "CVE-2026-48988: markdown-it 14.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-48988: markdown-it 14.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "markdown-it is a Markdown parser. Versions 14.1.1 and below contain a  ...\n\nmarkdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the smartquotes rule. The issue stems from repeatedly modifying strings with replaceAt(), which performs O(n) slicing and concatenation per quote character. This can cause excessive CPU consumption when parsing quote-heavy, user-supplied markdown and may let attackers degrade or disrupt service availability. Although typo\n\nPackage: markdown-it\nInstalled: 14.1.1\nFixed in: 14.2.0\nSeverity: MEDIUM\nFix: Upgrade markdown-it to 14.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2dd7982841ebdc54", "name": "CVE-2026-41148: mermaid 11.14.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41148: mermaid 11.14.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "mermaid: Mermaid: CSS injection vulnerability allows page defacement and information disclosure\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS injection through improper sanitization. The state diagram (and any other diagram type that routes user-controlled style strings through the createCssStyles parser) captures classDef values using an unrestricted regex that matches everything up to a newline. That value then flows unsanitized through \n\nPackage: mermaid\nInstalled: 11.14.0\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-66f8c9ed1f03530a", "name": "CVE-2026-41149: mermaid 11.14.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41149: mermaid 11.14.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "mermaid: Mermaid: HTML injection via classDef directive in state diagrams\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configuration. Specifically, the classDef directive in Mermaid state diagrams permits DOM injection that escapes the SVG context. However, <script> tags are stripped, which prevents cross-site scripting (XSS). This issue has been fixed in versions 10.9.6 and 11.15.0. If de\n\nPackage: mermaid\nInstalled: 11.14.0\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-474ccc0bb6f6c545", "name": "CVE-2026-41150: mermaid 11.14.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41150: mermaid 11.14.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "mermaid: Mermaid: Denial of Service via specially crafted gantt charts\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates. mermaid.parse is unaffected, unless you then call the ganttDb.getTasks() (which is called when rendering a diagram). This vulnerability is fixed in 10.9.6 and 11.15.0.\n\nPackage: mermaid\nInstalled: 11.14.0\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-27bee6b6abfc6e0e", "name": "CVE-2026-41159: mermaid 11.14.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41159: mermaid 11.14.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "mermaid: Mermaid: Information disclosure and page defacement via CSS injection\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0,  Mermaid's default configuration allows injecting CSS that applies outside of the Mermaid diagram via the fontFamily, themeCSS, and altFontFamily configuration options. The injected CSS exploits stylis's & (scope reference) handling. :not(&) escapes the #mermaid-xxx automatic scoping, applying styles to all page elements. Global at-rules (@font-face, @keyframes, @c\n\nPackage: mermaid\nInstalled: 11.14.0\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-97626e505a1b3c07", "name": "CVE-2026-44573: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44573: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed data route, allowing an attacker to retrieve SSR JSON for protected pages without passing the intende\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a0d14c027f2fa43b", "name": "CVE-2026-44574: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44574: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Next.js: Authorization bypass via crafted query parameters\n\nNext.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check. This vulnerability is fixed in 1\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ec0fc622339496d6", "name": "CVE-2026-44575: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44575: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Unauthorized access to protected content via middleware bypass\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a57e9f8f4cc01f45", "name": "CVE-2026-44578: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44578: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests\n\nNext.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5e5cf5b1f564fc7e", "name": "CVE-2026-44579: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44579: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service via crafted POST requests to server actions\n\nNext.js is a React framework for building full-stack web applications. From  to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open for an extended period, consuming file descriptors and server capacity until legitimate users are den\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b786ed9cb9a4a312", "name": "CVE-2026-45109: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-45109: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.18, 16.2.6\nSeverity: HIGH\nFix: Upgrade next to 15.5.18, 16.2.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5451b7692d10069b", "name": "CVE-2026-64641: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64641: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Denial of Service in App Router using Server Actions\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.\n\n## Workarounds\n\nNo workaround exists besides upgrading. Applications using Pages Router or not using Server Actions are not vulnerable.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-791e2caf22771e93", "name": "CVE-2026-64642: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64642: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router built with Turbopack and a **single** entry in `config.i18n.locales` can bypass middleware/proxy based authentication.\n\n## Workarounds\n\nIf you cannot upgrade immediately, enforce authorization in the page's server-side data path instead of relying solely on middleware.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e24093207db87bf9", "name": "CVE-2026-64645: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64645: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\n## Impact\n\nA `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's\u00a0hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect.\n\nThis affects any destination that puts a dynamic segmen\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d25c68e839f18a1e", "name": "CVE-2026-64649: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64649: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in Server Actions on custom servers\n\n## Impact\n\nWhen a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization.\n\nApplications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-785029bd5422fdc7", "name": "GHSA-8h8q-6873-q5fj: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-8h8q-6873-q5fj: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js Vulnerable to Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh). \n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of \n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-23bcfe2069663b0a", "name": "GHSA-h25m-26qc-wcjf: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-h25m-26qc-wcjf: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.0.x, 19.1.x, and 19.2.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23864](https://github.com/facebook/react/security/advisories/GHSA-83fc-fqcc-2hmg).\n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage, out-of-m\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5\nSeverity: HIGH\nFix: Upgrade next to 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9fc8c7703b37ab21", "name": "GHSA-q4gf-8mx6-v5v3: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-q4gf-8mx6-v5v3: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js has a Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react/security/advisories/GHSA-479c-33wc-g2pg). You can read more about this advisory our [this changelog](https://vercel.com/changelog/summary-of-cve-2026-23869).\n\nA specially crafted HTTP request can be sent to any App Rout\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.15, 16.2.3\nSeverity: HIGH\nFix: Upgrade next to 15.5.15, 16.2.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-df3c05752c379e10", "name": "CVE-2025-59471: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-59471: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "next: NextJS Denial of Service in Image Optimizer\n\nA denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing a maximum size limit, allowing an attacker to cause out-of-memory conditions by requesting optimization of arbitrarily large images. This vulnerability requires that `remotePatterns` is configured to allow image optimization from external domains and\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.10, 16.1.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.10, 16.1.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-98b3e50526fe9b06", "name": "CVE-2025-59472: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-59472: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "next: NextJS Denial of Service in Partial Pre Rendering\n\nA denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests with the `Next-Resume: 1` header and processes attacker-controlled postponed state data. Two closely related vulnerabilities allow an attacker to crash the server process through memory exhaustion:\n\n1. **Unbounded request body buffering**: The server buffers the entire POST request body into memory using `\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.5, 15.6.0-canary.61\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.5, 15.6.0-canary.61"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-89b3f0c25d7ced7a", "name": "CVE-2026-27978: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-27978: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: null origin can bypass Server Actions CSRF checks\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, `origin: null` was treated as a \"missing\" origin during Server Action CSRF validation. As a result, requests from opaque contexts (such as sandboxed iframes) could bypass origin verification instead of being validated as cross-origin requests. An attacker could induce a victim browser to submit Server Actions from a sandboxed context, potentially executing state-changing\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7ed994e8975a7ef3", "name": "CVE-2026-27979: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-27979: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Unbounded postponed resume buffering can lead to DoS\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing the `next-resume: 1` header (corresponding with a PPR resume request) would buffer request bodies without consistently enforcing `maxPostponedStateSize` in certain setups. The previous mitigation protected minimal-mode deployments, but equivalent non-minimal deployments remained vulnerable to the same unbounded postponed resume-body buffering behavio\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ce01f56283ddb4e9", "name": "CVE-2026-27980: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-27980: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Unbounded next/image disk cache growth can exhaust storage\n\nNext.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unbounded cache growth. An attacker could generate many unique image-optimization variants and exhaust disk space, causing denial of service. This is fixed in version 16.1.7 by adding an LRU-backed disk cache with `images.maximumDiskCacheSize`, including e\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7, 15.5.14\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b0db9091546811bd", "name": "CVE-2026-29057: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-29057: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: HTTP request smuggling in rewrites\n\nNext.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfer-Encoding: chunked` could trigger request boundary disagreement between the proxy and backend. This could allow request smuggling through rewritten routes. An attacker could smuggle a second request to unintended backend routes (for example, interna\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7, 15.5.13\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-715a4140f9e3c685", "name": "CVE-2026-44576: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44576: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning vulnerability in React Server Components\n\nNext.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later visitors receive component payloads instead of the expected HTML. This vulnerability is fixed in 15.5\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d46d7c1e01ea9fdf", "name": "CVE-2026-44577: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44577: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Next.js: Denial of Service via Image Optimization API\n\nNext.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the /_next/image endpoint that match the images.localPatterns configuration (by default, all patterns are allowed). This vulnerability\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aaa97a670870a27b", "name": "CVE-2026-44580: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44580: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Cross-site scripting allows arbitrary code execution via untrusted script content\n\nNext.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to break out of the intended script context and execute arbitrary JavaScript in a visitor's browser. This vu\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5792d6f035023c92", "name": "CVE-2026-44581: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44581: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Stored Cross-Site Scripting via malformed nonce values in cached responses\n\nNext.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to poison cached responses and cause script execution for later visitors. This vulnerability is fixed i\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-894ddc0e35cdee60", "name": "CVE-2026-64643: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64643: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Unauthenticated disclosure of internal Server Function endpoints\n\n## Impact\n\nIn Next.js applications using App Router, Server Actions (`use server`) or `use cache` endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used.\n\nServer Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references).\n\nAffected users are applications using App Router + Server Actions.  \n\nBy itself, this disclosure is typically a recon/enumeration primi\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c1689fb7065a38d1", "name": "CVE-2026-64644: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64644: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Denial of Service in the Image Optimization API using SVGs\n\n### Impact\n\nWhen self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in  `/_next/image` endpoints.\n\n- If you are using `config.images.remotePatterns`, only the patterns in that array are impacted.\n- If you are using `config.images.unoptimized: true`, you are NOT impacted.\n- If you are using `config.images.loader: 'custom'`\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-70a313ad8a8884ef", "name": "CVE-2026-64646: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64646: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Unbounded Server Action payload in Edge runtime\n\n## Impact\n\nRequests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime\n\n## Workarounds\n\nIf you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should be allowed at max by your hosting provider.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c2cec4d317eed887", "name": "CVE-2026-64647: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64647: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for `\uc083\uc083` and `\uc104\uc104` in the request body would share the same cache.\n\n##\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28b4dba1a648bae9", "name": "CVE-2026-64648: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64648: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis only applies to `fetch` calls with a request that has a different init than the one passed to `fetch`.\nSafe: `fetch(new Request(init), init)`\nUnsafe: `fetch(new Request(init), aDifferentInit)`\n\n## Work\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bff05d415cc2b43e", "name": "CVE-2026-27977: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-27977: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: null origin can bypass dev HMR websocket CSRF checks\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in `next dev`, cross-site protection for internal websocket endpoints could treat `Origin: null` as a bypass case even if `allowedDevOrigins` is configured, allowing privacy-sensitive/opaque contexts (for example sandboxed documents) to connect unexpectedly. If a dev server is reachable from attacker-controlled content, an attacker may be able to connect to the HMR webso\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7\nSeverity: LOW\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba3fc24f68369dd1", "name": "CVE-2026-44572: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44572: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service due to improper handling of x-nextjs-data header with redirects\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When that happened, the middleware/proxy could treat the request as a data request and replace the standard Location redirect header with the internal x-nextjs-redirect header. Browsers do not follow x-nextjs-redirect, so the response became an unusable red\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a982509542acabd4", "name": "CVE-2026-44582: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44582: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning allows incorrect response delivery\n\nNext.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL. This vulnerability is fixed in 15.5.16 and 16.2.5.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-69b3d74bfb9d489c", "name": "CVE-2026-41305: postcss 8.4.31 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.4.31\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-88ea987e3f005eaf", "name": "CVE-2026-41305: postcss 8.5.8 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41305: postcss 8.5.8 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.5.8\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0765674e0f501112", "name": "CVE-2024-53382: prismjs 1.27.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2024-53382: prismjs 1.27.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "prismjs: DOM Clobbering vulnerability within the Prism library's prism-autoloader plugin\n\nPrism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.\n\nPackage: prismjs\nInstalled: 1.27.0\nFixed in: 1.30.0\nSeverity: MEDIUM\nFix: Upgrade prismjs to 1.30.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-efb5a0bcf62857e9", "name": "CVE-2026-41242: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41242: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the \"type\" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.\n\nPackage: protobufjs\nInstalled: 7.5.4\nFixed in: 8.0.1, 7.5.5\nSeverity: CRITICAL\nFix: Upgrade protobufjs to 8.0.1, 7.5.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-8c4126834d7c4a5e", "name": "CVE-2026-44289: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44289: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via uncontrolled recursion in protobuf decoding\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields. A crafted protobuf binary payload could cause the JavaScript call stack to be exhausted during decoding. This vulnerability is fixed in 7.5.6 and 8.0.2.\n\nPackage: protobufjs\nInstalled: 7.5.4\nFixed in: 7.5.6, 8.0.2\nSeverity: HIGH\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d4c7e614dd81731d", "name": "CVE-2026-44290: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44290: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via crafted schema\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs allowed certain schema option paths to traverse through inherited object properties while applying options. A crafted protobuf schema or JSON descriptor could cause option handling to write to properties on global JavaScript constructors, corrupting process-wide built-in functionality. This vulnerability is fixed in 7.5.6 and 8.0.2.\n\nPackage: protobufjs\nInstalled: 7.5.4\nFixed in: 7.5.6, 8.0.2\nSeverity: HIGH\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d7842a22007aab80", "name": "CVE-2026-44291: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44291: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs: Arbitrary Code Execution via prototype pollution\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode functions. If Object.prototype had already been polluted, those lookup tables could resolve attacker-controlled inherited properties as valid protobuf type information. This could cause attacker-controlled strings to be emitted into generated JavaScript code. This vulnerabilit\n\nPackage: protobufjs\nInstalled: 7.5.4\nFixed in: 7.5.6, 8.0.2\nSeverity: HIGH\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-be649db53c281eef", "name": "CVE-2026-44293: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44293: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default value for a bytes field could cause attacker-controlled code to be emitted into the generated conversion function. This vulnerability is fixed in 7.5.6 and 8.0.2.\n\nPackage: protobufjs\nInstalled: 7.5.4\nFixed in: 7.5.6, 8.0.2\nSeverity: HIGH\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-49a285db6d989e5d", "name": "CVE-2026-48712: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-48712: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via uncontrolled recursion with crafted protobuf payload\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recurse without a depth limit while converting decoded messages to plain objects or JSON. This affected generated toObject() conversion and the custom google.protobuf.Any JSON conversion path. A crafted protobuf binary payload containing deeply nested Any values could cause the JavaScript call stack to be exhausted during conversion to JSON. This vulnerability is fixed in 7.6.1 and\n\nPackage: protobufjs\nInstalled: 7.5.4\nFixed in: 7.6.1, 8.4.1\nSeverity: HIGH\nFix: Upgrade protobufjs to 7.6.1, 8.4.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d6f5848a58efeb0b", "name": "CVE-2026-44288: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44288: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs: Security control bypass due to improper handling of overlong UTF-8 sequences\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them. An attacker who can provide protobuf binary data decoded through the affected UTF-8 path may be able to bypass application-level checks that inspect raw bytes before protobuf string decoding. For example, bytes that do not contain certain \n\nPackage: protobufjs\nInstalled: 7.5.4\nFixed in: 7.5.6, 8.0.2\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-39695d4bb8601afd", "name": "CVE-2026-44292: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44292: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs: Data integrity impact due to prototype pollution\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated message constructors copied enumerable properties from a provided properties object without filtering the __proto__ key. If an application constructed a message from an attacker-controlled plain object, an own enumerable __proto__ property could alter the prototype of that individual message instance. This vulnerability is fixed in 7.5.6 and 8.0.2.\n\nPackage: protobufjs\nInstalled: 7.5.4\nFixed in: 7.5.6, 8.0.2\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e1676a6d9cb65d50", "name": "CVE-2026-44294: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44294: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service due to unescaped control characters in field names\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript property accessors from schema-controlled field and oneof names. Certain control characters in field names were not escaped before being embedded into generated function bodies. A crafted schema or JSON descriptor could therefore cause generated encode, decode, verify, or conversion functions to fail during compilation. This vulnerability is fixed in 7.5.6 and 8.0.2.\n\nPackage: protobufjs\nInstalled: 7.5.4\nFixed in: 7.5.6, 8.0.2\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-75c09b8ae933ee31", "name": "CVE-2026-45740: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-45740: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via crafted JSON descriptors\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recurse without a depth limit while expanding nested JSON descriptors through Root.fromJSON() and Namespace.addJSON(). A crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading. This vulnerability is fixed in 7.5.8 and 8.2.0.\n\nPackage: protobufjs\nInstalled: 7.5.4\nFixed in: 7.5.8, 8.2.0\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.5.8, 8.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4cfbfd9aaf43a366", "name": "CVE-2026-54269: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54269: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs-cli: protobufjs: Denial of Service due to name collision with runtime helpers\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted certain schema-derived names that could collide with properties used by protobufjs runtime helpers. The known affected names are fields named hasOwnProperty, field or oneof names such as $type when loaded through protobufjs JSON/reflection descriptors, and service methods whose generated helper name is rpcCall. When affected message or service types were used, protobufjs could r\n\nPackage: protobufjs\nInstalled: 7.5.4\nFixed in: 7.6.3, 8.6.0\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.6.3, 8.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c7358c1b78485bba", "name": "CVE-2026-59877: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59877: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via crafted .proto schema\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.\n\nPackage: protobufjs\nInstalled: 7.5.4\nFixed in: 7.6.5, 8.6.6\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.6.5, 8.6.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-67f565b3a6348a2f", "name": "CVE-2026-8723: qs 6.14.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-8723: qs 6.14.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "### Summary    `qs.stringify` throws `TypeError` when called with `arr ...\n\n### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti\n\nPackage: qs\nInstalled: 6.14.2\nFixed in: 6.15.2\nSeverity: MEDIUM\nFix: Upgrade qs to 6.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b76c482485c8be13", "name": "CVE-2026-8723: qs 6.15.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-8723: qs 6.15.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "### Summary    `qs.stringify` throws `TypeError` when called with `arr ...\n\n### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti\n\nPackage: qs\nInstalled: 6.15.0\nFixed in: 6.15.2\nSeverity: MEDIUM\nFix: Upgrade qs to 6.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-421ac77a0b4a2ec5", "name": "CVE-2026-34077: react-router 7.13.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-34077: react-router 7.13.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "react-router: React Router: Denial of Service via client-side Cross-Site Scripting in RSC redirect handling\n\nReact Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2.\n\nPackage: react-router\nInstalled: 7.13.2\nFixed in: 7.14.0\nSeverity: HIGH\nFix: Upgrade react-router to 7.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eb4efd0c3213999b", "name": "CVE-2026-42211: react-router 7.13.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-42211: react-router 7.13.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "react-router: React Router: Remote Code Execution via prototype pollution in Framework Mode\n\nReact Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unauthorized remote code execution (RCE) through external requests. This attack requires the application code to have an existing prototype pollution vulnerability, which can then be leveraged in a 2-step attack where the second step triggers unauthorized RCE on the remote server. This does not impact applications using Declarative Mode (`<BrowserRouter>\n\nPackage: react-router\nInstalled: 7.13.2\nFixed in: 7.14.2\nSeverity: HIGH\nFix: Upgrade react-router to 7.14.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-30f86e1408bbce91", "name": "CVE-2026-42342: react-router 7.13.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-42342: react-router 7.13.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpoint\n\nReact Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can consume disproportionate server resources via unbounded path expansion in the __manifest endpoint, resulting in response time degradation and/or service unavailability for end users. This affects React Router Framework Mode applications as well as Remix applications. This does not impact applications using Declarative M\n\nPackage: react-router\nInstalled: 7.13.2\nFixed in: 7.15.0\nSeverity: HIGH\nFix: Upgrade react-router to 7.15.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3275dd453d5a2971", "name": "CVE-2026-40181: react-router 7.13.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-40181: react-router 7.13.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "react-router: React Router: Open redirect vulnerability via specially crafted URLs\n\nReact Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigger an open redirect to an external domain due to path values starting with // being reinterpreted as protocol-relative URLs. The level of impact depends on the validation done by the application prior to returning the redirect. This does not impact applications using Declarative Mode (<BrowserRouter>). This is patched in versions 7.14.1 and 6.30.4.\n\nPackage: react-router\nInstalled: 7.13.2\nFixed in: 7.14.1, 6.30.4\nSeverity: MEDIUM\nFix: Upgrade react-router to 7.14.1, 6.30.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-65fd9d03b7e8d358", "name": "CVE-2026-53663: react-router 7.13.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-53663: react-router 7.13.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "react-router: @remix-run/server-runtime: React Router: Insufficient CSRF protection allows integrity impact\n\nReact Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were bypassed on PUT/PATCH/DELETE requests. This is a low severity vulnerability because modern browser protections (CORS preflight, SameSite cookies) already block the cross-origin attack vectors that this missing CSRF check would otherwise gate. This vulnerability is fixed in 7.15.1.\n\nPackage: react-router\nInstalled: 7.13.2\nFixed in: 7.15.1\nSeverity: LOW\nFix: Upgrade react-router to 7.15.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-46346e448c6c11ad", "name": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591\n\n### Impact\n\nA number of vulnerabilities, two rated as \"High\" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency.\n\nThose processing untrusted input with versions of sharp prior to 0.35.0 are affected.\n\n### Patches\n\n#### Using prebuilt binaries provided by sharp?\n\nMost people rely on the prebuilt binaries provided by sharp.\n\nPlease upgrade sharp to the latest version, currently 0.35.3, which provides libvips 8.18.3.\n\n#### Using a globally-installed libvips?\n\nP\n\nPackage: sharp\nInstalled: 0.34.5\nFixed in: 0.35.0\nSeverity: HIGH\nFix: Upgrade sharp to 0.35.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6a28b0b8e8517a9c", "name": "CVE-2026-59873: tar 7.5.13 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59873: tar 7.5.13 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "tar: node-tar: Denial of Service via crafted gzip bomb\n\nnode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.\n\nPackage: tar\nInstalled: 7.5.13\nFixed in: 7.5.19\nSeverity: CRITICAL\nFix: Upgrade tar to 7.5.19"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-90af57803c1be2e6", "name": "CVE-2026-59874: tar 7.5.13 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59874: tar 7.5.13 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "tar: Node-tar: Denial of Service via malformed tar archive header\n\nnode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.\n\nPackage: tar\nInstalled: 7.5.13\nFixed in: 7.5.18\nSeverity: HIGH\nFix: Upgrade tar to 7.5.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b967a82df4bcb772", "name": "CVE-2026-53655: tar 7.5.13 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-53655: tar 7.5.13 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "node-tar: node-tar: File smuggling due to inconsistent tar archive parsing\n\nnode-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata headers such as a GNU long-name (L) or long-link (K) entry. Per POSIX pax, a PAX extended header (x) describes the next file entry, not the intermediary extension headers that may sit between the x header and the file it annotates. Because node-tar lets the PAX size override the by\n\nPackage: tar\nInstalled: 7.5.13\nFixed in: 7.5.16\nSeverity: MEDIUM\nFix: Upgrade tar to 7.5.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5ffbc7b09ed6cb96", "name": "CVE-2026-59871: tar 7.5.13 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59871: tar 7.5.13 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "node-tar: node-tar: Denial of Service due to incorrect PAX path handling\n\nnode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is fixed in version 7.5.18.\n\nPackage: tar\nInstalled: 7.5.13\nFixed in: 7.5.18\nSeverity: MEDIUM\nFix: Upgrade tar to 7.5.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ae4cfd95051a88ae", "name": "CVE-2026-59875: tar 7.5.13 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59875: tar 7.5.13 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata\n\nnode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.\n\nPackage: tar\nInstalled: 7.5.13\nFixed in: 7.5.17\nSeverity: MEDIUM\nFix: Upgrade tar to 7.5.17"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-17e382f7b42f9d94", "name": "CVE-2026-12644: ts-deepmerge 7.0.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-12644: ts-deepmerge 7.0.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "ts-deepmerge: Prototype Method Override leads to DoS\n\nVersions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of built-in Object.prototype methods (such as toString, valueOf). When user-controlled input contains these keys with non-function values, the resulting merged object becomes broken \u2014 any string context operation throws a TypeError, crashing the application.\n\nPackage: ts-deepmerge\nInstalled: 7.0.3\nFixed in: 8.0.0\nSeverity: MEDIUM\nFix: Upgrade ts-deepmerge to 8.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8fc0874561a7da84", "name": "CVE-2026-41907: uuid 10.0.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41907: uuid 10.0.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 10.0.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e5eca0332f773fdb", "name": "CVE-2026-41907: uuid 11.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 11.1.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c575cf5f7fc3fa4f", "name": "CVE-2026-41907: uuid 13.0.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41907: uuid 13.0.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 13.0.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-66869d2a79a0974c", "name": "CVE-2026-41907: uuid 9.0.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 9.0.1\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-517dc4aba531e62f", "name": "CVE-2026-39363: vite 7.3.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-39363: vite 7.3.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Vite: Vite: Information disclosure via WebSocket connection bypasses access control\n\nVite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server\u2019s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., export default \"...\"). The access control enforced in the HTTP request path (such as server.fs.allo\n\nPackage: vite\nInstalled: 7.3.1\nFixed in: 8.0.5, 7.3.2, 6.4.2\nSeverity: HIGH\nFix: Upgrade vite to 8.0.5, 7.3.2, 6.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e251cae305e13fd2", "name": "CVE-2026-39364: vite 7.3.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-39364: vite 7.3.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "vite: Vite: Information disclosure via query parameter manipulation on the development server\n\nVite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.\n\nPackage: vite\nInstalled: 7.3.1\nFixed in: 8.0.5, 7.3.2\nSeverity: HIGH\nFix: Upgrade vite to 8.0.5, 7.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c887b75d574aa151", "name": "CVE-2026-53571: vite 7.3.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-53571: vite 7.3.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "vite: `server.fs.deny` bypass on Windows alternate paths\n\nVite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite\u2019s dev server denies direct access to sensitive files through server.fs.deny, including entries such as .env, .env.*, and *.{crt,pem}. However, on Windows, the deny logic does not correctly normalize NTFS ADS path forms before access checks are applied. Because of this, requests such as /.env::$DATA?raw a\n\nPackage: vite\nInstalled: 7.3.1\nFixed in: 8.0.16, 7.3.5, 6.4.3\nSeverity: HIGH\nFix: Upgrade vite to 8.0.16, 7.3.5, 6.4.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fb17f77ccf054c3a", "name": "CVE-2026-39365: vite 7.3.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-39365: vite 7.3.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "vite: Vite: Information disclosure via path traversal in dev server's .map request handling\n\nVite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server\u2019s handling of .map requests for optimized dependencies resolves file paths and calls readFile without restricting ../ segments in the URL. As a result, it is possible to bypass the server.fs.strict allow list and retrieve .map files located outside the project root, provided they can be parsed as valid source map JSON. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.\n\nPackage: vite\nInstalled: 7.3.1\nFixed in: 8.0.5, 7.3.2, 6.4.2\nSeverity: MEDIUM\nFix: Upgrade vite to 8.0.5, 7.3.2, 6.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4344b4fdc4e95b26", "name": "CVE-2026-53632: vite 7.3.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-53632: vite 7.3.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "launch-editor: launch-editor: Credential compromise via NTLMv2 password hash leak through UNC path access\n\nlaunch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user\u2019s NTLMv2 password hash to be leaked to an attacker-controlled SMB server. This can result in credential compromise through offline hash cracking. This vulnerability is fixed in 2.14.1.\n\nPackage: vite\nInstalled: 7.3.1\nFixed in: 8.0.16, 7.3.5, 6.4.3\nSeverity: MEDIUM\nFix: Upgrade vite to 8.0.16, 7.3.5, 6.4.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28771a6dc29e3619", "name": "CVE-2026-39363: vite 8.0.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-39363: vite 8.0.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "Vite: Vite: Information disclosure via WebSocket connection bypasses access control\n\nVite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server\u2019s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., export default \"...\"). The access control enforced in the HTTP request path (such as server.fs.allo\n\nPackage: vite\nInstalled: 8.0.3\nFixed in: 8.0.5, 7.3.2, 6.4.2\nSeverity: HIGH\nFix: Upgrade vite to 8.0.5, 7.3.2, 6.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0bc597416bdeb338", "name": "CVE-2026-39364: vite 8.0.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-39364: vite 8.0.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "vite: Vite: Information disclosure via query parameter manipulation on the development server\n\nVite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.\n\nPackage: vite\nInstalled: 8.0.3\nFixed in: 8.0.5, 7.3.2\nSeverity: HIGH\nFix: Upgrade vite to 8.0.5, 7.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-53f622b1f95222f6", "name": "CVE-2026-53571: vite 8.0.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-53571: vite 8.0.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "vite: `server.fs.deny` bypass on Windows alternate paths\n\nVite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite\u2019s dev server denies direct access to sensitive files through server.fs.deny, including entries such as .env, .env.*, and *.{crt,pem}. However, on Windows, the deny logic does not correctly normalize NTFS ADS path forms before access checks are applied. Because of this, requests such as /.env::$DATA?raw a\n\nPackage: vite\nInstalled: 8.0.3\nFixed in: 8.0.16, 7.3.5, 6.4.3\nSeverity: HIGH\nFix: Upgrade vite to 8.0.16, 7.3.5, 6.4.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5ac2d058f346ff1e", "name": "CVE-2026-39365: vite 8.0.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-39365: vite 8.0.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "vite: Vite: Information disclosure via path traversal in dev server's .map request handling\n\nVite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server\u2019s handling of .map requests for optimized dependencies resolves file paths and calls readFile without restricting ../ segments in the URL. As a result, it is possible to bypass the server.fs.strict allow list and retrieve .map files located outside the project root, provided they can be parsed as valid source map JSON. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.\n\nPackage: vite\nInstalled: 8.0.3\nFixed in: 8.0.5, 7.3.2, 6.4.2\nSeverity: MEDIUM\nFix: Upgrade vite to 8.0.5, 7.3.2, 6.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e453a02452b1ebac", "name": "CVE-2026-53632: vite 8.0.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-53632: vite 8.0.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "launch-editor: launch-editor: Credential compromise via NTLMv2 password hash leak through UNC path access\n\nlaunch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user\u2019s NTLMv2 password hash to be leaked to an attacker-controlled SMB server. This can result in credential compromise through offline hash cracking. This vulnerability is fixed in 2.14.1.\n\nPackage: vite\nInstalled: 8.0.3\nFixed in: 8.0.16, 7.3.5, 6.4.3\nSeverity: MEDIUM\nFix: Upgrade vite to 8.0.16, 7.3.5, 6.4.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-628a8a0e2e77150f", "name": "CVE-2026-48779: ws 8.20.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-48779: ws 8.20.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments\n\nws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-si\n\nPackage: ws\nInstalled: 8.20.0\nFixed in: 5.2.5, 6.2.4, 7.5.11, 8.21.0\nSeverity: HIGH\nFix: Upgrade ws to 5.2.5, 6.2.4, 7.5.11, 8.21.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6d035f4255d07a3c", "name": "CVE-2026-45736: ws 8.20.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-45736: ws 8.20.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "fullDescription": {"text": "ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`\n\nws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.\n\nPackage: ws\nInstalled: 8.20.0\nFixed in: 8.20.1\nSeverity: MEDIUM\nFix: Upgrade ws to 8.20.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d5fd01ba6d4dab28", "name": "CVE-2026-45409: idna 3.11 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-45409: idna 3.11 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "python-idna: idna: Denial of Service via specially crafted long inputs\n\nInternationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fi\n\nPackage: idna\nInstalled: 3.11\nFixed in: 3.15\nSeverity: MEDIUM\nFix: Upgrade idna to 3.15"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3c620c9b8b653482", "name": "CVE-2026-55443: langchain 1.2.0 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-55443: langchain 1.2.0 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended root directory. Affected behaviors include: a file-search agent middleware that validates a starting directory but not the search pattern or the resolved target of matched files, so glob patterns and symlinks can reach files outside the configured root; prompt- \n\nPackage: langchain\nInstalled: 1.2.0\nFixed in: 1.3.9\nSeverity: MEDIUM\nFix: Upgrade langchain to 1.3.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b43a520329315d09", "name": "CVE-2026-34070: langchain-core 1.2.16 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-34070: langchain-core 1.2.16 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "langchain: path traversal in legacy load_prompt functions in langchain-core\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path injection. When an application passes user-influenced prompt configurations to load_prompt() or load_prompt_from_config(), an attacker can read arbitrary files on the host filesystem, constrained only by file-extension chec\n\nPackage: langchain-core\nInstalled: 1.2.16\nFixed in: 1.2.22\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.2.22"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8fe834f814bad093", "name": "CVE-2026-44843: langchain-core 1.2.16 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-44843: langchain-core 1.2.16 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call load() with allowed_objects=\"all\". This does not enable arbitrary Python object deserialization, but it does allow any trusted LangChain-serializable object to be revived, which is broader than these runtime path\n\nPackage: langchain-core\nInstalled: 1.2.16\nFixed in: 1.3.3, 0.3.85\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.3.3, 0.3.85"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bf9cf71c80181c87", "name": "CVE-2026-40087: langchain-core 1.2.16 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-40087: langchain-core 1.2.16 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "langchain: incomplete f-string validation in prompt templates\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-string prompt-template validation was incomplete in two respects. First, some prompt template classes accepted f-string templates and formatted them without enforcing the same attribute-access validation as PromptTemplate. In particular, DictPromptTemplate and ImagePromptTemplate could accept templates containing attribute access or indexing expressions and subsequently evaluate t\n\nPackage: langchain-core\nInstalled: 1.2.16\nFixed in: 0.3.84, 1.2.28\nSeverity: MEDIUM\nFix: Upgrade langchain-core to 0.3.84, 1.2.28"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-848cca510f37d60e", "name": "CVE-2026-41488: langchain-openai 1.1.9 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-41488: langchain-openai 1.1.9 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "langchain-openai: Langchain-openai: Server-Side Request Forgery (SSRF) protection bypass via DNS rebinding\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size() helper (used by get_num_tokens_from_messages for image token counting) validated URLs for SSRF protection and then fetched them in a separate network operation with independent DNS resolution. This left a TOCTOU / DNS rebinding window: an attacker-controlled hostname could resolve to a public IP during validation and then to a private/localhost IP during the actual fetch.\n\nPackage: langchain-openai\nInstalled: 1.1.9\nFixed in: 1.1.14\nSeverity: LOW\nFix: Upgrade langchain-openai to 1.1.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5efb7dd8275cff1e", "name": "CVE-2026-28277: langgraph 1.0.7 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-28277: langgraph 1.0.7 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "LangGraph checkpoint loading has unsafe msgpack deserialization\n\nLangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.0.9 and prior, LangGraph checkpointers can load msgpack-encoded checkpoints that reconstruct Python objects during deserialization. If an attacker can modify checkpoint data in the backing store (for example, after a database compromise or other privileged write access to the persistence layer), they can potentially supply a crafted payload that tri\n\nPackage: langgraph\nInstalled: 1.0.7\nFixed in: 1.0.10\nSeverity: MEDIUM\nFix: Upgrade langgraph to 1.0.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b104dd588c5a47f7", "name": "CVE-2026-27794: langgraph-checkpoint 3.0.1 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-27794: langgraph-checkpoint 3.0.1 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "langgraph-checkpoint: LangGraph Checkpoint: Remote Code Execution via insecure deserialization in caching layer\n\nLangGraph Checkpoint defines the base interface for LangGraph checkpointers. Prior to version 4.0.0, a Remote Code Execution vulnerability exists in LangGraph's caching layer when applications enable cache backends that inherit from `BaseCache` and opt nodes into caching via `CachePolicy`. Prior to `langgraph-checkpoint` 4.0.0, `BaseCache` defaults to `JsonPlusSerializer(pickle_fallback=True)`. When msgpack serialization fails, cached values can be deserialized via `pickle.loads(...)`. Caching i\n\nPackage: langgraph-checkpoint\nInstalled: 3.0.1\nFixed in: 4.0.0\nSeverity: MEDIUM\nFix: Upgrade langgraph-checkpoint to 4.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-739253171751eb47", "name": "CVE-2026-48775: langgraph-checkpoint 3.0.1 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48775: langgraph-checkpoint 3.0.1 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "langgraph: langgraph-checkpoint: LangGraph: Arbitrary code execution via insecure deserialization of modified checkpoint bytes\n\nLangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest in the backing store, the deserialization path could reconstruct objects beyond what the application expects, which could in turn result in code execution at checkpoint load time. T\n\nPackage: langgraph-checkpoint\nInstalled: 3.0.1\nFixed in: 4.1.1\nSeverity: MEDIUM\nFix: Upgrade langgraph-checkpoint to 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c070c288aa5a9226", "name": "CVE-2026-48776: langgraph-sdk 0.3.9 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48776: langgraph-sdk 0.3.9 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "langgraph: langgraph-sdk: LangGraph Python SDK: Unsafe URL path construction leads to unauthorized resource access\n\nLangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versions 0.3.14 and prior have unsafe URL path construction through unsanitized caller-supplied identifier values used in HTTP request paths for resource operations. Without sanitization of those values, identifiers that contain characters with special meaning in URL paths could cause the resulting request to address a different resource (and potentially \n\nPackage: langgraph-sdk\nInstalled: 0.3.9\nFixed in: 0.3.15\nSeverity: MEDIUM\nFix: Upgrade langgraph-sdk to 0.3.15"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-35707d83d62572c4", "name": "CVE-2026-45134: langsmith 0.6.6 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-45134: langsmith 0.6.6 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest\n\nPackage: langsmith\nInstalled: 0.6.6\nFixed in: 0.8.0\nSeverity: HIGH\nFix: Upgrade langsmith to 0.8.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-964eb03f56802418", "name": "GHSA-f4xh-w4cj-qxq8: langsmith 0.6.6 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "GHSA-f4xh-w4cj-qxq8: langsmith 0.6.6 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "LangSmith SDK TracingMiddleware: Arbitrary server-side file read\n\n# Summary\n\nAn attacker who can send an HTTP request to a server running the LangSmith SDK's `TracingMiddleware` can cause that server to read an arbitrary file from its local filesystem and upload the contents to LangSmith as a trace attachment. Depending on how the distributed trace system is deployed, triggering a read may not require authentication. Retrieving the contents requires read access to the LangSmith workspace the traces are sent to. The net effect is a trust-boundary crossing: a pa\n\nPackage: langsmith\nInstalled: 0.6.6\nFixed in: 0.8.18\nSeverity: HIGH\nFix: Upgrade langsmith to 0.8.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f7543ad5de1e740c", "name": "CVE-2026-41182: langsmith 0.6.6 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-41182: langsmith 0.6.6 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "LangSmith SDK: Streaming token events bypass output redaction\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces streaming output, each chunk is recorded as a new_token event containing the raw token value. These events bypass the redaction pipeline entirely \u2014 prepareRunCreateOrUpdateInputs (\n\nPackage: langsmith\nInstalled: 0.6.6\nFixed in: 0.7.31\nSeverity: MEDIUM\nFix: Upgrade langsmith to 0.7.31"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d1fd62523402be34", "name": "CVE-2025-67221: orjson 3.11.5 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2025-67221: orjson 3.11.5 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "orjson: orjson: Denial of Service due to unbounded recursion with deeply nested JSON documents\n\nThe orjson.dumps function in orjson thru 3.11.4 does not limit recursion for deeply nested JSON documents.\n\nPackage: orjson\nInstalled: 3.11.5\nFixed in: 3.11.6\nSeverity: HIGH\nFix: Upgrade orjson to 3.11.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-92074ac3e8ca54b0", "name": "CVE-2026-28684: python-dotenv 1.2.1 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-28684: python-dotenv 1.2.1 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following\n\npython-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when a cross-device rename fallback is triggered. Users should upgrade to v.1.2.2 or, as a workaround, apply the patch manually.\n\nPackage: python-dotenv\nInstalled: 1.2.1\nFixed in: 1.2.2\nSeverity: MEDIUM\nFix: Upgrade python-dotenv to 1.2.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-df75b91b7cfbc021", "name": "CVE-2026-25645: requests 2.32.5 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-25645: requests 2.32.5 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "requests: Requests: Security bypass due to predictable temporary file creation\n\nRequests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulner\n\nPackage: requests\nInstalled: 2.32.5\nFixed in: 2.33.0\nSeverity: MEDIUM\nFix: Upgrade requests to 2.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-86e790278cbbcccd", "name": "CVE-2025-62727: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2025-62727: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette DoS via Range header merging\n\nStarlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileResponse Range parsing/merging logic. This enables CPU exhaustion per request, causing denial\u2011of\u2011service for endpoints serving files (e.g., StaticFiles or any use of FileResponse). This vulnerability is fixed in 0.49.1.\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 0.49.1\nSeverity: HIGH\nFix: Upgrade starlette to 0.49.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-279aa150f7e92795", "name": "CVE-2026-48818: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48818: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows\n\nStarlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\\\attacker.com\\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account\u2019s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as Fas\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.1.0\nSeverity: HIGH\nFix: Upgrade starlette to 1.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-afd74256d3e78799", "name": "CVE-2026-54283: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-54283: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS\n\nStarlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, but silently ignored for application/x-www-form-urlencoded. An unauthenticated attacker can therefore send a urlencoded body with an arbitrarily large number of fields or an arbitrarily large field, even when the application configured limits it believed would apply.\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.3.1\nSeverity: HIGH\nFix: Upgrade starlette to 1.3.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9f764996dbf098e3", "name": "CVE-2025-54121: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2025-54121: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette denial-of-service\n\nStarlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In versions 0.47.1 and below, when parsing a multi-part form with large files (greater than the default max spool size) starlette will block the main thread to roll the file over to disk. This blocks the event thread which means the application can't accept new connections. The UploadFile code has a minor bug where instead of just checking for self._in_me\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 0.47.2\nSeverity: MEDIUM\nFix: Upgrade starlette to 0.47.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c6bfd47f89f06db6", "name": "CVE-2026-48710: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48710: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Security restriction bypass via malformed HTTP Host header\n\nStarlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) \n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.0.1\nSeverity: MEDIUM\nFix: Upgrade starlette to 1.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ce958434e86ef24c", "name": "CVE-2026-48817: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48817: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Information disclosure and unintended method execution via non-standard HTTP methods\n\nStarlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs. When an HTTPEndpoint subclass is registered through Route(...) without an explicit methods= argument, the route does not constrain the method and every method reaches the endpoint. If a non-standard HTTP method whose lo\n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.1.0\nSeverity: MEDIUM\nFix: Upgrade starlette to 1.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-76697b4837768cdd", "name": "CVE-2026-54282: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-54282: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Information disclosure due to improper HTTP request path validation\n\nStarlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path} and re-parsing the result, a path that does not begin with / (for example @google.com) moves the authority boundary during re-parsing, so request.url.hostname and request.url.netloc become attacker-controlled. Code that reads request.url.hostname (rather than the Host header \n\nPackage: starlette\nInstalled: 0.46.2\nFixed in: 1.3.0\nSeverity: LOW\nFix: Upgrade starlette to 1.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a08fa486784a6adf", "name": "CVE-2026-44431: urllib3 2.6.3 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-44431: urllib3 2.6.3 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers\n\nurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.\n\nPackage: urllib3\nInstalled: 2.6.3\nFixed in: 2.7.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-23f04ee111f10e6d", "name": "CVE-2026-44432: urllib3 2.6.3 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock", "shortDescription": {"text": "CVE-2026-44432: urllib3 2.6.3 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3: Denial of Service due to excessive HTTP response decompression\n\nurllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly \n\nPackage: urllib3\nInstalled: 2.6.3\nFixed in: 2.7.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c12cd2dbfaf4bd12", "name": "GHSA-537c-gmf6-5ccf: cryptography 46.0.7 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "GHSA-537c-gmf6-5ccf: cryptography 46.0.7 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "Vulnerable OpenSSL included in cryptography wheels\n\npyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt.\n\nIf you are building cryptography source (\"sdist\") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on \n\nPackage: cryptography\nInstalled: 46.0.7\nFixed in: 48.0.1\nSeverity: HIGH\nFix: Upgrade cryptography to 48.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2a754f4757f2a1ea", "name": "CVE-2026-45409: idna 3.11 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-45409: idna 3.11 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "python-idna: idna: Denial of Service via specially crafted long inputs\n\nInternationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fi\n\nPackage: idna\nInstalled: 3.11\nFixed in: 3.15\nSeverity: MEDIUM\nFix: Upgrade idna to 3.15"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e7bb311ad65559cd", "name": "CVE-2026-55443: langchain 1.2.15 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-55443: langchain 1.2.15 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended root directory. Affected behaviors include: a file-search agent middleware that validates a starting directory but not the search pattern or the resolved target of matched files, so glob patterns and symlinks can reach files outside the configured root; prompt- \n\nPackage: langchain\nInstalled: 1.2.15\nFixed in: 1.3.9\nSeverity: MEDIUM\nFix: Upgrade langchain to 1.3.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dc4df28ad44638c1", "name": "CVE-2026-55443: langchain-anthropic 1.4.0 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-55443: langchain-anthropic 1.4.0 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended root directory. Affected behaviors include: a file-search agent middleware that validates a starting directory but not the search pattern or the resolved target of matched files, so glob patterns and symlinks can reach files outside the configured root; prompt- \n\nPackage: langchain-anthropic\nInstalled: 1.4.0\nFixed in: 1.4.6\nSeverity: MEDIUM\nFix: Upgrade langchain-anthropic to 1.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7f11b3c268e35697", "name": "CVE-2026-44843: langchain-core 1.2.29 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-44843: langchain-core 1.2.29 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call load() with allowed_objects=\"all\". This does not enable arbitrary Python object deserialization, but it does allow any trusted LangChain-serializable object to be revived, which is broader than these runtime path\n\nPackage: langchain-core\nInstalled: 1.2.29\nFixed in: 1.3.3, 0.3.85\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.3.3, 0.3.85"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-02bf108b1abb68a9", "name": "CVE-2026-41488: langchain-openai 1.1.9 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-41488: langchain-openai 1.1.9 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "langchain-openai: Langchain-openai: Server-Side Request Forgery (SSRF) protection bypass via DNS rebinding\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size() helper (used by get_num_tokens_from_messages for image token counting) validated URLs for SSRF protection and then fetched them in a separate network operation with independent DNS resolution. This left a TOCTOU / DNS rebinding window: an attacker-controlled hostname could resolve to a public IP during validation and then to a private/localhost IP during the actual fetch.\n\nPackage: langchain-openai\nInstalled: 1.1.9\nFixed in: 1.1.14\nSeverity: LOW\nFix: Upgrade langchain-openai to 1.1.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-af75016864d1dfcf", "name": "CVE-2026-48775: langgraph-checkpoint 4.0.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48775: langgraph-checkpoint 4.0.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "langgraph: langgraph-checkpoint: LangGraph: Arbitrary code execution via insecure deserialization of modified checkpoint bytes\n\nLangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest in the backing store, the deserialization path could reconstruct objects beyond what the application expects, which could in turn result in code execution at checkpoint load time. T\n\nPackage: langgraph-checkpoint\nInstalled: 4.0.1\nFixed in: 4.1.1\nSeverity: MEDIUM\nFix: Upgrade langgraph-checkpoint to 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7c7c86bfd1679e45", "name": "CVE-2026-48776: langgraph-sdk 0.3.13 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48776: langgraph-sdk 0.3.13 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "langgraph: langgraph-sdk: LangGraph Python SDK: Unsafe URL path construction leads to unauthorized resource access\n\nLangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versions 0.3.14 and prior have unsafe URL path construction through unsanitized caller-supplied identifier values used in HTTP request paths for resource operations. Without sanitization of those values, identifiers that contain characters with special meaning in URL paths could cause the resulting request to address a different resource (and potentially \n\nPackage: langgraph-sdk\nInstalled: 0.3.13\nFixed in: 0.3.15\nSeverity: MEDIUM\nFix: Upgrade langgraph-sdk to 0.3.15"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2937a496b8882054", "name": "CVE-2026-45134: langsmith 0.7.31 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-45134: langsmith 0.7.31 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest\n\nPackage: langsmith\nInstalled: 0.7.31\nFixed in: 0.8.0\nSeverity: HIGH\nFix: Upgrade langsmith to 0.8.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ac81c2a6e4d0136c", "name": "GHSA-f4xh-w4cj-qxq8: langsmith 0.7.31 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "GHSA-f4xh-w4cj-qxq8: langsmith 0.7.31 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "LangSmith SDK TracingMiddleware: Arbitrary server-side file read\n\n# Summary\n\nAn attacker who can send an HTTP request to a server running the LangSmith SDK's `TracingMiddleware` can cause that server to read an arbitrary file from its local filesystem and upload the contents to LangSmith as a trace attachment. Depending on how the distributed trace system is deployed, triggering a read may not require authentication. Retrieving the contents requires read access to the LangSmith workspace the traces are sent to. The net effect is a trust-boundary crossing: a pa\n\nPackage: langsmith\nInstalled: 0.7.31\nFixed in: 0.8.18\nSeverity: HIGH\nFix: Upgrade langsmith to 0.8.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7cc9dda9d8566fc2", "name": "CVE-2026-3219: pip 26.0.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-3219: pip 26.0.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "pip: pip: Incorrect file installation due to improper archive handling\n\npip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing \"incorrect\" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.\n\nPackage: pip\nInstalled: 26.0.1\nFixed in: 26.1\nSeverity: MEDIUM\nFix: Upgrade pip to 26.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3390af1d58f99c86", "name": "CVE-2026-6357: pip 26.0.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-6357: pip 26.0.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "pip: pip: Arbitrary code execution or information disclosure via malicious wheel package installation\n\npip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.\n\nPackage: pip\nInstalled: 26.0.1\nFixed in: 26.1\nSeverity: MEDIUM\nFix: Upgrade pip to 26.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-942c55b0b87db8e9", "name": "CVE-2026-8643: pip 26.0.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-8643: pip 26.0.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite\n\npip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.\n\nPackage: pip\nInstalled: 26.0.1\nFixed in: 26.1.2\nSeverity: MEDIUM\nFix: Upgrade pip to 26.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-754185f6fbdd39ce", "name": "CVE-2026-48526: pyjwt 2.12.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48526: pyjwt 2.12.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens\n\nPyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.\n\nPackage: pyjwt\nInstalled: 2.12.1\nFixed in: 2.13.0\nSeverity: HIGH\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2b815afe51ae2f30", "name": "CVE-2026-48522: pyjwt 2.12.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48522: pyjwt 2.12.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Server-Side Request Forgery (SSRF) via uncontrolled URL fetching in PyJWKClient\n\nPyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registering HTTPHandler, HTTPSHandler, FTPHandler, FileHandler, and DataHandler. There is currently no documented option to restrict which schemes PyJWKClient will fetch. If an application's jku URL ingestion path accepts attacker-influenced URLs (e.g., from JWT header, configuration file, OAuth flow parame\n\nPackage: pyjwt\nInstalled: 2.12.1\nFixed in: 2.13.0\nSeverity: MEDIUM\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4ee91ae7cfec29f9", "name": "CVE-2026-48523: pyjwt 2.12.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48523: pyjwt 2.12.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Verifier-side algorithm bypass leads to unauthorized information access\n\nPyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-supplied algorithms allow-list, but signature verification is performed with the algorithm bound to the PyJWK object instead of the header algorithm. An attacker who controls a registered JWK/JWKS private key can sign with a disallowed algorithm, adv\n\nPackage: pyjwt\nInstalled: 2.12.1\nFixed in: 2.13.0\nSeverity: MEDIUM\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8eb841638dfa8679", "name": "CVE-2026-48525: pyjwt 2.12.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48525: pyjwt 2.12.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Denial of Service via processing of crafted detached JWS tokens\n\nPyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option (\"b64\": false, RFC 7797), PyJWT performs Base64URL decoding of the compact-serialization payload segment before enforcing the detached-payload rules. For b64=false, PyJWT later discards that decoded payload and replaces it with the caller-provided detached_payload. In practice, this turns the middle segment into an attacker-controlled \u201cwork amplifier\u201d: a\n\nPackage: pyjwt\nInstalled: 2.12.1\nFixed in: 2.13.0\nSeverity: MEDIUM\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b10e65267635823e", "name": "CVE-2026-48524: pyjwt 2.12.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48524: pyjwt 2.12.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Denial of Service via unverified JSON Web Token key IDs\n\nPyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no rate limiting. Since kid comes from the unverified token header, an attacker can trigger unlimited outbound requests. The vulnerability surfaces only when a JWKS fetch fails; an attacker can attempt to provoke that with sustained unknown-kid traffic, but the outcome depends on upstream JWKS-endpoint be\n\nPackage: pyjwt\nInstalled: 2.12.1\nFixed in: 2.13.0\nSeverity: LOW\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9e0cad3311afaa32", "name": "CVE-2026-59890: setuptools 82.0.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-59890: setuptools 82.0.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD)\n\nsetuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.\n\nPackage: setuptools\nInstalled: 82.0.1\nFixed in: 83.0.0\nSeverity: MEDIUM\nFix: Upgrade setuptools to 83.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-52ad2c819a1cf4fe", "name": "CVE-2026-48818: starlette 1.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48818: starlette 1.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows\n\nStarlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\\\attacker.com\\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account\u2019s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as Fas\n\nPackage: starlette\nInstalled: 1.0.0\nFixed in: 1.1.0\nSeverity: HIGH\nFix: Upgrade starlette to 1.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-81bd8dba781f9278", "name": "CVE-2026-54283: starlette 1.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-54283: starlette 1.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS\n\nStarlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, but silently ignored for application/x-www-form-urlencoded. An unauthenticated attacker can therefore send a urlencoded body with an arbitrarily large number of fields or an arbitrarily large field, even when the application configured limits it believed would apply.\n\nPackage: starlette\nInstalled: 1.0.0\nFixed in: 1.3.1\nSeverity: HIGH\nFix: Upgrade starlette to 1.3.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-39dbc0da9ecbfcdd", "name": "CVE-2026-48710: starlette 1.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48710: starlette 1.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Security restriction bypass via malformed HTTP Host header\n\nStarlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) \n\nPackage: starlette\nInstalled: 1.0.0\nFixed in: 1.0.1\nSeverity: MEDIUM\nFix: Upgrade starlette to 1.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1b2035737e08539e", "name": "CVE-2026-48817: starlette 1.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-48817: starlette 1.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Information disclosure and unintended method execution via non-standard HTTP methods\n\nStarlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs. When an HTTPEndpoint subclass is registered through Route(...) without an explicit methods= argument, the route does not constrain the method and every method reaches the endpoint. If a non-standard HTTP method whose lo\n\nPackage: starlette\nInstalled: 1.0.0\nFixed in: 1.1.0\nSeverity: MEDIUM\nFix: Upgrade starlette to 1.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-afa2383b5649d776", "name": "CVE-2026-54282: starlette 1.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-54282: starlette 1.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Information disclosure due to improper HTTP request path validation\n\nStarlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path} and re-parsing the result, a path that does not begin with / (for example @google.com) moves the authority boundary during re-parsing, so request.url.hostname and request.url.netloc become attacker-controlled. Code that reads request.url.hostname (rather than the Host header \n\nPackage: starlette\nInstalled: 1.0.0\nFixed in: 1.3.0\nSeverity: LOW\nFix: Upgrade starlette to 1.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-223021c7a3771297", "name": "CVE-2026-44431: urllib3 2.6.3 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-44431: urllib3 2.6.3 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers\n\nurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.\n\nPackage: urllib3\nInstalled: 2.6.3\nFixed in: 2.7.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-466ae3a4e5bf66e7", "name": "CVE-2026-44432: urllib3 2.6.3 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock", "shortDescription": {"text": "CVE-2026-44432: urllib3 2.6.3 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "fullDescription": {"text": "urllib3: urllib3: Denial of Service due to excessive HTTP response decompression\n\nurllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly \n\nPackage: urllib3\nInstalled: 2.6.3\nFixed in: 2.7.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-11a67cd726d5d6a1", "name": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.23 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.23 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue\n\nA vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.\n\nPackage: @ai-sdk/provider-utils\nInstalled: 3.0.23\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-83e5a62b91b852b2", "name": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nThe same as the `hono` core [Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44).\n\n### Summary\n\nOn Windows hosts, an encoded backslash (`%5C`) in the request path decodes to `\\`, which the Windows path resolver treats as a separator. `serve-static` then resolves a single URL segment such as `admin\\secret.txt` into a nested file under the root and serves it, letting an attacker read static files meant t\n\nPackage: @hono/node-server\nInstalled: 1.19.14\nFixed in: 2.0.5\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 2.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-36b9d4f4131ac5fd", "name": "CVE-2026-12590: body-parser 1.20.4 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-12590: body-parser 1.20.4 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 1.20.4\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2808c3d92866e979", "name": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 2.2.2\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d97cb18437268502", "name": "CVE-2026-49458: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-49458: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting due to improper sanitization of DOM nodes\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks used parent-realm constructors, causing instanceof checks for forms, named node maps, document fragments, and elements to fail and skip clobber, template-content, and shadow-DOM sanitization branches so executable markup could survive. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.4.1\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-34d805abfe015a76", "name": "CVE-2026-49459: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-49459: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting bypass allows arbitrary script execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.4.1\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-322253a31faa4796", "name": "CVE-2026-49978: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-49978: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.\n\nPackage: dompurify\nInstalled: 3.4.1\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0827525b06208a12", "name": "GHSA-76mc-f452-cxcm: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "GHSA-76mc-f452-cxcm: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\n# Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\n**CWE**: CWE-501 (Trust Boundary Violation \u2014 hook-scoped mutation leaks to global default sets) via CWE-693 (Protection Mechanism Failure \u2014 the default allow-list is silently widened for all subsequent sanitize calls)\n\n## Summary\n\nThe `data.allowedTags` and `data.allowedAttributes` fields passed to `uponSanitizeElement` and `uponSanitizeAttribute` hooks are **dir\n\nPackage: dompurify\nInstalled: 3.4.1\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ad214f539558c3e4", "name": "GHSA-cmwh-pvxp-8882: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)\n\n## Summary\n\nDOMPurify 3.4.7 shipped a security fix (\"permanent hook pollution\") that makes a registered `uponSanitizeAttribute` hook's mutation of `data.allowedAttributes` **non-persistent** \u2014 so allowing an attribute for one element does not leak into later `sanitize()` calls. The fix clones `ALLOWED_ATTR` inside `_parseConfig`.\n\nThat guard is **silently bypassed whenever the application uses the persistent-config API `DOMPurify.setConfig()`.** `setConfig()` sets the module flag `SET_CONFIG = t\n\nPackage: dompurify\nInstalled: 3.4.1\nFixed in: 3.4.11\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-18f57badd0fd4af1", "name": "GHSA-c2j3-45gr-mqc4: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.\n\n## Summary\n\nThere is a possible hook-policy inconsistency in DOMPurify 3.4.11 involving `CUSTOM_ELEMENT_HANDLING`.\n\nWhen a custom element is allowed via `CUSTOM_ELEMENT_HANDLING.tagNameCheck`, it appears that the element does not go through `afterSanitizeElements` in the same way as a normal element. As a result, an application that relies on `afterSanitizeElements` as a security policy layer to strip sensitive attributes from all elements may see those attributes removed from normal elements bu\n\nPackage: dompurify\nInstalled: 3.4.1\nFixed in: 3.4.12\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6e4bdf81fc46f368", "name": "GHSA-gvmj-g25r-r7wr: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes\n\n## Summary\n\nWhen DOMPurify is configured with both `SAFE_FOR_TEMPLATES: true` and `RETURN_DOM: true` (or `IN_PLACE: true`), an attacker can inject template expressions, such as `${evil}`, `{{evil}}`, or `<%evil%>`, that survive the sanitization pass inside `<template>` element content. This bypasses the explicit purpose of `SAFE_FOR_TEMPLATES`, which is to prevent template engine evaluation of user-supplied content.\n\n> **Note:** The string output path is **not** affected. Only the DOM return pat\n\nPackage: dompurify\nInstalled: 3.4.1\nFixed in: 3.4.8\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6d8dbda2a4d66cd1", "name": "GHSA-vxr8-fq34-vvx9: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output\n\n## Impact\n\nA DOMPurify instance that is reused across trust boundaries can stay bound to a previously supplied `TRUSTED_TYPES_POLICY` even after `clearConfig()` is called. A later caller that requests `RETURN_TRUSTED_TYPE` receives a `TrustedHTML` object created by the old policy, not by a clean default configuration.\n\nIf the old policy is unsafe or controlled by a less-trusted integration, this turns a later \"default\" sanitize call into script execution at a Trusted Types sink. `TRUSTED_TYPES_P\n\nPackage: dompurify\nInstalled: 3.4.1\nFixed in: 3.4.9\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7cfd38e9652fd6fe", "name": "GHSA-x4vx-rjvf-j5p4: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "GHSA-x4vx-rjvf-j5p4: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects\n\n## Summary\n\nWhen `DOMPurify.sanitize(root, { IN_PLACE: true })` is called on an attacker-supplied live DOM node, `DOMPurify` still trusts `currentNode.nodeName` for non-`form` nodes in the main `_sanitizeElements` pipeline. A real `<script>` child node whose observable `nodeName` is attacker-controlled can therefore be misclassified as an allowed element and retained. When the sanitized tree is inserted into a live document, the script executes.\n\nThis affects current `3.4.6`. The recent `IN_PLAC\n\nPackage: dompurify\nInstalled: 3.4.1\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-067a4e1b257f697e", "name": "CVE-2026-13676: fast-uri 3.1.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization\n\nfast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 4.0.1, 3.1.3, 2.4.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 4.0.1, 3.1.3, 2.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8d028ff036b5844d", "name": "CVE-2026-16221: fast-uri 3.1.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...\n\nImpact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 2.4.3, 3.1.4, 4.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 2.4.3, 3.1.4, 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-be3652dd795e141b", "name": "CVE-2026-6321: fast-uri 3.1.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies\n\nfast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Version\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-af13ca299103e969", "name": "CVE-2026-6322: fast-uri 3.1.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: URI authority bypass due to improper delimiter handling\n\nfast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a differ\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ed44c8464a18e17c", "name": "CVE-2026-54290: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-54290: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials: true and no explicit origin (the default wildcard), the CORS Middleware reflects the request's Origin and sends Access-Control-Allow-Credentials: true. Any site can then make credentialed cross-origin requests and read the responses, exposing cookie-authenticated endpoints to arbitrary origins. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.14\nFixed in: 4.12.25\nSeverity: HIGH\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1b9424d4f7d7f032", "name": "CVE-2026-44455: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-44455: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handling of JSX element tag names in hono/jsx allowed unvalidated tag names to be directly inserted into the generated HTML output. When untrusted input is used as a tag name via the programmatic jsx() or createElement() APIs during server-side rendering, specially crafted values may break out of the intended element context and inject unintended HTML. This vulnerability is fixed in 4\n\nPackage: hono\nInstalled: 4.12.14\nFixed in: 4.12.16\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1d65a910a167425b", "name": "CVE-2026-44456: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-44456: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Hono: bodyLimit() can be bypassed for chunked / unknown-length requests\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize for requests without a usable Content-Length (e.g. Transfer-Encoding: chunked). Oversized requests can reach handlers and return 200 instead of 413. This vulnerability is fixed in 4.12.16.\n\nPackage: hono\nInstalled: 4.12.14\nFixed in: 4.12.16\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c57360000792e92b", "name": "CVE-2026-44457: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-44457: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for responses that declare per-user variance via Vary: Authorization or Vary: Cookie. As a result, a response cached for one authenticated user may be served to subsequent requests from different users. This vulnerability is fixed in 4.12.18.\n\nPackage: hono\nInstalled: 4.12.14\nFixed in: 4.12.18\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-544420910dcd13e6", "name": "CVE-2026-44458: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-44458: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Hono has CSS Declaration Injection via Style Object Values in JSX SSR\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer escapes style attribute object values for HTML but not for CSS. Untrusted input in a style object value or property name can therefore inject additional CSS declarations into the rendered style attribute. The impact is limited to CSS and does not allow JavaScript execution or HTML attribute breakout. This vulnerability is fixed in 4.12.18.\n\nPackage: hono\nInstalled: 4.12.14\nFixed in: 4.12.18\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-936b4df305d7b946", "name": "CVE-2026-47673: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-47673: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Hono: JWT middleware accepts any Authorization scheme, not only Bearer\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that the Authorization header value uses theBearer scheme. Any two-part header value \u2014 regardless of the scheme name in the first position \u2014 proceeds to JWT verification. A request presenting a valid JWT under a non-Bearer scheme identifier (such as Basic or Token) is authenticated identically to a correctly formed Bearer request. This vulnerability is\n\nPackage: hono\nInstalled: 4.12.14\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0c667af609290a6f", "name": "CVE-2026-47674: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-47674: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 \n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against configured deny and allow rules using string equality after partial normalization. Non-canonical IPv6 representations of an address already listed in a static rule \u2014 such as compressed forms, explicit-zero forms, or hex-notation IPv4-mapped addresses \u2014 do not match the normalized rule entry, causing the \n\nPackage: hono\nInstalled: 4.12.14\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9fa0e1aa87173fa6", "name": "CVE-2026-47675: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-47675: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters that corrupt Set-Cookie header syntax (;, \\r, \\n), but does not apply the same validation to sameSite and priority. An application that passes user-controlled input into either option may produce a Set-Cookie response header containing attacker-chosen additional attributes. This vulnerability is fixed \n\nPackage: hono\nInstalled: 4.12.14\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9556fb33fe5c4764", "name": "CVE-2026-47676: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-47676: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request path using the raw URL pathname, while route matching is performed against the percent-decoded path. This inconsistency causes the prefix to be stripped at the wrong position when the path contains percent-encoded multi-byte characters, resulting in the mounted sub-application receiving an incorrect path. This vulnerability is fixed\n\nPackage: hono\nInstalled: 4.12.14\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e487033b7c93e6fe", "name": "CVE-2026-54286: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-54286: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \\, which the Windows path resolver treats as a separator. serve-static then resolves a single URL segment such as admin\\secret.txt into a nested file under the root and serves it, letting an attacker read static files meant to be protected behind prefix-mounted middleware. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.14\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3a13f2b5249d1ba6", "name": "CVE-2026-54287: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-54287: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, the ALB single-header response and the VPC Lattice v2 response join multiple Set-Cookie headers into one comma-separated value. Because commas also appear inside cookie attributes (for example Expires dates), clients cannot split the value back into individual cookies and silently drop or misparse them. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.14\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-30e3c85062d7e093", "name": "CVE-2026-54288: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-54288: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit Middleware trusts the request's Content-Length header to decide whether a body is within the limit. On AWS Lambda (API Gateway v1/v2, ALB, VPC Lattice, and Lambda@Edge) the body is delivered fully buffered and the adapter builds the request with the client-declared Content-Length, which need not match the actual payload. A client can declare a tiny Content-Length while sending a\n\nPackage: hono\nInstalled: 4.12.14\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ba4a8ad90b4c1385", "name": "CVE-2026-54289: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-54289: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Edge, CloudFront delivers a request header that appears more than once as several separate entries. The adapter writes each value with Headers.set instead of Headers.append, so every value overwrites the previous one and only the last reaches the application. Repeated request headers such as X-Forwarded-For, Forwarded, and Via are silently truncated to a single value. Request mid\n\nPackage: hono\nInstalled: 4.12.14\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4e61c4864c5405fd", "name": "CVE-2026-59895: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-59895: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.14\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-602fd1a3594be12d", "name": "CVE-2026-59896: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-59896: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "hono/jsx does not isolate context per request, leading to cross-request data disclosure\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async component. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.14\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7b7b24e5bf221553", "name": "CVE-2026-59897: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-59897: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete X-Forwarded-For chain, rate limiting, audit logging, or proxy-chain validation can receive incomplete data. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.14\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7c2d9f163b5df5ea", "name": "CVE-2026-44459: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-44459: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validation of the JWT NumericDate claims exp, nbf, and iat in hono/utils/jwt allows tokens with non-spec-compliant claim values to silently bypass time-based checks. This issue is not exploitable by an anonymous attacker; it only manifests when a malformed claim value reaches verify() \u2014 typically when the application itself issues such tokens, or when the signing key is otherwise unde\n\nPackage: hono\nInstalled: 4.12.14\nFixed in: 4.12.18\nSeverity: LOW\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9454f7734bbfaf4b", "name": "CVE-2026-42338: ip-address 10.1.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-42338: ip-address 10.1.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input\n\nip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods,\n\nPackage: ip-address\nInstalled: 10.1.0\nFixed in: 10.1.1\nSeverity: MEDIUM\nFix: Upgrade ip-address to 10.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eee5b8e1ff355710", "name": "CVE-2026-45134: langsmith 0.5.21 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-45134: langsmith 0.5.21 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest\n\nPackage: langsmith\nInstalled: 0.5.21\nFixed in: 0.6.0\nSeverity: HIGH\nFix: Upgrade langsmith to 0.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a4aa78c4d144537f", "name": "CVE-2026-41148: mermaid 11.14.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-41148: mermaid 11.14.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: CSS injection vulnerability allows page defacement and information disclosure\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS injection through improper sanitization. The state diagram (and any other diagram type that routes user-controlled style strings through the createCssStyles parser) captures classDef values using an unrestricted regex that matches everything up to a newline. That value then flows unsanitized through \n\nPackage: mermaid\nInstalled: 11.14.0\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8a4809f0980762bf", "name": "CVE-2026-41149: mermaid 11.14.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-41149: mermaid 11.14.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: HTML injection via classDef directive in state diagrams\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configuration. Specifically, the classDef directive in Mermaid state diagrams permits DOM injection that escapes the SVG context. However, <script> tags are stripped, which prevents cross-site scripting (XSS). This issue has been fixed in versions 10.9.6 and 11.15.0. If de\n\nPackage: mermaid\nInstalled: 11.14.0\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-feaec2448f219421", "name": "CVE-2026-41150: mermaid 11.14.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-41150: mermaid 11.14.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: Denial of Service via specially crafted gantt charts\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates. mermaid.parse is unaffected, unless you then call the ganttDb.getTasks() (which is called when rendering a diagram). This vulnerability is fixed in 10.9.6 and 11.15.0.\n\nPackage: mermaid\nInstalled: 11.14.0\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3a81102eca625a06", "name": "CVE-2026-41159: mermaid 11.14.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-41159: mermaid 11.14.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: Information disclosure and page defacement via CSS injection\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0,  Mermaid's default configuration allows injecting CSS that applies outside of the Mermaid diagram via the fontFamily, themeCSS, and altFontFamily configuration options. The injected CSS exploits stylis's & (scope reference) handling. :not(&) escapes the #mermaid-xxx automatic scoping, applying styles to all page elements. Global at-rules (@font-face, @keyframes, @c\n\nPackage: mermaid\nInstalled: 11.14.0\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-62601947e05e3ab7", "name": "CVE-2026-44573: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-44573: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed data route, allowing an attacker to retrieve SSR JSON for protected pages without passing the intende\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7231eb09d5d3cdbc", "name": "CVE-2026-44574: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-44574: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Authorization bypass via crafted query parameters\n\nNext.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check. This vulnerability is fixed in 1\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0c2dc4ae9d7b853a", "name": "CVE-2026-44575: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-44575: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Unauthorized access to protected content via middleware bypass\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5a195e73470d7706", "name": "CVE-2026-44578: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-44578: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests\n\nNext.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cb29acaf9f949a7d", "name": "CVE-2026-44579: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-44579: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service via crafted POST requests to server actions\n\nNext.js is a React framework for building full-stack web applications. From  to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open for an extended period, consuming file descriptors and server capacity until legitimate users are den\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-06b73217ea077493", "name": "CVE-2026-45109: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-45109: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.18, 16.2.6\nSeverity: HIGH\nFix: Upgrade next to 15.5.18, 16.2.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-664322f0d5f266bc", "name": "CVE-2026-64641: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-64641: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Next.js: Denial of Service in App Router using Server Actions\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.\n\n## Workarounds\n\nNo workaround exists besides upgrading. Applications using Pages Router or not using Server Actions are not vulnerable.\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f36d63b75d044f93", "name": "CVE-2026-64642: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-64642: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router built with Turbopack and a **single** entry in `config.i18n.locales` can bypass middleware/proxy based authentication.\n\n## Workarounds\n\nIf you cannot upgrade immediately, enforce authorization in the page's server-side data path instead of relying solely on middleware.\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-adba62ef09835ce9", "name": "CVE-2026-64645: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-64645: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\n## Impact\n\nA `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's\u00a0hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect.\n\nThis affects any destination that puts a dynamic segmen\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b0c6e2a74e741c10", "name": "CVE-2026-64649: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-64649: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in Server Actions on custom servers\n\n## Impact\n\nWhen a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization.\n\nApplications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-152189684a4daed2", "name": "GHSA-8h8q-6873-q5fj: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "GHSA-8h8q-6873-q5fj: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Next.js Vulnerable to Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh). \n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of \n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-60a1c64aed0d5e09", "name": "GHSA-q4gf-8mx6-v5v3: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "GHSA-q4gf-8mx6-v5v3: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Next.js has a Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react/security/advisories/GHSA-479c-33wc-g2pg). You can read more about this advisory our [this changelog](https://vercel.com/changelog/summary-of-cve-2026-23869).\n\nA specially crafted HTTP request can be sent to any App Rout\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.15, 16.2.3\nSeverity: HIGH\nFix: Upgrade next to 15.5.15, 16.2.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eb40897608bf69c9", "name": "CVE-2026-27978: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-27978: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: null origin can bypass Server Actions CSRF checks\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, `origin: null` was treated as a \"missing\" origin during Server Action CSRF validation. As a result, requests from opaque contexts (such as sandboxed iframes) could bypass origin verification instead of being validated as cross-origin requests. An attacker could induce a victim browser to submit Server Actions from a sandboxed context, potentially executing state-changing\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 16.1.7\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f5ce31f22caefa19", "name": "CVE-2026-27979: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-27979: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Unbounded postponed resume buffering can lead to DoS\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing the `next-resume: 1` header (corresponding with a PPR resume request) would buffer request bodies without consistently enforcing `maxPostponedStateSize` in certain setups. The previous mitigation protected minimal-mode deployments, but equivalent non-minimal deployments remained vulnerable to the same unbounded postponed resume-body buffering behavio\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 16.1.7\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f154ec74d025273a", "name": "CVE-2026-27980: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-27980: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Unbounded next/image disk cache growth can exhaust storage\n\nNext.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unbounded cache growth. An attacker could generate many unique image-optimization variants and exhaust disk space, causing denial of service. This is fixed in version 16.1.7 by adding an LRU-backed disk cache with `images.maximumDiskCacheSize`, including e\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 16.1.7, 15.5.14\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-661cfdb1133fb3aa", "name": "CVE-2026-29057: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-29057: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: HTTP request smuggling in rewrites\n\nNext.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfer-Encoding: chunked` could trigger request boundary disagreement between the proxy and backend. This could allow request smuggling through rewritten routes. An attacker could smuggle a second request to unintended backend routes (for example, interna\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 16.1.7, 15.5.13\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cf76c79f44bf2a04", "name": "CVE-2026-44576: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-44576: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning vulnerability in React Server Components\n\nNext.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later visitors receive component payloads instead of the expected HTML. This vulnerability is fixed in 15.5\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9491b7f7fef56ebc", "name": "CVE-2026-44577: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-44577: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Denial of Service via Image Optimization API\n\nNext.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the /_next/image endpoint that match the images.localPatterns configuration (by default, all patterns are allowed). This vulnerability\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a2c025d2e3b307a9", "name": "CVE-2026-44580: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-44580: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Cross-site scripting allows arbitrary code execution via untrusted script content\n\nNext.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to break out of the intended script context and execute arbitrary JavaScript in a visitor's browser. This vu\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0028fd72e4b8a478", "name": "CVE-2026-44581: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-44581: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Stored Cross-Site Scripting via malformed nonce values in cached responses\n\nNext.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to poison cached responses and cause script execution for later visitors. This vulnerability is fixed i\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c274b7f6bd5fc652", "name": "CVE-2026-64643: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-64643: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Next.js: Unauthenticated disclosure of internal Server Function endpoints\n\n## Impact\n\nIn Next.js applications using App Router, Server Actions (`use server`) or `use cache` endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used.\n\nServer Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references).\n\nAffected users are applications using App Router + Server Actions.  \n\nBy itself, this disclosure is typically a recon/enumeration primi\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-26fadf6cb78b78bf", "name": "CVE-2026-64644: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-64644: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Next.js: Denial of Service in the Image Optimization API using SVGs\n\n### Impact\n\nWhen self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in  `/_next/image` endpoints.\n\n- If you are using `config.images.remotePatterns`, only the patterns in that array are impacted.\n- If you are using `config.images.unoptimized: true`, you are NOT impacted.\n- If you are using `config.images.loader: 'custom'`\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-966a989702fbc54a", "name": "CVE-2026-64646: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-64646: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Next.js: Unbounded Server Action payload in Edge runtime\n\n## Impact\n\nRequests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime\n\n## Workarounds\n\nIf you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should be allowed at max by your hosting provider.\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2667b67d8af4e20d", "name": "CVE-2026-64647: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-64647: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for `\uc083\uc083` and `\uc104\uc104` in the request body would share the same cache.\n\n##\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-11f2b3e5a7869fdf", "name": "CVE-2026-64648: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-64648: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis only applies to `fetch` calls with a request that has a different init than the one passed to `fetch`.\nSafe: `fetch(new Request(init), init)`\nUnsafe: `fetch(new Request(init), aDifferentInit)`\n\n## Work\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-908909cb72c4e435", "name": "CVE-2026-27977: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-27977: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: null origin can bypass dev HMR websocket CSRF checks\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in `next dev`, cross-site protection for internal websocket endpoints could treat `Origin: null` as a bypass case even if `allowedDevOrigins` is configured, allowing privacy-sensitive/opaque contexts (for example sandboxed documents) to connect unexpectedly. If a dev server is reachable from attacker-controlled content, an attacker may be able to connect to the HMR webso\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 16.1.7\nSeverity: LOW\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b781bf6c7f5b108f", "name": "CVE-2026-44572: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-44572: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service due to improper handling of x-nextjs-data header with redirects\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When that happened, the middleware/proxy could treat the request as a data request and replace the standard Location redirect header with the internal x-nextjs-redirect header. Browsers do not follow x-nextjs-redirect, so the response became an unusable red\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9f204e29a02752e2", "name": "CVE-2026-44582: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-44582: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning allows incorrect response delivery\n\nNext.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL. This vulnerability is fixed in 15.5.16 and 16.2.5.\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5461e65421bf4388", "name": "CVE-2026-41305: postcss 8.4.31 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.4.31\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b8483ec3c153d2c5", "name": "CVE-2024-53382: prismjs 1.27.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2024-53382: prismjs 1.27.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "prismjs: DOM Clobbering vulnerability within the Prism library's prism-autoloader plugin\n\nPrism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.\n\nPackage: prismjs\nInstalled: 1.27.0\nFixed in: 1.30.0\nSeverity: MEDIUM\nFix: Upgrade prismjs to 1.30.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bca13151d4aaa654", "name": "CVE-2026-8723: qs 6.14.2 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-8723: qs 6.14.2 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "### Summary    `qs.stringify` throws `TypeError` when called with `arr ...\n\n### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti\n\nPackage: qs\nInstalled: 6.14.2\nFixed in: 6.15.2\nSeverity: MEDIUM\nFix: Upgrade qs to 6.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-73f7aa5c2625abbb", "name": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591\n\n### Impact\n\nA number of vulnerabilities, two rated as \"High\" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency.\n\nThose processing untrusted input with versions of sharp prior to 0.35.0 are affected.\n\n### Patches\n\n#### Using prebuilt binaries provided by sharp?\n\nMost people rely on the prebuilt binaries provided by sharp.\n\nPlease upgrade sharp to the latest version, currently 0.35.3, which provides libvips 8.18.3.\n\n#### Using a globally-installed libvips?\n\nP\n\nPackage: sharp\nInstalled: 0.34.5\nFixed in: 0.35.0\nSeverity: HIGH\nFix: Upgrade sharp to 0.35.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a7ba74f0779959f0", "name": "CVE-2026-41907: uuid 10.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 10.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 10.0.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-40cce4303294c04a", "name": "CVE-2026-41907: uuid 11.1.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 11.1.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-67babef6b644f24a", "name": "CVE-2026-41907: uuid 13.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 13.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 13.0.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-80bf17e95a4ebbf9", "name": "CVE-2026-48779: ws 8.20.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-48779: ws 8.20.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments\n\nws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-si\n\nPackage: ws\nInstalled: 8.20.0\nFixed in: 5.2.5, 6.2.4, 7.5.11, 8.21.0\nSeverity: HIGH\nFix: Upgrade ws to 5.2.5, 6.2.4, 7.5.11, 8.21.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fa3b848ad227bbb8", "name": "CVE-2026-45736: ws 8.20.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json", "shortDescription": {"text": "CVE-2026-45736: ws 8.20.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "fullDescription": {"text": "ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`\n\nws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.\n\nPackage: ws\nInstalled: 8.20.0\nFixed in: 8.20.1\nSeverity: MEDIUM\nFix: Upgrade ws to 8.20.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-51f663f681915dc0", "name": "CVE-2026-29087: @hono/node-server 1.19.8 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.", "shortDescription": {"text": "CVE-2026-29087: @hono/node-server 1.19.8 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware\n\n@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting /admin/*), inconsistent URL decoding can allow protected static resources to be accessed without authorization. In particular, paths containing encoded slashes (%2F) may be evaluated differently by routing/middleware matching versus static file path resolution, enabling a bypass where middl\n\nPackage: @hono/node-server\nInstalled: 1.19.8\nFixed in: 1.19.10\nSeverity: HIGH\nFix: Upgrade @hono/node-server to 1.19.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-207bbda1e2149e2b", "name": "CVE-2026-39406: @hono/node-server 1.19.8 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.", "shortDescription": {"text": "CVE-2026-39406: @hono/node-server 1.19.8 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "@hono/node-server: Middleware bypass via repeated slashes in serveStatic\n\n@hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware (e.g., /admin/*) is used for authorization, the router may not match paths containing repeated slashes, while serveStatic resolves them as normalized paths. This can lead to a middleware bypass. This vulnerability is fixed in 1.19.13.\n\nPackage: @hono/node-server\nInstalled: 1.19.8\nFixed in: 1.19.13\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 1.19.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e806cd6d334e2953", "name": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.8 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-", "shortDescription": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.8 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nThe same as the `hono` core [Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44).\n\n### Summary\n\nOn Windows hosts, an encoded backslash (`%5C`) in the request path decodes to `\\`, which the Windows path resolver treats as a separator. `serve-static` then resolves a single URL segment such as `admin\\secret.txt` into a nested file under the root and serves it, letting an attacker read static files meant t\n\nPackage: @hono/node-server\nInstalled: 1.19.8\nFixed in: 2.0.5\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 2.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-65af261c31564624", "name": "CVE-2026-25536: @modelcontextprotocol/sdk 1.25.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/packa", "shortDescription": {"text": "CVE-2026-25536: @modelcontextprotocol/sdk 1.25.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "@modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leak\n\nMCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport deployments. This issue has been patched in version 1.26.0.\n\nPackage: @modelcontextprotocol/sdk\nInstalled: 1.25.2\nFixed in: 1.26.0\nSeverity: HIGH\nFix: Upgrade @modelcontextprotocol/sdk to 1.26.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cef37e57736da3b5", "name": "CVE-2025-69873: ajv 8.17.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2025-69873: ajv 8.17.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "ajv: ReDoS via $data reference\n\najv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., \"^(a|a)*$\") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds\n\nPackage: ajv\nInstalled: 8.17.1\nFixed in: 8.18.0, 6.14.0\nSeverity: MEDIUM\nFix: Upgrade ajv to 8.18.0, 6.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-df9047f9cce2a5d3", "name": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 2.2.2\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5af28f8097a88083", "name": "CVE-2026-13676: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization\n\nfast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 4.0.1, 3.1.3, 2.4.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 4.0.1, 3.1.3, 2.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-60bcf4c1ef1ab72c", "name": "CVE-2026-16221: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...\n\nImpact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 2.4.3, 3.1.4, 4.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 2.4.3, 3.1.4, 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ed178292236c2003", "name": "CVE-2026-6321: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies\n\nfast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Version\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-23c05c2885391dce", "name": "CVE-2026-6322: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: URI authority bypass due to improper delimiter handling\n\nfast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a differ\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f52b6fa470daad21", "name": "CVE-2026-22817: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-22817: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono\u2019s JWK/JWKS JWT verification middleware allowed the JWT header\u2019s alg value to influence signature verification when the selected JWK did not explicitly specify an algorithm. This could enable JWT algorithm confusion and, in certain configurations, allow forged tokens to be accepted. As part of this fix, the JWT middleware now requires the alg option to be explicitly speci\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.11.4\nSeverity: HIGH\nFix: Upgrade hono to 4.11.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f8b4257b4ae28b34", "name": "CVE-2026-22818: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-22818: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks \"alg\" (untrusted header.alg fallback)\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono\u2019s JWK/JWKS JWT verification middleware allowed the algorithm specified in the JWT header to influence signature verification when the selected JWK did not explicitly define an algorithm. This could enable JWT algorithm confusion and, in certain configurations, allow forged tokens to be accepted. The JWK/JWKS JWT verification middleware has been updated to require an expl\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.11.4\nSeverity: HIGH\nFix: Upgrade hono to 4.11.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2f09895837e89b9b", "name": "CVE-2026-29045: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-29045: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono vulnerable to arbitrary file access via serveStatic vulnerability \n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/admin/*', ...)), inconsistent URL decoding allowed protected static resources to be accessed without authorization. The router used decodeURI, while serveStatic used decodeURIComponent. This mismatch allowed paths containing encoded slashes (%2F) to bypass middleware protections while still resolving\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.4\nSeverity: HIGH\nFix: Upgrade hono to 4.12.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1b423080b4e152bc", "name": "CVE-2026-54290: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-54290: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials: true and no explicit origin (the default wildcard), the CORS Middleware reflects the request's Origin and sends Access-Control-Allow-Credentials: true. Any site can then make credentialed cross-origin requests and read the responses, exposing cookie-authenticated endpoints to arbitrary origins. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.25\nSeverity: HIGH\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eecfc29420986a61", "name": "CVE-2026-24398: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-24398: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, IP Restriction Middleware in Hono is vulnerable to an IP address validation bypass. The `IPV4_REGEX` pattern and `convertIPv4ToBinary` function in `src/utils/ipaddr.ts` do not properly validate that IPv4 octet values are within the valid range of 0-255, allowing attackers to craft malformed IP addresses that bypass IP-based access controls. Version 4.11.7 contains a patch for the issue.\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.11.7\nSeverity: MEDIUM\nFix: Upgrade hono to 4.11.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-30d7024e05ab2730", "name": "CVE-2026-24472: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-24472: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono cache middleware ignores \"Cache-Control: private\" leading to Web Cache Deception\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Cache Middleware contains an information disclosure vulnerability caused by improper handling of HTTP cache control directives. The middleware does not respect standard cache control headers such as `Cache-Control: private` or `Cache-Control: no-store`, which may result in private or authenticated responses being cached and subsequently exposed to unauthorized users. Version 4.11.7 has \n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.11.7\nSeverity: MEDIUM\nFix: Upgrade hono to 4.11.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2a8cfe6797ead01d", "name": "CVE-2026-24473: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-24473: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Serve static Middleware for the Cloudflare Workers adapter contains an information disclosure vulnerability that may allow attackers to read arbitrary keys from the Workers environment. Improper validation of user-controlled paths can result in unintended access to internal asset keys. Version 4.11.7 contains a patch for the issue.\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.11.7\nSeverity: MEDIUM\nFix: Upgrade hono to 4.11.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-64fe450cc735f44c", "name": "CVE-2026-24771: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-24771: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono vulnerable to XSS through ErrorBoundary component \n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, a Cross-Site Scripting (XSS) vulnerability exists in the `ErrorBoundary` component of the hono/jsx library. Under certain usage patterns, untrusted user-controlled strings may be rendered as raw HTML, allowing arbitrary script execution in the victim's browser. Version 4.11.7 patches the issue.\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.11.7\nSeverity: MEDIUM\nFix: Upgrade hono to 4.11.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-000d05f58453734d", "name": "CVE-2026-29085: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-29085: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming Helper, the event, id, and retry fields were not validated for carriage return (\\r) or newline (\\n) characters. Because the SSE protocol uses line breaks as field delimiters, this could allow injection of additional SSE fields within the same event frame if untrusted input was passed into these fields. This issue has been patched in version 4.12.4.\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.4\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cf660c7300890968", "name": "CVE-2026-29086: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-29086: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, the setCookie() utility did not validate semicolons (;), carriage returns (\\r), or newline characters (\\n) in the domain and path options when constructing the Set-Cookie header. Because cookie attributes are delimited by semicolons, this could allow injection of additional cookie attributes if untrusted input was passed into these fields. This issue has been patched in version 4.12.4.\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.4\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e2b2d283e623f81a", "name": "CVE-2026-39407: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-39407: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono: Middleware bypass via repeated slashes in serveStatic\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware (e.g., /admin/*) is used for authorization, the router may not match paths containing repeated slashes, while serveStatic resolves them as normalized paths. This can lead to a middleware bypass. This vulnerability is fixed in \n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f88800658902deb3", "name": "CVE-2026-39408: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-39408: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono: Path traversal in toSSG() allows writing files outside the output directory\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to be written outside the configured output directory during static site generation. When using dynamic route parameters via ssgParams, specially crafted values can cause generated file paths to escape the intended output directory. This vulnerability is fixed in 4.12.12.\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-acaab246a9744250", "name": "CVE-2026-39409: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-39409: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-mapped IPv6 client addresses (e.g. ::ffff:127.0.0.1) before applying IPv4 allow or deny rules. In environments such as Node.js dual-stack, this can cause IPv4 rules to fail to match, leading to unintended authorization behavior. This vulnerability is fixed in 4.12.12.\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3c7268d1d3af096f", "name": "CVE-2026-39410: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-39410: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono: Non-breaking space prefix bypass in cookie name handling in getCookie()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy between browser cookie parsing and parse() handling allows cookie prefix protections to be bypassed. Cookie names that are treated as distinct by the browser may be normalized to the same key by parse(), allowing attacker-controlled cookies to override legitimate ones. This vulnerability is fixed in 4.12.12.\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-48e6385e6594326b", "name": "CVE-2026-44455: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-44455: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handling of JSX element tag names in hono/jsx allowed unvalidated tag names to be directly inserted into the generated HTML output. When untrusted input is used as a tag name via the programmatic jsx() or createElement() APIs during server-side rendering, specially crafted values may break out of the intended element context and inject unintended HTML. This vulnerability is fixed in 4\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.16\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7f58313e98fbe941", "name": "CVE-2026-44456: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-44456: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono: bodyLimit() can be bypassed for chunked / unknown-length requests\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize for requests without a usable Content-Length (e.g. Transfer-Encoding: chunked). Oversized requests can reach handlers and return 200 instead of 413. This vulnerability is fixed in 4.12.16.\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.16\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-03de96718127de76", "name": "CVE-2026-44457: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-44457: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for responses that declare per-user variance via Vary: Authorization or Vary: Cookie. As a result, a response cached for one authenticated user may be served to subsequent requests from different users. This vulnerability is fixed in 4.12.18.\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.18\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5b86333aece57367", "name": "CVE-2026-44458: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-44458: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono has CSS Declaration Injection via Style Object Values in JSX SSR\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer escapes style attribute object values for HTML but not for CSS. Untrusted input in a style object value or property name can therefore inject additional CSS declarations into the rendered style attribute. The impact is limited to CSS and does not allow JavaScript execution or HTML attribute breakout. This vulnerability is fixed in 4.12.18.\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.18\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-751de4567ca9471f", "name": "CVE-2026-47673: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-47673: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono: JWT middleware accepts any Authorization scheme, not only Bearer\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that the Authorization header value uses theBearer scheme. Any two-part header value \u2014 regardless of the scheme name in the first position \u2014 proceeds to JWT verification. A request presenting a valid JWT under a non-Bearer scheme identifier (such as Basic or Token) is authenticated identically to a correctly formed Bearer request. This vulnerability is\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-62a9c82cfef90538", "name": "CVE-2026-47674: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-47674: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 \n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against configured deny and allow rules using string equality after partial normalization. Non-canonical IPv6 representations of an address already listed in a static rule \u2014 such as compressed forms, explicit-zero forms, or hex-notation IPv4-mapped addresses \u2014 do not match the normalized rule entry, causing the \n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fe77ecf260220a38", "name": "CVE-2026-47675: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-47675: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters that corrupt Set-Cookie header syntax (;, \\r, \\n), but does not apply the same validation to sameSite and priority. An application that passes user-controlled input into either option may produce a Set-Cookie response header containing attacker-chosen additional attributes. This vulnerability is fixed \n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2b36c3a7ea8ab725", "name": "CVE-2026-47676: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-47676: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request path using the raw URL pathname, while route matching is performed against the percent-decoded path. This inconsistency causes the prefix to be stripped at the wrong position when the path contains percent-encoded multi-byte characters, resulting in the mounted sub-application receiving an incorrect path. This vulnerability is fixed\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ec16223a7044fd1e", "name": "CVE-2026-54286: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-54286: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \\, which the Windows path resolver treats as a separator. serve-static then resolves a single URL segment such as admin\\secret.txt into a nested file under the root and serves it, letting an attacker read static files meant to be protected behind prefix-mounted middleware. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-af987d68cb9147b8", "name": "CVE-2026-54287: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-54287: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, the ALB single-header response and the VPC Lattice v2 response join multiple Set-Cookie headers into one comma-separated value. Because commas also appear inside cookie attributes (for example Expires dates), clients cannot split the value back into individual cookies and silently drop or misparse them. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e81538a28e90526e", "name": "CVE-2026-54288: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-54288: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit Middleware trusts the request's Content-Length header to decide whether a body is within the limit. On AWS Lambda (API Gateway v1/v2, ALB, VPC Lattice, and Lambda@Edge) the body is delivered fully buffered and the adapter builds the request with the client-declared Content-Length, which need not match the actual payload. A client can declare a tiny Content-Length while sending a\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5c41bca572154f58", "name": "CVE-2026-54289: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-54289: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Edge, CloudFront delivers a request header that appears more than once as several separate entries. The adapter writes each value with Headers.set instead of Headers.append, so every value overwrites the previous one and only the last reaches the application. Repeated request headers such as X-Forwarded-For, Forwarded, and Via are silently truncated to a single value. Request mid\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-baff8c3107b61b69", "name": "CVE-2026-56761: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-56761: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR\n\nhono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers can craft specially crafted attribute keys containing characters like quotes or angle brackets to break html tag boundaries and inject arbitrary attributes or elements.\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.14\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3457fe547dce3733", "name": "CVE-2026-59895: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-59895: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9870dfc02feb5fbf", "name": "CVE-2026-59897: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-59897: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete X-Forwarded-For chain, rate limiting, audit logging, or proxy-chain validation can receive incomplete data. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1474f4039d7bb323", "name": "GHSA-26pp-8wgv-hjvm: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "GHSA-26pp-8wgv-hjvm: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono missing validation of cookie name on write path in setCookie()\n\n## Summary\n\nCookie names are not validated on the write path when using `setCookie()`, `serialize()`, or `serializeSigned()` to generate Set-Cookie headers.\n\nWhile certain cookie attributes such as domain and path are validated, the cookie name itself may contain invalid characters.\n\nThis results in inconsistent handling of cookie names between parsing (read path) and serialization (write path).\n\n## Details\n\nWhen applications use `setCookie()`, `serialize()`, or `serializeSigned()` with a user-c\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-97df703fd7385306", "name": "GHSA-v8w9-8mx6-g223: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "GHSA-v8w9-8mx6-g223: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })\n\n## Summary\n\nWhen using `parseBody({ dot: true })` in HonoRequest, specially crafted form field names such as `__proto__.x` could create objects containing a `__proto__` property.\n\nIf the parsed result is later merged into regular JavaScript objects using unsafe merge patterns, this may lead to prototype pollution in the target object.\n\n## Details\n\nThe `parseBody({ dot: true })` feature supports dot notation to construct nested objects from form field names.\n\nIn previous versions, the `__proto__`\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.7\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-efaf6dcda886535f", "name": "CVE-2026-44459: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-44459: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validation of the JWT NumericDate claims exp, nbf, and iat in hono/utils/jwt allows tokens with non-spec-compliant claim values to silently bypass time-based checks. This issue is not exploitable by an anonymous attacker; it only manifests when a malformed claim value reaches verify() \u2014 typically when the application itself issues such tokens, or when the signing key is otherwise unde\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.12.18\nSeverity: LOW\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6fa3a2eae6998a04", "name": "GHSA-gq3j-xvxp-8hrf: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "GHSA-gq3j-xvxp-8hrf: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "Hono added timing comparison hardening in basicAuth and bearerAuth\n\n## Summary\n\nThe `basicAuth` and `bearerAuth` middlewares previously used a comparison that was not fully timing-safe.\n\nThe `timingSafeEqual` function used normal string equality (`===`) when comparing hash values. This comparison may stop early if values differ, which can theoretically cause small timing differences.\n\nThe implementation has been updated to use a safer comparison method.\n\n\n## Details\n\nThe issue was caused by the use of normal string equality (`===`) when comparing hash values ins\n\nPackage: hono\nInstalled: 4.11.3\nFixed in: 4.11.10\nSeverity: LOW\nFix: Upgrade hono to 4.11.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-32b3b281a6007f2f", "name": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions\n\nImpact:\n\nA bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service.\n\nPatches:\n\nFixed in version 8.4.0.\n\nWorkarounds:\n\nLimit the number of sequential optional groups in route patterns. Avoid passing user-controlled input as route patterns.\n\nPackage: path-to-regexp\nInstalled: 8.3.0\nFixed in: 8.4.0\nSeverity: HIGH\nFix: Upgrade path-to-regexp to 8.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c67ed73a52296347", "name": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via specially crafted paths with multiple wildcards\n\nImpact:\n\nWhen using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path.\n\nUnsafe examples:\n\n/*foo-*bar-:baz\n/*a-:b-*c-:d\n/x/*a-:b/*c/y\n\nSafe examples:\n\n/*foo-:bar\n/*foo-:bar-*baz\n\nPatches:\n\nUpgrade to version 8.4.0.\n\nWorkarounds:\n\nIf you are using multiple wildcard parameters, you can check the regex output with a too\n\nPackage: path-to-regexp\nInstalled: 8.3.0\nFixed in: 8.4.0\nSeverity: MEDIUM\nFix: Upgrade path-to-regexp to 8.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eb33deb7fbd06155", "name": "CVE-2026-8723: qs 6.14.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-8723: qs 6.14.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "### Summary    `qs.stringify` throws `TypeError` when called with `arr ...\n\n### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti\n\nPackage: qs\nInstalled: 6.14.1\nFixed in: 6.15.2\nSeverity: MEDIUM\nFix: Upgrade qs to 6.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fb9c8251ba37bfb7", "name": "CVE-2026-2391: qs 6.14.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json", "shortDescription": {"text": "CVE-2026-2391: qs 6.14.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "fullDescription": {"text": "qs: qs's arrayLimit bypass in comma parsing allows denial of service\n\n### Summary\nThe `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).\n\n### Details\nWhen the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?\n\nPackage: qs\nInstalled: 6.14.1\nFixed in: 6.14.2\nSeverity: LOW\nFix: Upgrade qs to 6.14.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-16e1745aa32dd020", "name": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.25 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.25 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue\n\nA vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.\n\nPackage: @ai-sdk/provider-utils\nInstalled: 3.0.25\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9e022c85ec76f360", "name": "CVE-2026-29087: @hono/node-server 1.19.8 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-29087: @hono/node-server 1.19.8 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware\n\n@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting /admin/*), inconsistent URL decoding can allow protected static resources to be accessed without authorization. In particular, paths containing encoded slashes (%2F) may be evaluated differently by routing/middleware matching versus static file path resolution, enabling a bypass where middl\n\nPackage: @hono/node-server\nInstalled: 1.19.8\nFixed in: 1.19.10\nSeverity: HIGH\nFix: Upgrade @hono/node-server to 1.19.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5f3ad48a2cfeb6d8", "name": "CVE-2026-39406: @hono/node-server 1.19.8 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-39406: @hono/node-server 1.19.8 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "@hono/node-server: Middleware bypass via repeated slashes in serveStatic\n\n@hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware (e.g., /admin/*) is used for authorization, the router may not match paths containing repeated slashes, while serveStatic resolves them as normalized paths. This can lead to a middleware bypass. This vulnerability is fixed in 1.19.13.\n\nPackage: @hono/node-server\nInstalled: 1.19.8\nFixed in: 1.19.13\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 1.19.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1c670bc818d28838", "name": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.8 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.8 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nThe same as the `hono` core [Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44).\n\n### Summary\n\nOn Windows hosts, an encoded backslash (`%5C`) in the request path decodes to `\\`, which the Windows path resolver treats as a separator. `serve-static` then resolves a single URL segment such as `admin\\secret.txt` into a nested file under the root and serves it, letting an attacker read static files meant t\n\nPackage: @hono/node-server\nInstalled: 1.19.8\nFixed in: 2.0.5\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 2.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dd38dca968f75e6b", "name": "CVE-2026-25536: @modelcontextprotocol/sdk 1.25.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-25536: @modelcontextprotocol/sdk 1.25.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "@modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leak\n\nMCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport deployments. This issue has been patched in version 1.26.0.\n\nPackage: @modelcontextprotocol/sdk\nInstalled: 1.25.2\nFixed in: 1.26.0\nSeverity: HIGH\nFix: Upgrade @modelcontextprotocol/sdk to 1.26.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a18bf677381bb8a1", "name": "CVE-2025-69873: ajv 8.17.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-69873: ajv 8.17.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "ajv: ReDoS via $data reference\n\najv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., \"^(a|a)*$\") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds\n\nPackage: ajv\nInstalled: 8.17.1\nFixed in: 8.18.0, 6.14.0\nSeverity: MEDIUM\nFix: Upgrade ajv to 8.18.0, 6.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7c76834c093875b3", "name": "CVE-2026-12590: body-parser 1.20.4 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-12590: body-parser 1.20.4 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 1.20.4\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-14322d3d495edad3", "name": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 2.2.2\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7566da4be22b0841", "name": "CVE-2026-0540: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-0540: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: DOMPurify: Cross-site scripting vulnerability\n\nDOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like </noscript><img src=x onerror=alert(1)> in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2, 2.5.9\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2, 2.5.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-186fe07963bca754", "name": "CVE-2026-41238: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41238: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: DOMPurify: Cross-Site Scripting bypass via prototype pollution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (no `CUSTOM_ELEMENT_HANDLING` option), a prior prototype pollution gadget can inject permissive `tagNameCheck` and `attributeNameCheck` regex values into `Object.prototype`, causing DOMPurify to allow arbitrary custom elements with arbitrary attributes\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-38084c8ee5b29ec9", "name": "CVE-2026-41239: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41239: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: Vue 2: DOMPurify: Cross-site scripting due to incomplete sanitization of template expressions\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS via template-evaluating frameworks like Vue 2. Version 3.4.0 patches the issue.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2f2529ed704fd48a", "name": "CVE-2026-41240: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41240: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TAGS is used. Commit c361baa added an early exit for FORBID_ATTR at line 1214. The same fix was not applied to FORBID_TAGS. At line 1118-1123, when EXTRA_ELEMENT_HANDLING.tagCheck returns true, the short-circuit evaluation skips the FORBID_TAGS check entirely. This allows forbidden elements to survive \n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-355f4f848a053f51", "name": "CVE-2026-49458: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-49458: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting due to improper sanitization of DOM nodes\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks used parent-realm constructors, causing instanceof checks for forms, named node maps, document fragments, and elements to fail and skip clobber, template-content, and shadow-DOM sanitization branches so executable markup could survive. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eb567e396ede09c2", "name": "CVE-2026-49459: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-49459: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting bypass allows arbitrary script execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-402b461e36bc5660", "name": "CVE-2026-49978: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-49978: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e27ef218d25523a7", "name": "GHSA-39q2-94rc-95cp: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-39q2-94rc-95cp: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation\n\n## Summary\nIn `src/purify.ts:1117-1123`, `ADD_TAGS` as a function (via `EXTRA_ELEMENT_HANDLING.tagCheck`) bypasses `FORBID_TAGS` due to short-circuit evaluation.\n\nThe condition:\n```\n!(tagCheck(tagName)) && (!ALLOWED_TAGS[tagName] || FORBID_TAGS[tagName])\n```\nWhen `tagCheck(tagName)` returns `true`, the entire condition is `false` and the element is kept \u2014 `FORBID_TAGS[tagName]` is never evaluated.\n\n## Inconsistency\nThis contradicts the attribute-side pattern at line 1214 where `FORBID_ATTR` expl\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-66f488559fad40d8", "name": "GHSA-76mc-f452-cxcm: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-76mc-f452-cxcm: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\n# Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\n**CWE**: CWE-501 (Trust Boundary Violation \u2014 hook-scoped mutation leaks to global default sets) via CWE-693 (Protection Mechanism Failure \u2014 the default allow-list is silently widened for all subsequent sanitize calls)\n\n## Summary\n\nThe `data.allowedTags` and `data.allowedAttributes` fields passed to `uponSanitizeElement` and `uponSanitizeAttribute` hooks are **dir\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-67990391f8833a4a", "name": "GHSA-cj63-jhhr-wcxv: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-cj63-jhhr-wcxv: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify USE_PROFILES prototype pollution allows event handlers\n\n## Summary\nWhen `USE_PROFILES` is enabled, DOMPurify rebuilds `ALLOWED_ATTR` as a plain array before populating it with the requested allowlists. Because the sanitizer still looks up attributes via `ALLOWED_ATTR[lcName]`, any `Array.prototype` property that is polluted also counts as an allowlisted attribute. An attacker who can set `Array.prototype.onclick = true` (or a runtime already subject to prototype pollution) can thus force DOMPurify to keep event handlers such as `onclick` even when th\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bb6c55bff02fb430", "name": "GHSA-cjmm-f4jc-qw8r: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-cjmm-f4jc-qw8r: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify ADD_ATTR predicate skips URI validation\n\n## Summary\nDOMPurify allows `ADD_ATTR` to be provided as a predicate function via `EXTRA_ELEMENT_HANDLING.attributeCheck`. When the predicate returns `true`, `_isValidAttribute` short-circuits the attribute check before URI-safe validation runs. An attacker who supplies a predicate that accepts specific attribute/tag combinations can then sanitize input such as `<a href=\"javascript:alert(document.domain)\">` and have the `javascript:` URL survive, because URI validation is skipped for that attrib\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-184e6b7cfcb638fd", "name": "GHSA-cmwh-pvxp-8882: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)\n\n## Summary\n\nDOMPurify 3.4.7 shipped a security fix (\"permanent hook pollution\") that makes a registered `uponSanitizeAttribute` hook's mutation of `data.allowedAttributes` **non-persistent** \u2014 so allowing an attribute for one element does not leak into later `sanitize()` calls. The fix clones `ALLOWED_ATTR` inside `_parseConfig`.\n\nThat guard is **silently bypassed whenever the application uses the persistent-config API `DOMPurify.setConfig()`.** `setConfig()` sets the module flag `SET_CONFIG = t\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.11\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5150be295628e674", "name": "GHSA-h8r8-wccr-v5f2: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-h8r8-wccr-v5f2: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify is vulnerable to mutation-XSS via Re-Contextualization \n\n## Description\n\nA mutation-XSS (mXSS) condition was confirmed when sanitized HTML is reinserted into a new parsing context using `innerHTML` and special wrappers. The vulnerable wrappers confirmed in browser behavior are `script`, `xmp`, `iframe`, `noembed`, `noframes`, and `noscript`. The payload remains seemingly benign after `DOMPurify.sanitize()`, but mutates during the second parse into executable markup with an event handler, enabling JavaScript execution in the client (`alert(1)` in the P\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4760529717455ebf", "name": "GHSA-c2j3-45gr-mqc4: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.\n\n## Summary\n\nThere is a possible hook-policy inconsistency in DOMPurify 3.4.11 involving `CUSTOM_ELEMENT_HANDLING`.\n\nWhen a custom element is allowed via `CUSTOM_ELEMENT_HANDLING.tagNameCheck`, it appears that the element does not go through `afterSanitizeElements` in the same way as a normal element. As a result, an application that relies on `afterSanitizeElements` as a security policy layer to strip sensitive attributes from all elements may see those attributes removed from normal elements bu\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.12\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-486b9d345bb12fe7", "name": "GHSA-gvmj-g25r-r7wr: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes\n\n## Summary\n\nWhen DOMPurify is configured with both `SAFE_FOR_TEMPLATES: true` and `RETURN_DOM: true` (or `IN_PLACE: true`), an attacker can inject template expressions, such as `${evil}`, `{{evil}}`, or `<%evil%>`, that survive the sanitization pass inside `<template>` element content. This bypasses the explicit purpose of `SAFE_FOR_TEMPLATES`, which is to prevent template engine evaluation of user-supplied content.\n\n> **Note:** The string output path is **not** affected. Only the DOM return pat\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.8\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1079b32ab8ce98ac", "name": "GHSA-vxr8-fq34-vvx9: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output\n\n## Impact\n\nA DOMPurify instance that is reused across trust boundaries can stay bound to a previously supplied `TRUSTED_TYPES_POLICY` even after `clearConfig()` is called. A later caller that requests `RETURN_TRUSTED_TYPE` receives a `TrustedHTML` object created by the old policy, not by a clean default configuration.\n\nIf the old policy is unsafe or controlled by a less-trusted integration, this turns a later \"default\" sanitize call into script execution at a Trusted Types sink. `TRUSTED_TYPES_P\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.9\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d24eb3d228985d50", "name": "GHSA-x4vx-rjvf-j5p4: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-x4vx-rjvf-j5p4: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects\n\n## Summary\n\nWhen `DOMPurify.sanitize(root, { IN_PLACE: true })` is called on an attacker-supplied live DOM node, `DOMPurify` still trusts `currentNode.nodeName` for non-`form` nodes in the main `_sanitizeElements` pipeline. A real `<script>` child node whose observable `nodeName` is attacker-controlled can therefore be misclassified as an allowed element and retained. When the sanitized tree is inserted into a live document, the script executes.\n\nThis affects current `3.4.6`. The recent `IN_PLAC\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b6c122ddb0aebd13", "name": "CVE-2026-13676: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization\n\nfast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 4.0.1, 3.1.3, 2.4.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 4.0.1, 3.1.3, 2.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-40636ce14373d4ca", "name": "CVE-2026-16221: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...\n\nImpact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 2.4.3, 3.1.4, 4.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 2.4.3, 3.1.4, 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e3ed2e85ae19a431", "name": "CVE-2026-6321: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies\n\nfast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Version\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1c628d44d9a099c7", "name": "CVE-2026-6322: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-uri: fast-uri: URI authority bypass due to improper delimiter handling\n\nfast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a differ\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1c7f046caaebefbf", "name": "CVE-2026-54290: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54290: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials: true and no explicit origin (the default wildcard), the CORS Middleware reflects the request's Origin and sends Access-Control-Allow-Credentials: true. Any site can then make credentialed cross-origin requests and read the responses, exposing cookie-authenticated endpoints to arbitrary origins. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.23\nFixed in: 4.12.25\nSeverity: HIGH\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2efe592e8099ccd6", "name": "CVE-2026-54286: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54286: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \\, which the Windows path resolver treats as a separator. serve-static then resolves a single URL segment such as admin\\secret.txt into a nested file under the root and serves it, letting an attacker read static files meant to be protected behind prefix-mounted middleware. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.23\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0cdfacc305045a09", "name": "CVE-2026-54287: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54287: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, the ALB single-header response and the VPC Lattice v2 response join multiple Set-Cookie headers into one comma-separated value. Because commas also appear inside cookie attributes (for example Expires dates), clients cannot split the value back into individual cookies and silently drop or misparse them. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.23\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-155d59755dc87913", "name": "CVE-2026-54288: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54288: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit Middleware trusts the request's Content-Length header to decide whether a body is within the limit. On AWS Lambda (API Gateway v1/v2, ALB, VPC Lattice, and Lambda@Edge) the body is delivered fully buffered and the adapter builds the request with the client-declared Content-Length, which need not match the actual payload. A client can declare a tiny Content-Length while sending a\n\nPackage: hono\nInstalled: 4.12.23\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dbce38cb467ce1d5", "name": "CVE-2026-54289: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54289: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Edge, CloudFront delivers a request header that appears more than once as several separate entries. The adapter writes each value with Headers.set instead of Headers.append, so every value overwrites the previous one and only the last reaches the application. Repeated request headers such as X-Forwarded-For, Forwarded, and Via are silently truncated to a single value. Request mid\n\nPackage: hono\nInstalled: 4.12.23\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d5a8215482cb74a1", "name": "CVE-2026-59895: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59895: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.23\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-72f1f966410cb394", "name": "CVE-2026-59896: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59896: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "hono/jsx does not isolate context per request, leading to cross-request data disclosure\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async component. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.23\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7e2ddcf268168780", "name": "CVE-2026-59897: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59897: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete X-Forwarded-For chain, rate limiting, audit logging, or proxy-chain validation can receive incomplete data. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.23\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2bd8b324bf6d5f29", "name": "CVE-2026-4800: lodash-es 4.17.21 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-4800: lodash-es 4.17.21 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e58b345a4e5bba48", "name": "CVE-2025-13465: lodash-es 4.17.21 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-13465: lodash-es 4.17.21 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "lodash: prototype pollution in _.unset and _.omit functions\n\nLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset\u00a0and _.omit\u00a0functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.\n\nThe issue permits deletion of properties but does not allow overwriting their original behavior.\n\nThis issue is patched on 4.17.23\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.17.23\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.17.23"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e6f408965346503e", "name": "CVE-2026-2950: lodash-es 4.17.21 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-2950: lodash-es 4.17.21 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f4cbe2a0b223d084", "name": "CVE-2026-4800: lodash-es 4.17.22 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-4800: lodash-es 4.17.22 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash-es\nInstalled: 4.17.22\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a95dd78113636459", "name": "CVE-2025-13465: lodash-es 4.17.22 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-13465: lodash-es 4.17.22 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "lodash: prototype pollution in _.unset and _.omit functions\n\nLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset\u00a0and _.omit\u00a0functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.\n\nThe issue permits deletion of properties but does not allow overwriting their original behavior.\n\nThis issue is patched on 4.17.23\n\nPackage: lodash-es\nInstalled: 4.17.22\nFixed in: 4.17.23\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.17.23"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d9a02e4e708da652", "name": "CVE-2026-2950: lodash-es 4.17.22 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-2950: lodash-es 4.17.22 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash-es\nInstalled: 4.17.22\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5122d5417bba57fa", "name": "CVE-2026-41148: mermaid 11.12.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41148: mermaid 11.12.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "mermaid: Mermaid: CSS injection vulnerability allows page defacement and information disclosure\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS injection through improper sanitization. The state diagram (and any other diagram type that routes user-controlled style strings through the createCssStyles parser) captures classDef values using an unrestricted regex that matches everything up to a newline. That value then flows unsanitized through \n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-de4dd1941398da98", "name": "CVE-2026-41149: mermaid 11.12.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41149: mermaid 11.12.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "mermaid: Mermaid: HTML injection via classDef directive in state diagrams\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configuration. Specifically, the classDef directive in Mermaid state diagrams permits DOM injection that escapes the SVG context. However, <script> tags are stripped, which prevents cross-site scripting (XSS). This issue has been fixed in versions 10.9.6 and 11.15.0. If de\n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1676e90c0990cb40", "name": "CVE-2026-41150: mermaid 11.12.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41150: mermaid 11.12.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "mermaid: Mermaid: Denial of Service via specially crafted gantt charts\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates. mermaid.parse is unaffected, unless you then call the ganttDb.getTasks() (which is called when rendering a diagram). This vulnerability is fixed in 10.9.6 and 11.15.0.\n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a951d250b992c88d", "name": "CVE-2026-41159: mermaid 11.12.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41159: mermaid 11.12.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "mermaid: Mermaid: Information disclosure and page defacement via CSS injection\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0,  Mermaid's default configuration allows injecting CSS that applies outside of the Mermaid diagram via the fontFamily, themeCSS, and altFontFamily configuration options. The injected CSS exploits stylis's & (scope reference) handling. :not(&) escapes the #mermaid-xxx automatic scoping, applying styles to all page elements. Global at-rules (@font-face, @keyframes, @c\n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fee84d588b5ab2da", "name": "CVE-2026-44573: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44573: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed data route, allowing an attacker to retrieve SSR JSON for protected pages without passing the intende\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c44e833c5e3ef452", "name": "CVE-2026-44574: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44574: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Next.js: Authorization bypass via crafted query parameters\n\nNext.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check. This vulnerability is fixed in 1\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-daac8ac9d153600b", "name": "CVE-2026-44575: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44575: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Unauthorized access to protected content via middleware bypass\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6a3c47c7a8409aee", "name": "CVE-2026-44578: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44578: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests\n\nNext.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-589a25f36c6e5c56", "name": "CVE-2026-44579: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44579: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service via crafted POST requests to server actions\n\nNext.js is a React framework for building full-stack web applications. From  to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open for an extended period, consuming file descriptors and server capacity until legitimate users are den\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-70a6a8a118696afd", "name": "CVE-2026-45109: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-45109: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.18, 16.2.6\nSeverity: HIGH\nFix: Upgrade next to 15.5.18, 16.2.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-68ad75ed84fee85a", "name": "CVE-2026-64641: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64641: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Denial of Service in App Router using Server Actions\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.\n\n## Workarounds\n\nNo workaround exists besides upgrading. Applications using Pages Router or not using Server Actions are not vulnerable.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-81e27f1a5537116e", "name": "CVE-2026-64642: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64642: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router built with Turbopack and a **single** entry in `config.i18n.locales` can bypass middleware/proxy based authentication.\n\n## Workarounds\n\nIf you cannot upgrade immediately, enforce authorization in the page's server-side data path instead of relying solely on middleware.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-61fc7382f1d60637", "name": "CVE-2026-64645: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64645: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\n## Impact\n\nA `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's\u00a0hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect.\n\nThis affects any destination that puts a dynamic segmen\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-25eb76023e69b2f7", "name": "CVE-2026-64649: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64649: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in Server Actions on custom servers\n\n## Impact\n\nWhen a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization.\n\nApplications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-903a35efcbd83faa", "name": "GHSA-8h8q-6873-q5fj: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-8h8q-6873-q5fj: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js Vulnerable to Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh). \n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of \n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7cd745804d7c9f22", "name": "GHSA-h25m-26qc-wcjf: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-h25m-26qc-wcjf: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.0.x, 19.1.x, and 19.2.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23864](https://github.com/facebook/react/security/advisories/GHSA-83fc-fqcc-2hmg).\n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage, out-of-m\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5\nSeverity: HIGH\nFix: Upgrade next to 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-90514de3bff32b52", "name": "GHSA-q4gf-8mx6-v5v3: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-q4gf-8mx6-v5v3: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js has a Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react/security/advisories/GHSA-479c-33wc-g2pg). You can read more about this advisory our [this changelog](https://vercel.com/changelog/summary-of-cve-2026-23869).\n\nA specially crafted HTTP request can be sent to any App Rout\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.15, 16.2.3\nSeverity: HIGH\nFix: Upgrade next to 15.5.15, 16.2.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9aee0ecf4eeec9d3", "name": "CVE-2025-59471: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-59471: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "next: NextJS Denial of Service in Image Optimizer\n\nA denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing a maximum size limit, allowing an attacker to cause out-of-memory conditions by requesting optimization of arbitrarily large images. This vulnerability requires that `remotePatterns` is configured to allow image optimization from external domains and\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.10, 16.1.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.10, 16.1.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a6b94515f07b2188", "name": "CVE-2025-59472: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-59472: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "next: NextJS Denial of Service in Partial Pre Rendering\n\nA denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests with the `Next-Resume: 1` header and processes attacker-controlled postponed state data. Two closely related vulnerabilities allow an attacker to crash the server process through memory exhaustion:\n\n1. **Unbounded request body buffering**: The server buffers the entire POST request body into memory using `\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.5, 15.6.0-canary.61\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.5, 15.6.0-canary.61"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6c4085f56157ba3f", "name": "CVE-2026-27978: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-27978: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: null origin can bypass Server Actions CSRF checks\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, `origin: null` was treated as a \"missing\" origin during Server Action CSRF validation. As a result, requests from opaque contexts (such as sandboxed iframes) could bypass origin verification instead of being validated as cross-origin requests. An attacker could induce a victim browser to submit Server Actions from a sandboxed context, potentially executing state-changing\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b1bfc52c9cd13723", "name": "CVE-2026-27979: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-27979: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Unbounded postponed resume buffering can lead to DoS\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing the `next-resume: 1` header (corresponding with a PPR resume request) would buffer request bodies without consistently enforcing `maxPostponedStateSize` in certain setups. The previous mitigation protected minimal-mode deployments, but equivalent non-minimal deployments remained vulnerable to the same unbounded postponed resume-body buffering behavio\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ef5c25ad9b0bc001", "name": "CVE-2026-27980: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-27980: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Unbounded next/image disk cache growth can exhaust storage\n\nNext.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unbounded cache growth. An attacker could generate many unique image-optimization variants and exhaust disk space, causing denial of service. This is fixed in version 16.1.7 by adding an LRU-backed disk cache with `images.maximumDiskCacheSize`, including e\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7, 15.5.14\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2dbb8b08bd85da2a", "name": "CVE-2026-29057: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-29057: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: HTTP request smuggling in rewrites\n\nNext.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfer-Encoding: chunked` could trigger request boundary disagreement between the proxy and backend. This could allow request smuggling through rewritten routes. An attacker could smuggle a second request to unintended backend routes (for example, interna\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7, 15.5.13\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-92446a80d43550c7", "name": "CVE-2026-44576: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44576: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning vulnerability in React Server Components\n\nNext.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later visitors receive component payloads instead of the expected HTML. This vulnerability is fixed in 15.5\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-193f314c5b0e1d3c", "name": "CVE-2026-44577: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44577: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Next.js: Denial of Service via Image Optimization API\n\nNext.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the /_next/image endpoint that match the images.localPatterns configuration (by default, all patterns are allowed). This vulnerability\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-575032f3b662a166", "name": "CVE-2026-44580: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44580: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Cross-site scripting allows arbitrary code execution via untrusted script content\n\nNext.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to break out of the intended script context and execute arbitrary JavaScript in a visitor's browser. This vu\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e40d66835ed0b001", "name": "CVE-2026-44581: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44581: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Stored Cross-Site Scripting via malformed nonce values in cached responses\n\nNext.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to poison cached responses and cause script execution for later visitors. This vulnerability is fixed i\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bc1eaa36e104e0b5", "name": "CVE-2026-64643: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64643: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Unauthenticated disclosure of internal Server Function endpoints\n\n## Impact\n\nIn Next.js applications using App Router, Server Actions (`use server`) or `use cache` endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used.\n\nServer Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references).\n\nAffected users are applications using App Router + Server Actions.  \n\nBy itself, this disclosure is typically a recon/enumeration primi\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0d0f5ee3fea5d82a", "name": "CVE-2026-64644: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64644: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Denial of Service in the Image Optimization API using SVGs\n\n### Impact\n\nWhen self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in  `/_next/image` endpoints.\n\n- If you are using `config.images.remotePatterns`, only the patterns in that array are impacted.\n- If you are using `config.images.unoptimized: true`, you are NOT impacted.\n- If you are using `config.images.loader: 'custom'`\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3d99815d120e5720", "name": "CVE-2026-64646: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64646: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Unbounded Server Action payload in Edge runtime\n\n## Impact\n\nRequests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime\n\n## Workarounds\n\nIf you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should be allowed at max by your hosting provider.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-47f1e7ccec44b321", "name": "CVE-2026-64647: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64647: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for `\uc083\uc083` and `\uc104\uc104` in the request body would share the same cache.\n\n##\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-25f9c72a027a671b", "name": "CVE-2026-64648: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-64648: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis only applies to `fetch` calls with a request that has a different init than the one passed to `fetch`.\nSafe: `fetch(new Request(init), init)`\nUnsafe: `fetch(new Request(init), aDifferentInit)`\n\n## Work\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4ff678e5afacfd3b", "name": "CVE-2026-27977: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-27977: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: null origin can bypass dev HMR websocket CSRF checks\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in `next dev`, cross-site protection for internal websocket endpoints could treat `Origin: null` as a bypass case even if `allowedDevOrigins` is configured, allowing privacy-sensitive/opaque contexts (for example sandboxed documents) to connect unexpectedly. If a dev server is reachable from attacker-controlled content, an attacker may be able to connect to the HMR webso\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 16.1.7\nSeverity: LOW\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4a5067e99d1d2839", "name": "CVE-2026-44572: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44572: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service due to improper handling of x-nextjs-data header with redirects\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When that happened, the middleware/proxy could treat the request as a data request and replace the standard Location redirect header with the internal x-nextjs-redirect header. Browsers do not follow x-nextjs-redirect, so the response became an unusable red\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8572864282e9d2cd", "name": "CVE-2026-44582: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-44582: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning allows incorrect response delivery\n\nNext.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL. This vulnerability is fixed in 15.5.16 and 16.2.5.\n\nPackage: next\nInstalled: 16.1.1\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-66a7181321cd4574", "name": "CVE-2026-4867: path-to-regexp 0.1.12 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-4867: path-to-regexp 0.1.12 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters\n\nImpact:\n\nA bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c or /:a-:b-:c-:d. The backtrack protection added in path-to-regexp@0.1.12 only prevents ambiguity for two parameters. With three or more, the generated lookahead does not block single separator characters, so capture groups overlap and cause catastrophic backtracking.\n\nPatches:\n\nUpgrade to path-to-regexp@0.1.13\n\n\n\nPackage: path-to-regexp\nInstalled: 0.1.12\nFixed in: 0.1.13\nSeverity: HIGH\nFix: Upgrade path-to-regexp to 0.1.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3278edd8bb36e9a3", "name": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions\n\nImpact:\n\nA bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service.\n\nPatches:\n\nFixed in version 8.4.0.\n\nWorkarounds:\n\nLimit the number of sequential optional groups in route patterns. Avoid passing user-controlled input as route patterns.\n\nPackage: path-to-regexp\nInstalled: 8.3.0\nFixed in: 8.4.0\nSeverity: HIGH\nFix: Upgrade path-to-regexp to 8.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3e1e9f0ddfde7210", "name": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via specially crafted paths with multiple wildcards\n\nImpact:\n\nWhen using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path.\n\nUnsafe examples:\n\n/*foo-*bar-:baz\n/*a-:b-*c-:d\n/x/*a-:b/*c/y\n\nSafe examples:\n\n/*foo-:bar\n/*foo-:bar-*baz\n\nPatches:\n\nUpgrade to version 8.4.0.\n\nWorkarounds:\n\nIf you are using multiple wildcard parameters, you can check the regex output with a too\n\nPackage: path-to-regexp\nInstalled: 8.3.0\nFixed in: 8.4.0\nSeverity: MEDIUM\nFix: Upgrade path-to-regexp to 8.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-69dae9ce198962e4", "name": "CVE-2026-41305: postcss 8.4.31 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.4.31\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-72c20d0d98cfe94d", "name": "CVE-2026-8723: qs 6.14.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-8723: qs 6.14.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "### Summary    `qs.stringify` throws `TypeError` when called with `arr ...\n\n### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti\n\nPackage: qs\nInstalled: 6.14.1\nFixed in: 6.15.2\nSeverity: MEDIUM\nFix: Upgrade qs to 6.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-37160a2bb9cd508a", "name": "CVE-2026-2391: qs 6.14.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-2391: qs 6.14.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "qs: qs's arrayLimit bypass in comma parsing allows denial of service\n\n### Summary\nThe `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).\n\n### Details\nWhen the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?\n\nPackage: qs\nInstalled: 6.14.1\nFixed in: 6.14.2\nSeverity: LOW\nFix: Upgrade qs to 6.14.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6cf6b4b26d8f68b5", "name": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591\n\n### Impact\n\nA number of vulnerabilities, two rated as \"High\" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency.\n\nThose processing untrusted input with versions of sharp prior to 0.35.0 are affected.\n\n### Patches\n\n#### Using prebuilt binaries provided by sharp?\n\nMost people rely on the prebuilt binaries provided by sharp.\n\nPlease upgrade sharp to the latest version, currently 0.35.3, which provides libvips 8.18.3.\n\n#### Using a globally-installed libvips?\n\nP\n\nPackage: sharp\nInstalled: 0.34.5\nFixed in: 0.35.0\nSeverity: HIGH\nFix: Upgrade sharp to 0.35.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-28a33e70e381c6cd", "name": "CVE-2026-41907: uuid 10.0.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41907: uuid 10.0.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 10.0.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a91f6f94f1957178", "name": "CVE-2026-41907: uuid 11.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 11.1.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b6d266a673b5606c", "name": "CVE-2025-12695: dspy 2.6.18 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt", "shortDescription": {"text": "CVE-2025-12695: dspy 2.6.18 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt"}, "fullDescription": {"text": "DSPy does not properly restrict file reads\n\nThe overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the \u201cPythonInterpreter\u201d class.\n\nPackage: dspy\nInstalled: 2.6.18\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f3a2831de2156e54", "name": "CVE-2025-7707: llama-index 0.12.33 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt", "shortDescription": {"text": "CVE-2025-7707: llama-index 0.12.33 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt"}, "fullDescription": {"text": "llama-index: World-Writable Cache Directory Vulnerability in llama_index\n\nThe llama_index library version 0.12.33 sets the NLTK data directory to a subdirectory of the codebase by default, which is world-writable in multi-user environments. This configuration allows local users to overwrite, delete, or corrupt NLTK data files, leading to potential denial of service, data tampering, or privilege escalation. The vulnerability arises from the use of a shared cache directory instead of a user-specific one, making it susceptible to local data tampering and denial of servic\n\nPackage: llama-index\nInstalled: 0.12.33\nFixed in: 0.13.0\nSeverity: HIGH\nFix: Upgrade llama-index to 0.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-031abdba9947ef90", "name": "CVE-2025-6211: llama-index 0.12.33 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt", "shortDescription": {"text": "CVE-2025-6211: llama-index 0.12.33 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt"}, "fullDescription": {"text": "llama-index: llama_index MD5 Hash Collision\n\nA vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the use of MD5 hashing to generate IDs for document chunks. This approach leads to hash collisions when structurally distinct chunks contain identical text, resulting in one chunk overwriting another. This can cause loss of semantically or legally important document content, breakage of parent-child chunk hierarchies, and inaccurate or hallucinated responses in AI outputs. The iss\n\nPackage: llama-index\nInstalled: 0.12.33\nFixed in: 0.12.41\nSeverity: MEDIUM\nFix: Upgrade llama-index to 0.12.41"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0daf8de7326d41ae", "name": "CVE-2026-28684: python-dotenv 1.1.0 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-28684: python-dotenv 1.1.0 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt"}, "fullDescription": {"text": "python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following\n\npython-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when a cross-device rename fallback is triggered. Users should upgrade to v.1.2.2 or, as a workaround, apply the patch manually.\n\nPackage: python-dotenv\nInstalled: 1.1.0\nFixed in: 1.2.2\nSeverity: MEDIUM\nFix: Upgrade python-dotenv to 1.2.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-baee8b37dd27fd46", "name": "CVE-2024-47081: requests 2.32.3 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt", "shortDescription": {"text": "CVE-2024-47081: requests 2.32.3 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt"}, "fullDescription": {"text": "requests: Requests vulnerable to .netrc credentials leak via malicious URLs\n\nRequests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.\n\nPackage: requests\nInstalled: 2.32.3\nFixed in: 2.32.4\nSeverity: MEDIUM\nFix: Upgrade requests to 2.32.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2f4848150f72695b", "name": "CVE-2026-25645: requests 2.32.3 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-25645: requests 2.32.3 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt"}, "fullDescription": {"text": "requests: Requests: Security bypass due to predictable temporary file creation\n\nRequests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulner\n\nPackage: requests\nInstalled: 2.32.3\nFixed in: 2.33.0\nSeverity: MEDIUM\nFix: Upgrade requests to 2.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3cbe65dabb02179c", "name": "CVE-2026-33682: streamlit 1.44.1 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.44.1 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.44.1\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c4b2b1cb8c672815", "name": "CVE-2026-10804: streamlit 1.44.1 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.44.1 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.44.1\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-028a713c1e3b2c6c", "name": "CVE-2026-33682: streamlit 1.40.2 \u2014 rag_tutorials/contextualai_rag_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.40.2 \u2014 rag_tutorials/contextualai_rag_agent/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.40.2\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d19bd25122751719", "name": "CVE-2026-10804: streamlit 1.40.2 \u2014 rag_tutorials/contextualai_rag_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.40.2 \u2014 rag_tutorials/contextualai_rag_agent/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.40.2\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0a85762140d8c4bd", "name": "CVE-2026-45134: langchain 0.3.12 \u2014 rag_tutorials/corrective_rag/requirements.txt", "shortDescription": {"text": "CVE-2026-45134: langchain 0.3.12 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "fullDescription": {"text": "LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest\n\nPackage: langchain\nInstalled: 0.3.12\nFixed in: 0.3.30\nSeverity: HIGH\nFix: Upgrade langchain to 0.3.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2abf42730d67fe75", "name": "CVE-2026-55443: langchain 0.3.12 \u2014 rag_tutorials/corrective_rag/requirements.txt", "shortDescription": {"text": "CVE-2026-55443: langchain 0.3.12 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "fullDescription": {"text": "LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended root directory. Affected behaviors include: a file-search agent middleware that validates a starting directory but not the search pattern or the resolved target of matched files, so glob patterns and symlinks can reach files outside the configured root; prompt- \n\nPackage: langchain\nInstalled: 0.3.12\nFixed in: 1.3.9\nSeverity: MEDIUM\nFix: Upgrade langchain to 1.3.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a06608ca1836a0c6", "name": "CVE-2026-55443: langchain-anthropic 0.3.0 \u2014 rag_tutorials/corrective_rag/requirements.txt", "shortDescription": {"text": "CVE-2026-55443: langchain-anthropic 0.3.0 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "fullDescription": {"text": "LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended root directory. Affected behaviors include: a file-search agent middleware that validates a starting directory but not the search pattern or the resolved target of matched files, so glob patterns and symlinks can reach files outside the configured root; prompt- \n\nPackage: langchain-anthropic\nInstalled: 0.3.0\nFixed in: 1.4.6\nSeverity: MEDIUM\nFix: Upgrade langchain-anthropic to 1.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4841fb5b69798c8c", "name": "CVE-2025-6984: langchain-community 0.3.12 \u2014 rag_tutorials/corrective_rag/requirements.txt", "shortDescription": {"text": "CVE-2025-6984: langchain-community 0.3.12 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "fullDescription": {"text": "langchain-community: Langchain-community insecure XML parsing\n\nThe langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.\n\nPackage: langchain-community\nInstalled: 0.3.12\nFixed in: 0.3.27\nSeverity: HIGH\nFix: Upgrade langchain-community to 0.3.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ecb0ea337cb6d656", "name": "CVE-2025-68664: langchain-core 0.3.28 \u2014 rag_tutorials/corrective_rag/requirements.txt", "shortDescription": {"text": "CVE-2025-68664: langchain-core 0.3.28 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "fullDescription": {"text": "langchain-core: LangChain: Arbitrary code execution via serialization injection\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd() functions. The functions do not escape dictionaries with 'lc' keys when serializing free-form dictionaries. The 'lc' key is used internally by LangChain to mark serialized objects. When user-controlled data contains this key structure, it is treated as a legitimate LangChain object during deserialization r\n\nPackage: langchain-core\nInstalled: 0.3.28\nFixed in: 1.2.5, 0.3.81\nSeverity: CRITICAL\nFix: Upgrade langchain-core to 1.2.5, 0.3.81"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-5c829f7948e1a160", "name": "CVE-2025-65106: langchain-core 0.3.28 \u2014 rag_tutorials/corrective_rag/requirements.txt", "shortDescription": {"text": "CVE-2025-65106: langchain-core 0.3.28 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "fullDescription": {"text": "langchain-core: LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates\n\nLangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template system that allows attackers to access Python object internals through template syntax. This vulnerability affects applications that accept untrusted template strings (not just template variables) in ChatPromptTemplate and related prompt template classes. This issue has been patched in versions 0.3.8\n\nPackage: langchain-core\nInstalled: 0.3.28\nFixed in: 1.0.7, 0.3.80\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.0.7, 0.3.80"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-23e58946dd98817c", "name": "CVE-2026-34070: langchain-core 0.3.28 \u2014 rag_tutorials/corrective_rag/requirements.txt", "shortDescription": {"text": "CVE-2026-34070: langchain-core 0.3.28 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "fullDescription": {"text": "langchain: path traversal in legacy load_prompt functions in langchain-core\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path injection. When an application passes user-influenced prompt configurations to load_prompt() or load_prompt_from_config(), an attacker can read arbitrary files on the host filesystem, constrained only by file-extension chec\n\nPackage: langchain-core\nInstalled: 0.3.28\nFixed in: 1.2.22\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.2.22"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a187341b67b1e9ae", "name": "CVE-2026-44843: langchain-core 0.3.28 \u2014 rag_tutorials/corrective_rag/requirements.txt", "shortDescription": {"text": "CVE-2026-44843: langchain-core 0.3.28 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "fullDescription": {"text": "langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call load() with allowed_objects=\"all\". This does not enable arbitrary Python object deserialization, but it does allow any trusted LangChain-serializable object to be revived, which is broader than these runtime path\n\nPackage: langchain-core\nInstalled: 0.3.28\nFixed in: 1.3.3, 0.3.85\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.3.3, 0.3.85"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8cbf0bfbb205a452", "name": "CVE-2026-40087: langchain-core 0.3.28 \u2014 rag_tutorials/corrective_rag/requirements.txt", "shortDescription": {"text": "CVE-2026-40087: langchain-core 0.3.28 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "fullDescription": {"text": "langchain: incomplete f-string validation in prompt templates\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-string prompt-template validation was incomplete in two respects. First, some prompt template classes accepted f-string templates and formatted them without enforcing the same attribute-access validation as PromptTemplate. In particular, DictPromptTemplate and ImagePromptTemplate could accept templates containing attribute access or indexing expressions and subsequently evaluate t\n\nPackage: langchain-core\nInstalled: 0.3.28\nFixed in: 0.3.84, 1.2.28\nSeverity: MEDIUM\nFix: Upgrade langchain-core to 0.3.84, 1.2.28"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eb03055588e02d5c", "name": "CVE-2026-26013: langchain-core 0.3.28 \u2014 rag_tutorials/corrective_rag/requirements.txt", "shortDescription": {"text": "CVE-2026-26013: langchain-core 0.3.28 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "fullDescription": {"text": "langchain: SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side Request Forgery (SSRF) attacks by providing malicious image URLs in user input. This vulnerability is fixed in 1.2.11.\n\nPackage: langchain-core\nInstalled: 0.3.28\nFixed in: 1.2.11\nSeverity: LOW\nFix: Upgrade langchain-core to 1.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-92383730c079c89d", "name": "CVE-2026-41488: langchain-openai 0.2.14 \u2014 rag_tutorials/corrective_rag/requirements.txt", "shortDescription": {"text": "CVE-2026-41488: langchain-openai 0.2.14 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "fullDescription": {"text": "langchain-openai: Langchain-openai: Server-Side Request Forgery (SSRF) protection bypass via DNS rebinding\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size() helper (used by get_num_tokens_from_messages for image token counting) validated URLs for SSRF protection and then fetched them in a separate network operation with independent DNS resolution. This left a TOCTOU / DNS rebinding window: an attacker-controlled hostname could resolve to a public IP during validation and then to a private/localhost IP during the actual fetch.\n\nPackage: langchain-openai\nInstalled: 0.2.14\nFixed in: 1.1.14\nSeverity: LOW\nFix: Upgrade langchain-openai to 1.1.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-90d56bafffb98c2c", "name": "CVE-2026-28277: langgraph 0.2.53 \u2014 rag_tutorials/corrective_rag/requirements.txt", "shortDescription": {"text": "CVE-2026-28277: langgraph 0.2.53 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "fullDescription": {"text": "LangGraph checkpoint loading has unsafe msgpack deserialization\n\nLangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.0.9 and prior, LangGraph checkpointers can load msgpack-encoded checkpoints that reconstruct Python objects during deserialization. If an attacker can modify checkpoint data in the backing store (for example, after a database compromise or other privileged write access to the persistence layer), they can potentially supply a crafted payload that tri\n\nPackage: langgraph\nInstalled: 0.2.53\nFixed in: 1.0.10\nSeverity: MEDIUM\nFix: Upgrade langgraph to 1.0.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-73d2f93a146b7041", "name": "CVE-2026-33682: streamlit 1.41.1 \u2014 rag_tutorials/corrective_rag/requirements.txt", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.41.1 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.41.1\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-556fc9207b6f7353", "name": "CVE-2026-10804: streamlit 1.41.1 \u2014 rag_tutorials/corrective_rag/requirements.txt", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.41.1 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.41.1\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ad70eb282b028267", "name": "CVE-2025-6984: langchain-community 0.3.13 \u2014 rag_tutorials/deepseek_local_rag_agent/requirements.txt", "shortDescription": {"text": "CVE-2025-6984: langchain-community 0.3.13 \u2014 rag_tutorials/deepseek_local_rag_agent/requirements.txt"}, "fullDescription": {"text": "langchain-community: Langchain-community insecure XML parsing\n\nThe langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.\n\nPackage: langchain-community\nInstalled: 0.3.13\nFixed in: 0.3.27\nSeverity: HIGH\nFix: Upgrade langchain-community to 0.3.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-55dc2961bad3ea2a", "name": "CVE-2026-33682: streamlit 1.41.1 \u2014 rag_tutorials/deepseek_local_rag_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.41.1 \u2014 rag_tutorials/deepseek_local_rag_agent/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.41.1\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1f9582fbb6c71345", "name": "CVE-2026-10804: streamlit 1.41.1 \u2014 rag_tutorials/deepseek_local_rag_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.41.1 \u2014 rag_tutorials/deepseek_local_rag_agent/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.41.1\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f9fa1d0d8c36bb2e", "name": "CVE-2025-6984: langchain-community 0.3.13 \u2014 rag_tutorials/gemini_agentic_rag/requirements.txt", "shortDescription": {"text": "CVE-2025-6984: langchain-community 0.3.13 \u2014 rag_tutorials/gemini_agentic_rag/requirements.txt"}, "fullDescription": {"text": "langchain-community: Langchain-community insecure XML parsing\n\nThe langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.\n\nPackage: langchain-community\nInstalled: 0.3.13\nFixed in: 0.3.27\nSeverity: HIGH\nFix: Upgrade langchain-community to 0.3.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-76684795b6d49ddf", "name": "CVE-2026-33682: streamlit 1.41.1 \u2014 rag_tutorials/gemini_agentic_rag/requirements.txt", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.41.1 \u2014 rag_tutorials/gemini_agentic_rag/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.41.1\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-20bb93f1f7d80f1e", "name": "CVE-2026-10804: streamlit 1.41.1 \u2014 rag_tutorials/gemini_agentic_rag/requirements.txt", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.41.1 \u2014 rag_tutorials/gemini_agentic_rag/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.41.1\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-73248433c69e1c19", "name": "CVE-2026-49356: @babel/core 7.29.0 \u2014 rag_tutorials/multimodal_agentic_rag/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-49356: @babel/core 7.29.0 \u2014 rag_tutorials/multimodal_agentic_rag/frontend/package-lock.json"}, "fullDescription": {"text": "@babel/core: @babel/core: Arbitrary file read via sourceMappingURL comment\n\nBabel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile maliciously crafted code can allow an attacker to read any source map from the system that is running Babel, if the attacker controls the input source code, can read the output source code, and knows the path of the source map file that they want to read. This vulnerability is fixed in 8.0.0-rc.6 an\n\nPackage: @babel/core\nInstalled: 7.29.0\nFixed in: 8.0.0-rc.6, 7.29.6\nSeverity: LOW\nFix: Upgrade @babel/core to 8.0.0-rc.6, 7.29.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be0bd023b5f7bbcd", "name": "GHSA-g7r4-m6w7-qqqr: esbuild 0.27.7 \u2014 rag_tutorials/multimodal_agentic_rag/frontend/package-lock.json", "shortDescription": {"text": "GHSA-g7r4-m6w7-qqqr: esbuild 0.27.7 \u2014 rag_tutorials/multimodal_agentic_rag/frontend/package-lock.json"}, "fullDescription": {"text": "esbuild allows arbitrary file read when running the development server on Windows\n\n### Summary\n\nThe development server contains a path traversal vulnerability on Windows when serving files from `servedir`.\n\nDue to the use of `path.Clean()` (which only normalizes forward-slash `/` separators) instead of a Windows-aware path normalization function, it is possible to craft requests using backslashes (`\\`) that bypass the intended directory containment logic. An attacker can escape the configured `servedir` root and access arbitrary files on the filesystem.\nThis issue affects Wind\n\nPackage: esbuild\nInstalled: 0.27.7\nFixed in: 0.28.1\nSeverity: LOW\nFix: Upgrade esbuild to 0.28.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e5763f1e06e84d2f", "name": "CVE-2026-53571: vite 7.3.2 \u2014 rag_tutorials/multimodal_agentic_rag/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-53571: vite 7.3.2 \u2014 rag_tutorials/multimodal_agentic_rag/frontend/package-lock.json"}, "fullDescription": {"text": "vite: `server.fs.deny` bypass on Windows alternate paths\n\nVite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite\u2019s dev server denies direct access to sensitive files through server.fs.deny, including entries such as .env, .env.*, and *.{crt,pem}. However, on Windows, the deny logic does not correctly normalize NTFS ADS path forms before access checks are applied. Because of this, requests such as /.env::$DATA?raw a\n\nPackage: vite\nInstalled: 7.3.2\nFixed in: 8.0.16, 7.3.5, 6.4.3\nSeverity: HIGH\nFix: Upgrade vite to 8.0.16, 7.3.5, 6.4.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7e8de1f0a3dc4fb5", "name": "CVE-2026-53632: vite 7.3.2 \u2014 rag_tutorials/multimodal_agentic_rag/frontend/package-lock.json", "shortDescription": {"text": "CVE-2026-53632: vite 7.3.2 \u2014 rag_tutorials/multimodal_agentic_rag/frontend/package-lock.json"}, "fullDescription": {"text": "launch-editor: launch-editor: Credential compromise via NTLMv2 password hash leak through UNC path access\n\nlaunch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user\u2019s NTLMv2 password hash to be leaked to an attacker-controlled SMB server. This can result in credential compromise through offline hash cracking. This vulnerability is fixed in 2.14.1.\n\nPackage: vite\nInstalled: 7.3.2\nFixed in: 8.0.16, 7.3.5, 6.4.3\nSeverity: MEDIUM\nFix: Upgrade vite to 8.0.16, 7.3.5, 6.4.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c80187d503672659", "name": "CVE-2026-45134: langchain 0.3.12 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt", "shortDescription": {"text": "CVE-2026-45134: langchain 0.3.12 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "fullDescription": {"text": "LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest\n\nPackage: langchain\nInstalled: 0.3.12\nFixed in: 0.3.30\nSeverity: HIGH\nFix: Upgrade langchain to 0.3.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d3e1c44e1c96cd5a", "name": "CVE-2026-55443: langchain 0.3.12 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt", "shortDescription": {"text": "CVE-2026-55443: langchain 0.3.12 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "fullDescription": {"text": "LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended root directory. Affected behaviors include: a file-search agent middleware that validates a starting directory but not the search pattern or the resolved target of matched files, so glob patterns and symlinks can reach files outside the configured root; prompt- \n\nPackage: langchain\nInstalled: 0.3.12\nFixed in: 1.3.9\nSeverity: MEDIUM\nFix: Upgrade langchain to 1.3.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c7d585f501f0d6d7", "name": "CVE-2025-6984: langchain-community 0.3.12 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt", "shortDescription": {"text": "CVE-2025-6984: langchain-community 0.3.12 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "fullDescription": {"text": "langchain-community: Langchain-community insecure XML parsing\n\nThe langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.\n\nPackage: langchain-community\nInstalled: 0.3.12\nFixed in: 0.3.27\nSeverity: HIGH\nFix: Upgrade langchain-community to 0.3.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-71bd658d01e091bc", "name": "CVE-2025-68664: langchain-core 0.3.25 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt", "shortDescription": {"text": "CVE-2025-68664: langchain-core 0.3.25 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "fullDescription": {"text": "langchain-core: LangChain: Arbitrary code execution via serialization injection\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd() functions. The functions do not escape dictionaries with 'lc' keys when serializing free-form dictionaries. The 'lc' key is used internally by LangChain to mark serialized objects. When user-controlled data contains this key structure, it is treated as a legitimate LangChain object during deserialization r\n\nPackage: langchain-core\nInstalled: 0.3.25\nFixed in: 1.2.5, 0.3.81\nSeverity: CRITICAL\nFix: Upgrade langchain-core to 1.2.5, 0.3.81"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-044c4cbca4db85f3", "name": "CVE-2025-65106: langchain-core 0.3.25 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt", "shortDescription": {"text": "CVE-2025-65106: langchain-core 0.3.25 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "fullDescription": {"text": "langchain-core: LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates\n\nLangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template system that allows attackers to access Python object internals through template syntax. This vulnerability affects applications that accept untrusted template strings (not just template variables) in ChatPromptTemplate and related prompt template classes. This issue has been patched in versions 0.3.8\n\nPackage: langchain-core\nInstalled: 0.3.25\nFixed in: 1.0.7, 0.3.80\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.0.7, 0.3.80"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e77897ff5c53b223", "name": "CVE-2026-34070: langchain-core 0.3.25 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt", "shortDescription": {"text": "CVE-2026-34070: langchain-core 0.3.25 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "fullDescription": {"text": "langchain: path traversal in legacy load_prompt functions in langchain-core\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path injection. When an application passes user-influenced prompt configurations to load_prompt() or load_prompt_from_config(), an attacker can read arbitrary files on the host filesystem, constrained only by file-extension chec\n\nPackage: langchain-core\nInstalled: 0.3.25\nFixed in: 1.2.22\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.2.22"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a0b495d2d74f9086", "name": "CVE-2026-44843: langchain-core 0.3.25 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt", "shortDescription": {"text": "CVE-2026-44843: langchain-core 0.3.25 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "fullDescription": {"text": "langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call load() with allowed_objects=\"all\". This does not enable arbitrary Python object deserialization, but it does allow any trusted LangChain-serializable object to be revived, which is broader than these runtime path\n\nPackage: langchain-core\nInstalled: 0.3.25\nFixed in: 1.3.3, 0.3.85\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.3.3, 0.3.85"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-54688a30e3eed570", "name": "CVE-2026-40087: langchain-core 0.3.25 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt", "shortDescription": {"text": "CVE-2026-40087: langchain-core 0.3.25 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "fullDescription": {"text": "langchain: incomplete f-string validation in prompt templates\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-string prompt-template validation was incomplete in two respects. First, some prompt template classes accepted f-string templates and formatted them without enforcing the same attribute-access validation as PromptTemplate. In particular, DictPromptTemplate and ImagePromptTemplate could accept templates containing attribute access or indexing expressions and subsequently evaluate t\n\nPackage: langchain-core\nInstalled: 0.3.25\nFixed in: 0.3.84, 1.2.28\nSeverity: MEDIUM\nFix: Upgrade langchain-core to 0.3.84, 1.2.28"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dc62b242bbeabc38", "name": "CVE-2026-26013: langchain-core 0.3.25 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt", "shortDescription": {"text": "CVE-2026-26013: langchain-core 0.3.25 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "fullDescription": {"text": "langchain: SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side Request Forgery (SSRF) attacks by providing malicious image URLs in user input. This vulnerability is fixed in 1.2.11.\n\nPackage: langchain-core\nInstalled: 0.3.25\nFixed in: 1.2.11\nSeverity: LOW\nFix: Upgrade langchain-core to 1.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1dee694b79363a57", "name": "CVE-2026-28277: langgraph 0.2.53 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt", "shortDescription": {"text": "CVE-2026-28277: langgraph 0.2.53 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "fullDescription": {"text": "LangGraph checkpoint loading has unsafe msgpack deserialization\n\nLangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.0.9 and prior, LangGraph checkpointers can load msgpack-encoded checkpoints that reconstruct Python objects during deserialization. If an attacker can modify checkpoint data in the backing store (for example, after a database compromise or other privileged write access to the persistence layer), they can potentially supply a crafted payload that tri\n\nPackage: langgraph\nInstalled: 0.2.53\nFixed in: 1.0.10\nSeverity: MEDIUM\nFix: Upgrade langgraph to 1.0.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-044fa0ada09ca62a", "name": "CVE-2026-33682: streamlit 1.40.2 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.40.2 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.40.2\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6ce328fcd4edd599", "name": "CVE-2026-10804: streamlit 1.40.2 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.40.2 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.40.2\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dd3258de198264df", "name": "CVE-2026-45134: langchain 0.3.12 \u2014 rag_tutorials/rag_database_routing/requirements.txt", "shortDescription": {"text": "CVE-2026-45134: langchain 0.3.12 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "fullDescription": {"text": "LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nLangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest\n\nPackage: langchain\nInstalled: 0.3.12\nFixed in: 0.3.30\nSeverity: HIGH\nFix: Upgrade langchain to 0.3.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-41028822093a78ec", "name": "CVE-2026-55443: langchain 0.3.12 \u2014 rag_tutorials/rag_database_routing/requirements.txt", "shortDescription": {"text": "CVE-2026-55443: langchain 0.3.12 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "fullDescription": {"text": "LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended root directory. Affected behaviors include: a file-search agent middleware that validates a starting directory but not the search pattern or the resolved target of matched files, so glob patterns and symlinks can reach files outside the configured root; prompt- \n\nPackage: langchain\nInstalled: 0.3.12\nFixed in: 1.3.9\nSeverity: MEDIUM\nFix: Upgrade langchain to 1.3.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a106ef367caaa98a", "name": "CVE-2025-6984: langchain-community 0.3.12 \u2014 rag_tutorials/rag_database_routing/requirements.txt", "shortDescription": {"text": "CVE-2025-6984: langchain-community 0.3.12 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "fullDescription": {"text": "langchain-community: Langchain-community insecure XML parsing\n\nThe langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.\n\nPackage: langchain-community\nInstalled: 0.3.12\nFixed in: 0.3.27\nSeverity: HIGH\nFix: Upgrade langchain-community to 0.3.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e009a0109531c29c", "name": "CVE-2025-68664: langchain-core 0.3.28 \u2014 rag_tutorials/rag_database_routing/requirements.txt", "shortDescription": {"text": "CVE-2025-68664: langchain-core 0.3.28 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "fullDescription": {"text": "langchain-core: LangChain: Arbitrary code execution via serialization injection\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd() functions. The functions do not escape dictionaries with 'lc' keys when serializing free-form dictionaries. The 'lc' key is used internally by LangChain to mark serialized objects. When user-controlled data contains this key structure, it is treated as a legitimate LangChain object during deserialization r\n\nPackage: langchain-core\nInstalled: 0.3.28\nFixed in: 1.2.5, 0.3.81\nSeverity: CRITICAL\nFix: Upgrade langchain-core to 1.2.5, 0.3.81"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-5f4a3369e55beaa3", "name": "CVE-2025-65106: langchain-core 0.3.28 \u2014 rag_tutorials/rag_database_routing/requirements.txt", "shortDescription": {"text": "CVE-2025-65106: langchain-core 0.3.28 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "fullDescription": {"text": "langchain-core: LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates\n\nLangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template system that allows attackers to access Python object internals through template syntax. This vulnerability affects applications that accept untrusted template strings (not just template variables) in ChatPromptTemplate and related prompt template classes. This issue has been patched in versions 0.3.8\n\nPackage: langchain-core\nInstalled: 0.3.28\nFixed in: 1.0.7, 0.3.80\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.0.7, 0.3.80"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-128154cb6c002e60", "name": "CVE-2026-34070: langchain-core 0.3.28 \u2014 rag_tutorials/rag_database_routing/requirements.txt", "shortDescription": {"text": "CVE-2026-34070: langchain-core 0.3.28 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "fullDescription": {"text": "langchain: path traversal in legacy load_prompt functions in langchain-core\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path injection. When an application passes user-influenced prompt configurations to load_prompt() or load_prompt_from_config(), an attacker can read arbitrary files on the host filesystem, constrained only by file-extension chec\n\nPackage: langchain-core\nInstalled: 0.3.28\nFixed in: 1.2.22\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.2.22"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d8a8f9d61b6fd1c8", "name": "CVE-2026-44843: langchain-core 0.3.28 \u2014 rag_tutorials/rag_database_routing/requirements.txt", "shortDescription": {"text": "CVE-2026-44843: langchain-core 0.3.28 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "fullDescription": {"text": "langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call load() with allowed_objects=\"all\". This does not enable arbitrary Python object deserialization, but it does allow any trusted LangChain-serializable object to be revived, which is broader than these runtime path\n\nPackage: langchain-core\nInstalled: 0.3.28\nFixed in: 1.3.3, 0.3.85\nSeverity: HIGH\nFix: Upgrade langchain-core to 1.3.3, 0.3.85"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-728f207e52b5ecdb", "name": "CVE-2026-40087: langchain-core 0.3.28 \u2014 rag_tutorials/rag_database_routing/requirements.txt", "shortDescription": {"text": "CVE-2026-40087: langchain-core 0.3.28 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "fullDescription": {"text": "langchain: incomplete f-string validation in prompt templates\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-string prompt-template validation was incomplete in two respects. First, some prompt template classes accepted f-string templates and formatted them without enforcing the same attribute-access validation as PromptTemplate. In particular, DictPromptTemplate and ImagePromptTemplate could accept templates containing attribute access or indexing expressions and subsequently evaluate t\n\nPackage: langchain-core\nInstalled: 0.3.28\nFixed in: 0.3.84, 1.2.28\nSeverity: MEDIUM\nFix: Upgrade langchain-core to 0.3.84, 1.2.28"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-41237beb7fafa1ea", "name": "CVE-2026-26013: langchain-core 0.3.28 \u2014 rag_tutorials/rag_database_routing/requirements.txt", "shortDescription": {"text": "CVE-2026-26013: langchain-core 0.3.28 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "fullDescription": {"text": "langchain: SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side Request Forgery (SSRF) attacks by providing malicious image URLs in user input. This vulnerability is fixed in 1.2.11.\n\nPackage: langchain-core\nInstalled: 0.3.28\nFixed in: 1.2.11\nSeverity: LOW\nFix: Upgrade langchain-core to 1.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b00a7c58db8f3d87", "name": "CVE-2026-41488: langchain-openai 0.2.14 \u2014 rag_tutorials/rag_database_routing/requirements.txt", "shortDescription": {"text": "CVE-2026-41488: langchain-openai 0.2.14 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "fullDescription": {"text": "langchain-openai: Langchain-openai: Server-Side Request Forgery (SSRF) protection bypass via DNS rebinding\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size() helper (used by get_num_tokens_from_messages for image token counting) validated URLs for SSRF protection and then fetched them in a separate network operation with independent DNS resolution. This left a TOCTOU / DNS rebinding window: an attacker-controlled hostname could resolve to a public IP during validation and then to a private/localhost IP during the actual fetch.\n\nPackage: langchain-openai\nInstalled: 0.2.14\nFixed in: 1.1.14\nSeverity: LOW\nFix: Upgrade langchain-openai to 1.1.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ade24ce6477e7a42", "name": "CVE-2026-28277: langgraph 0.2.53 \u2014 rag_tutorials/rag_database_routing/requirements.txt", "shortDescription": {"text": "CVE-2026-28277: langgraph 0.2.53 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "fullDescription": {"text": "LangGraph checkpoint loading has unsafe msgpack deserialization\n\nLangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.0.9 and prior, LangGraph checkpointers can load msgpack-encoded checkpoints that reconstruct Python objects during deserialization. If an attacker can modify checkpoint data in the backing store (for example, after a database compromise or other privileged write access to the persistence layer), they can potentially supply a crafted payload that tri\n\nPackage: langgraph\nInstalled: 0.2.53\nFixed in: 1.0.10\nSeverity: MEDIUM\nFix: Upgrade langgraph to 1.0.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b84fec6e04ecbd70", "name": "CVE-2026-25990: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-25990: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image\n\nPillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.1.1\nSeverity: HIGH\nFix: Upgrade pillow to 12.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9ccf9c4795d48007", "name": "CVE-2026-40192: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-40192: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing\n\nPillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.2.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-566543b094f7afba", "name": "CVE-2026-42311: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-42311: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing\n\nPillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.2.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b063e0a74070afc7", "name": "CVE-2026-54058: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-54058: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image\n\nPillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ee68a691fb69b747", "name": "CVE-2026-54059: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-54059: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted PCF font data\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f966c3a326f35dbd", "name": "CVE-2026-54060: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-54060: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(\"1\", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ca976ffffa09ed88", "name": "CVE-2026-55379: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-55379: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted BDF font file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b26ddb37009f7229", "name": "CVE-2026-55380: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-55380: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted GD 2.x image file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c71ab73de60f94f2", "name": "CVE-2026-59197: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-59197: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Native heap out-of-bounds write\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-056ff754b495f044", "name": "CVE-2026-59199: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-59199: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via out-of-bounds write in image processing\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d25d42a50249f16a", "name": "CVE-2026-59200: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-59200: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of service via crafted PDF stream\n\nPillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0775a3d0d9ae391f", "name": "CVE-2026-59204: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-59204: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via crafted JPEG2000 image\n\nPillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a89b009f459c6893", "name": "CVE-2026-59205: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-59205: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cba3103613a8f0d0", "name": "CVE-2026-42308: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-42308: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: python: Pillow: Denial of Service via integer overflow in font processing\n\nPillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b5fd46d5ec8915f5", "name": "CVE-2026-42310: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-42310: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via malicious PDF processing\n\nPillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aa6c4ed8e3ea2302", "name": "CVE-2026-55798: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-55798: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Arbitrary command injection via shell metacharacters in file paths\n\nPillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cc3f0f04aaafed5a", "name": "CVE-2026-59198: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-59198: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Information disclosure via TGA RLE encoder out-of-bounds read\n\nPillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 11.1.0\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f27554fc1ed50399", "name": "CVE-2026-33682: streamlit 1.44.1 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.44.1 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.44.1\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f184a96da9b8a0a2", "name": "CVE-2026-10804: streamlit 1.44.1 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.44.1 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.44.1\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a315cc20f6b90517", "name": "CVE-2026-33682: streamlit 1.41.1 \u2014 starter_ai_agents/ai_data_analysis_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.41.1 \u2014 starter_ai_agents/ai_data_analysis_agent/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.41.1\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4b7be45732420fdf", "name": "CVE-2026-10804: streamlit 1.41.1 \u2014 starter_ai_agents/ai_data_analysis_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.41.1 \u2014 starter_ai_agents/ai_data_analysis_agent/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.41.1\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be64002deca969c0", "name": "CVE-2026-25990: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-25990: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "fullDescription": {"text": "pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image\n\nPillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.\n\nPackage: Pillow\nInstalled: 10.4.0\nFixed in: 12.1.1\nSeverity: HIGH\nFix: Upgrade Pillow to 12.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4a7ffe9e14e8f6ce", "name": "CVE-2026-40192: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-40192: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing\n\nPillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.\n\nPackage: Pillow\nInstalled: 10.4.0\nFixed in: 12.2.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eb376a1bd95bc207", "name": "CVE-2026-42311: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-42311: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing\n\nPillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.\n\nPackage: Pillow\nInstalled: 10.4.0\nFixed in: 12.2.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e20cd4880e31a6ad", "name": "CVE-2026-54058: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-54058: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image\n\nPillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.4.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-87cbb2446bb5cf68", "name": "CVE-2026-54059: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-54059: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted PCF font data\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.4.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cdf72b4cb8dfa33b", "name": "CVE-2026-54060: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-54060: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(\"1\", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.4.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-42d91a848a8007c9", "name": "CVE-2026-55379: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-55379: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted BDF font file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.4.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0f6f8754368ca5bb", "name": "CVE-2026-55380: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-55380: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted GD 2.x image file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.4.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-95c45aa6ec6a4c0a", "name": "CVE-2026-59197: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-59197: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Native heap out-of-bounds write\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.4.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6fb524501403d8a0", "name": "CVE-2026-59199: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-59199: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via out-of-bounds write in image processing\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.4.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-50ddbe77500ea919", "name": "CVE-2026-59200: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-59200: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of service via crafted PDF stream\n\nPillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.4.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-263f336633c6bc4b", "name": "CVE-2026-59204: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-59204: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via crafted JPEG2000 image\n\nPillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.4.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1a7a62cf2aba602c", "name": "CVE-2026-59205: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-59205: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.4.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6c3b2915f7bb2e3f", "name": "CVE-2026-42308: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-42308: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: python: Pillow: Denial of Service via integer overflow in font processing\n\nPillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.\n\nPackage: Pillow\nInstalled: 10.4.0\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade Pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-697bd035e7c634e2", "name": "CVE-2026-42310: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-42310: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via malicious PDF processing\n\nPillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.\n\nPackage: Pillow\nInstalled: 10.4.0\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade Pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e0799d41925203c", "name": "CVE-2026-55798: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-55798: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Arbitrary command injection via shell metacharacters in file paths\n\nPillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.4.0\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3e9ebd415b1ee270", "name": "CVE-2026-59198: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-59198: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Information disclosure via TGA RLE encoder out-of-bounds read\n\nPillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.4.0\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9a46ed01e516b553", "name": "CVE-2023-50447: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2023-50447: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "pillow: Arbitrary Code Execution via the environment parameter\n\nPillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).\n\nPackage: Pillow\nInstalled: 10.0.0\nFixed in: 10.2.0\nSeverity: CRITICAL\nFix: Upgrade Pillow to 10.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-ecb128c487b08ce8", "name": "CVE-2023-4863: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2023-4863: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "libwebp: Heap buffer overflow in WebP Codec\n\nHeap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)\n\nPackage: Pillow\nInstalled: 10.0.0\nFixed in: 10.0.1\nSeverity: HIGH\nFix: Upgrade Pillow to 10.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bcda5eee34d17507", "name": "CVE-2024-28219: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2024-28219: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: buffer overflow in _imagingcms.c\n\nIn _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.\n\nPackage: Pillow\nInstalled: 10.0.0\nFixed in: 10.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 10.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-69c345f05864dac2", "name": "CVE-2026-54058: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-54058: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image\n\nPillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-75ef2cec54078611", "name": "CVE-2026-54059: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-54059: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted PCF font data\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-daf9c301aa069472", "name": "CVE-2026-54060: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-54060: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(\"1\", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-17cf5a5cbcc29410", "name": "CVE-2026-55379: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-55379: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted BDF font file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-37dc457dbfce119e", "name": "CVE-2026-55380: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-55380: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted GD 2.x image file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-35eb9d21246003bc", "name": "CVE-2026-59197: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-59197: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Native heap out-of-bounds write\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7cec6be97549d94d", "name": "CVE-2026-59199: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-59199: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via out-of-bounds write in image processing\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1d5603a2f3f9459a", "name": "CVE-2026-59200: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-59200: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of service via crafted PDF stream\n\nPillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3618bc13a322a601", "name": "CVE-2026-59204: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-59204: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via crafted JPEG2000 image\n\nPillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7be48508a1b3254b", "name": "CVE-2026-59205: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-59205: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-177c5ca8fa4e240a", "name": "CVE-2026-42308: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-42308: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: python: Pillow: Denial of Service via integer overflow in font processing\n\nPillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.\n\nPackage: Pillow\nInstalled: 10.0.0\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade Pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7a0f2e5a6e45c946", "name": "CVE-2026-42310: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-42310: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via malicious PDF processing\n\nPillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.\n\nPackage: Pillow\nInstalled: 10.0.0\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade Pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8c038172829226bd", "name": "CVE-2026-55798: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-55798: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "python-pillow: Pillow: Arbitrary command injection via shell metacharacters in file paths\n\nPillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.0.0\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2801d34288aa337d", "name": "CVE-2026-59198: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-59198: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "Pillow: Pillow: Information disclosure via TGA RLE encoder out-of-bounds read\n\nPillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.\n\nPackage: Pillow\nInstalled: 10.0.0\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade Pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fa6415a2f9898168", "name": "CVE-2026-33682: streamlit 1.40.2 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.40.2 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.40.2\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-086c3cbbf7180871", "name": "CVE-2026-10804: streamlit 1.40.2 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.40.2 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.40.2\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50ffa3ccc5778840", "name": "CVE-2025-47241: browser-use 0.1.26 \u2014 starter_ai_agents/ai_meme_generator_agent_browseruse/requirements.txt", "shortDescription": {"text": "CVE-2025-47241: browser-use 0.1.26 \u2014 starter_ai_agents/ai_meme_generator_agent_browseruse/requirements.txt"}, "fullDescription": {"text": "Browser Use allows bypassing `allowed_domains` by putting a decoy domain in http auth username portion of a URL\n\nIn browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.\n\nPackage: browser-use\nInstalled: 0.1.26\nFixed in: 0.1.45\nSeverity: CRITICAL\nFix: Upgrade browser-use to 0.1.45"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-f9514c12492c75b2", "name": "CVE-2024-47081: Requests 2.32.3 \u2014 starter_ai_agents/ai_music_generator_agent/requirements.txt", "shortDescription": {"text": "CVE-2024-47081: Requests 2.32.3 \u2014 starter_ai_agents/ai_music_generator_agent/requirements.txt"}, "fullDescription": {"text": "requests: Requests vulnerable to .netrc credentials leak via malicious URLs\n\nRequests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.\n\nPackage: Requests\nInstalled: 2.32.3\nFixed in: 2.32.4\nSeverity: MEDIUM\nFix: Upgrade Requests to 2.32.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-26d86af34b4291bf", "name": "CVE-2026-25645: Requests 2.32.3 \u2014 starter_ai_agents/ai_music_generator_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-25645: Requests 2.32.3 \u2014 starter_ai_agents/ai_music_generator_agent/requirements.txt"}, "fullDescription": {"text": "requests: Requests: Security bypass due to predictable temporary file creation\n\nRequests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulner\n\nPackage: Requests\nInstalled: 2.32.3\nFixed in: 2.33.0\nSeverity: MEDIUM\nFix: Upgrade Requests to 2.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bec541e27cf2c78c", "name": "CVE-2026-33682: streamlit 1.44.1 \u2014 starter_ai_agents/ai_music_generator_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.44.1 \u2014 starter_ai_agents/ai_music_generator_agent/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.44.1\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cfc0037fe907b69c", "name": "CVE-2026-10804: streamlit 1.44.1 \u2014 starter_ai_agents/ai_music_generator_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.44.1 \u2014 starter_ai_agents/ai_music_generator_agent/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.44.1\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3e4be090e8dc43fd", "name": "CVE-2026-49825: lxml_html_clean 0.4.1 \u2014 starter_ai_agents/ai_startup_trend_analysis_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-49825: lxml_html_clean 0.4.1 \u2014 starter_ai_agents/ai_startup_trend_analysis_agent/requirements.txt"}, "fullDescription": {"text": "`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes\n\n# `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (`xlink:href`)\n\n**Reporter:** Guillem Lefait <guillem@datamq.com> \u00b7 **Date:** 2026-05-10\n**Affected:** `lxml` \u2264 6.1.0 and `lxml_html_clean` \u2264 0.4.4 (latest stable)\n**Confirmed against:** lxml 6.1.0 + lxml_html_clean 0.4.4 on Python 3.13.5, 3.14.4, and 3.15.0a8 (libxml2 2.14.6 / 2.9.14 \u2014 bug is in pure-Python sanitizer logic, independent of the libxml2 backend)\n**Root-cause class:** same as CVE-2021-28957\n\nPackage: lxml_html_clean\nInstalled: 0.4.1\nFixed in: 0.4.5\nSeverity: HIGH\nFix: Upgrade lxml_html_clean to 0.4.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4d17463603288f86", "name": "CVE-2026-28348: lxml_html_clean 0.4.1 \u2014 starter_ai_agents/ai_startup_trend_analysis_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-28348: lxml_html_clean 0.4.1 \u2014 starter_ai_agents/ai_startup_trend_analysis_agent/requirements.txt"}, "fullDescription": {"text": "lxml_html_clean is a project for HTML cleaning functionalities copied  ...\n\nlxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the _has_sneaky_javascript() method strips backslashes before checking for dangerous CSS keywords. This causes CSS Unicode escape sequences to bypass the @import and expression() filters, allowing external CSS loading or XSS in older browsers. This issue has been patched in version 0.4.4.\n\nPackage: lxml_html_clean\nInstalled: 0.4.1\nFixed in: 0.4.4\nSeverity: MEDIUM\nFix: Upgrade lxml_html_clean to 0.4.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0eace0482081f955", "name": "CVE-2026-28350: lxml_html_clean 0.4.1 \u2014 starter_ai_agents/ai_startup_trend_analysis_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-28350: lxml_html_clean 0.4.1 \u2014 starter_ai_agents/ai_startup_trend_analysis_agent/requirements.txt"}, "fullDescription": {"text": "lxml_html_clean is a project for HTML cleaning functionalities copied  ...\n\nlxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the <base> tag passes through the default Cleaner configuration. While page_structure=True removes html, head, and title tags, there is no specific handling for <base>, allowing an attacker to inject it and hijack relative links on the page. This issue has been patched in version 0.4.4.\n\nPackage: lxml_html_clean\nInstalled: 0.4.1\nFixed in: 0.4.4\nSeverity: MEDIUM\nFix: Upgrade lxml_html_clean to 0.4.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-94671a265290be2c", "name": "CVE-2026-33682: streamlit 1.40.2 \u2014 starter_ai_agents/ai_startup_trend_analysis_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.40.2 \u2014 starter_ai_agents/ai_startup_trend_analysis_agent/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.40.2\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-31786e3ca25810a0", "name": "CVE-2026-10804: streamlit 1.40.2 \u2014 starter_ai_agents/ai_startup_trend_analysis_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.40.2 \u2014 starter_ai_agents/ai_startup_trend_analysis_agent/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.40.2\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-00b68e0977411b0a", "name": "CVE-2026-33682: streamlit 1.40.2 \u2014 starter_ai_agents/multimodal_ai_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.40.2 \u2014 starter_ai_agents/multimodal_ai_agent/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.40.2\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8bec9abb4ff675ea", "name": "CVE-2026-10804: streamlit 1.40.2 \u2014 starter_ai_agents/multimodal_ai_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.40.2 \u2014 starter_ai_agents/multimodal_ai_agent/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.40.2\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-24e50370336732b7", "name": "CVE-2026-28684: python-dotenv 1.0.1 \u2014 voice_ai_agents/ai_audio_tour_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-28684: python-dotenv 1.0.1 \u2014 voice_ai_agents/ai_audio_tour_agent/requirements.txt"}, "fullDescription": {"text": "python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following\n\npython-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when a cross-device rename fallback is triggered. Users should upgrade to v.1.2.2 or, as a workaround, apply the patch manually.\n\nPackage: python-dotenv\nInstalled: 1.0.1\nFixed in: 1.2.2\nSeverity: MEDIUM\nFix: Upgrade python-dotenv to 1.2.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0ca870d181070bd1", "name": "CVE-2026-33682: streamlit 1.43.2 \u2014 voice_ai_agents/ai_audio_tour_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.43.2 \u2014 voice_ai_agents/ai_audio_tour_agent/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.43.2\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9fa8c450417ce0a8", "name": "CVE-2026-10804: streamlit 1.43.2 \u2014 voice_ai_agents/ai_audio_tour_agent/requirements.txt", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.43.2 \u2014 voice_ai_agents/ai_audio_tour_agent/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.43.2\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-73be0e5ba6f6a888", "name": "CVE-2026-55443: langchain 1.0.3 \u2014 voice_ai_agents/voice_rag_openaisdk/requirements.txt", "shortDescription": {"text": "CVE-2026-55443: langchain 1.0.3 \u2014 voice_ai_agents/voice_rag_openaisdk/requirements.txt"}, "fullDescription": {"text": "LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended root directory. Affected behaviors include: a file-search agent middleware that validates a starting directory but not the search pattern or the resolved target of matched files, so glob patterns and symlinks can reach files outside the configured root; prompt- \n\nPackage: langchain\nInstalled: 1.0.3\nFixed in: 1.3.9\nSeverity: MEDIUM\nFix: Upgrade langchain to 1.3.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9aebeeac2dd6a742", "name": "CVE-2026-41488: langchain-openai 1.0.2 \u2014 voice_ai_agents/voice_rag_openaisdk/requirements.txt", "shortDescription": {"text": "CVE-2026-41488: langchain-openai 1.0.2 \u2014 voice_ai_agents/voice_rag_openaisdk/requirements.txt"}, "fullDescription": {"text": "langchain-openai: Langchain-openai: Server-Side Request Forgery (SSRF) protection bypass via DNS rebinding\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size() helper (used by get_num_tokens_from_messages for image token counting) validated URLs for SSRF protection and then fetched them in a separate network operation with independent DNS resolution. This left a TOCTOU / DNS rebinding window: an attacker-controlled hostname could resolve to a public IP during validation and then to a private/localhost IP during the actual fetch.\n\nPackage: langchain-openai\nInstalled: 1.0.2\nFixed in: 1.1.14\nSeverity: LOW\nFix: Upgrade langchain-openai to 1.1.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a554fac8520e9d28", "name": "CVE-2026-41481: langchain-text-splitters 1.0.0 \u2014 voice_ai_agents/voice_rag_openaisdk/requirements.txt", "shortDescription": {"text": "CVE-2026-41481: langchain-text-splitters 1.0.0 \u2014 voice_ai_agents/voice_rag_openaisdk/requirements.txt"}, "fullDescription": {"text": "langchain-text-splitters: LangChain: Information Disclosure via Server-Side Request Forgery (SSRF) Redirect Bypass\n\nLangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters\n 1.1.2, HTMLHeaderTextSplitter.split_text_from_url() validated the initial URL using validate_safe_url() but then performed the fetch with requests.get() with redirects enabled (the default). Because redirect targets were not revalidated, a URL pointing to an attacker-controlled server could redirect to internal, localhost, or cloud metadata endpoints, bypassing SSRF protections. The resp\n\nPackage: langchain-text-splitters\nInstalled: 1.0.0\nFixed in: 1.1.2\nSeverity: MEDIUM\nFix: Upgrade langchain-text-splitters to 1.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f0e87a3bb4d98a32", "name": "CVE-2026-33682: streamlit 1.51.0 \u2014 voice_ai_agents/voice_rag_openaisdk/requirements.txt", "shortDescription": {"text": "CVE-2026-33682: streamlit 1.51.0 \u2014 voice_ai_agents/voice_rag_openaisdk/requirements.txt"}, "fullDescription": {"text": "Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)\n\nStreamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Wi\n\nPackage: streamlit\nInstalled: 1.51.0\nFixed in: 1.54.0\nSeverity: MEDIUM\nFix: Upgrade streamlit to 1.54.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2305c18156848004", "name": "CVE-2026-10804: streamlit 1.51.0 \u2014 voice_ai_agents/voice_rag_openaisdk/requirements.txt", "shortDescription": {"text": "CVE-2026-10804: streamlit 1.51.0 \u2014 voice_ai_agents/voice_rag_openaisdk/requirements.txt"}, "fullDescription": {"text": "streamlit: Streamlit: Weak hash usage leading to low integrity and availability impact\n\nA vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.\n\nPackage: streamlit\nInstalled: 1.51.0\nFixed in: 1.53.1\nSeverity: LOW\nFix: Upgrade streamlit to 1.53.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8938d771197d84ac", "name": "DS-0002: Image user should not be 'root' \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-839e962f2f1ffccc", "name": "DS-0026: No HEALTHCHECK defined \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/D", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b21aca1308f11221", "name": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/ai-deep-research-agent/Dockerfile", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/ai-deep-research-agent/Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: generative_ui_agents/ai-deep-research-agent/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-081a48a6697b6153", "name": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/ai-deep-research-agent/Dockerfile", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/ai-deep-research-agent/Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: generative_ui_agents/ai-deep-research-agent/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5bf9d24cc015f39e", "name": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/ai-financial-coach-agent/Dockerfile", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/ai-financial-coach-agent/Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: generative_ui_agents/ai-financial-coach-agent/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-31f7c4a60d8e456d", "name": "DS-0013: 'RUN cd ...' to change directory \u2014 generative_ui_agents/ai-financial-coach-agent/Dockerfile", "shortDescription": {"text": "DS-0013: 'RUN cd ...' to change directory \u2014 generative_ui_agents/ai-financial-coach-agent/Dockerfile"}, "fullDescription": {"text": "'RUN cd ...' to change directory\n\nRUN should not be used to change directory: 'cd agent && uv pip install --system -e .'. Use 'WORKDIR' statement instead.\n\nRule: DS-0013\nSeverity: MEDIUM\nTarget: generative_ui_agents/ai-financial-coach-agent/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-91906d0e116a5960", "name": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/ai-financial-coach-agent/Dockerfile", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/ai-financial-coach-agent/Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: generative_ui_agents/ai-financial-coach-agent/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac9f1191b5ce66ac", "name": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/ai-financial-coach-agent/docker/Dockerfile.agent", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/ai-financial-coach-agent/docker/Dockerfile.agent"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: generative_ui_agents/ai-financial-coach-agent/docker/Dockerfile.agent"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-26be52808012d0c5", "name": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/ai-financial-coach-agent/docker/Dockerfile.agent", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/ai-financial-coach-agent/docker/Dockerfile.agent"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: generative_ui_agents/ai-financial-coach-agent/docker/Dockerfile.agent"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fa0975fc495021a4", "name": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/ai-financial-coach-agent/docker/Dockerfile.app", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/ai-financial-coach-agent/docker/Dockerfile.app"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: generative_ui_agents/ai-financial-coach-agent/docker/Dockerfile.app"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-507e4e17ddb45104", "name": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/ai-mcp-app-builder/Dockerfile", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/ai-mcp-app-builder/Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: generative_ui_agents/ai-mcp-app-builder/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b6d057d4af9502ec", "name": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/generative-ui-starter-project/Dockerfile", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/generative-ui-starter-project/Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: generative_ui_agents/generative-ui-starter-project/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c48646794ac03091", "name": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/generative-ui-starter-project/Dockerfile", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/generative-ui-starter-project/Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: generative_ui_agents/generative-ui-starter-project/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea7fc5d12b158d6d", "name": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/generative-ui-starter-project/docker/Dockerfile.agent", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/generative-ui-starter-project/docker/Dockerfile.agent"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: generative_ui_agents/generative-ui-starter-project/docker/Dockerfile.agent"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1cf4323a20789861", "name": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/generative-ui-starter-project/docker/Dockerfile.agent", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/generative-ui-starter-project/docker/Dockerfile.agent"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: generative_ui_agents/generative-ui-starter-project/docker/Dockerfile.agent"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-198bc87686f1287c", "name": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/generative-ui-starter-project/docker/Dockerfile.app", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/generative-ui-starter-project/docker/Dockerfile.app"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: generative_ui_agents/generative-ui-starter-project/docker/Dockerfile.app"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-093c0107b9bab304", "name": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/Dockerfile", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: generative_ui_agents/mcp-apps-generative-ui-showcase/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-aff8f1d6b1d8da6b", "name": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/Dockerfile", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: generative_ui_agents/mcp-apps-generative-ui-showcase/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c5880ea9dadba81f", "name": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/Dockerfile", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a2eca1a6cdf16a2e", "name": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/Dockerfile", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f3eb66f7f6cc9a54", "name": "DS-0002: Image user should not be 'root' \u2014 rag_tutorials/knowledge_graph_rag_citations/Dockerfile", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 rag_tutorials/knowledge_graph_rag_citations/Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: rag_tutorials/knowledge_graph_rag_citations/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ba1a339a3725a627", "name": "DS-0026: No HEALTHCHECK defined \u2014 rag_tutorials/knowledge_graph_rag_citations/Dockerfile", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 rag_tutorials/knowledge_graph_rag_citations/Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: rag_tutorials/knowledge_graph_rag_citations/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-30f81ea77323cb9a", "name": "Agent authority lacks a verifier contract: agent_skills/commit-archaeologist/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: agent_skills/commit-archaeologist/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-acd837563f524652", "name": "Agent authority lacks a verifier contract: agent_skills/project-graveyard/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: agent_skills/project-graveyard/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8b57d2c201369bdd", "name": "Agent authority lacks a verifier contract: generative_ui_agents/ai-shadcn-component-generator/.mcp.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: generative_ui_agents/ai-shadcn-component-generator/.mcp.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-45e53fb3ee663120", "name": "Agent authority lacks a verifier contract: generative_ui_agents/ai-dashboard-canvas-agent/AGENTS.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: generative_ui_agents/ai-dashboard-canvas-agent/AGENTS.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-54b357e483905b5f", "name": "SkillSpector E1 (data-exfil) in agent_skills/advisor-orchestrator-worker/references/fallbacks.md", "shortDescription": {"text": "SkillSpector E1 (data-exfil) in agent_skills/advisor-orchestrator-worker/references/fallbacks.md"}, "fullDescription": {"text": "curl -sS --fail --max-time 300 \\\n      \"https://generativelanguage.googleapis.com/v1beta/models/gemini-3.5-flash:generateContent\" \\\n      -H \"x-goog-api-key: $api_key\" -H \"Content-Type: application/js\n\nData is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.\n\nSkill: advisor-orchestrator-worker\nRule: E1  Category: data-exfil\nSeverity: MEDIUM  Confidence: 0.60\n\nRemediation: Verify the destination URL is trusted and necessary. Remove or replace with documented APIs. Ensure no secrets, tokens, or PII are transmitted."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.6}}, {"id": "scanner-8c1d1336667d25e7", "name": "SkillSpector EA3 (excessive-agency) in agent_skills/advisor-orchestrator-worker/README.md", "shortDescription": {"text": "SkillSpector EA3 (excessive-agency) in agent_skills/advisor-orchestrator-worker/README.md"}, "fullDescription": {"text": "expand scope\n\nSkill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.\n\nSkill: advisor-orchestrator-worker\nRule: EA3  Category: excessive-agency\nSeverity: LOW  Confidence: 0.75\n\nRemediation: Limit the skill's scope to its documented purpose. Remove instructions that enable the agent to perform actions outside its stated functionality."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.75}}, {"id": "scanner-1dc3805cb32d42d5", "name": "SkillSpector TM2 (tool-misuse) in agent_skills/advisor-orchestrator-worker/SKILL.md", "shortDescription": {"text": "SkillSpector TM2 (tool-misuse) in agent_skills/advisor-orchestrator-worker/SKILL.md"}, "fullDescription": {"text": "; rm -\n\nTool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.\n\nSkill: advisor-orchestrator-worker\nRule: TM2  Category: tool-misuse\nSeverity: HIGH  Confidence: 0.75\n\nRemediation: Limit tool chaining depth and validate the output of each tool before passing it to the next. Require explicit user approval for multi-step chains."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-d5fad7a53d87de8c", "name": "SkillSpector AST4 (behavioral-ast) in agent_skills/commit-archaeologist/scripts/archaeologist.py", "shortDescription": {"text": "SkillSpector AST4 (behavioral-ast) in agent_skills/commit-archaeologist/scripts/archaeologist.py"}, "fullDescription": {"text": "result = subprocess.run(\n            [\"git\", \"-C\", repo, *args],\n            capture_output=True,\n            text=True,\n            # Decode git output as UTF-8. With text=True and no encodin\n\nsubprocess module calls execute external commands. Without careful input validation, this enables command injection.\n\nSkill: commit-archaeologist\nRule: AST4  Category: behavioral-ast\nSeverity: MEDIUM  Confidence: 0.60\n\nRemediation: Use subprocess.run() with shell=False and an explicit argument list. Validate all inputs and avoid passing user-controlled data to commands."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.6}}, {"id": "scanner-09bc9d14b99cab54", "name": "SkillSpector LP3 (mcp-least-priv) in agent_skills/commit-archaeologist/SKILL.md", "shortDescription": {"text": "SkillSpector LP3 (mcp-least-priv) in agent_skills/commit-archaeologist/SKILL.md"}, "fullDescription": {"text": "MCP Least Privilege\n\nWithout declared permissions the skill's intent is opaque and cannot be validated.\n\nSkill: commit-archaeologist\nRule: LP3  Category: mcp-least-priv\nSeverity: MEDIUM  Confidence: 0.70\n\nRemediation: Add a 'permissions' field to SKILL.md listing the capabilities this skill requires."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-ccccec0ff2b15dfa", "name": "SkillSpector OH1 (output-handling) in agent_skills/commit-archaeologist/scripts/archaeologist.py", "shortDescription": {"text": "SkillSpector OH1 (output-handling) in agent_skills/commit-archaeologist/scripts/archaeologist.py"}, "fullDescription": {"text": "subprocess.run(\n            [\"git\", \"-C\", repo, *args],\n            capture_output=True,\n            text=True,\n            # Decode git output\n\nModel output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.\n\nSkill: commit-archaeologist\nRule: OH1  Category: output-handling\nSeverity: HIGH  Confidence: 0.95\n\nRemediation: Validate and sanitize all model output before using it in downstream contexts. Use parameterized queries for SQL, shell quoting for commands, and HTML encoding for web output."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.95}}, {"id": "scanner-569a37efd41eeb09", "name": "SkillSpector AST4 (behavioral-ast) in agent_skills/project-graveyard/scripts/graveyard.py", "shortDescription": {"text": "SkillSpector AST4 (behavioral-ast) in agent_skills/project-graveyard/scripts/graveyard.py"}, "fullDescription": {"text": "out = subprocess.run(args, cwd=cwd, capture_output=True, text=True,\n                             encoding=\"utf-8\", errors=\"replace\", timeout=30)\n\nsubprocess module calls execute external commands. Without careful input validation, this enables command injection.\n\nSkill: project-graveyard\nRule: AST4  Category: behavioral-ast\nSeverity: MEDIUM  Confidence: 0.60\n\nRemediation: Use subprocess.run() with shell=False and an explicit argument list. Validate all inputs and avoid passing user-controlled data to commands."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.6}}, {"id": "scanner-87a345ddad05493c", "name": "SkillSpector LP3 (mcp-least-priv) in agent_skills/project-graveyard/SKILL.md", "shortDescription": {"text": "SkillSpector LP3 (mcp-least-priv) in agent_skills/project-graveyard/SKILL.md"}, "fullDescription": {"text": "MCP Least Privilege\n\nWithout declared permissions the skill's intent is opaque and cannot be validated.\n\nSkill: project-graveyard\nRule: LP3  Category: mcp-least-priv\nSeverity: MEDIUM  Confidence: 0.70\n\nRemediation: Add a 'permissions' field to SKILL.md listing the capabilities this skill requires."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-c43f4e4ae5eeb967", "name": "SkillSpector OH1 (output-handling) in agent_skills/project-graveyard/scripts/graveyard.py", "shortDescription": {"text": "SkillSpector OH1 (output-handling) in agent_skills/project-graveyard/scripts/graveyard.py"}, "fullDescription": {"text": "subprocess.run(args, cwd=cwd, capture_output\n\nModel output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.\n\nSkill: project-graveyard\nRule: OH1  Category: output-handling\nSeverity: HIGH  Confidence: 0.95\n\nRemediation: Validate and sanitize all model output before using it in downstream contexts. Use parameterized queries for SQL, shell quoting for commands, and HTML encoding for web output."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.95}}, {"id": "scanner-7ac10d9fa1ef5161", "name": "SkillSpector RA2 (rogue-agent) in agent_skills/project-graveyard/SKILL.md", "shortDescription": {"text": "SkillSpector RA2 (rogue-agent) in agent_skills/project-graveyard/SKILL.md"}, "fullDescription": {"text": "write the resurrection plan. The per-cause dig strategy is in\n`references/causes-of-death.md` (each cause has a \"resurrection angle\" \u2014\ndeploy-fear corpses need shipping steps only, wall deaths need th\n\nSkill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.\n\nSkill: project-graveyard\nRule: RA2  Category: rogue-agent\nSeverity: MEDIUM  Confidence: 0.60\n\nRemediation: Remove any persistence mechanisms (cron jobs, startup scripts, state files). Skills should not maintain state across sessions without explicit user consent."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.6}}, {"id": "scanner-7e7d84e51266fcd6", "name": "SkillSpector AST4 (behavioral-ast) in agent_skills/scope-creep-detector/scripts/scope_creep.py", "shortDescription": {"text": "SkillSpector AST4 (behavioral-ast) in agent_skills/scope-creep-detector/scripts/scope_creep.py"}, "fullDescription": {"text": "result = subprocess.run(\n        [\"git\", \"-C\", repo, *args],\n        capture_output=True,\n        text=True,\n        # Decode git output as UTF-8. With text=True and no encoding, Python uses\n\nsubprocess module calls execute external commands. Without careful input validation, this enables command injection.\n\nSkill: scope-creep-detector\nRule: AST4  Category: behavioral-ast\nSeverity: MEDIUM  Confidence: 0.60\n\nRemediation: Use subprocess.run() with shell=False and an explicit argument list. Validate all inputs and avoid passing user-controlled data to commands."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.6}}, {"id": "scanner-fd9cde77f014e8c9", "name": "SkillSpector LP3 (mcp-least-priv) in agent_skills/scope-creep-detector/SKILL.md", "shortDescription": {"text": "SkillSpector LP3 (mcp-least-priv) in agent_skills/scope-creep-detector/SKILL.md"}, "fullDescription": {"text": "MCP Least Privilege\n\nWithout declared permissions the skill's intent is opaque and cannot be validated.\n\nSkill: scope-creep-detector\nRule: LP3  Category: mcp-least-priv\nSeverity: MEDIUM  Confidence: 0.70\n\nRemediation: Add a 'permissions' field to SKILL.md listing the capabilities this skill requires."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-ce9adb40c7043c45", "name": "SkillSpector OH1 (output-handling) in agent_skills/scope-creep-detector/scripts/scope_creep.py", "shortDescription": {"text": "SkillSpector OH1 (output-handling) in agent_skills/scope-creep-detector/scripts/scope_creep.py"}, "fullDescription": {"text": "subprocess.run(\n        [\"git\", \"-C\", repo, *args],\n        capture_output=True,\n        text=True,\n        # Decode git output\n\nModel output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.\n\nSkill: scope-creep-detector\nRule: OH1  Category: output-handling\nSeverity: HIGH  Confidence: 0.95\n\nRemediation: Validate and sanitize all model output before using it in downstream contexts. Use parameterized queries for SQL, shell quoting for commands, and HTML encoding for web output."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.95}}, {"id": "scanner-79cbe26707ef2b73", "name": "SkillSpector EA2 (excessive-agency) in agent_skills/thinking-out-loud/README.md", "shortDescription": {"text": "SkillSpector EA2 (excessive-agency) in agent_skills/thinking-out-loud/README.md"}, "fullDescription": {"text": "without asking\n\nSkill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.\n\nSkill: thinking-out-loud\nRule: EA2  Category: excessive-agency\nSeverity: MEDIUM  Confidence: 0.75\n\nRemediation: Add human-in-the-loop confirmation for destructive, irreversible, or high-impact operations. Never auto-execute commands that modify files, send data, or alter system state."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.75}}, {"id": "scanner-e637c415447867e4", "name": "Run SkillSpector's LLM-backed analysis in your own pipeline", "shortDescription": {"text": "Run SkillSpector's LLM-backed analysis in your own pipeline"}, "fullDescription": {"text": "Repobility ran SkillSpector's static rules server-side. The deeper LLM-backed analyzers \u2014 tool-poisoning (TP*), semantic security discovery (SSD*), developer-intent mismatch (SDI*) \u2014 are meant to run on YOUR machine with YOUR model; repobility never sends your code to an LLM. Recipe:\n\n# 1. Install SkillSpector in your own isolated env\npipx install \"skillspector @ git+https://github.com/NVIDIA/SkillSpector.git\"\n\n# 2. Point it at YOUR LLM pipeline (pick one) - your code stays on your machine\nexport SKILLSPECTOR_PROVIDER=anthropic && export ANTHROPIC_API_KEY=sk-ant-...\n# export SKILLSPECTOR_PROVIDER=openai   && export OPENAI_API_KEY=sk-...\n# export SKILLSPECTOR_PROVIDER=openai OPENAI_API_KEY=ollama OPENAI_BASE_URL=http://localhost:11434/v1 SKILLSPECTOR_MODEL=llama3.1:8b\n# export SKILLSPECTOR_PROVIDER=nv_build && export NVIDIA_INFERENCE_KEY=nvapi-...\n\n# 3. Run the LLM-backed scan per skill (omit --no-llm to enable the LLM analyzers)\nskillspector scan agent_skills/advisor-orchestrator-worke"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0996d21f4d7057fe", "name": "Dockerfile runs as root: rag_tutorials/knowledge_graph_rag_citations/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: rag_tutorials/knowledge_graph_rag_citations/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-124e8b75ae537f2d", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d81e2fbc3ea73b52", "name": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bf5ee7e9e953b467", "name": "Dockerfile runs as root: generative_ui_agents/mcp-apps-generative-ui-showcase/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: generative_ui_agents/mcp-apps-generative-ui-showcase/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0a92dc478fc49a78", "name": "Docker base image is tag-pinned but not digest-pinned: node:20-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-30f23287d71c59b5", "name": "Dockerfile runs as root: generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-59733e35f10f58df", "name": "Docker base image is tag-pinned but not digest-pinned: node:20-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7c203178a6c043d3", "name": "Dockerfile runs as root: generative_ui_agents/generative-ui-starter-project/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: generative_ui_agents/generative-ui-starter-project/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c333e416b5eb87a3", "name": "Docker base image is tag-pinned but not digest-pinned: node:20-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-deb95921985c0eba", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.12.10-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12.10-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-908ced333e1756aa", "name": "Dockerfile runs as root: generative_ui_agents/ai-financial-coach-agent/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: generative_ui_agents/ai-financial-coach-agent/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-137b47b1586706ea", "name": "Docker base image is tag-pinned but not digest-pinned: node:20-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7cf87170c056b4ce", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2587dffec04f204d", "name": "Dockerfile runs as root: generative_ui_agents/ai-deep-research-agent/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: generative_ui_agents/ai-deep-research-agent/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b7c8b2c0e3faccc1", "name": "Docker base image is tag-pinned but not digest-pinned: node:20-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5c2bdbe291c36263", "name": "Dockerfile runs as root: advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fcaaee4a9a3b1419", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim-bookworm", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim-bookworm"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6084631fc9d83f2e", "name": "Insecure pattern 'dangerous_innerhtml' in agent_skills/self-improving-agent-skills/frontend/src/app/layout.tsx:21", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in agent_skills/self-improving-agent-skills/frontend/src/app/layout.tsx:21"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-d58bb89ade03cfdf", "name": "Insecure pattern 'cors_wildcard' in agent_skills/self-improving-agent-skills/backend/app.py:36", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in agent_skills/self-improving-agent-skills/backend/app.py:36"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6a9d1b01da28042f", "name": "Insecure pattern 'cors_wildcard' in generative_ui_agents/ai-mcp-app-builder/apps/threejs-server/server-utils.ts:29", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in generative_ui_agents/ai-mcp-app-builder/apps/threejs-server/server-utils.ts:29"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-811f4c0054412f39", "name": "Insecure pattern 'new_function_used' in generative_ui_agents/ai-mcp-app-builder/apps/threejs-server/src/threejs-app.tsx:", "shortDescription": {"text": "Insecure pattern 'new_function_used' in generative_ui_agents/ai-mcp-app-builder/apps/threejs-server/src/threejs-app.tsx:152"}, "fullDescription": {"text": "Found a known-risky pattern (new_function_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-be05b94be89f8482", "name": "Insecure pattern 'exec_used' in generative_ui_agents/ai-mcp-app-builder/apps/web/app/api/copilotkit/route.ts:224", "shortDescription": {"text": "Insecure pattern 'exec_used' in generative_ui_agents/ai-mcp-app-builder/apps/web/app/api/copilotkit/route.ts:224"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-338b6d95f886c01c", "name": "Insecure pattern 'exec_used' in generative_ui_agents/ai-mcp-app-builder/apps/web/lib/workspace/types.ts:35", "shortDescription": {"text": "Insecure pattern 'exec_used' in generative_ui_agents/ai-mcp-app-builder/apps/web/lib/workspace/types.ts:35"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-72d1bfd86c18bddd", "name": "Insecure pattern 'exec_used' in generative_ui_agents/ai-mcp-app-builder/apps/web/lib/workspace/e2b.ts:121", "shortDescription": {"text": "Insecure pattern 'exec_used' in generative_ui_agents/ai-mcp-app-builder/apps/web/lib/workspace/e2b.ts:121"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5b447def713a97aa", "name": "Insecure pattern 'cors_wildcard' in generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/server.ts:1011", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/server.ts:1011"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7debbe8750a4dc50", "name": "Insecure pattern 'direct_innerhtml_assignment' in generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/apps/t", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/apps/trading-app.html:1251"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-45c29b0ae527233a", "name": "Insecure pattern 'direct_innerhtml_assignment' in generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/apps/k", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/apps/kanban-app.html:1255"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-5a6a73adb0304304", "name": "Insecure pattern 'cors_wildcard' in generative_ui_agents/generative-ui-starter-project/serve.py:35", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in generative_ui_agents/generative-ui-starter-project/serve.py:35"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4566df7e467de5ab", "name": "Insecure pattern 'dangerous_innerhtml' in generative_ui_agents/ai-shadcn-component-generator/apps/ui/src/components/ui/c", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in generative_ui_agents/ai-shadcn-component-generator/apps/ui/src/components/ui/chart.tsx:75"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-ea4a8a80849d9085", "name": "Insecure pattern 'cors_wildcard' in generative_ui_agents/ai-shadcn-component-generator/apps/runtime/server.ts:25", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in generative_ui_agents/ai-shadcn-component-generator/apps/runtime/server.ts:25"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-df43e23c70c7c0ac", "name": "Insecure pattern 'dangerous_innerhtml' in generative_ui_agents/ai-dashboard-canvas-agent/src/components/ui/chart.tsx:83", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in generative_ui_agents/ai-dashboard-canvas-agent/src/components/ui/chart.tsx:83"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-8452a3b1942852d9", "name": "Insecure pattern 'cors_wildcard' in generative_ui_agents/ai-deep-research-agent/agent/main.py:30", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in generative_ui_agents/ai-deep-research-agent/agent/main.py:30"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8d6e1a2745160507", "name": "Insecure pattern 'cors_wildcard' in advanced_llm_apps/multimodal_video_moment_finder/backend/server.py:25", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in advanced_llm_apps/multimodal_video_moment_finder/backend/server.py:25"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ff6f9d00edcd112c", "name": "Insecure pattern 'direct_innerhtml_assignment' in advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent/live_", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent/live_demo/app.js:234"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-4f4fb7777a289e32", "name": "Insecure pattern 'cors_wildcard' in advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/api/app.py:47"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-11e607b5080657ef", "name": "Insecure pattern 'cors_wildcard' in advanced_ai_agents/multi_agent_apps/ai_speech_trainer_agent/backend/main.py:19", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in advanced_ai_agents/multi_agent_apps/ai_speech_trainer_agent/backend/main.py:19"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aee83c85e2149402", "name": "Insecure pattern 'subprocess_shell_true' in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/sched", "shortDescription": {"text": "Insecure pattern 'subprocess_shell_true' in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/scheduler.py:97"}, "fullDescription": {"text": "Found a known-risky pattern (subprocess_shell_true). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7e952106ac751d6c", "name": "Insecure pattern 'cors_wildcard' in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/main.py:43", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/main.py:43"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c84de2baf86a7c9a", "name": "Insecure pattern 'dangerous_innerhtml' in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/compone", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ScriptConfirmation.js:116"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-46157b1f2a30f4d9", "name": "Insecure pattern 'dangerous_innerhtml' in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/compone", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ChatMessage.js:320"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-2a7a31d542a1ad59", "name": "Insecure pattern 'dangerous_innerhtml' in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/A", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/ArticleDetail.js:217"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-7c814311053a5c62", "name": "Insecure pattern 'direct_innerhtml_assignment' in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/ArticleDetail.js:37"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-10db8d5934adbdd5", "name": "Possible secret in ai_agent_framework_crash_course/google_adk_crash_course/4_tool_using_agent/4_2_function_tools/utility", "shortDescription": {"text": "Possible secret in ai_agent_framework_crash_course/google_adk_crash_course/4_tool_using_agent/4_2_function_tools/utility_agent/agent.py"}, "fullDescription": {"text": "Detected 1 occurrence(s) matching password_literal. Rotate real credentials and move them to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.58}}, {"id": "scanner-ebad02ab93d6ca4d", "name": "Insecure pattern 'weak_hash' in ai_agent_framework_crash_course/google_adk_crash_course/4_tool_using_agent/4_2_function_", "shortDescription": {"text": "Insecure pattern 'weak_hash' in ai_agent_framework_crash_course/google_adk_crash_course/4_tool_using_agent/4_2_function_tools/utility_agent/agent.py:39"}, "fullDescription": {"text": "Found a known-risky pattern (weak_hash). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0df1d3afe4852060", "name": "Insecure pattern 'eval_used' in ai_agent_framework_crash_course/google_adk_crash_course/4_tool_using_agent/4_2_function_", "shortDescription": {"text": "Insecure pattern 'eval_used' in ai_agent_framework_crash_course/google_adk_crash_course/4_tool_using_agent/4_2_function_tools/calculator_agent/tools.py:30"}, "fullDescription": {"text": "Found a known-risky pattern (eval_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-79d4ad6330dc2aba", "name": "Insecure pattern 'direct_innerhtml_assignment' in voice_ai_agents/insurance_claim_live_agent_team/live_demo/app.js:88", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in voice_ai_agents/insurance_claim_live_agent_team/live_demo/app.js:88"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-de53ac274e5b4ecf", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-37716d9c0a33ad5c", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5b2949ca1261d964", "name": "Install-time lifecycle script performs network/shell-sensitive actions", "shortDescription": {"text": "Install-time lifecycle script performs network/shell-sensitive actions"}, "fullDescription": {"text": "preinstall/install/postinstall/prepare scripts execute during dependency installation. Review them carefully for network calls, obfuscation, shell execution, or credential access."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a705dfe1f502cc21", "name": "package.json defines install-time lifecycle scripts", "shortDescription": {"text": "package.json defines install-time lifecycle scripts"}, "fullDescription": {"text": "preinstall/install/postinstall/prepare scripts execute during dependency installation. Review them carefully for network calls, obfuscation, shell execution, or credential access."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-823c96aab48f155e", "name": "package.json defines install-time lifecycle scripts", "shortDescription": {"text": "package.json defines install-time lifecycle scripts"}, "fullDescription": {"text": "preinstall/install/postinstall/prepare scripts execute during dependency installation. Review them carefully for network calls, obfuscation, shell execution, or credential access."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9eed015d6887d44c", "name": "package.json defines install-time lifecycle scripts", "shortDescription": {"text": "package.json defines install-time lifecycle scripts"}, "fullDescription": {"text": "preinstall/install/postinstall/prepare scripts execute during dependency installation. Review them carefully for network calls, obfuscation, shell execution, or credential access."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-caab76011a0db20c", "name": "Very large file: advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/app/plan/page.tsx (", "shortDescription": {"text": "Very large file: advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/app/plan/page.tsx (1570 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-635f69733dae0e7a", "name": "Very large file: advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/app/plan/[id]/page.", "shortDescription": {"text": "Very large file: advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/app/plan/[id]/page.tsx (1408 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0be509d7d6947cf4", "name": "Very large file: advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/StudioChat.js (1117 lines)", "shortDescription": {"text": "Very large file: advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/StudioChat.js (1117 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-48bb1e4ea95373c5", "name": "Very large file: advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/Voyager.js (1149 lines)", "shortDescription": {"text": "Very large file: advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/Voyager.js (1149 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f8adda22c6c7cf34", "name": "Very large file: advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/icons/Spoot.js (1606 lines)", "shortDescription": {"text": "Very large file: advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/icons/Spoot.js (1606 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "21 test file(s) for 866 source file(s) (ratio 0.02). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cc50b20e62a007b0", "name": "Node manifest has dependencies but no lockfile: generative_ui_agents/ai-mcp-app-builder/apps/mcp-use-server/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: generative_ui_agents/ai-mcp-app-builder/apps/mcp-use-server/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-872999b329355dc0", "name": "Node manifest has dependencies but no lockfile: generative_ui_agents/ai-mcp-app-builder/apps/threejs-server/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: generative_ui_agents/ai-mcp-app-builder/apps/threejs-server/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7841b0cd403d4440", "name": "Node manifest has dependencies but no lockfile: generative_ui_agents/ai-mcp-app-builder/apps/web/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: generative_ui_agents/ai-mcp-app-builder/apps/web/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e4b50c035209810b", "name": "Node manifest has dependencies but no lockfile: generative_ui_agents/ai-shadcn-component-generator/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: generative_ui_agents/ai-shadcn-component-generator/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-39738f8ef6ff0eed", "name": "Node manifest has dependencies but no lockfile: generative_ui_agents/ai-shadcn-component-generator/apps/ui/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: generative_ui_agents/ai-shadcn-component-generator/apps/ui/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-43d15c3aa1283e4e", "name": "Node manifest has dependencies but no lockfile: generative_ui_agents/ai-shadcn-component-generator/apps/runtime/package.", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: generative_ui_agents/ai-shadcn-component-generator/apps/runtime/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e47f1e9c51c8bd25", "name": "Node manifest has dependencies but no lockfile: advanced_llm_apps/chat_with_X_tutorials/streaming_ai_chatbot/package.jso", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: advanced_llm_apps/chat_with_X_tutorials/streaming_ai_chatbot/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b1479f7ec75d9ba8", "name": "Node manifest has dependencies but no lockfile: advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/packa", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 1886 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 198 placeholder/mock markers across 95 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing lockfile. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a49eac436c6b66f7", "name": "Network/subprocess call without timeout or try/except \u2014 starter_ai_agents/ai_music_generator_agent/music_generator_agent", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 starter_ai_agents/ai_music_generator_agent/music_generator_agent.py:56"}, "fullDescription": {"text": "`requests.get(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-2c748e4c47855574", "name": "Legacy-named symbol `eleven_multilingual_v2` in starter_ai_agents/ai_blog_to_podcast_agent/blog_to_podcast_agent.py:57", "shortDescription": {"text": "Legacy-named symbol `eleven_multilingual_v2` in starter_ai_agents/ai_blog_to_podcast_agent/blog_to_podcast_agent.py:57"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a3c153f48164339c", "name": "Network/subprocess call without timeout or try/except \u2014 agent_skills/scope-creep-detector/scripts/scope_creep.py:427", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 agent_skills/scope-creep-detector/scripts/scope_creep.py:427"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-96705cdbd4436716", "name": "Network/subprocess call without timeout or try/except \u2014 rag_tutorials/rag-as-a-service/rag_app.py:40", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 rag_tutorials/rag-as-a-service/rag_app.py:40"}, "fullDescription": {"text": "`requests.post(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-1852c16d70f02b90", "name": "Legacy-named symbol `model_copy` in rag_tutorials/agentic_typed_rag_pydanticai/agent.py:217", "shortDescription": {"text": "Legacy-named symbol `model_copy` in rag_tutorials/agentic_typed_rag_pydanticai/agent.py:217"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-81b04e2bb62c8118", "name": "Network/subprocess call without timeout or try/except \u2014 rag_tutorials/agentic_rag_math_agent/rag/query_router.py:61", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 rag_tutorials/agentic_rag_math_agent/rag/query_router.py:61"}, "fullDescription": {"text": "`requests.post(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-8f1b3d32e2605136", "name": "Fire-and-forget `fetch()` has no rejection handler \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/page.tsx:226", "shortDescription": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/page.tsx:226"}, "fullDescription": {"text": "This fetch result is neither awaited, returned, assigned, nor followed by `.catch(...)`. A network failure can therefore become an unhandled promise rejection. Await/return the promise or attach an explicit rejection handler."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e3cc5b8a888d4a2f", "name": "Commented-code block (6 lines) in generative_ui_agents/ai-dashboard-canvas-agent/agent/state.py:5", "shortDescription": {"text": "Commented-code block (6 lines) in generative_ui_agents/ai-dashboard-canvas-agent/agent/state.py:5"}, "fullDescription": {"text": "6 of 6 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-7d0d0669f49a41f9", "name": "Network/subprocess call without timeout or try/except \u2014 advanced_llm_apps/multimodal_video_moment_finder/backend/video_s", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 advanced_llm_apps/multimodal_video_moment_finder/backend/video_store.py:89"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-d728da5a2e75f623", "name": "Network/subprocess call without timeout or try/except \u2014 advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent/youtube_ingest.py:332"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-5ae8d134083a71e4", "name": "Legacy-named symbol `model_copy` in advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent/agent.py:235", "shortDescription": {"text": "Legacy-named symbol `model_copy` in advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent/agent.py:235"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b6b2aa877ba27ad2", "name": "Network/subprocess call without timeout or try/except \u2014 advanced_ai_agents/single_agent_apps/ai_fraud_investigation_agen", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 advanced_ai_agents/single_agent_apps/ai_fraud_investigation_agent/fraud_investigation_agent.py:634"}, "fullDescription": {"text": "`requests.get(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-71d7cc7a73b2fe1e", "name": "Legacy-named symbol `kitchen_modern_renovation_v1` in advanced_ai_agents/multi_agent_apps/ai_home_renovation_agent/agent", "shortDescription": {"text": "Legacy-named symbol `kitchen_modern_renovation_v1` in advanced_ai_agents/multi_agent_apps/ai_home_renovation_agent/agent.py:151"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7950fd1d9182434a", "name": "Legacy-named symbol `landing_page_v1` in advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_uiux_feedback_agent_", "shortDescription": {"text": "Legacy-named symbol `landing_page_v1` in advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_uiux_feedback_agent_team/agent.py:64"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-468b5acbb598a972", "name": "Commented-code block (6 lines) in advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/b", "shortDescription": {"text": "Commented-code block (6 lines) in advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/broswer.py:37"}, "fullDescription": {"text": "4 of 6 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-be783e8c72fcdf64", "name": "Commented-code block (5 lines) in advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/c", "shortDescription": {"text": "Commented-code block (5 lines) in advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/config/logger.py:40"}, "fullDescription": {"text": "3 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-a55eff85d3e0f5f7", "name": "Commented-code block (7 lines) in advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/a", "shortDescription": {"text": "Commented-code block (7 lines) in advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/agents/team.py:13"}, "fullDescription": {"text": "4 of 7 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-31f40a004d49d5c3", "name": "Network/subprocess call without timeout or try/except \u2014 advanced_ai_agents/multi_agent_apps/ai_speech_trainer_agent/fron", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 advanced_ai_agents/multi_agent_apps/ai_speech_trainer_agent/frontend/Home.py:106"}, "fullDescription": {"text": "`requests.post(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-c1f7398cf92ed3b8", "name": "Network/subprocess call without timeout or try/except \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/b", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/bootstrap_demo.py:26"}, "fullDescription": {"text": "`requests.get(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-09fb576b3e715218", "name": "Legacy-named symbol `eleven_multilingual_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/u", "shortDescription": {"text": "Legacy-named symbol `eleven_multilingual_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/utils/tts_engine_selector.py:7"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ed3aa9d0eb9c153", "name": "Legacy-named symbol `eleven_multilingual_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/u", "shortDescription": {"text": "Legacy-named symbol `eleven_multilingual_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/utils/text_to_audio_elevenslab.py:8"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eb0ec874aaf31986", "name": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/processo", "shortDescription": {"text": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/processors/podcast_generator_processor.py:11"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ebfe452bbcefede", "name": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/agents/i", "shortDescription": {"text": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/agents/image_generate_agent.py:8"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-404af33d6e730e42", "name": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/services", "shortDescription": {"text": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/services/celery_tasks.py:8"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e62817dec9afdfd", "name": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/services", "shortDescription": {"text": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/services/internal_session_service.py:6"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a21fac9cb1b0dbb5", "name": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/services", "shortDescription": {"text": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/services/async_podcast_agent_service.py:10"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9c5c35d717897304", "name": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/tools/ui", "shortDescription": {"text": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/tools/ui_manager.py:3"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4235c803d9fb73d8", "name": "Network/subprocess call without timeout or try/except \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/b", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/tools/wikipedia_search.py:32"}, "fullDescription": {"text": "`requests.get(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-6ea3cc34c2d9c136", "name": "Network/subprocess call without timeout or try/except \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/b", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/tools/jikan_search.py:53"}, "fullDescription": {"text": "`requests.get(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-fd3f23453e3191e7", "name": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/tools/pi", "shortDescription": {"text": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/tools/pipeline/image_generate_agent.py:8"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5423af470f883720", "name": "Legacy-named symbol `board_copy` in advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/utils.py:", "shortDescription": {"text": "Legacy-named symbol `board_copy` in advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/utils.py:185"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9a4850d5fbbc29bd", "name": "59 env vars used in code but missing from .env.example", "shortDescription": {"text": "59 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `AGENTSCOUT_DELIVERY`, `AGENTSCOUT_LIVE_HN`, `AGENTSCOUT_WEBHOOK_TOKEN`, `AGENTSCOUT_WEBHOOK_URL`, `AGENT_PORT`, `AGENT_RELOAD`, `ALLOWED_ORIGINS`, `ALLOW_PRIVATE_URLS` + 51 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same substantial AST body hash:\nstarter_ai_agents/ai_travel_agent/local_travel_agent.py:12:generate_ics_content, starter_ai_agents/ai_travel_agent/travel_agent.py:12:generate_ics_content\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same substantial AST body hash:\nrag_tutorials/gemini_agentic_rag/agentic_rag_gemini.py:296:check_document_relevance, rag_tutorials/qwen_local_rag/qwen_local_rag_agent.py:289:check_document_relevance, rag_tutorials/deepseek_local_rag_agent/deepseek_rag_agent.py:306:check_document_relevance\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-91d2d7fd41747bf9", "name": "Frontend route `/studio/chat/:sessionId` has no Link/navigate to it \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_po", "shortDescription": {"text": "Frontend route `/studio/chat/:sessionId` has no Link/navigate to it \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/App.js"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-51072af88bcd328f", "name": "Frontend route `/articles/:articleId` has no Link/navigate to it \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podca", "shortDescription": {"text": "Frontend route `/articles/:articleId` has no Link/navigate to it \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/App.js"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6d34df607b93ea5d", "name": "Frontend route `/podcasts/:identifier` has no Link/navigate to it \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podc", "shortDescription": {"text": "Frontend route `/podcasts/:identifier` has no Link/navigate to it \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/App.js"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1f969b91b1f4ca8f", "name": "Frontend route `/sources/:sourceId/edit` has no Link/navigate to it \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_po", "shortDescription": {"text": "Frontend route `/sources/:sourceId/edit` has no Link/navigate to it \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/App.js"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-10fa0dcd7990bf47", "name": "Frontend route `/sources/:sourceId` has no Link/navigate to it \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast", "shortDescription": {"text": "Frontend route `/sources/:sourceId` has no Link/navigate to it \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/App.js"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-84ed6fc3e78a60cc", "name": "Frontend route `/social-media/:postId` has no Link/navigate to it \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podc", "shortDescription": {"text": "Frontend route `/social-media/:postId` has no Link/navigate to it \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/App.js"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-61caf05e28b3d9fd", "name": "FastAPI POST `scheduler_trigger` without auth dependency \u2014 always_on_agents/release_radar_agent/scheduler_api.py:100", "shortDescription": {"text": "FastAPI POST `scheduler_trigger` without auth dependency \u2014 always_on_agents/release_radar_agent/scheduler_api.py:100"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-c509fb643aec15ce", "name": "FastAPI POST `pubsub_trigger` without auth dependency \u2014 always_on_agents/release_radar_agent/scheduler_api.py:109", "shortDescription": {"text": "FastAPI POST `pubsub_trigger` without auth dependency \u2014 always_on_agents/release_radar_agent/scheduler_api.py:109"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-81cd83813a501cae", "name": "FastAPI POST `scheduler_trigger` without auth dependency \u2014 always_on_agents/always_on_hn_briefing_agent/scheduler_api.py", "shortDescription": {"text": "FastAPI POST `scheduler_trigger` without auth dependency \u2014 always_on_agents/always_on_hn_briefing_agent/scheduler_api.py:93"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-ea1bbfeb180b97da", "name": "FastAPI POST `pubsub_trigger` without auth dependency \u2014 always_on_agents/always_on_hn_briefing_agent/scheduler_api.py:10", "shortDescription": {"text": "FastAPI POST `pubsub_trigger` without auth dependency \u2014 always_on_agents/always_on_hn_briefing_agent/scheduler_api.py:102"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-87b2632a52be4e97", "name": "FastAPI POST `upload_skill` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:124", "shortDescription": {"text": "FastAPI POST `upload_skill` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:124"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-5e0110760c7dce55", "name": "FastAPI POST `upload_files` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:173", "shortDescription": {"text": "FastAPI POST `upload_files` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:173"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-b32d4adc174d0535", "name": "FastAPI POST `analyze_skill` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:211", "shortDescription": {"text": "FastAPI POST `analyze_skill` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:211"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-5093b88dfaf70d52", "name": "FastAPI POST `regenerate_config` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:229", "shortDescription": {"text": "FastAPI POST `regenerate_config` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:229"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-5f80a1e4e0153d5e", "name": "FastAPI POST `update_config` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:236", "shortDescription": {"text": "FastAPI POST `update_config` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:236"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-00a0741302ff40cc", "name": "FastAPI POST `start_optimization` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:278", "shortDescription": {"text": "FastAPI POST `start_optimization` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:278"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-08647908d15abb93", "name": "FastAPI POST `stop_optimization` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:399", "shortDescription": {"text": "FastAPI POST `stop_optimization` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:399"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-047fcf3bd9e686c2", "name": "FastAPI POST `load_example` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:464", "shortDescription": {"text": "FastAPI POST `load_example` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:464"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-5a03991fcd5710b3", "name": "FastAPI POST `add_text_source` without auth dependency \u2014 rag_tutorials/multimodal_agentic_rag/backend/server.py:154", "shortDescription": {"text": "FastAPI POST `add_text_source` without auth dependency \u2014 rag_tutorials/multimodal_agentic_rag/backend/server.py:154"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-fe59c76b3fb256c2", "name": "FastAPI POST `add_url_source` without auth dependency \u2014 rag_tutorials/multimodal_agentic_rag/backend/server.py:164", "shortDescription": {"text": "FastAPI POST `add_url_source` without auth dependency \u2014 rag_tutorials/multimodal_agentic_rag/backend/server.py:164"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-b32c5ba50f1a2f17", "name": "FastAPI POST `add_file_source` without auth dependency \u2014 rag_tutorials/multimodal_agentic_rag/backend/server.py:181", "shortDescription": {"text": "FastAPI POST `add_file_source` without auth dependency \u2014 rag_tutorials/multimodal_agentic_rag/backend/server.py:181"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-ba5c8e076ce6bfa8", "name": "FastAPI DELETE `delete_source` without auth dependency \u2014 rag_tutorials/multimodal_agentic_rag/backend/server.py:204", "shortDescription": {"text": "FastAPI DELETE `delete_source` without auth dependency \u2014 rag_tutorials/multimodal_agentic_rag/backend/server.py:204"}, "fullDescription": {"text": "`@app.delete` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-dbcd74a51ecb43e0", "name": "FastAPI POST `ask` without auth dependency \u2014 rag_tutorials/multimodal_agentic_rag/backend/server.py:212", "shortDescription": {"text": "FastAPI POST `ask` without auth dependency \u2014 rag_tutorials/multimodal_agentic_rag/backend/server.py:212"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-3fa4242568f45ee3", "name": "FastAPI POST `upload_video` without auth dependency \u2014 advanced_llm_apps/multimodal_video_moment_finder/backend/server.py", "shortDescription": {"text": "FastAPI POST `upload_video` without auth dependency \u2014 advanced_llm_apps/multimodal_video_moment_finder/backend/server.py:52"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-ae641ccb8a8dd186", "name": "FastAPI POST `find_moment` without auth dependency \u2014 advanced_llm_apps/multimodal_video_moment_finder/backend/server.py:", "shortDescription": {"text": "FastAPI POST `find_moment` without auth dependency \u2014 advanced_llm_apps/multimodal_video_moment_finder/backend/server.py:76"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-dd64f451e1fa270b", "name": "FastAPI POST `find_moment_text` without auth dependency \u2014 advanced_llm_apps/multimodal_video_moment_finder/backend/serve", "shortDescription": {"text": "FastAPI POST `find_moment_text` without auth dependency \u2014 advanced_llm_apps/multimodal_video_moment_finder/backend/server.py:107"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-c99983543a29b0ff", "name": "FastAPI DELETE `delete_video` without auth dependency \u2014 advanced_llm_apps/multimodal_video_moment_finder/backend/server.", "shortDescription": {"text": "FastAPI DELETE `delete_video` without auth dependency \u2014 advanced_llm_apps/multimodal_video_moment_finder/backend/server.py:138"}, "fullDescription": {"text": "`@app.delete` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-43a18f40e146e507", "name": "FastAPI POST `create_session` without auth dependency \u2014 advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent", "shortDescription": {"text": "FastAPI POST `create_session` without auth dependency \u2014 advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent/live_demo/server.py:102"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-27c6cf93ba572773", "name": "FastAPI POST `trigger_trip_craft_agent` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_tra", "shortDescription": {"text": "FastAPI POST `trigger_trip_craft_agent` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/router/plan.py:13"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-569b8691fbd9862c", "name": "FastAPI POST `analyze` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_speech_trainer_agent/backend/mai", "shortDescription": {"text": "FastAPI POST `analyze` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_speech_trainer_agent/backend/main.py:35"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-f42399ea65be7d44", "name": "FastAPI POST `create_task` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beif", "shortDescription": {"text": "FastAPI POST `create_task` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/task_router.py:73"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-e73d311332e0a93f", "name": "FastAPI PUT `update_task` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifo", "shortDescription": {"text": "FastAPI PUT `update_task` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/task_router.py:90"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-d0a5609d2b32c99a", "name": "FastAPI DELETE `delete_task` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/be", "shortDescription": {"text": "FastAPI DELETE `delete_task` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/task_router.py:105"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-b7ef3afc7a42e602", "name": "FastAPI POST `enable_task` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beif", "shortDescription": {"text": "FastAPI POST `enable_task` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/task_router.py:117"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-c917a6628bbbd738", "name": "FastAPI POST `disable_task` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/bei", "shortDescription": {"text": "FastAPI POST `disable_task` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/task_router.py:129"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-ef7a4ae5dd07f76f", "name": "FastAPI POST `create_podcast_config` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_a", "shortDescription": {"text": "FastAPI POST `create_podcast_config` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_config_router.py:34"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-4c60e3fc8acdd932", "name": "FastAPI PUT `update_podcast_config` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_ag", "shortDescription": {"text": "FastAPI PUT `update_podcast_config` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_config_router.py:55"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-4b354f58200264e5", "name": "FastAPI DELETE `delete_podcast_config` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast", "shortDescription": {"text": "FastAPI DELETE `delete_podcast_config` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_config_router.py:70"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-2525800ab6320c12", "name": "FastAPI POST `enable_podcast_config` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_a", "shortDescription": {"text": "FastAPI POST `enable_podcast_config` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_config_router.py:82"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-d4c1f6f2dc85a9bc", "name": "FastAPI POST `disable_podcast_config` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_", "shortDescription": {"text": "FastAPI POST `disable_podcast_config` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_config_router.py:94"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-bb6012543cd29c46", "name": "FastAPI POST `create_session` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/b", "shortDescription": {"text": "FastAPI POST `create_session` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/async_podcast_agent_router.py:34"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-86ab646e542fea06", "name": "FastAPI POST `chat` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/rou", "shortDescription": {"text": "FastAPI POST `chat` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/async_podcast_agent_router.py:40"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-6e1dc6e164731c14", "name": "FastAPI POST `check_status` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/bei", "shortDescription": {"text": "FastAPI POST `check_status` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/async_podcast_agent_router.py:46"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-8d83bda11b8791aa", "name": "FastAPI DELETE `delete_session` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents", "shortDescription": {"text": "FastAPI DELETE `delete_session` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/async_podcast_agent_router.py:64"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-31212311ba87b129", "name": "FastAPI POST `create_source` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/be", "shortDescription": {"text": "FastAPI POST `create_source` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/source_router.py:67"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-c4ce1d65568530f9", "name": "FastAPI PUT `update_source` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/bei", "shortDescription": {"text": "FastAPI PUT `update_source` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/source_router.py:80"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-6be21128aefead6d", "name": "FastAPI DELETE `delete_source` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/", "shortDescription": {"text": "FastAPI DELETE `delete_source` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/source_router.py:94"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-57c34e9e9294e318", "name": "FastAPI POST `add_feed` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong", "shortDescription": {"text": "FastAPI POST `add_feed` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/source_router.py:107"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-b421669e475d0fd6", "name": "FastAPI PUT `update_feed` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifo", "shortDescription": {"text": "FastAPI PUT `update_feed` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/source_router.py:118"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-17cd587c9182a973", "name": "FastAPI DELETE `delete_feed` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/be", "shortDescription": {"text": "FastAPI DELETE `delete_feed` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/source_router.py:129"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-7dbce697e68b80f6", "name": "FastAPI POST `setup_browser_session` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_a", "shortDescription": {"text": "FastAPI POST `setup_browser_session` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/social_media_router.py:156"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-275b4ae145b2e292", "name": "FastAPI POST `create_podcast` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/b", "shortDescription": {"text": "FastAPI POST `create_podcast` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_router.py:107"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-3dd53eb22c0a65c7", "name": "FastAPI PUT `update_podcast` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/be", "shortDescription": {"text": "FastAPI PUT `update_podcast` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_router.py:128"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-f91cac77c75e470c", "name": "FastAPI DELETE `delete_podcast` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents", "shortDescription": {"text": "FastAPI DELETE `delete_podcast` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_router.py:143"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-ec3a38afb35d1c42", "name": "FastAPI POST `upload_audio` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/bei", "shortDescription": {"text": "FastAPI POST `upload_audio` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_router.py:159"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-a1c9702a99dfcc18", "name": "FastAPI POST `upload_banner` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/be", "shortDescription": {"text": "FastAPI POST `upload_banner` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_router.py:173"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-c3117bfd7b32518e", "name": "FastAPI POST `create_session` without auth dependency \u2014 voice_ai_agents/insurance_claim_live_agent_team/live_demo/server", "shortDescription": {"text": "FastAPI POST `create_session` without auth dependency \u2014 voice_ai_agents/insurance_claim_live_agent_team/live_demo/server.py:410"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-c794a6f8bced630c", "name": "FastAPI POST `message` without auth dependency \u2014 voice_ai_agents/insurance_claim_live_agent_team/live_demo/server.py:448", "shortDescription": {"text": "FastAPI POST `message` without auth dependency \u2014 voice_ai_agents/insurance_claim_live_agent_team/live_demo/server.py:448"}, "fullDescription": {"text": "`@app.post` has no route-local auth dependency, and `app` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-83d34cdc40ed7c37", "name": "Vulnerable dependency agno 1.5.6: GHSA-77rh-m34w-rv36", "shortDescription": {"text": "Vulnerable dependency agno 1.5.6: GHSA-77rh-m34w-rv36"}, "fullDescription": {"text": "OSV.dev reports `agno` at version `1.5.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-77rh-m34w-rv36.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-77rh-m34w-rv36\nFix: upgrade `agno` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-feea9b10efeda72c", "name": "Vulnerable dependency agno 1.5.6: GHSA-82m5-3pcp-hccq", "shortDescription": {"text": "Vulnerable dependency agno 1.5.6: GHSA-82m5-3pcp-hccq"}, "fullDescription": {"text": "OSV.dev reports `agno` at version `1.5.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-82m5-3pcp-hccq.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-82m5-3pcp-hccq\nFix: upgrade `agno` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-285d17e14917f08c", "name": "Vulnerable dependency agno 1.5.6: PYSEC-2026-2333", "shortDescription": {"text": "Vulnerable dependency agno 1.5.6: PYSEC-2026-2333"}, "fullDescription": {"text": "OSV.dev reports `agno` at version `1.5.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2333.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2333\nFix: upgrade `agno` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-840593fff2e1deab", "name": "Vulnerable dependency agno 1.5.6: PYSEC-2026-256", "shortDescription": {"text": "Vulnerable dependency agno 1.5.6: PYSEC-2026-256"}, "fullDescription": {"text": "OSV.dev reports `agno` at version `1.5.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-256.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-256\nFix: upgrade `agno` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-287cfd8bf7019f0e", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-2fqr-mr3j-6wp8", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-2fqr-mr3j-6wp8"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-2fqr-mr3j-6wp8 (aka CVE-2026-54279).\n\naiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence\n\nAliases: CVE-2026-54279, PYSEC-2026-2112\nAdvisory: https://osv.dev/vulnerability/GHSA-2fqr-mr3j-6wp8\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cf7edc8d7e4b6a60", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-2vrm-gr82-f7m5", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-2vrm-gr82-f7m5"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-2vrm-gr82-f7m5 (aka CVE-2026-34514).\n\nAIOHTTP has CRLF injection through multipart part content type header construction\n\nAliases: CVE-2026-34514, PYSEC-2026-2096\nAdvisory: https://osv.dev/vulnerability/GHSA-2vrm-gr82-f7m5\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ecf0f6efce210b05", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-3wq7-rqq7-wx6j", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-3wq7-rqq7-wx6j"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-3wq7-rqq7-wx6j (aka CVE-2026-34517).\n\nAIOHTTP has late size enforcement for non-file multipart fields causes memory DoS\n\nAliases: CVE-2026-34517, PYSEC-2026-2099\nAdvisory: https://osv.dev/vulnerability/GHSA-3wq7-rqq7-wx6j\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4551092bc2772a78", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-4fvr-rgm6-gqmc", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-4fvr-rgm6-gqmc"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-4fvr-rgm6-gqmc (aka CVE-2026-54273).\n\naiohttp: HTTP/1 Pipelined Requests Queue Without Limit\n\nAliases: CVE-2026-54273, PYSEC-2026-2107\nAdvisory: https://osv.dev/vulnerability/GHSA-4fvr-rgm6-gqmc\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d7101223db67bd98", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-4m7w-qmgq-4wj5", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-4m7w-qmgq-4wj5"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-4m7w-qmgq-4wj5 (aka CVE-2026-54275).\n\naiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections\n\nAliases: CVE-2026-54275, PYSEC-2026-237\nAdvisory: https://osv.dev/vulnerability/GHSA-4m7w-qmgq-4wj5\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c2d361bcf90cfd4d", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-54jq-c3m8-4m76", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-54jq-c3m8-4m76"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-54jq-c3m8-4m76.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-54jq-c3m8-4m76\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-02fa2a68ca55dedc", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-63hf-3vf5-4wqf", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-63hf-3vf5-4wqf"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-63hf-3vf5-4wqf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-63hf-3vf5-4wqf\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8f4d15d0633c14f2", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-63hw-fmq6-xxg2", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-63hw-fmq6-xxg2"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-63hw-fmq6-xxg2.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-63hw-fmq6-xxg2\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fb4968ce3299963a", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-69f9-5gxw-wvc2", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-69f9-5gxw-wvc2"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-69f9-5gxw-wvc2.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-69f9-5gxw-wvc2\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e7d05aa3c0d405ee", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-6jhg-hg63-jvvf", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-6jhg-hg63-jvvf"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-6jhg-hg63-jvvf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6jhg-hg63-jvvf\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-397fd315b3f1d627", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-6mq8-rvhq-8wgg", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-6mq8-rvhq-8wgg"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-6mq8-rvhq-8wgg.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6mq8-rvhq-8wgg\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bb2c31abce229abc", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-9548-qrrj-x5pj", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-9548-qrrj-x5pj"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-9548-qrrj-x5pj.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9548-qrrj-x5pj\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1ff12d5fec3a5a8c", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-966j-vmvw-g2g9", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-966j-vmvw-g2g9"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-966j-vmvw-g2g9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-966j-vmvw-g2g9\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-68248764f61388b5", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-9x8q-7h8h-wcw9", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-9x8q-7h8h-wcw9"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-9x8q-7h8h-wcw9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9x8q-7h8h-wcw9\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c0ff523e8aaff503", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-c427-h43c-vf67", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-c427-h43c-vf67"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-c427-h43c-vf67.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-c427-h43c-vf67\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b00e7f44ab64883e", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-fh55-r93g-j68g", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-fh55-r93g-j68g"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-fh55-r93g-j68g.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fh55-r93g-j68g\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-02c7f4709cc11079", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-g3cq-j2xw-wf74", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-g3cq-j2xw-wf74"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-g3cq-j2xw-wf74.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-g3cq-j2xw-wf74\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-15c7922dbcec6551", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-g84x-mcqj-x9qq", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-g84x-mcqj-x9qq"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-g84x-mcqj-x9qq.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-g84x-mcqj-x9qq\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fabcbdeb1d94c683", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-hcc4-c3v8-rx92", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-hcc4-c3v8-rx92"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-hcc4-c3v8-rx92.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hcc4-c3v8-rx92\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-34ddd8e905c3eccd", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-hg6j-4rv6-33pg", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-hg6j-4rv6-33pg"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-hg6j-4rv6-33pg.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hg6j-4rv6-33pg\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-be08d8aae712a66e", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-hpj7-wq8m-9hgp", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-hpj7-wq8m-9hgp"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-hpj7-wq8m-9hgp.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hpj7-wq8m-9hgp\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6f30c1afe3e7a592", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-jg22-mg44-37j8", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-jg22-mg44-37j8"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-jg22-mg44-37j8.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jg22-mg44-37j8\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f1c3425615956a24", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-jj3x-wxrx-4x23", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-jj3x-wxrx-4x23"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-jj3x-wxrx-4x23.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jj3x-wxrx-4x23\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0b3170f2b2f878c1", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-m5qp-6w8w-w647", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-m5qp-6w8w-w647"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-m5qp-6w8w-w647.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-m5qp-6w8w-w647\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-16dfe03ea34e1957", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-m6qw-4cw2-hm4m", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-m6qw-4cw2-hm4m"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-m6qw-4cw2-hm4m.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-m6qw-4cw2-hm4m\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7b282df70afd8044", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-mqqc-3gqh-h2x8", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-mqqc-3gqh-h2x8"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-mqqc-3gqh-h2x8.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mqqc-3gqh-h2x8\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7e9d68b44010f187", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-mwh4-6h8g-pg8w", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-mwh4-6h8g-pg8w"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-mwh4-6h8g-pg8w.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mwh4-6h8g-pg8w\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ef8fdbfb37390ec4", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-p998-jp59-783m", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-p998-jp59-783m"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-p998-jp59-783m.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p998-jp59-783m\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e0288627e2f42897", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-w2fm-2cpv-w7v5", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-w2fm-2cpv-w7v5"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-w2fm-2cpv-w7v5.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w2fm-2cpv-w7v5\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dfea9a62dec577dc", "name": "Vulnerable dependency aiohttp 3.12.6: GHSA-xcgm-r5h9-7989", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-xcgm-r5h9-7989"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-xcgm-r5h9-7989.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xcgm-r5h9-7989\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c7e3597f5e874cb9", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1097", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1097"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-1097.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1097\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d3102c3cd05489c3", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1099", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1099"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-1099.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1099\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d7a5d2727942a419", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1100", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1100"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-1100.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1100\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-399a4b53ffccf1da", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1101", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1101"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-1101.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1101\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aa7126575e0859b4", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1104", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1104"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-1104.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1104\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9c728ae8d18008b3", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1105", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1105"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-1105.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1105\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9b97ae6c28f10726", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1106", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1106"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-1106.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1106\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2533a7495f6be6a5", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1107", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1107"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-1107.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1107\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-df14aa7a1179b1f9", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1109", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1109"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-1109.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1109\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-df375ca47e347310", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2094", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2094"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2094.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2094\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eaa372b610040fcc", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2095", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2095"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2095.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2095\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-50739925cbc8e39f", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2097", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2097"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2097.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2097\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ef6c2ae9b2f86e49", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2098", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2098"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2098.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2098\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-11fd49cd2312eb74", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2100", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2100"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2100.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2100\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f7c2d12502193be4", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2101", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2101"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2101.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2101\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-24ad4c7f5fdb8128", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2102", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2102"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2102.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2102\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e5d81b2f6e4e3541", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2103", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2103"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2103.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2103\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c91a537c5ca59f60", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2104", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2104"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2104.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2104\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-501988317a274659", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2105", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2105"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2105.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2105\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-96007ce9d8897f16", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2106", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2106"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2106.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2106\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7cb4f44f56f33088", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2108", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2108"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2108.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2108\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7aaddd600d288926", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2109", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2109"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2109.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2109\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9b9f32d26884b623", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2110", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2110"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2110.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2110\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2372db1554f82fc0", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2111", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2111"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2111.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2111\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bdcb74fa87cc876e", "name": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2113", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2113"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.6` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2113.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2113\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f6ee4907d59a4e0f", "name": "Vulnerable dependency click 8.2.1: PYSEC-2026-2132", "shortDescription": {"text": "Vulnerable dependency click 8.2.1: PYSEC-2026-2132"}, "fullDescription": {"text": "OSV.dev reports `click` at version `8.2.1` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2132.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2132\nFix: upgrade `click` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-56346a9e7ea90bbc", "name": "Vulnerable dependency gitpython 3.1.44: GHSA-2f96-g7mh-g2hx", "shortDescription": {"text": "Vulnerable dependency gitpython 3.1.44: GHSA-2f96-g7mh-g2hx"}, "fullDescription": {"text": "OSV.dev reports `gitpython` at version `3.1.44` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-2f96-g7mh-g2hx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-2f96-g7mh-g2hx\nFix: upgrade `gitpython` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fbdec05475a3fa9a", "name": "Vulnerable dependency gitpython 3.1.44: GHSA-7545-fcxq-7j24", "shortDescription": {"text": "Vulnerable dependency gitpython 3.1.44: GHSA-7545-fcxq-7j24"}, "fullDescription": {"text": "OSV.dev reports `gitpython` at version `3.1.44` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-7545-fcxq-7j24.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-7545-fcxq-7j24\nFix: upgrade `gitpython` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-23df121e023af519", "name": "Vulnerable dependency gitpython 3.1.44: GHSA-956x-8gvw-wg5v", "shortDescription": {"text": "Vulnerable dependency gitpython 3.1.44: GHSA-956x-8gvw-wg5v"}, "fullDescription": {"text": "OSV.dev reports `gitpython` at version `3.1.44` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-956x-8gvw-wg5v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-956x-8gvw-wg5v\nFix: upgrade `gitpython` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d06118c4c1dd4228", "name": "Vulnerable dependency gitpython 3.1.44: GHSA-mv93-w799-cj2w", "shortDescription": {"text": "Vulnerable dependency gitpython 3.1.44: GHSA-mv93-w799-cj2w"}, "fullDescription": {"text": "OSV.dev reports `gitpython` at version `3.1.44` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-mv93-w799-cj2w.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mv93-w799-cj2w\nFix: upgrade `gitpython` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dfd77c6ec01f5a08", "name": "Vulnerable dependency gitpython 3.1.44: GHSA-rpm5-65cw-6hj4", "shortDescription": {"text": "Vulnerable dependency gitpython 3.1.44: GHSA-rpm5-65cw-6hj4"}, "fullDescription": {"text": "OSV.dev reports `gitpython` at version `3.1.44` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-rpm5-65cw-6hj4.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rpm5-65cw-6hj4\nFix: upgrade `gitpython` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2ce08b845b170e46", "name": "Vulnerable dependency gitpython 3.1.44: GHSA-rwj8-pgh3-r573", "shortDescription": {"text": "Vulnerable dependency gitpython 3.1.44: GHSA-rwj8-pgh3-r573"}, "fullDescription": {"text": "OSV.dev reports `gitpython` at version `3.1.44` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-rwj8-pgh3-r573.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rwj8-pgh3-r573\nFix: upgrade `gitpython` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dccadf61db2cd2bb", "name": "Vulnerable dependency gitpython 3.1.44: GHSA-v87r-6q3f-2j67", "shortDescription": {"text": "Vulnerable dependency gitpython 3.1.44: GHSA-v87r-6q3f-2j67"}, "fullDescription": {"text": "OSV.dev reports `gitpython` at version `3.1.44` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-v87r-6q3f-2j67.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v87r-6q3f-2j67\nFix: upgrade `gitpython` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-51f142bd8e15a20e", "name": "Vulnerable dependency gitpython 3.1.44: GHSA-x2qx-6953-8485", "shortDescription": {"text": "Vulnerable dependency gitpython 3.1.44: GHSA-x2qx-6953-8485"}, "fullDescription": {"text": "OSV.dev reports `gitpython` at version `3.1.44` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-x2qx-6953-8485.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-x2qx-6953-8485\nFix: upgrade `gitpython` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-88a30670956769c2", "name": "Vulnerable dependency gitpython 3.1.44: PYSEC-2026-2160", "shortDescription": {"text": "Vulnerable dependency gitpython 3.1.44: PYSEC-2026-2160"}, "fullDescription": {"text": "OSV.dev reports `gitpython` at version `3.1.44` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-2160.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2160\nFix: upgrade `gitpython` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0703d01599e1b3e6", "name": "Vulnerable dependency gitpython 3.1.44: PYSEC-2026-2161", "shortDescription": {"text": "Vulnerable dependency gitpython 3.1.44: PYSEC-2026-2161"}, "fullDescription": {"text": "OSV.dev reports `gitpython` at version `3.1.44` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-2161.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2161\nFix: upgrade `gitpython` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-13d61b7424fc860c", "name": "Vulnerable dependency gitpython 3.1.44: PYSEC-2026-2162", "shortDescription": {"text": "Vulnerable dependency gitpython 3.1.44: PYSEC-2026-2162"}, "fullDescription": {"text": "OSV.dev reports `gitpython` at version `3.1.44` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-2162.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2162\nFix: upgrade `gitpython` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2eb88effe9bb9e73", "name": "Vulnerable dependency gitpython 3.1.44: PYSEC-2026-2163", "shortDescription": {"text": "Vulnerable dependency gitpython 3.1.44: PYSEC-2026-2163"}, "fullDescription": {"text": "OSV.dev reports `gitpython` at version `3.1.44` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-2163.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2163\nFix: upgrade `gitpython` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3dba88bf6c9678c9", "name": "Vulnerable dependency h2 4.2.0: GHSA-847f-9342-265h", "shortDescription": {"text": "Vulnerable dependency h2 4.2.0: GHSA-847f-9342-265h"}, "fullDescription": {"text": "OSV.dev reports `h2` at version `4.2.0` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-847f-9342-265h.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-847f-9342-265h\nFix: upgrade `h2` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-599e0119804a5427", "name": "Vulnerable dependency h2 4.2.0: PYSEC-2026-1435", "shortDescription": {"text": "Vulnerable dependency h2 4.2.0: PYSEC-2026-1435"}, "fullDescription": {"text": "OSV.dev reports `h2` at version `4.2.0` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-1435.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1435\nFix: upgrade `h2` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-81ba7c156ede9306", "name": "Vulnerable dependency idna 3.10: GHSA-65pc-fj4g-8rjx", "shortDescription": {"text": "Vulnerable dependency idna 3.10: GHSA-65pc-fj4g-8rjx"}, "fullDescription": {"text": "OSV.dev reports `idna` at version `3.10` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-65pc-fj4g-8rjx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-65pc-fj4g-8rjx\nFix: upgrade `idna` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fe83bd5958898558", "name": "Vulnerable dependency idna 3.10: PYSEC-2026-215", "shortDescription": {"text": "Vulnerable dependency idna 3.10: PYSEC-2026-215"}, "fullDescription": {"text": "OSV.dev reports `idna` at version `3.10` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-215.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-215\nFix: upgrade `idna` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fb9ef090a27dccdd", "name": "Vulnerable dependency mem0ai 0.1.102: GHSA-cgx8-qgvr-f7vf", "shortDescription": {"text": "Vulnerable dependency mem0ai 0.1.102: GHSA-cgx8-qgvr-f7vf"}, "fullDescription": {"text": "OSV.dev reports `mem0ai` at version `0.1.102` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-cgx8-qgvr-f7vf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-cgx8-qgvr-f7vf\nFix: upgrade `mem0ai` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5f50c0c9f906b360", "name": "Vulnerable dependency mem0ai 0.1.102: GHSA-gq6f-qwv9-rf4j", "shortDescription": {"text": "Vulnerable dependency mem0ai 0.1.102: GHSA-gq6f-qwv9-rf4j"}, "fullDescription": {"text": "OSV.dev reports `mem0ai` at version `0.1.102` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-gq6f-qwv9-rf4j.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gq6f-qwv9-rf4j\nFix: upgrade `mem0ai` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f071f9c0bd81cebc", "name": "Vulnerable dependency mem0ai 0.1.102: GHSA-jfv9-68m5-gjjr", "shortDescription": {"text": "Vulnerable dependency mem0ai 0.1.102: GHSA-jfv9-68m5-gjjr"}, "fullDescription": {"text": "OSV.dev reports `mem0ai` at version `0.1.102` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-jfv9-68m5-gjjr.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jfv9-68m5-gjjr\nFix: upgrade `mem0ai` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-07bf0f76bd23d38a", "name": "Vulnerable dependency mem0ai 0.1.102: GHSA-xqxw-r767-67m7", "shortDescription": {"text": "Vulnerable dependency mem0ai 0.1.102: GHSA-xqxw-r767-67m7"}, "fullDescription": {"text": "OSV.dev reports `mem0ai` at version `0.1.102` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-xqxw-r767-67m7.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xqxw-r767-67m7\nFix: upgrade `mem0ai` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0922b48893e45be1", "name": "Vulnerable dependency mem0ai 0.1.102: PYSEC-2026-2633", "shortDescription": {"text": "Vulnerable dependency mem0ai 0.1.102: PYSEC-2026-2633"}, "fullDescription": {"text": "OSV.dev reports `mem0ai` at version `0.1.102` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2633.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2633\nFix: upgrade `mem0ai` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cfe2837b2d9ec571", "name": "Vulnerable dependency mem0ai 0.1.102: PYSEC-2026-2634", "shortDescription": {"text": "Vulnerable dependency mem0ai 0.1.102: PYSEC-2026-2634"}, "fullDescription": {"text": "OSV.dev reports `mem0ai` at version `0.1.102` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2634.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2634\nFix: upgrade `mem0ai` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c734b48858cc7f44", "name": "Vulnerable dependency mem0ai 0.1.102: PYSEC-2026-2635", "shortDescription": {"text": "Vulnerable dependency mem0ai 0.1.102: PYSEC-2026-2635"}, "fullDescription": {"text": "OSV.dev reports `mem0ai` at version `0.1.102` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2635.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2635\nFix: upgrade `mem0ai` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-261329f4f16f17fe", "name": "Vulnerable dependency mem0ai 0.1.102: PYSEC-2026-2636", "shortDescription": {"text": "Vulnerable dependency mem0ai 0.1.102: PYSEC-2026-2636"}, "fullDescription": {"text": "OSV.dev reports `mem0ai` at version `0.1.102` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-2636.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2636\nFix: upgrade `mem0ai` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5027315bcb24ff20", "name": "Vulnerable dependency protobuf 6.31.1: GHSA-7gcm-g887-7qv7", "shortDescription": {"text": "Vulnerable dependency protobuf 6.31.1: GHSA-7gcm-g887-7qv7"}, "fullDescription": {"text": "OSV.dev reports `protobuf` at version `6.31.1` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-7gcm-g887-7qv7.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-7gcm-g887-7qv7\nFix: upgrade `protobuf` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-15f89a3ba893666e", "name": "Vulnerable dependency protobuf 6.31.1: PYSEC-2026-1805", "shortDescription": {"text": "Vulnerable dependency protobuf 6.31.1: PYSEC-2026-1805"}, "fullDescription": {"text": "OSV.dev reports `protobuf` at version `6.31.1` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-1805.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1805\nFix: upgrade `protobuf` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7fbf26228463805b", "name": "Vulnerable dependency pyasn1 0.6.1: GHSA-63vm-454h-vhhq", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.1: GHSA-63vm-454h-vhhq"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.1` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-63vm-454h-vhhq.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-63vm-454h-vhhq\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-470d6112a4d90d65", "name": "Vulnerable dependency pyasn1 0.6.1: GHSA-8ppf-4f7h-5ppj", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.1: GHSA-8ppf-4f7h-5ppj"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.1` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-8ppf-4f7h-5ppj.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8ppf-4f7h-5ppj\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1a9e1ece58347580", "name": "Vulnerable dependency pyasn1 0.6.1: GHSA-hm4w-wwcw-mr6r", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.1: GHSA-hm4w-wwcw-mr6r"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.1` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-hm4w-wwcw-mr6r.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hm4w-wwcw-mr6r\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5a071fa1c5ca1b33", "name": "Vulnerable dependency pyasn1 0.6.1: GHSA-jr27-m4p2-rc6r", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.1: GHSA-jr27-m4p2-rc6r"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.1` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-jr27-m4p2-rc6r.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jr27-m4p2-rc6r\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-782f39797ff0711f", "name": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-1810", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-1810"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.1` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-1810.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1810\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-11200cdd7bfea923", "name": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-2263", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-2263"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.1` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-2263.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2263\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-df3981f12693b1bd", "name": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3455", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3455"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.1` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-3455.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3455\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f008a1d5687f4a65", "name": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3456", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3456"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.1` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-3456.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3456\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f20b3f488a5e53d6", "name": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3457", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3457"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.1` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-3457.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3457\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-650d99b27fbbe9db", "name": "Vulnerable dependency pygments 2.19.1: GHSA-5239-wwwm-4pmq", "shortDescription": {"text": "Vulnerable dependency pygments 2.19.1: GHSA-5239-wwwm-4pmq"}, "fullDescription": {"text": "OSV.dev reports `pygments` at version `2.19.1` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-5239-wwwm-4pmq.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-5239-wwwm-4pmq\nFix: upgrade `pygments` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-186ea5b4d906f6c4", "name": "Vulnerable dependency pygments 2.19.1: PYSEC-2026-2987", "shortDescription": {"text": "Vulnerable dependency pygments 2.19.1: PYSEC-2026-2987"}, "fullDescription": {"text": "OSV.dev reports `pygments` at version `2.19.1` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-2987.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2987\nFix: upgrade `pygments` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4f42112bc2e80a54", "name": "Vulnerable dependency pytest 8.3.5: GHSA-6w46-j5rx-g56g", "shortDescription": {"text": "Vulnerable dependency pytest 8.3.5: GHSA-6w46-j5rx-g56g"}, "fullDescription": {"text": "OSV.dev reports `pytest` at version `8.3.5` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by GHSA-6w46-j5rx-g56g.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6w46-j5rx-g56g\nFix: upgrade `pytest` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9f399a73d9f84ebf", "name": "Vulnerable dependency pytest 8.3.5: PYSEC-2026-1845", "shortDescription": {"text": "Vulnerable dependency pytest 8.3.5: PYSEC-2026-1845"}, "fullDescription": {"text": "OSV.dev reports `pytest` at version `8.3.5` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock`) is affected by PYSEC-2026-1845.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1845\nFix: upgrade `pytest` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f9a44dcfab63eba7", "name": "Vulnerable dependency python-dotenv 1.1.0: GHSA-mf9w-mj56-hr94", "shortDescription": {"text": "Vulnerable dependency python-dotenv 1.1.0: GHSA-mf9w-mj56-hr94"}, "fullDescription": {"text": "OSV.dev reports `python-dotenv` at version `1.1.0` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-mf9w-mj56-hr94.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mf9w-mj56-hr94\nFix: upgrade `python-dotenv` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dd3ef06c2eec2234", "name": "Vulnerable dependency python-dotenv 1.1.0: PYSEC-2026-2270", "shortDescription": {"text": "Vulnerable dependency python-dotenv 1.1.0: PYSEC-2026-2270"}, "fullDescription": {"text": "OSV.dev reports `python-dotenv` at version `1.1.0` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-2270.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2270\nFix: upgrade `python-dotenv` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-49686e89d9b8742a", "name": "Vulnerable dependency python-multipart 0.0.20: GHSA-5rvq-cxj2-64vf", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.20: GHSA-5rvq-cxj2-64vf"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.20` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-5rvq-cxj2-64vf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-5rvq-cxj2-64vf\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-06649765a144f32c", "name": "Vulnerable dependency python-multipart 0.0.20: GHSA-6jv3-5f52-599m", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.20: GHSA-6jv3-5f52-599m"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.20` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-6jv3-5f52-599m.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6jv3-5f52-599m\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e3f56f829239e231", "name": "Vulnerable dependency python-multipart 0.0.20: GHSA-mj87-hwqh-73pj", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.20: GHSA-mj87-hwqh-73pj"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.20` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-mj87-hwqh-73pj.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mj87-hwqh-73pj\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4b80a4994a090c6a", "name": "Vulnerable dependency python-multipart 0.0.20: GHSA-pp6c-gr5w-3c5g", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.20: GHSA-pp6c-gr5w-3c5g"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.20` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-pp6c-gr5w-3c5g.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pp6c-gr5w-3c5g\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d300907710daee1f", "name": "Vulnerable dependency python-multipart 0.0.20: GHSA-v9pg-7xvm-68hf", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.20: GHSA-v9pg-7xvm-68hf"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.20` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-v9pg-7xvm-68hf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v9pg-7xvm-68hf\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bc259b4c527b353a", "name": "Vulnerable dependency python-multipart 0.0.20: GHSA-vffw-93wf-4j4q", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.20: GHSA-vffw-93wf-4j4q"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.20` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-vffw-93wf-4j4q.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vffw-93wf-4j4q\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-afc563be12710e46", "name": "Vulnerable dependency python-multipart 0.0.20: GHSA-wp53-j4wj-2cfg", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.20: GHSA-wp53-j4wj-2cfg"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.20` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-wp53-j4wj-2cfg.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wp53-j4wj-2cfg\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-96455aad9cbe5dba", "name": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-1852", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-1852"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.20` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-1852.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1852\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-46c008b7cdc3c743", "name": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-3036", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-3036"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.20` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-3036.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3036\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0dc9da349d54f592", "name": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-3037", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-3037"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.20` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-3037.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3037\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-898b2e747719b517", "name": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-3038", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-3038"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.20` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-3038.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3038\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-de9d09c97366e3fc", "name": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-3039", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-3039"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.20` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-3039.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3039\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bee0e69c84d7132c", "name": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-3040", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-3040"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.20` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-3040.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3040\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0aec62f3aa56be46", "name": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-3041", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-3041"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.20` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-3041.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3041\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-74843c1929b64b79", "name": "Vulnerable dependency requests 2.32.3: GHSA-9hjg-9r4m-mvj7", "shortDescription": {"text": "Vulnerable dependency requests 2.32.3: GHSA-9hjg-9r4m-mvj7"}, "fullDescription": {"text": "OSV.dev reports `requests` at version `2.32.3` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-9hjg-9r4m-mvj7.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9hjg-9r4m-mvj7\nFix: upgrade `requests` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7a33c32467acd12b", "name": "Vulnerable dependency requests 2.32.3: GHSA-gc5v-m9x4-r6x2", "shortDescription": {"text": "Vulnerable dependency requests 2.32.3: GHSA-gc5v-m9x4-r6x2"}, "fullDescription": {"text": "OSV.dev reports `requests` at version `2.32.3` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by GHSA-gc5v-m9x4-r6x2.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gc5v-m9x4-r6x2\nFix: upgrade `requests` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-748056b95c60a7e5", "name": "Vulnerable dependency requests 2.32.3: PYSEC-2026-1872", "shortDescription": {"text": "Vulnerable dependency requests 2.32.3: PYSEC-2026-1872"}, "fullDescription": {"text": "OSV.dev reports `requests` at version `2.32.3` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-1872.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1872\nFix: upgrade `requests` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-128ec0dbaed4496b", "name": "Vulnerable dependency requests 2.32.3: PYSEC-2026-2275", "shortDescription": {"text": "Vulnerable dependency requests 2.32.3: PYSEC-2026-2275"}, "fullDescription": {"text": "OSV.dev reports `requests` at version `2.32.3` (declared in `advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt`) is affected by PYSEC-2026-2275.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2275\nFix: upgrade `requests` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9a123c9e344a2675", "name": "Vulnerable dependency starlette 0.46.2: GHSA-2c2j-9gv5-cj73", "shortDescription": {"text": "Vulnerable dependency starlette 0.46.2: GHSA-2c2j-9gv5-cj73"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.46.2` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-2c2j-9gv5-cj73.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-2c2j-9gv5-cj73\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-30b296101ff59fbb", "name": "Vulnerable dependency starlette 0.46.2: GHSA-7f5h-v6xp-fcq8", "shortDescription": {"text": "Vulnerable dependency starlette 0.46.2: GHSA-7f5h-v6xp-fcq8"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.46.2` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-7f5h-v6xp-fcq8.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-7f5h-v6xp-fcq8\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-179c1c219207eb2b", "name": "Vulnerable dependency starlette 0.46.2: GHSA-82w8-qh3p-5jfq", "shortDescription": {"text": "Vulnerable dependency starlette 0.46.2: GHSA-82w8-qh3p-5jfq"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.46.2` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-82w8-qh3p-5jfq.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-82w8-qh3p-5jfq\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-677edecf6ab66014", "name": "Vulnerable dependency starlette 0.46.2: GHSA-86qp-5c8j-p5mr", "shortDescription": {"text": "Vulnerable dependency starlette 0.46.2: GHSA-86qp-5c8j-p5mr"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.46.2` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-86qp-5c8j-p5mr.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-86qp-5c8j-p5mr\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-99acd821a9de3b5c", "name": "Vulnerable dependency starlette 0.46.2: GHSA-jp82-jpqv-5vv3", "shortDescription": {"text": "Vulnerable dependency starlette 0.46.2: GHSA-jp82-jpqv-5vv3"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.46.2` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-jp82-jpqv-5vv3.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jp82-jpqv-5vv3\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-170da18f7077eeab", "name": "Vulnerable dependency starlette 0.46.2: GHSA-wqp7-x3pw-xc5r", "shortDescription": {"text": "Vulnerable dependency starlette 0.46.2: GHSA-wqp7-x3pw-xc5r"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.46.2` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-wqp7-x3pw-xc5r.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wqp7-x3pw-xc5r\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-42d88c1b398c0576", "name": "Vulnerable dependency starlette 0.46.2: GHSA-x746-7m8f-x49c", "shortDescription": {"text": "Vulnerable dependency starlette 0.46.2: GHSA-x746-7m8f-x49c"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.46.2` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-x746-7m8f-x49c.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-x746-7m8f-x49c\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a49b7496266d3f5c", "name": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-161", "shortDescription": {"text": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-161"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.46.2` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-161.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-161\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8de9337408fa0766", "name": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-1941", "shortDescription": {"text": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-1941"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.46.2` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-1941.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1941\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-20559aa906fc1ef2", "name": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-1942", "shortDescription": {"text": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-1942"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.46.2` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-1942.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1942\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-68f3d0d1cdcbda74", "name": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-2280", "shortDescription": {"text": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-2280"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.46.2` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-2280.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2280\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-795b90303383c9a9", "name": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-2281", "shortDescription": {"text": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-2281"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.46.2` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-2281.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2281\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1d7adc6af694fc2a", "name": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-248", "shortDescription": {"text": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-248"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.46.2` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-248.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-248\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-44e6cd02b30a52b3", "name": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-249", "shortDescription": {"text": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-249"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.46.2` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-249.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-249\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6c22ce5017cfa400", "name": "Vulnerable dependency urllib3 2.4.0: GHSA-2xpw-w6gg-jr37", "shortDescription": {"text": "Vulnerable dependency urllib3 2.4.0: GHSA-2xpw-w6gg-jr37"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.4.0` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-2xpw-w6gg-jr37.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-2xpw-w6gg-jr37\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6eaf9142750ed99a", "name": "Vulnerable dependency urllib3 2.4.0: GHSA-38jv-5279-wg99", "shortDescription": {"text": "Vulnerable dependency urllib3 2.4.0: GHSA-38jv-5279-wg99"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.4.0` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-38jv-5279-wg99.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-38jv-5279-wg99\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-212dabf1482f8852", "name": "Vulnerable dependency urllib3 2.4.0: GHSA-48p4-8xcf-vxj5", "shortDescription": {"text": "Vulnerable dependency urllib3 2.4.0: GHSA-48p4-8xcf-vxj5"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.4.0` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-48p4-8xcf-vxj5.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-48p4-8xcf-vxj5\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4f3366091d009050", "name": "Vulnerable dependency urllib3 2.4.0: GHSA-gm62-xv2j-4w53", "shortDescription": {"text": "Vulnerable dependency urllib3 2.4.0: GHSA-gm62-xv2j-4w53"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.4.0` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-gm62-xv2j-4w53.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gm62-xv2j-4w53\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5d66f1fa7a3c0872", "name": "Vulnerable dependency urllib3 2.4.0: GHSA-pq67-6m6q-mj2v", "shortDescription": {"text": "Vulnerable dependency urllib3 2.4.0: GHSA-pq67-6m6q-mj2v"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.4.0` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-pq67-6m6q-mj2v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pq67-6m6q-mj2v\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-66d913f223d3edc8", "name": "Vulnerable dependency urllib3 2.4.0: GHSA-qccp-gfcp-xxvc", "shortDescription": {"text": "Vulnerable dependency urllib3 2.4.0: GHSA-qccp-gfcp-xxvc"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.4.0` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-qccp-gfcp-xxvc.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qccp-gfcp-xxvc\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e0c716881d5fe073", "name": "Vulnerable dependency urllib3 2.4.0: PYSEC-2026-141", "shortDescription": {"text": "Vulnerable dependency urllib3 2.4.0: PYSEC-2026-141"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.4.0` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-141.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-141\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a22f51fc9de629f6", "name": "Vulnerable dependency urllib3 2.4.0: PYSEC-2026-1994", "shortDescription": {"text": "Vulnerable dependency urllib3 2.4.0: PYSEC-2026-1994"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.4.0` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-1994.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1994\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-38632d6285de9bcb", "name": "Vulnerable dependency urllib3 2.4.0: PYSEC-2026-1996", "shortDescription": {"text": "Vulnerable dependency urllib3 2.4.0: PYSEC-2026-1996"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.4.0` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-1996.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1996\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fb6c5d3a218172d1", "name": "Vulnerable dependency urllib3 2.4.0: PYSEC-2026-1997", "shortDescription": {"text": "Vulnerable dependency urllib3 2.4.0: PYSEC-2026-1997"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.4.0` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-1997.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1997\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-90450112510e1c7c", "name": "Vulnerable dependency urllib3 2.4.0: PYSEC-2026-1998", "shortDescription": {"text": "Vulnerable dependency urllib3 2.4.0: PYSEC-2026-1998"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.4.0` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-1998.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1998\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28096e034d4da2d9", "name": "Vulnerable dependency urllib3 2.4.0: PYSEC-2026-1999", "shortDescription": {"text": "Vulnerable dependency urllib3 2.4.0: PYSEC-2026-1999"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.4.0` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-1999.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1999\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7b609220a3384bcb", "name": "Vulnerable dependency better-auth 1.2.8: GHSA-2vg6-77g8-24mp", "shortDescription": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-2vg6-77g8-24mp"}, "fullDescription": {"text": "OSV.dev reports `better-auth` at version `1.2.8` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-2vg6-77g8-24mp.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-2vg6-77g8-24mp\nFix: upgrade `better-auth` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e807eaa175b7dba", "name": "Vulnerable dependency better-auth 1.2.8: GHSA-36rg-gfq2-3h56", "shortDescription": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-36rg-gfq2-3h56"}, "fullDescription": {"text": "OSV.dev reports `better-auth` at version `1.2.8` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-36rg-gfq2-3h56.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-36rg-gfq2-3h56\nFix: upgrade `better-auth` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0cf9d5cebbba24df", "name": "Vulnerable dependency better-auth 1.2.8: GHSA-569q-mpph-wgww", "shortDescription": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-569q-mpph-wgww"}, "fullDescription": {"text": "OSV.dev reports `better-auth` at version `1.2.8` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-569q-mpph-wgww.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-569q-mpph-wgww\nFix: upgrade `better-auth` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3a45d5e8fee0413c", "name": "Vulnerable dependency better-auth 1.2.8: GHSA-7w99-5wm4-3g79", "shortDescription": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-7w99-5wm4-3g79"}, "fullDescription": {"text": "OSV.dev reports `better-auth` at version `1.2.8` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-7w99-5wm4-3g79.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-7w99-5wm4-3g79\nFix: upgrade `better-auth` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3fa68a03d953891f", "name": "Vulnerable dependency better-auth 1.2.8: GHSA-86j7-9j95-vpqj", "shortDescription": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-86j7-9j95-vpqj"}, "fullDescription": {"text": "OSV.dev reports `better-auth` at version `1.2.8` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-86j7-9j95-vpqj.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-86j7-9j95-vpqj\nFix: upgrade `better-auth` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-257a4df60d2073e3", "name": "Vulnerable dependency better-auth 1.2.8: GHSA-99h5-pjcv-gr6v", "shortDescription": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-99h5-pjcv-gr6v"}, "fullDescription": {"text": "OSV.dev reports `better-auth` at version `1.2.8` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-99h5-pjcv-gr6v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-99h5-pjcv-gr6v\nFix: upgrade `better-auth` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-efed22d8b242c21f", "name": "Vulnerable dependency better-auth 1.2.8: GHSA-9h47-pqcx-hjr4", "shortDescription": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-9h47-pqcx-hjr4"}, "fullDescription": {"text": "OSV.dev reports `better-auth` at version `1.2.8` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-9h47-pqcx-hjr4.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9h47-pqcx-hjr4\nFix: upgrade `better-auth` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-38e32962c3439ba7", "name": "Vulnerable dependency better-auth 1.2.8: GHSA-fmh4-wcc4-5jm3", "shortDescription": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-fmh4-wcc4-5jm3"}, "fullDescription": {"text": "OSV.dev reports `better-auth` at version `1.2.8` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-fmh4-wcc4-5jm3.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fmh4-wcc4-5jm3\nFix: upgrade `better-auth` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-edfcd7ad190df690", "name": "Vulnerable dependency better-auth 1.2.8: GHSA-g38m-r43w-p2q7", "shortDescription": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-g38m-r43w-p2q7"}, "fullDescription": {"text": "OSV.dev reports `better-auth` at version `1.2.8` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-g38m-r43w-p2q7.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-g38m-r43w-p2q7\nFix: upgrade `better-auth` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7974783fa5f2312d", "name": "Vulnerable dependency better-auth 1.2.8: GHSA-p6v2-xcpg-h6xw", "shortDescription": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-p6v2-xcpg-h6xw"}, "fullDescription": {"text": "OSV.dev reports `better-auth` at version `1.2.8` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-p6v2-xcpg-h6xw.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p6v2-xcpg-h6xw\nFix: upgrade `better-auth` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e418b75b567f9e3", "name": "Vulnerable dependency better-auth 1.2.8: GHSA-pw9m-5jxm-xr6h", "shortDescription": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-pw9m-5jxm-xr6h"}, "fullDescription": {"text": "OSV.dev reports `better-auth` at version `1.2.8` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-pw9m-5jxm-xr6h.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pw9m-5jxm-xr6h\nFix: upgrade `better-auth` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-69909e6552e8998c", "name": "Vulnerable dependency better-auth 1.2.8: GHSA-wxw3-q3m9-c3jr", "shortDescription": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-wxw3-q3m9-c3jr"}, "fullDescription": {"text": "OSV.dev reports `better-auth` at version `1.2.8` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-wxw3-q3m9-c3jr.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wxw3-q3m9-c3jr\nFix: upgrade `better-auth` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2b5343a0c2da46c6", "name": "Vulnerable dependency better-auth 1.2.8: GHSA-x732-6j76-qmhm", "shortDescription": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-x732-6j76-qmhm"}, "fullDescription": {"text": "OSV.dev reports `better-auth` at version `1.2.8` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-x732-6j76-qmhm.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-x732-6j76-qmhm\nFix: upgrade `better-auth` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-777bb3e971b0912b", "name": "Vulnerable dependency better-auth 1.2.8: GHSA-xg6x-h9c9-2m83", "shortDescription": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-xg6x-h9c9-2m83"}, "fullDescription": {"text": "OSV.dev reports `better-auth` at version `1.2.8` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-xg6x-h9c9-2m83.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xg6x-h9c9-2m83\nFix: upgrade `better-auth` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5da10e8c8e832db7", "name": "Vulnerable dependency next 15.3.3: GHSA-267c-6grr-h53f", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-267c-6grr-h53f"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-267c-6grr-h53f (aka CVE-2026-44575).\n\nNext.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes\n\nAliases: CVE-2026-44575\nAdvisory: https://osv.dev/vulnerability/GHSA-267c-6grr-h53f\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c662c4f78e841fd6", "name": "Vulnerable dependency next 15.3.3: GHSA-26hh-7cqf-hhc6", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-26hh-7cqf-hhc6"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-26hh-7cqf-hhc6 (aka CVE-2026-45109).\n\nNext.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up\n\nAliases: CVE-2026-45109\nAdvisory: https://osv.dev/vulnerability/GHSA-26hh-7cqf-hhc6\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-20c59a52543d948c", "name": "Vulnerable dependency next 15.3.3: GHSA-36qx-fr4f-26g5", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-36qx-fr4f-26g5"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-36qx-fr4f-26g5 (aka CVE-2026-44573).\n\nNext.js has a Middleware / Proxy bypass in Pages Router applications using i18n\n\nAliases: CVE-2026-44573\nAdvisory: https://osv.dev/vulnerability/GHSA-36qx-fr4f-26g5\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dcaf034db29b0769", "name": "Vulnerable dependency next 15.3.3: GHSA-3g8h-86w9-wvmq", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-3g8h-86w9-wvmq"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-3g8h-86w9-wvmq (aka CVE-2026-44572).\n\nNext.js's Middleware / Proxy redirects can be cache-poisoned\n\nAliases: CVE-2026-44572\nAdvisory: https://osv.dev/vulnerability/GHSA-3g8h-86w9-wvmq\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b36f4917ac1bf954", "name": "Vulnerable dependency next 15.3.3: GHSA-3x4c-7xq6-9pq8", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-3x4c-7xq6-9pq8"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-3x4c-7xq6-9pq8 (aka CVE-2026-27980).\n\nNext.js: Unbounded next/image disk cache growth can exhaust storage\n\nAliases: CVE-2026-27980\nAdvisory: https://osv.dev/vulnerability/GHSA-3x4c-7xq6-9pq8\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9f18b2ae3ebe4935", "name": "Vulnerable dependency next 15.3.3: GHSA-4342-x723-ch2f", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-4342-x723-ch2f"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-4342-x723-ch2f.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-4342-x723-ch2f\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6e9864fca1357703", "name": "Vulnerable dependency next 15.3.3: GHSA-4633-3j49-mh5q", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-4633-3j49-mh5q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-4633-3j49-mh5q (aka CVE-2026-64647).\n\nNext.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\nAliases: CVE-2026-64647\nAdvisory: https://osv.dev/vulnerability/GHSA-4633-3j49-mh5q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-91d5f6593346a691", "name": "Vulnerable dependency next 15.3.3: GHSA-4c39-4ccg-62r3", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-4c39-4ccg-62r3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-4c39-4ccg-62r3 (aka CVE-2026-64646).\n\nNext.js: Unbounded Server Action payload in Edge runtime\n\nAliases: CVE-2026-64646\nAdvisory: https://osv.dev/vulnerability/GHSA-4c39-4ccg-62r3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1ce5be35c3336360", "name": "Vulnerable dependency next 15.3.3: GHSA-68g3-v927-f742", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-68g3-v927-f742"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-68g3-v927-f742 (aka CVE-2026-64648).\n\nNext.js: Cache confusion of response bodies for requests with bodies\n\nAliases: CVE-2026-64648\nAdvisory: https://osv.dev/vulnerability/GHSA-68g3-v927-f742\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9026c23407580f4f", "name": "Vulnerable dependency next 15.3.3: GHSA-89xv-2m56-2m9x", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-89xv-2m56-2m9x"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-89xv-2m56-2m9x (aka CVE-2026-64649).\n\nNext.js: Server-Side Request Forgery in Server Actions on custom servers\n\nAliases: CVE-2026-64649\nAdvisory: https://osv.dev/vulnerability/GHSA-89xv-2m56-2m9x\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-25babb73c6b5e08f", "name": "Vulnerable dependency next 15.3.3: GHSA-8h8q-6873-q5fj", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-8h8q-6873-q5fj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-8h8q-6873-q5fj.\n\nNext.js Vulnerable to Denial of Service with Server Components\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8h8q-6873-q5fj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e4952da4c5ddb0af", "name": "Vulnerable dependency next 15.3.3: GHSA-955p-x3mx-jcvp", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-955p-x3mx-jcvp"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-955p-x3mx-jcvp (aka CVE-2026-64643).\n\nNext.js: Unauthenticated disclosure of internal Server Function endpoints\n\nAliases: CVE-2026-64643\nAdvisory: https://osv.dev/vulnerability/GHSA-955p-x3mx-jcvp\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ced1ec76b2dd9305", "name": "Vulnerable dependency next 15.3.3: GHSA-9g9p-9gw9-jx7f", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-9g9p-9gw9-jx7f"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-9g9p-9gw9-jx7f.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9g9p-9gw9-jx7f\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d0f5da35f882dc34", "name": "Vulnerable dependency next 15.3.3: GHSA-9qr9-h5gf-34mp", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-9qr9-h5gf-34mp"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-9qr9-h5gf-34mp.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9qr9-h5gf-34mp\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-709b71355fe6f634", "name": "Vulnerable dependency next 15.3.3: GHSA-c4j6-fc7j-m34r", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-c4j6-fc7j-m34r"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-c4j6-fc7j-m34r (aka CVE-2026-44578).\n\nNext.js vulnerable to server-side request forgery in applications using WebSocket upgrades\n\nAliases: CVE-2026-44578\nAdvisory: https://osv.dev/vulnerability/GHSA-c4j6-fc7j-m34r\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6807b1cf47e05d30", "name": "Vulnerable dependency next 15.3.3: GHSA-ffhc-5mcf-pf4q", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-ffhc-5mcf-pf4q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-ffhc-5mcf-pf4q (aka CVE-2026-44581).\n\nNext.js vulnerable to cross-site scripting in App Router applications using CSP nonces\n\nAliases: CVE-2026-44581\nAdvisory: https://osv.dev/vulnerability/GHSA-ffhc-5mcf-pf4q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a2886d884e567448", "name": "Vulnerable dependency next 15.3.3: GHSA-g5qg-72qw-gw5v", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-g5qg-72qw-gw5v"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-g5qg-72qw-gw5v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-g5qg-72qw-gw5v\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-49bea8a3cbf28055", "name": "Vulnerable dependency next 15.3.3: GHSA-ggv3-7p47-pfv8", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-ggv3-7p47-pfv8"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-ggv3-7p47-pfv8 (aka CVE-2026-29057).\n\nNext.js: HTTP request smuggling in rewrites\n\nAliases: CVE-2026-29057\nAdvisory: https://osv.dev/vulnerability/GHSA-ggv3-7p47-pfv8\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-85b4c5189cc53309", "name": "Vulnerable dependency next 15.3.3: GHSA-gx5p-jg67-6x7h", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-gx5p-jg67-6x7h"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-gx5p-jg67-6x7h (aka CVE-2026-44580).\n\nNext.js has cross-site scripting in beforeInteractive scripts with untrusted input\n\nAliases: CVE-2026-44580\nAdvisory: https://osv.dev/vulnerability/GHSA-gx5p-jg67-6x7h\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1c6cb64e82353ee4", "name": "Vulnerable dependency next 15.3.3: GHSA-h25m-26qc-wcjf", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-h25m-26qc-wcjf"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-h25m-26qc-wcjf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-h25m-26qc-wcjf\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-abd9e2dd2baca3a3", "name": "Vulnerable dependency next 15.3.3: GHSA-h64f-5h5j-jqjh", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-h64f-5h5j-jqjh"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-h64f-5h5j-jqjh (aka CVE-2026-44577).\n\nNext.js has a Denial of Service in the Image Optimization API\n\nAliases: CVE-2026-44577\nAdvisory: https://osv.dev/vulnerability/GHSA-h64f-5h5j-jqjh\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b80a5d1ae604bb16", "name": "Vulnerable dependency next 15.3.3: GHSA-m99w-x7hq-7vfj", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-m99w-x7hq-7vfj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-m99w-x7hq-7vfj (aka CVE-2026-64641).\n\nNext.js: Denial of Service in App Router using Server Actions\n\nAliases: CVE-2026-64641\nAdvisory: https://osv.dev/vulnerability/GHSA-m99w-x7hq-7vfj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7224a862c3eeb23a", "name": "Vulnerable dependency next 15.3.3: GHSA-mg66-mrh9-m8jx", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-mg66-mrh9-m8jx"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-mg66-mrh9-m8jx (aka CVE-2026-44579).\n\nNext.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components\n\nAliases: CVE-2026-44579\nAdvisory: https://osv.dev/vulnerability/GHSA-mg66-mrh9-m8jx\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3cad4943eaa4f9d6", "name": "Vulnerable dependency next 15.3.3: GHSA-mwv6-3258-q52c", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-mwv6-3258-q52c"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-mwv6-3258-q52c.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mwv6-3258-q52c\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cb45d5b7663a38fe", "name": "Vulnerable dependency next 15.3.3: GHSA-p9j2-gv94-2wf4", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-p9j2-gv94-2wf4"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-p9j2-gv94-2wf4 (aka CVE-2026-64645).\n\nNext.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\nAliases: CVE-2026-64645\nAdvisory: https://osv.dev/vulnerability/GHSA-p9j2-gv94-2wf4\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-98096085a2c4306a", "name": "Vulnerable dependency next 15.3.3: GHSA-q4gf-8mx6-v5v3", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-q4gf-8mx6-v5v3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-q4gf-8mx6-v5v3.\n\nNext.js has a Denial of Service with Server Components\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q4gf-8mx6-v5v3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ae1145fe6d646e0f", "name": "Vulnerable dependency next 15.3.3: GHSA-vfv6-92ff-j949", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-vfv6-92ff-j949"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-vfv6-92ff-j949 (aka CVE-2026-44582).\n\nNext.js vulnerable to cache poisoning via collisions in React Server Component cache-busting\n\nAliases: CVE-2026-44582\nAdvisory: https://osv.dev/vulnerability/GHSA-vfv6-92ff-j949\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac1fa2c170311189", "name": "Vulnerable dependency next 15.3.3: GHSA-w37m-7fhw-fmv9", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-w37m-7fhw-fmv9"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-w37m-7fhw-fmv9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w37m-7fhw-fmv9\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-97f8cee7297a1bbc", "name": "Vulnerable dependency next 15.3.3: GHSA-wfc6-r584-vfw7", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-wfc6-r584-vfw7"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-wfc6-r584-vfw7 (aka CVE-2026-44576).\n\nNext.js vulnerable to cache poisoning in React Server Component responses\n\nAliases: CVE-2026-44576\nAdvisory: https://osv.dev/vulnerability/GHSA-wfc6-r584-vfw7\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2b9aec619e0c3a43", "name": "Vulnerable dependency next 15.3.3: GHSA-xv57-4mr9-wg8v", "shortDescription": {"text": "Vulnerable dependency next 15.3.3: GHSA-xv57-4mr9-wg8v"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-xv57-4mr9-wg8v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xv57-4mr9-wg8v\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4e19ec5a29905d86", "name": "Vulnerable dependency postcss 8.4.31: GHSA-6g55-p6wh-862q", "shortDescription": {"text": "Vulnerable dependency postcss 8.4.31: GHSA-6g55-p6wh-862q"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.4.31` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-6g55-p6wh-862q (aka CVE-2026-45623).\n\nPostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments\n\nAliases: CVE-2026-45623\nAdvisory: https://osv.dev/vulnerability/GHSA-6g55-p6wh-862q\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ac1de0e7a590a6db", "name": "Vulnerable dependency postcss 8.4.31: GHSA-qx2v-qp2m-jg93", "shortDescription": {"text": "Vulnerable dependency postcss 8.4.31: GHSA-qx2v-qp2m-jg93"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.4.31` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-qx2v-qp2m-jg93 (aka CVE-2026-41305).\n\nPostCSS has XSS via Unescaped </style> in its CSS Stringify Output\n\nAliases: CVE-2026-41305\nAdvisory: https://osv.dev/vulnerability/GHSA-qx2v-qp2m-jg93\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a64e0d4d479f868a", "name": "Vulnerable dependency postcss 8.5.4: GHSA-6g55-p6wh-862q", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.4: GHSA-6g55-p6wh-862q"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.4` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-6g55-p6wh-862q (aka CVE-2026-45623).\n\nPostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments\n\nAliases: CVE-2026-45623\nAdvisory: https://osv.dev/vulnerability/GHSA-6g55-p6wh-862q\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6ed4051c0564006b", "name": "Vulnerable dependency postcss 8.5.4: GHSA-qx2v-qp2m-jg93", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.4: GHSA-qx2v-qp2m-jg93"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.4` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-qx2v-qp2m-jg93 (aka CVE-2026-41305).\n\nPostCSS has XSS via Unescaped </style> in its CSS Stringify Output\n\nAliases: CVE-2026-41305\nAdvisory: https://osv.dev/vulnerability/GHSA-qx2v-qp2m-jg93\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-11cd97ebbbf20189", "name": "Vulnerable dependency tar 7.4.3: GHSA-23hp-3jrh-7fpw", "shortDescription": {"text": "Vulnerable dependency tar 7.4.3: GHSA-23hp-3jrh-7fpw"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `7.4.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-23hp-3jrh-7fpw.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-23hp-3jrh-7fpw\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f150a2229ae61a26", "name": "Vulnerable dependency tar 7.4.3: GHSA-34x7-hfp2-rc4v", "shortDescription": {"text": "Vulnerable dependency tar 7.4.3: GHSA-34x7-hfp2-rc4v"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `7.4.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-34x7-hfp2-rc4v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-34x7-hfp2-rc4v\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0323477449708360", "name": "Vulnerable dependency tar 7.4.3: GHSA-83g3-92jg-28cx", "shortDescription": {"text": "Vulnerable dependency tar 7.4.3: GHSA-83g3-92jg-28cx"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `7.4.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-83g3-92jg-28cx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-83g3-92jg-28cx\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fff91d36e8073c77", "name": "Vulnerable dependency tar 7.4.3: GHSA-8qq5-rm4j-mr97", "shortDescription": {"text": "Vulnerable dependency tar 7.4.3: GHSA-8qq5-rm4j-mr97"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `7.4.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-8qq5-rm4j-mr97.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8qq5-rm4j-mr97\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-64873ca0df37026c", "name": "Vulnerable dependency tar 7.4.3: GHSA-8x88-c5mf-7j5w", "shortDescription": {"text": "Vulnerable dependency tar 7.4.3: GHSA-8x88-c5mf-7j5w"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `7.4.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-8x88-c5mf-7j5w.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8x88-c5mf-7j5w\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6bd4be222882688c", "name": "Vulnerable dependency tar 7.4.3: GHSA-9ppj-qmqm-q256", "shortDescription": {"text": "Vulnerable dependency tar 7.4.3: GHSA-9ppj-qmqm-q256"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `7.4.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-9ppj-qmqm-q256.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9ppj-qmqm-q256\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d6f822e32a674755", "name": "Vulnerable dependency tar 7.4.3: GHSA-gvwx-54wh-qm9j", "shortDescription": {"text": "Vulnerable dependency tar 7.4.3: GHSA-gvwx-54wh-qm9j"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `7.4.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-gvwx-54wh-qm9j.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gvwx-54wh-qm9j\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bdd46a2a0fecbb63", "name": "Vulnerable dependency tar 7.4.3: GHSA-qffp-2rhf-9h96", "shortDescription": {"text": "Vulnerable dependency tar 7.4.3: GHSA-qffp-2rhf-9h96"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `7.4.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-qffp-2rhf-9h96.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qffp-2rhf-9h96\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5ab42ba718bb54ad", "name": "Vulnerable dependency tar 7.4.3: GHSA-r6q2-hw4h-h46w", "shortDescription": {"text": "Vulnerable dependency tar 7.4.3: GHSA-r6q2-hw4h-h46w"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `7.4.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-r6q2-hw4h-h46w.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r6q2-hw4h-h46w\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b048abe6812739ea", "name": "Vulnerable dependency tar 7.4.3: GHSA-vmf3-w455-68vh", "shortDescription": {"text": "Vulnerable dependency tar 7.4.3: GHSA-vmf3-w455-68vh"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `7.4.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-vmf3-w455-68vh.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vmf3-w455-68vh\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-82997768a250bec7", "name": "Vulnerable dependency tar 7.4.3: GHSA-w8wr-v893-vjvp", "shortDescription": {"text": "Vulnerable dependency tar 7.4.3: GHSA-w8wr-v893-vjvp"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `7.4.3` (resolved in `advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml`) is affected by GHSA-w8wr-v893-vjvp.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w8wr-v893-vjvp\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c2eb24934dedabce", "name": "Vulnerable dependency @hono/node-server 1.19.9: GHSA-92pp-h63x-v22m", "shortDescription": {"text": "Vulnerable dependency @hono/node-server 1.19.9: GHSA-92pp-h63x-v22m"}, "fullDescription": {"text": "OSV.dev reports `@hono/node-server` at version `1.19.9` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-92pp-h63x-v22m.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-92pp-h63x-v22m\nFix: upgrade `@hono/node-server` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e7c7d90aa359f40e", "name": "Vulnerable dependency @hono/node-server 1.19.9: GHSA-frvp-7c67-39w9", "shortDescription": {"text": "Vulnerable dependency @hono/node-server 1.19.9: GHSA-frvp-7c67-39w9"}, "fullDescription": {"text": "OSV.dev reports `@hono/node-server` at version `1.19.9` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-frvp-7c67-39w9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-frvp-7c67-39w9\nFix: upgrade `@hono/node-server` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ffc3fc5852012edd", "name": "Vulnerable dependency @hono/node-server 1.19.9: GHSA-wc8c-qw6v-h7f6", "shortDescription": {"text": "Vulnerable dependency @hono/node-server 1.19.9: GHSA-wc8c-qw6v-h7f6"}, "fullDescription": {"text": "OSV.dev reports `@hono/node-server` at version `1.19.9` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-wc8c-qw6v-h7f6.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wc8c-qw6v-h7f6\nFix: upgrade `@hono/node-server` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9ca71e2dd617063a", "name": "Vulnerable dependency hono 4.11.7: GHSA-26pp-8wgv-hjvm", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-26pp-8wgv-hjvm"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-26pp-8wgv-hjvm.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-26pp-8wgv-hjvm\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aac04a277f139b46", "name": "Vulnerable dependency hono 4.11.7: GHSA-2gcr-mfcq-wcc3", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-2gcr-mfcq-wcc3"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-2gcr-mfcq-wcc3.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-2gcr-mfcq-wcc3\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-48b4b407e033c993", "name": "Vulnerable dependency hono 4.11.7: GHSA-3hrh-pfw6-9m5x", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-3hrh-pfw6-9m5x"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-3hrh-pfw6-9m5x.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-3hrh-pfw6-9m5x\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6540c8ab0bf3a69a", "name": "Vulnerable dependency hono 4.11.7: GHSA-458j-xx4x-4375", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-458j-xx4x-4375"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-458j-xx4x-4375.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-458j-xx4x-4375\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a64877f56d386ca4", "name": "Vulnerable dependency hono 4.11.7: GHSA-5pq2-9x2x-5p6w", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-5pq2-9x2x-5p6w"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-5pq2-9x2x-5p6w.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-5pq2-9x2x-5p6w\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e5858355d36ee9b", "name": "Vulnerable dependency hono 4.11.7: GHSA-69xw-7hcm-h432", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-69xw-7hcm-h432"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-69xw-7hcm-h432.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-69xw-7hcm-h432\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5cc34e760aeca336", "name": "Vulnerable dependency hono 4.11.7: GHSA-88fw-hqm2-52qc", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-88fw-hqm2-52qc"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-88fw-hqm2-52qc (aka CVE-2026-54290).\n\nhono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nAliases: CVE-2026-54290\nAdvisory: https://osv.dev/vulnerability/GHSA-88fw-hqm2-52qc\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0b5bb81bf4d13459", "name": "Vulnerable dependency hono 4.11.7: GHSA-9vqf-7f2p-gf9v", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-9vqf-7f2p-gf9v"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-9vqf-7f2p-gf9v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9vqf-7f2p-gf9v\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a5b633ce2b7e8102", "name": "Vulnerable dependency hono 4.11.7: GHSA-f577-qrjj-4474", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-f577-qrjj-4474"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-f577-qrjj-4474.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-f577-qrjj-4474\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-34c20cb3c07404a2", "name": "Vulnerable dependency hono 4.11.7: GHSA-gq3j-xvxp-8hrf", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-gq3j-xvxp-8hrf"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-gq3j-xvxp-8hrf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gq3j-xvxp-8hrf\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-82530e94cdc05637", "name": "Vulnerable dependency hono 4.11.7: GHSA-hm8q-7f3q-5f36", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-hm8q-7f3q-5f36"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-hm8q-7f3q-5f36.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hm8q-7f3q-5f36\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d3f08a51b730fc68", "name": "Vulnerable dependency hono 4.11.7: GHSA-j6c9-x7qj-28xf", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-j6c9-x7qj-28xf"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-j6c9-x7qj-28xf (aka CVE-2026-54287).\n\nhono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nAliases: CVE-2026-54287\nAdvisory: https://osv.dev/vulnerability/GHSA-j6c9-x7qj-28xf\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c8b0c8d4a914c29e", "name": "Vulnerable dependency hono 4.11.7: GHSA-p6xx-57qc-3wxr", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-p6xx-57qc-3wxr"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-p6xx-57qc-3wxr.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p6xx-57qc-3wxr\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c679e4824777ab75", "name": "Vulnerable dependency hono 4.11.7: GHSA-p77w-8qqv-26rm", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-p77w-8qqv-26rm"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-p77w-8qqv-26rm.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p77w-8qqv-26rm\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d5569135a9ae3249", "name": "Vulnerable dependency hono 4.11.7: GHSA-q5qw-h33p-qvwr", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-q5qw-h33p-qvwr"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-q5qw-h33p-qvwr.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q5qw-h33p-qvwr\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dcdcde43d9000b52", "name": "Vulnerable dependency hono 4.11.7: GHSA-qp7p-654g-cw7p", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-qp7p-654g-cw7p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-qp7p-654g-cw7p.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qp7p-654g-cw7p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a31b05c818db37d2", "name": "Vulnerable dependency hono 4.11.7: GHSA-r5rp-j6wh-rvv4", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-r5rp-j6wh-rvv4"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-r5rp-j6wh-rvv4.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r5rp-j6wh-rvv4\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8d8946a3471f476c", "name": "Vulnerable dependency hono 4.11.7: GHSA-rv63-4mwf-qqc2", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-rv63-4mwf-qqc2"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-rv63-4mwf-qqc2 (aka CVE-2026-54288).\n\nhono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`\n\nAliases: CVE-2026-54288\nAdvisory: https://osv.dev/vulnerability/GHSA-rv63-4mwf-qqc2\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-713787bb34064797", "name": "Vulnerable dependency hono 4.11.7: GHSA-v8w9-8mx6-g223", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-v8w9-8mx6-g223"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-v8w9-8mx6-g223.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v8w9-8mx6-g223\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-380a4be0b5b49d13", "name": "Vulnerable dependency hono 4.11.7: GHSA-w62v-xxxg-mg59", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-w62v-xxxg-mg59"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-w62v-xxxg-mg59 (aka CVE-2026-59895).\n\nHono: Server-Side XSS via JSX Escaping Bypass in cx() Utility\n\nAliases: CVE-2026-59895\nAdvisory: https://osv.dev/vulnerability/GHSA-w62v-xxxg-mg59\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8efed76c3471ca5e", "name": "Vulnerable dependency hono 4.11.7: GHSA-wgpf-jwqj-8h8p", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-wgpf-jwqj-8h8p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-wgpf-jwqj-8h8p (aka CVE-2026-54289).\n\nhono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest\n\nAliases: CVE-2026-54289\nAdvisory: https://osv.dev/vulnerability/GHSA-wgpf-jwqj-8h8p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c8f355cf3dcdf5f5", "name": "Vulnerable dependency hono 4.11.7: GHSA-wmmm-f939-6g9c", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-wmmm-f939-6g9c"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-wmmm-f939-6g9c.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wmmm-f939-6g9c\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1d7a03ed5d250718", "name": "Vulnerable dependency hono 4.11.7: GHSA-wwfh-h76j-fc44", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-wwfh-h76j-fc44"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-wwfh-h76j-fc44 (aka CVE-2026-54286).\n\nhono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nAliases: CVE-2026-54286\nAdvisory: https://osv.dev/vulnerability/GHSA-wwfh-h76j-fc44\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b0ee02c8ab1fa57b", "name": "Vulnerable dependency hono 4.11.7: GHSA-xf4j-xp2r-rqqx", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-xf4j-xp2r-rqqx"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-xf4j-xp2r-rqqx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xf4j-xp2r-rqqx\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-53bfb8b30e3a82f5", "name": "Vulnerable dependency hono 4.11.7: GHSA-xgm2-5f3f-mvvc", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-xgm2-5f3f-mvvc"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-xgm2-5f3f-mvvc (aka CVE-2026-59897).\n\nHono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication\n\nAliases: CVE-2026-59897\nAdvisory: https://osv.dev/vulnerability/GHSA-xgm2-5f3f-mvvc\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-44ec0d81833cc010", "name": "Vulnerable dependency hono 4.11.7: GHSA-xpcf-pg52-r92g", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-xpcf-pg52-r92g"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-xpcf-pg52-r92g.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xpcf-pg52-r92g\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bd06d5c0254a2fab", "name": "Vulnerable dependency hono 4.11.7: GHSA-xrhx-7g5j-rcj5", "shortDescription": {"text": "Vulnerable dependency hono 4.11.7: GHSA-xrhx-7g5j-rcj5"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.7` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-xrhx-7g5j-rcj5.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xrhx-7g5j-rcj5\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ec65e0136f55e6fe", "name": "Vulnerable dependency next 15.5.12: GHSA-267c-6grr-h53f", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-267c-6grr-h53f"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-267c-6grr-h53f (aka CVE-2026-44575).\n\nNext.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes\n\nAliases: CVE-2026-44575\nAdvisory: https://osv.dev/vulnerability/GHSA-267c-6grr-h53f\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a4549c4241c29a4b", "name": "Vulnerable dependency next 15.5.12: GHSA-26hh-7cqf-hhc6", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-26hh-7cqf-hhc6"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-26hh-7cqf-hhc6 (aka CVE-2026-45109).\n\nNext.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up\n\nAliases: CVE-2026-45109\nAdvisory: https://osv.dev/vulnerability/GHSA-26hh-7cqf-hhc6\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7e8ace79fbd65aa9", "name": "Vulnerable dependency next 15.5.12: GHSA-36qx-fr4f-26g5", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-36qx-fr4f-26g5"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-36qx-fr4f-26g5 (aka CVE-2026-44573).\n\nNext.js has a Middleware / Proxy bypass in Pages Router applications using i18n\n\nAliases: CVE-2026-44573\nAdvisory: https://osv.dev/vulnerability/GHSA-36qx-fr4f-26g5\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-14db7748fd13ec0c", "name": "Vulnerable dependency next 15.5.12: GHSA-3g8h-86w9-wvmq", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-3g8h-86w9-wvmq"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-3g8h-86w9-wvmq (aka CVE-2026-44572).\n\nNext.js's Middleware / Proxy redirects can be cache-poisoned\n\nAliases: CVE-2026-44572\nAdvisory: https://osv.dev/vulnerability/GHSA-3g8h-86w9-wvmq\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a1d0ffcf32d6fe28", "name": "Vulnerable dependency next 15.5.12: GHSA-3x4c-7xq6-9pq8", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-3x4c-7xq6-9pq8"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-3x4c-7xq6-9pq8 (aka CVE-2026-27980).\n\nNext.js: Unbounded next/image disk cache growth can exhaust storage\n\nAliases: CVE-2026-27980\nAdvisory: https://osv.dev/vulnerability/GHSA-3x4c-7xq6-9pq8\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b1e83e463a74d76f", "name": "Vulnerable dependency next 15.5.12: GHSA-4633-3j49-mh5q", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-4633-3j49-mh5q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-4633-3j49-mh5q (aka CVE-2026-64647).\n\nNext.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\nAliases: CVE-2026-64647\nAdvisory: https://osv.dev/vulnerability/GHSA-4633-3j49-mh5q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c5c5bdf10f1f011d", "name": "Vulnerable dependency next 15.5.12: GHSA-492v-c6pp-mqqv", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-492v-c6pp-mqqv"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-492v-c6pp-mqqv (aka CVE-2026-44574).\n\nNext.js has a Middleware / Proxy bypass through dynamic route parameter injection\n\nAliases: CVE-2026-44574\nAdvisory: https://osv.dev/vulnerability/GHSA-492v-c6pp-mqqv\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bdccac0189d86cad", "name": "Vulnerable dependency next 15.5.12: GHSA-4c39-4ccg-62r3", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-4c39-4ccg-62r3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-4c39-4ccg-62r3 (aka CVE-2026-64646).\n\nNext.js: Unbounded Server Action payload in Edge runtime\n\nAliases: CVE-2026-64646\nAdvisory: https://osv.dev/vulnerability/GHSA-4c39-4ccg-62r3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8fd06ae5d4dc1e38", "name": "Vulnerable dependency next 15.5.12: GHSA-68g3-v927-f742", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-68g3-v927-f742"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-68g3-v927-f742 (aka CVE-2026-64648).\n\nNext.js: Cache confusion of response bodies for requests with bodies\n\nAliases: CVE-2026-64648\nAdvisory: https://osv.dev/vulnerability/GHSA-68g3-v927-f742\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-210ac085b29c04f3", "name": "Vulnerable dependency next 15.5.12: GHSA-89xv-2m56-2m9x", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-89xv-2m56-2m9x"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-89xv-2m56-2m9x (aka CVE-2026-64649).\n\nNext.js: Server-Side Request Forgery in Server Actions on custom servers\n\nAliases: CVE-2026-64649\nAdvisory: https://osv.dev/vulnerability/GHSA-89xv-2m56-2m9x\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dfa758b109d2fdd5", "name": "Vulnerable dependency next 15.5.12: GHSA-8h8q-6873-q5fj", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-8h8q-6873-q5fj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-8h8q-6873-q5fj.\n\nNext.js Vulnerable to Denial of Service with Server Components\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8h8q-6873-q5fj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-322ec4b5fe1872ef", "name": "Vulnerable dependency next 15.5.12: GHSA-955p-x3mx-jcvp", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-955p-x3mx-jcvp"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-955p-x3mx-jcvp (aka CVE-2026-64643).\n\nNext.js: Unauthenticated disclosure of internal Server Function endpoints\n\nAliases: CVE-2026-64643\nAdvisory: https://osv.dev/vulnerability/GHSA-955p-x3mx-jcvp\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-300721534e7a06f4", "name": "Vulnerable dependency next 15.5.12: GHSA-c4j6-fc7j-m34r", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-c4j6-fc7j-m34r"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-c4j6-fc7j-m34r (aka CVE-2026-44578).\n\nNext.js vulnerable to server-side request forgery in applications using WebSocket upgrades\n\nAliases: CVE-2026-44578\nAdvisory: https://osv.dev/vulnerability/GHSA-c4j6-fc7j-m34r\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8eac48cd33d1821b", "name": "Vulnerable dependency next 15.5.12: GHSA-ffhc-5mcf-pf4q", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-ffhc-5mcf-pf4q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-ffhc-5mcf-pf4q (aka CVE-2026-44581).\n\nNext.js vulnerable to cross-site scripting in App Router applications using CSP nonces\n\nAliases: CVE-2026-44581\nAdvisory: https://osv.dev/vulnerability/GHSA-ffhc-5mcf-pf4q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e3c02f790fc692db", "name": "Vulnerable dependency next 15.5.12: GHSA-ggv3-7p47-pfv8", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-ggv3-7p47-pfv8"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-ggv3-7p47-pfv8 (aka CVE-2026-29057).\n\nNext.js: HTTP request smuggling in rewrites\n\nAliases: CVE-2026-29057\nAdvisory: https://osv.dev/vulnerability/GHSA-ggv3-7p47-pfv8\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4170b81b2197ba71", "name": "Vulnerable dependency next 15.5.12: GHSA-gx5p-jg67-6x7h", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-gx5p-jg67-6x7h"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-gx5p-jg67-6x7h (aka CVE-2026-44580).\n\nNext.js has cross-site scripting in beforeInteractive scripts with untrusted input\n\nAliases: CVE-2026-44580\nAdvisory: https://osv.dev/vulnerability/GHSA-gx5p-jg67-6x7h\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ff28515acbdfdc9a", "name": "Vulnerable dependency next 15.5.12: GHSA-h64f-5h5j-jqjh", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-h64f-5h5j-jqjh"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-h64f-5h5j-jqjh (aka CVE-2026-44577).\n\nNext.js has a Denial of Service in the Image Optimization API\n\nAliases: CVE-2026-44577\nAdvisory: https://osv.dev/vulnerability/GHSA-h64f-5h5j-jqjh\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-567ad37756ffc375", "name": "Vulnerable dependency next 15.5.12: GHSA-m99w-x7hq-7vfj", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-m99w-x7hq-7vfj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-m99w-x7hq-7vfj (aka CVE-2026-64641).\n\nNext.js: Denial of Service in App Router using Server Actions\n\nAliases: CVE-2026-64641\nAdvisory: https://osv.dev/vulnerability/GHSA-m99w-x7hq-7vfj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bfc1e35b68029dd4", "name": "Vulnerable dependency next 15.5.12: GHSA-mg66-mrh9-m8jx", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-mg66-mrh9-m8jx"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-mg66-mrh9-m8jx (aka CVE-2026-44579).\n\nNext.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components\n\nAliases: CVE-2026-44579\nAdvisory: https://osv.dev/vulnerability/GHSA-mg66-mrh9-m8jx\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b758ad5b471ac69a", "name": "Vulnerable dependency next 15.5.12: GHSA-p9j2-gv94-2wf4", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-p9j2-gv94-2wf4"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-p9j2-gv94-2wf4 (aka CVE-2026-64645).\n\nNext.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\nAliases: CVE-2026-64645\nAdvisory: https://osv.dev/vulnerability/GHSA-p9j2-gv94-2wf4\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1c58fb5f5d2afde9", "name": "Vulnerable dependency next 15.5.12: GHSA-q4gf-8mx6-v5v3", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-q4gf-8mx6-v5v3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-q4gf-8mx6-v5v3.\n\nNext.js has a Denial of Service with Server Components\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q4gf-8mx6-v5v3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2b64effc8f493ea6", "name": "Vulnerable dependency next 15.5.12: GHSA-q8wf-6r8g-63ch", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-q8wf-6r8g-63ch"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-q8wf-6r8g-63ch (aka CVE-2026-64644).\n\nNext.js: Denial of Service in the Image Optimization API using SVGs\n\nAliases: CVE-2026-64644\nAdvisory: https://osv.dev/vulnerability/GHSA-q8wf-6r8g-63ch\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-af5210b5beecc1a9", "name": "Vulnerable dependency next 15.5.12: GHSA-vfv6-92ff-j949", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-vfv6-92ff-j949"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-vfv6-92ff-j949 (aka CVE-2026-44582).\n\nNext.js vulnerable to cache poisoning via collisions in React Server Component cache-busting\n\nAliases: CVE-2026-44582\nAdvisory: https://osv.dev/vulnerability/GHSA-vfv6-92ff-j949\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-544354ab8799549a", "name": "Vulnerable dependency next 15.5.12: GHSA-wfc6-r584-vfw7", "shortDescription": {"text": "Vulnerable dependency next 15.5.12: GHSA-wfc6-r584-vfw7"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.12` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-wfc6-r584-vfw7 (aka CVE-2026-44576).\n\nNext.js vulnerable to cache poisoning in React Server Component responses\n\nAliases: CVE-2026-44576\nAdvisory: https://osv.dev/vulnerability/GHSA-wfc6-r584-vfw7\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-492f6212c8b6d40c", "name": "Vulnerable dependency postcss 8.5.6: GHSA-6g55-p6wh-862q", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-6g55-p6wh-862q"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.6` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-6g55-p6wh-862q (aka CVE-2026-45623).\n\nPostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments\n\nAliases: CVE-2026-45623\nAdvisory: https://osv.dev/vulnerability/GHSA-6g55-p6wh-862q\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c67336a6ee573687", "name": "Vulnerable dependency postcss 8.5.6: GHSA-qx2v-qp2m-jg93", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-qx2v-qp2m-jg93"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.6` (resolved in `advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json`) is affected by GHSA-qx2v-qp2m-jg93 (aka CVE-2026-41305).\n\nPostCSS has XSS via Unescaped </style> in its CSS Stringify Output\n\nAliases: CVE-2026-41305\nAdvisory: https://osv.dev/vulnerability/GHSA-qx2v-qp2m-jg93\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4bcd1705a2f9e0f8", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-2fqr-mr3j-6wp8", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-2fqr-mr3j-6wp8"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-2fqr-mr3j-6wp8 (aka CVE-2026-54279).\n\naiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence\n\nAliases: CVE-2026-54279, PYSEC-2026-2112\nAdvisory: https://osv.dev/vulnerability/GHSA-2fqr-mr3j-6wp8\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9121d174f2eeab15", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-2vrm-gr82-f7m5", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-2vrm-gr82-f7m5"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-2vrm-gr82-f7m5 (aka CVE-2026-34514).\n\nAIOHTTP has CRLF injection through multipart part content type header construction\n\nAliases: CVE-2026-34514, PYSEC-2026-2096\nAdvisory: https://osv.dev/vulnerability/GHSA-2vrm-gr82-f7m5\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b6c31bb511d3ccb6", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-3wq7-rqq7-wx6j", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-3wq7-rqq7-wx6j"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-3wq7-rqq7-wx6j (aka CVE-2026-34517).\n\nAIOHTTP has late size enforcement for non-file multipart fields causes memory DoS\n\nAliases: CVE-2026-34517, PYSEC-2026-2099\nAdvisory: https://osv.dev/vulnerability/GHSA-3wq7-rqq7-wx6j\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2193308d66e00036", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-4fvr-rgm6-gqmc", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-4fvr-rgm6-gqmc"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-4fvr-rgm6-gqmc (aka CVE-2026-54273).\n\naiohttp: HTTP/1 Pipelined Requests Queue Without Limit\n\nAliases: CVE-2026-54273, PYSEC-2026-2107\nAdvisory: https://osv.dev/vulnerability/GHSA-4fvr-rgm6-gqmc\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-05abe65493869090", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-4m7w-qmgq-4wj5", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-4m7w-qmgq-4wj5"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-4m7w-qmgq-4wj5 (aka CVE-2026-54275).\n\naiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections\n\nAliases: CVE-2026-54275, PYSEC-2026-237\nAdvisory: https://osv.dev/vulnerability/GHSA-4m7w-qmgq-4wj5\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-689a21a85fcdbea5", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-54jq-c3m8-4m76", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-54jq-c3m8-4m76"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-54jq-c3m8-4m76.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-54jq-c3m8-4m76\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f4349fe1a9a65278", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-63hf-3vf5-4wqf", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-63hf-3vf5-4wqf"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-63hf-3vf5-4wqf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-63hf-3vf5-4wqf\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6bb3dbc13ad5c0d1", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-63hw-fmq6-xxg2", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-63hw-fmq6-xxg2"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-63hw-fmq6-xxg2.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-63hw-fmq6-xxg2\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7897b187d4427a60", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-69f9-5gxw-wvc2", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-69f9-5gxw-wvc2"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-69f9-5gxw-wvc2.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-69f9-5gxw-wvc2\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-97a10e35839a3020", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-6jhg-hg63-jvvf", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-6jhg-hg63-jvvf"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-6jhg-hg63-jvvf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6jhg-hg63-jvvf\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-07ad91d50549f684", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-6mq8-rvhq-8wgg", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-6mq8-rvhq-8wgg"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-6mq8-rvhq-8wgg.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6mq8-rvhq-8wgg\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-89f0cdf705372708", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-9548-qrrj-x5pj", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-9548-qrrj-x5pj"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-9548-qrrj-x5pj.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9548-qrrj-x5pj\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-795a2409109a9f57", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-966j-vmvw-g2g9", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-966j-vmvw-g2g9"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-966j-vmvw-g2g9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-966j-vmvw-g2g9\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-681f13588d797e04", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-9x8q-7h8h-wcw9", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-9x8q-7h8h-wcw9"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-9x8q-7h8h-wcw9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9x8q-7h8h-wcw9\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e5f2e6d75ac86d30", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-c427-h43c-vf67", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-c427-h43c-vf67"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-c427-h43c-vf67.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-c427-h43c-vf67\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-031c59487bdcfa4b", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-fh55-r93g-j68g", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-fh55-r93g-j68g"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-fh55-r93g-j68g.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fh55-r93g-j68g\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-50a9d3f78b2b0792", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-g3cq-j2xw-wf74", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-g3cq-j2xw-wf74"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-g3cq-j2xw-wf74.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-g3cq-j2xw-wf74\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-49a1930ea07673be", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-g84x-mcqj-x9qq", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-g84x-mcqj-x9qq"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-g84x-mcqj-x9qq.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-g84x-mcqj-x9qq\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3939752ceeb3892f", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-hcc4-c3v8-rx92", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-hcc4-c3v8-rx92"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-hcc4-c3v8-rx92.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hcc4-c3v8-rx92\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-57fb787d196a4e61", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-hg6j-4rv6-33pg", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-hg6j-4rv6-33pg"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-hg6j-4rv6-33pg.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hg6j-4rv6-33pg\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-da725a7180e726ec", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-hpj7-wq8m-9hgp", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-hpj7-wq8m-9hgp"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-hpj7-wq8m-9hgp.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hpj7-wq8m-9hgp\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3e7374c79b08594a", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-jg22-mg44-37j8", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-jg22-mg44-37j8"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-jg22-mg44-37j8.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jg22-mg44-37j8\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e62e1b5161f77239", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-jj3x-wxrx-4x23", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-jj3x-wxrx-4x23"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-jj3x-wxrx-4x23.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jj3x-wxrx-4x23\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7a4adeb85ed9fbe3", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-m5qp-6w8w-w647", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-m5qp-6w8w-w647"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-m5qp-6w8w-w647.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-m5qp-6w8w-w647\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-594b024049d50710", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-m6qw-4cw2-hm4m", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-m6qw-4cw2-hm4m"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-m6qw-4cw2-hm4m.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-m6qw-4cw2-hm4m\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-868546cee51a8e37", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-mqqc-3gqh-h2x8", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-mqqc-3gqh-h2x8"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-mqqc-3gqh-h2x8.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mqqc-3gqh-h2x8\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e863e24cae2aff4f", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-mwh4-6h8g-pg8w", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-mwh4-6h8g-pg8w"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-mwh4-6h8g-pg8w.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mwh4-6h8g-pg8w\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2e3ea13c1d401696", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-p998-jp59-783m", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-p998-jp59-783m"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-p998-jp59-783m.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p998-jp59-783m\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e9d08674d44d1c32", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-w2fm-2cpv-w7v5", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-w2fm-2cpv-w7v5"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-w2fm-2cpv-w7v5.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w2fm-2cpv-w7v5\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-077b3c41d988230d", "name": "Vulnerable dependency aiohttp 3.12.12: GHSA-xcgm-r5h9-7989", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-xcgm-r5h9-7989"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-xcgm-r5h9-7989.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xcgm-r5h9-7989\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-102488ed35835f87", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1097", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1097"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-1097.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1097\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f1bcd00db0df4bb3", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1099", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1099"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-1099.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1099\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-464a897268a65de4", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1100", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1100"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-1100.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1100\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bc0b4304667c3a2d", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1101", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1101"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-1101.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1101\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-71a67320ce60edd0", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1104", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1104"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-1104.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1104\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e0ee500012acea27", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1105", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1105"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-1105.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1105\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-97ff2ef574696398", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1106", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1106"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-1106.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1106\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e285327e620d3a3e", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1107", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1107"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-1107.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1107\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a6c95e751a676054", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1109", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1109"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-1109.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1109\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8fa137bf6d43da61", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2094", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2094"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2094.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2094\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7949f5fdbebbd17c", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2095", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2095"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2095.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2095\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-24b3dcd87c71b423", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2097", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2097"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2097.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2097\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3fae733c4f38bc71", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2098", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2098"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2098.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2098\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1af58bbaaf1f7d55", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2100", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2100"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2100.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2100\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b7e1f46ecdb21ac8", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2101", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2101"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2101.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2101\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f6d7c2f2e6c6d8fd", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2102", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2102"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2102.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2102\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5a979d4a0615c818", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2103", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2103"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2103.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2103\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0506d69e23a8ec73", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2104", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2104"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2104.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2104\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ba270c40360697ce", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2105", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2105"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2105.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2105\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0e30944679632a5f", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2106", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2106"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2106.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2106\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2153e9edbaf12e2d", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2108", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2108"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2108.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2108\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cca9bdb5512fbb46", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2109", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2109"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2109.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2109\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2da3665b43197bcd", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2110", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2110"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2110.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2110\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1444597e19b16b35", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2111", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2111"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2111.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2111\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bb1630d6588aefc4", "name": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2113", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2113"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.12.12` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2113.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2113\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8411b87bc5e6120c", "name": "Vulnerable dependency langchain 0.3.25: GHSA-3644-q5cj-c5c7", "shortDescription": {"text": "Vulnerable dependency langchain 0.3.25: GHSA-3644-q5cj-c5c7"}, "fullDescription": {"text": "OSV.dev reports `langchain` at version `0.3.25` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-3644-q5cj-c5c7 (aka CVE-2026-45134).\n\nLangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nAliases: CVE-2026-45134, PYSEC-2026-2555, PYSEC-2026-2560, PYSEC-2026-2582\nAdvisory: https://osv.dev/vulnerability/GHSA-3644-q5cj-c5c7\nFix: upgrade `langchain` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cbba48a036cfbdbf", "name": "Vulnerable dependency langchain 0.3.25: GHSA-gr75-jv2w-4656", "shortDescription": {"text": "Vulnerable dependency langchain 0.3.25: GHSA-gr75-jv2w-4656"}, "fullDescription": {"text": "OSV.dev reports `langchain` at version `0.3.25` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-gr75-jv2w-4656 (aka CVE-2026-55443).\n\nLangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nAliases: CVE-2026-55443, PYSEC-2026-2192, PYSEC-2026-2556\nAdvisory: https://osv.dev/vulnerability/GHSA-gr75-jv2w-4656\nFix: upgrade `langchain` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-20f952129a3537e7", "name": "Vulnerable dependency langchain-community 0.3.25: GHSA-pc6w-59fv-rh23", "shortDescription": {"text": "Vulnerable dependency langchain-community 0.3.25: GHSA-pc6w-59fv-rh23"}, "fullDescription": {"text": "OSV.dev reports `langchain-community` at version `0.3.25` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-pc6w-59fv-rh23.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pc6w-59fv-rh23\nFix: upgrade `langchain-community` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-10b93e917252bd7f", "name": "Vulnerable dependency langchain-community 0.3.25: PYSEC-2026-1515", "shortDescription": {"text": "Vulnerable dependency langchain-community 0.3.25: PYSEC-2026-1515"}, "fullDescription": {"text": "OSV.dev reports `langchain-community` at version `0.3.25` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-1515.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1515\nFix: upgrade `langchain-community` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a113e7b71a5a8b52", "name": "Vulnerable dependency langchain-core 0.3.65: GHSA-2g6r-c272-w58r", "shortDescription": {"text": "Vulnerable dependency langchain-core 0.3.65: GHSA-2g6r-c272-w58r"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `0.3.65` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-2g6r-c272-w58r.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-2g6r-c272-w58r\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e0a656dd3a00eb86", "name": "Vulnerable dependency langchain-core 0.3.65: GHSA-6qv9-48xg-fc7f", "shortDescription": {"text": "Vulnerable dependency langchain-core 0.3.65: GHSA-6qv9-48xg-fc7f"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `0.3.65` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-6qv9-48xg-fc7f.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6qv9-48xg-fc7f\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-740046de036f13be", "name": "Vulnerable dependency langchain-core 0.3.65: GHSA-926x-3r5x-gfhw", "shortDescription": {"text": "Vulnerable dependency langchain-core 0.3.65: GHSA-926x-3r5x-gfhw"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `0.3.65` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-926x-3r5x-gfhw.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-926x-3r5x-gfhw\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3bb40c87bccffe52", "name": "Vulnerable dependency langchain-core 0.3.65: GHSA-c67j-w6g6-q2cm", "shortDescription": {"text": "Vulnerable dependency langchain-core 0.3.65: GHSA-c67j-w6g6-q2cm"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `0.3.65` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-c67j-w6g6-q2cm.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-c67j-w6g6-q2cm\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-92d89e3ae5aa0de5", "name": "Vulnerable dependency langchain-core 0.3.65: GHSA-pjwx-r37v-7724", "shortDescription": {"text": "Vulnerable dependency langchain-core 0.3.65: GHSA-pjwx-r37v-7724"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `0.3.65` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-pjwx-r37v-7724.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pjwx-r37v-7724\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-17e7c6ad4e4e9226", "name": "Vulnerable dependency langchain-core 0.3.65: GHSA-qh6h-p6c9-ff54", "shortDescription": {"text": "Vulnerable dependency langchain-core 0.3.65: GHSA-qh6h-p6c9-ff54"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `0.3.65` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-qh6h-p6c9-ff54.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qh6h-p6c9-ff54\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-16f09d51f5005c95", "name": "Vulnerable dependency langchain-core 0.3.65: PYSEC-2026-1518", "shortDescription": {"text": "Vulnerable dependency langchain-core 0.3.65: PYSEC-2026-1518"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `0.3.65` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-1518.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1518\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-22aac77ba9b23c20", "name": "Vulnerable dependency langchain-core 0.3.65: PYSEC-2026-2193", "shortDescription": {"text": "Vulnerable dependency langchain-core 0.3.65: PYSEC-2026-2193"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `0.3.65` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2193.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2193\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-32dc632836381b61", "name": "Vulnerable dependency langchain-core 0.3.65: PYSEC-2026-2562", "shortDescription": {"text": "Vulnerable dependency langchain-core 0.3.65: PYSEC-2026-2562"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `0.3.65` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2562.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2562\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5e70520ee7e595fb", "name": "Vulnerable dependency langchain-core 0.3.65: PYSEC-2026-2563", "shortDescription": {"text": "Vulnerable dependency langchain-core 0.3.65: PYSEC-2026-2563"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `0.3.65` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2563.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2563\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-19fe4c6ce92ed3b5", "name": "Vulnerable dependency langchain-core 0.3.65: PYSEC-2026-2564", "shortDescription": {"text": "Vulnerable dependency langchain-core 0.3.65: PYSEC-2026-2564"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `0.3.65` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2564.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2564\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0bf04c30d2b85274", "name": "Vulnerable dependency langchain-core 0.3.65: PYSEC-2026-373", "shortDescription": {"text": "Vulnerable dependency langchain-core 0.3.65: PYSEC-2026-373"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `0.3.65` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-373.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-373\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6501e27b43cd4211", "name": "Vulnerable dependency langchain-text-splitters 0.3.8: GHSA-fv5p-p927-qmxr", "shortDescription": {"text": "Vulnerable dependency langchain-text-splitters 0.3.8: GHSA-fv5p-p927-qmxr"}, "fullDescription": {"text": "OSV.dev reports `langchain-text-splitters` at version `0.3.8` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-fv5p-p927-qmxr.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fv5p-p927-qmxr\nFix: upgrade `langchain-text-splitters` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0be400af9052214f", "name": "Vulnerable dependency langchain-text-splitters 0.3.8: GHSA-m42m-m8cr-8m58", "shortDescription": {"text": "Vulnerable dependency langchain-text-splitters 0.3.8: GHSA-m42m-m8cr-8m58"}, "fullDescription": {"text": "OSV.dev reports `langchain-text-splitters` at version `0.3.8` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-m42m-m8cr-8m58.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-m42m-m8cr-8m58\nFix: upgrade `langchain-text-splitters` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6d580682113384c5", "name": "Vulnerable dependency langchain-text-splitters 0.3.8: PYSEC-2026-1520", "shortDescription": {"text": "Vulnerable dependency langchain-text-splitters 0.3.8: PYSEC-2026-1520"}, "fullDescription": {"text": "OSV.dev reports `langchain-text-splitters` at version `0.3.8` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-1520.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1520\nFix: upgrade `langchain-text-splitters` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5ce1c3787d1cb608", "name": "Vulnerable dependency langchain-text-splitters 0.3.8: PYSEC-2026-77", "shortDescription": {"text": "Vulnerable dependency langchain-text-splitters 0.3.8: PYSEC-2026-77"}, "fullDescription": {"text": "OSV.dev reports `langchain-text-splitters` at version `0.3.8` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-77.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-77\nFix: upgrade `langchain-text-splitters` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-10b03c5b9cdb769b", "name": "Vulnerable dependency langsmith 0.3.45: GHSA-3644-q5cj-c5c7", "shortDescription": {"text": "Vulnerable dependency langsmith 0.3.45: GHSA-3644-q5cj-c5c7"}, "fullDescription": {"text": "OSV.dev reports `langsmith` at version `0.3.45` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-3644-q5cj-c5c7 (aka CVE-2026-45134).\n\nLangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nAliases: CVE-2026-45134, PYSEC-2026-2555, PYSEC-2026-2560, PYSEC-2026-2582\nAdvisory: https://osv.dev/vulnerability/GHSA-3644-q5cj-c5c7\nFix: upgrade `langsmith` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ca79a62e0e914ee0", "name": "Vulnerable dependency langsmith 0.3.45: GHSA-f4xh-w4cj-qxq8", "shortDescription": {"text": "Vulnerable dependency langsmith 0.3.45: GHSA-f4xh-w4cj-qxq8"}, "fullDescription": {"text": "OSV.dev reports `langsmith` at version `0.3.45` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-f4xh-w4cj-qxq8.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-f4xh-w4cj-qxq8\nFix: upgrade `langsmith` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3cc9f966e34be408", "name": "Vulnerable dependency langsmith 0.3.45: GHSA-rr7j-v2q5-chgv", "shortDescription": {"text": "Vulnerable dependency langsmith 0.3.45: GHSA-rr7j-v2q5-chgv"}, "fullDescription": {"text": "OSV.dev reports `langsmith` at version `0.3.45` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-rr7j-v2q5-chgv.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rr7j-v2q5-chgv\nFix: upgrade `langsmith` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0216ae4f0f605ec9", "name": "Vulnerable dependency langsmith 0.3.45: PYSEC-2026-2583", "shortDescription": {"text": "Vulnerable dependency langsmith 0.3.45: PYSEC-2026-2583"}, "fullDescription": {"text": "OSV.dev reports `langsmith` at version `0.3.45` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2583.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2583\nFix: upgrade `langsmith` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-70ea3038bd1c4646", "name": "Vulnerable dependency orjson 3.10.18: GHSA-hx9q-6w63-j58v", "shortDescription": {"text": "Vulnerable dependency orjson 3.10.18: GHSA-hx9q-6w63-j58v"}, "fullDescription": {"text": "OSV.dev reports `orjson` at version `3.10.18` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-hx9q-6w63-j58v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hx9q-6w63-j58v\nFix: upgrade `orjson` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cdbccd33e54c30db", "name": "Vulnerable dependency orjson 3.10.18: PYSEC-2026-107", "shortDescription": {"text": "Vulnerable dependency orjson 3.10.18: PYSEC-2026-107"}, "fullDescription": {"text": "OSV.dev reports `orjson` at version `3.10.18` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-107.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-107\nFix: upgrade `orjson` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f9aadf6242994d35", "name": "Vulnerable dependency pillow 11.2.1: GHSA-45hq-cxwh-f6vc", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-45hq-cxwh-f6vc"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-45hq-cxwh-f6vc (aka CVE-2026-55379).\n\nPillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` \u2014 bomb protection bypass via font loading\n\nAliases: BIT-pillow-2026-55379, CVE-2026-55379, PYSEC-2026-2255\nAdvisory: https://osv.dev/vulnerability/GHSA-45hq-cxwh-f6vc\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0bfefeae95f962cb", "name": "Vulnerable dependency pillow 11.2.1: GHSA-4x4j-2g7c-83w6", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-4x4j-2g7c-83w6"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-4x4j-2g7c-83w6 (aka CVE-2026-55798).\n\nPillow: WindowsViewer.get_command() OS command injection via unescaped shell path\n\nAliases: BIT-pillow-2026-55798, CVE-2026-55798, PYSEC-2026-2257\nAdvisory: https://osv.dev/vulnerability/GHSA-4x4j-2g7c-83w6\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8d153e704171e85e", "name": "Vulnerable dependency pillow 11.2.1: GHSA-5x94-69rx-g8h2", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-5x94-69rx-g8h2"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-5x94-69rx-g8h2.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-5x94-69rx-g8h2\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fca132e2f3a30a63", "name": "Vulnerable dependency pillow 11.2.1: GHSA-5xmw-vc9v-4wf2", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-5xmw-vc9v-4wf2"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-5xmw-vc9v-4wf2.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-5xmw-vc9v-4wf2\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b80ab3ad93d0ccd0", "name": "Vulnerable dependency pillow 11.2.1: GHSA-62p4-gmf7-7g93", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-62p4-gmf7-7g93"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-62p4-gmf7-7g93.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-62p4-gmf7-7g93\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-25df7cc436c11952", "name": "Vulnerable dependency pillow 11.2.1: GHSA-6r8x-57c9-28j4", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-6r8x-57c9-28j4"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-6r8x-57c9-28j4.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6r8x-57c9-28j4\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e8536c8346be7e55", "name": "Vulnerable dependency pillow 11.2.1: GHSA-8v84-f9pq-wr9x", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-8v84-f9pq-wr9x"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-8v84-f9pq-wr9x.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8v84-f9pq-wr9x\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-addd35e9d34d29e8", "name": "Vulnerable dependency pillow 11.2.1: GHSA-9hw9-ch79-4vh6", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-9hw9-ch79-4vh6"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-9hw9-ch79-4vh6.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9hw9-ch79-4vh6\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c920a2a31e9d4c60", "name": "Vulnerable dependency pillow 11.2.1: GHSA-cfh3-3jmp-rvhc", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-cfh3-3jmp-rvhc"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-cfh3-3jmp-rvhc.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-cfh3-3jmp-rvhc\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-29f16fe6e38e84e1", "name": "Vulnerable dependency pillow 11.2.1: GHSA-fj7v-r99m-22gq", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-fj7v-r99m-22gq"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-fj7v-r99m-22gq.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fj7v-r99m-22gq\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a5ceac7a9d00be03", "name": "Vulnerable dependency pillow 11.2.1: GHSA-jjj6-mw9f-p565", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-jjj6-mw9f-p565"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-jjj6-mw9f-p565.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jjj6-mw9f-p565\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f2d74f05310123c0", "name": "Vulnerable dependency pillow 11.2.1: GHSA-phj9-mv4w-65pm", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-phj9-mv4w-65pm"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-phj9-mv4w-65pm.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-phj9-mv4w-65pm\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-00aaa31e082a9795", "name": "Vulnerable dependency pillow 11.2.1: GHSA-pwv6-vv43-88gr", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-pwv6-vv43-88gr"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-pwv6-vv43-88gr.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pwv6-vv43-88gr\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9de962c68203b514", "name": "Vulnerable dependency pillow 11.2.1: GHSA-r73j-pqj5-w3x7", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-r73j-pqj5-w3x7"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-r73j-pqj5-w3x7.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r73j-pqj5-w3x7\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e596db9c199c4f9b", "name": "Vulnerable dependency pillow 11.2.1: GHSA-vjc4-5qp5-m44j", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-vjc4-5qp5-m44j"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-vjc4-5qp5-m44j.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vjc4-5qp5-m44j\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a7cdeccf46d45d16", "name": "Vulnerable dependency pillow 11.2.1: GHSA-whj4-6x5x-4v2j", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-whj4-6x5x-4v2j"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-whj4-6x5x-4v2j.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-whj4-6x5x-4v2j\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b28c8653bc04cb81", "name": "Vulnerable dependency pillow 11.2.1: GHSA-wjx4-4jcj-g98j", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-wjx4-4jcj-g98j"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-wjx4-4jcj-g98j.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wjx4-4jcj-g98j\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-01d12da8456ae28a", "name": "Vulnerable dependency pillow 11.2.1: GHSA-xg8h-j46f-w952", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-xg8h-j46f-w952"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-xg8h-j46f-w952.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xg8h-j46f-w952\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-be25fb62f0112c5e", "name": "Vulnerable dependency pillow 11.2.1: GHSA-xj96-63gp-2gmr", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-xj96-63gp-2gmr"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by GHSA-xj96-63gp-2gmr.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xj96-63gp-2gmr\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b0b1d0f52e15be7d", "name": "Vulnerable dependency pillow 11.2.1: PYSEC-2025-61", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2025-61"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2025-61.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2025-61\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-16760e4c66e40292", "name": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-165", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-165"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-165.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-165\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8e73b43b75c29597", "name": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2249", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2249"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-2249.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2249\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-91a93e5a23ea08cc", "name": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2250", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2250"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-2250.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2250\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c1ecf5f517461864", "name": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2251", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2251"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-2251.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2251\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4bd6ba707ac37bdf", "name": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2252", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2252"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-2252.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2252\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f1351b1199df497a", "name": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2253", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2253"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-2253.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2253\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ead160560383bfdf", "name": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2254", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2254"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-2254.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2254\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c7849566ca5a8a9e", "name": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2256", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2256"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-2256.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2256\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-57bfb857705a69d8", "name": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2874", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2874"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-2874.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2874\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d920c3e11f2bdd6e", "name": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3451", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3451"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-3451.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3451\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d3d766fe6e93a4f5", "name": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3453", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3453"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-3453.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3453\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5ff0e56be1f88c20", "name": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3454", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3454"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-3454.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3454\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-682a95eb0d8f6b38", "name": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3493", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3493"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-3493.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3493\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6a86eed20037af58", "name": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3494", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3494"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-3494.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3494\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-59769f6ba6a2c0d7", "name": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3495", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3495"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-3495.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3495\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d3d17d25ca78f555", "name": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3496", "shortDescription": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3496"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `11.2.1` (declared in `advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt`) is affected by PYSEC-2026-3496.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3496\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3af9e92b16066e21", "name": "Vulnerable dependency requests 2.32.4: GHSA-gc5v-m9x4-r6x2", "shortDescription": {"text": "Vulnerable dependency requests 2.32.4: GHSA-gc5v-m9x4-r6x2"}, "fullDescription": {"text": "OSV.dev reports `requests` at version `2.32.4` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-gc5v-m9x4-r6x2.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gc5v-m9x4-r6x2\nFix: upgrade `requests` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c88ead0f3169aa49", "name": "Vulnerable dependency requests 2.32.4: PYSEC-2026-2275", "shortDescription": {"text": "Vulnerable dependency requests 2.32.4: PYSEC-2026-2275"}, "fullDescription": {"text": "OSV.dev reports `requests` at version `2.32.4` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-2275.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2275\nFix: upgrade `requests` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9a65bf71395b1a8f", "name": "Vulnerable dependency setuptools 80.9.0: GHSA-h35f-9h28-mq5c", "shortDescription": {"text": "Vulnerable dependency setuptools 80.9.0: GHSA-h35f-9h28-mq5c"}, "fullDescription": {"text": "OSV.dev reports `setuptools` at version `80.9.0` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-h35f-9h28-mq5c.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-h35f-9h28-mq5c\nFix: upgrade `setuptools` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f7ce7d7a5fe8eddf", "name": "Vulnerable dependency setuptools 80.9.0: PYSEC-2026-3447", "shortDescription": {"text": "Vulnerable dependency setuptools 80.9.0: PYSEC-2026-3447"}, "fullDescription": {"text": "OSV.dev reports `setuptools` at version `80.9.0` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-3447.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3447\nFix: upgrade `setuptools` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0929ca37e9f00f4c", "name": "Vulnerable dependency soupsieve 2.7: GHSA-2wc2-fm75-p42x", "shortDescription": {"text": "Vulnerable dependency soupsieve 2.7: GHSA-2wc2-fm75-p42x"}, "fullDescription": {"text": "OSV.dev reports `soupsieve` at version `2.7` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-2wc2-fm75-p42x.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-2wc2-fm75-p42x\nFix: upgrade `soupsieve` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f81e453504c55172", "name": "Vulnerable dependency soupsieve 2.7: GHSA-836r-79rf-4m37", "shortDescription": {"text": "Vulnerable dependency soupsieve 2.7: GHSA-836r-79rf-4m37"}, "fullDescription": {"text": "OSV.dev reports `soupsieve` at version `2.7` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by GHSA-836r-79rf-4m37.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-836r-79rf-4m37\nFix: upgrade `soupsieve` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-169d8af1521568f9", "name": "Vulnerable dependency soupsieve 2.7: PYSEC-2026-3071", "shortDescription": {"text": "Vulnerable dependency soupsieve 2.7: PYSEC-2026-3071"}, "fullDescription": {"text": "OSV.dev reports `soupsieve` at version `2.7` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-3071.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3071\nFix: upgrade `soupsieve` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7f27d27bfda0d727", "name": "Vulnerable dependency soupsieve 2.7: PYSEC-2026-3072", "shortDescription": {"text": "Vulnerable dependency soupsieve 2.7: PYSEC-2026-3072"}, "fullDescription": {"text": "OSV.dev reports `soupsieve` at version `2.7` (resolved in `advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock`) is affected by PYSEC-2026-3072.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3072\nFix: upgrade `soupsieve` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6d41d19b5d84477a", "name": "Vulnerable dependency next 16.1.6: GHSA-267c-6grr-h53f", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-267c-6grr-h53f"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-267c-6grr-h53f (aka CVE-2026-44575).\n\nNext.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes\n\nAliases: CVE-2026-44575\nAdvisory: https://osv.dev/vulnerability/GHSA-267c-6grr-h53f\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-228dd5f4bf333b1b", "name": "Vulnerable dependency next 16.1.6: GHSA-26hh-7cqf-hhc6", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-26hh-7cqf-hhc6"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-26hh-7cqf-hhc6 (aka CVE-2026-45109).\n\nNext.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up\n\nAliases: CVE-2026-45109\nAdvisory: https://osv.dev/vulnerability/GHSA-26hh-7cqf-hhc6\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fb47c794fababcf8", "name": "Vulnerable dependency next 16.1.6: GHSA-36qx-fr4f-26g5", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-36qx-fr4f-26g5"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-36qx-fr4f-26g5 (aka CVE-2026-44573).\n\nNext.js has a Middleware / Proxy bypass in Pages Router applications using i18n\n\nAliases: CVE-2026-44573\nAdvisory: https://osv.dev/vulnerability/GHSA-36qx-fr4f-26g5\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-db84db354100f56e", "name": "Vulnerable dependency next 16.1.6: GHSA-3g8h-86w9-wvmq", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-3g8h-86w9-wvmq"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-3g8h-86w9-wvmq (aka CVE-2026-44572).\n\nNext.js's Middleware / Proxy redirects can be cache-poisoned\n\nAliases: CVE-2026-44572\nAdvisory: https://osv.dev/vulnerability/GHSA-3g8h-86w9-wvmq\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6a8dbe98018cafcb", "name": "Vulnerable dependency next 16.1.6: GHSA-3x4c-7xq6-9pq8", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-3x4c-7xq6-9pq8"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-3x4c-7xq6-9pq8 (aka CVE-2026-27980).\n\nNext.js: Unbounded next/image disk cache growth can exhaust storage\n\nAliases: CVE-2026-27980\nAdvisory: https://osv.dev/vulnerability/GHSA-3x4c-7xq6-9pq8\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b12b9ec92f643a6f", "name": "Vulnerable dependency next 16.1.6: GHSA-4633-3j49-mh5q", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-4633-3j49-mh5q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-4633-3j49-mh5q (aka CVE-2026-64647).\n\nNext.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\nAliases: CVE-2026-64647\nAdvisory: https://osv.dev/vulnerability/GHSA-4633-3j49-mh5q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aa7763ceec966d7a", "name": "Vulnerable dependency next 16.1.6: GHSA-492v-c6pp-mqqv", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-492v-c6pp-mqqv"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-492v-c6pp-mqqv (aka CVE-2026-44574).\n\nNext.js has a Middleware / Proxy bypass through dynamic route parameter injection\n\nAliases: CVE-2026-44574\nAdvisory: https://osv.dev/vulnerability/GHSA-492v-c6pp-mqqv\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bddc434f7015e935", "name": "Vulnerable dependency next 16.1.6: GHSA-4c39-4ccg-62r3", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-4c39-4ccg-62r3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-4c39-4ccg-62r3 (aka CVE-2026-64646).\n\nNext.js: Unbounded Server Action payload in Edge runtime\n\nAliases: CVE-2026-64646\nAdvisory: https://osv.dev/vulnerability/GHSA-4c39-4ccg-62r3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2e70c96eac0d8d70", "name": "Vulnerable dependency next 16.1.6: GHSA-68g3-v927-f742", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-68g3-v927-f742"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-68g3-v927-f742 (aka CVE-2026-64648).\n\nNext.js: Cache confusion of response bodies for requests with bodies\n\nAliases: CVE-2026-64648\nAdvisory: https://osv.dev/vulnerability/GHSA-68g3-v927-f742\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-36b1c43e99b7367b", "name": "Vulnerable dependency next 16.1.6: GHSA-6gpp-xcg3-4w24", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-6gpp-xcg3-4w24"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-6gpp-xcg3-4w24 (aka CVE-2026-64642).\n\nNext.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale\n\nAliases: CVE-2026-64642\nAdvisory: https://osv.dev/vulnerability/GHSA-6gpp-xcg3-4w24\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e27ef00f1ca3aee6", "name": "Vulnerable dependency next 16.1.6: GHSA-89xv-2m56-2m9x", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-89xv-2m56-2m9x"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-89xv-2m56-2m9x (aka CVE-2026-64649).\n\nNext.js: Server-Side Request Forgery in Server Actions on custom servers\n\nAliases: CVE-2026-64649\nAdvisory: https://osv.dev/vulnerability/GHSA-89xv-2m56-2m9x\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6acfbfe7dcc12698", "name": "Vulnerable dependency next 16.1.6: GHSA-8h8q-6873-q5fj", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-8h8q-6873-q5fj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-8h8q-6873-q5fj.\n\nNext.js Vulnerable to Denial of Service with Server Components\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8h8q-6873-q5fj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5fb0f0f841969b5b", "name": "Vulnerable dependency next 16.1.6: GHSA-955p-x3mx-jcvp", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-955p-x3mx-jcvp"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-955p-x3mx-jcvp (aka CVE-2026-64643).\n\nNext.js: Unauthenticated disclosure of internal Server Function endpoints\n\nAliases: CVE-2026-64643\nAdvisory: https://osv.dev/vulnerability/GHSA-955p-x3mx-jcvp\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1643400d94fdae48", "name": "Vulnerable dependency next 16.1.6: GHSA-c4j6-fc7j-m34r", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-c4j6-fc7j-m34r"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-c4j6-fc7j-m34r (aka CVE-2026-44578).\n\nNext.js vulnerable to server-side request forgery in applications using WebSocket upgrades\n\nAliases: CVE-2026-44578\nAdvisory: https://osv.dev/vulnerability/GHSA-c4j6-fc7j-m34r\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7633ef9eeb7a0c32", "name": "Vulnerable dependency next 16.1.6: GHSA-ffhc-5mcf-pf4q", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-ffhc-5mcf-pf4q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-ffhc-5mcf-pf4q (aka CVE-2026-44581).\n\nNext.js vulnerable to cross-site scripting in App Router applications using CSP nonces\n\nAliases: CVE-2026-44581\nAdvisory: https://osv.dev/vulnerability/GHSA-ffhc-5mcf-pf4q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7a0a0d196bc2644f", "name": "Vulnerable dependency next 16.1.6: GHSA-ggv3-7p47-pfv8", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-ggv3-7p47-pfv8"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-ggv3-7p47-pfv8 (aka CVE-2026-29057).\n\nNext.js: HTTP request smuggling in rewrites\n\nAliases: CVE-2026-29057\nAdvisory: https://osv.dev/vulnerability/GHSA-ggv3-7p47-pfv8\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5d14c80dfcde339e", "name": "Vulnerable dependency next 16.1.6: GHSA-gx5p-jg67-6x7h", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-gx5p-jg67-6x7h"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-gx5p-jg67-6x7h (aka CVE-2026-44580).\n\nNext.js has cross-site scripting in beforeInteractive scripts with untrusted input\n\nAliases: CVE-2026-44580\nAdvisory: https://osv.dev/vulnerability/GHSA-gx5p-jg67-6x7h\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ecf38c6075b76510", "name": "Vulnerable dependency next 16.1.6: GHSA-h27x-g6w4-24gq", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-h27x-g6w4-24gq"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-h27x-g6w4-24gq.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-h27x-g6w4-24gq\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-21fc2c80639cc84e", "name": "Vulnerable dependency next 16.1.6: GHSA-h64f-5h5j-jqjh", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-h64f-5h5j-jqjh"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-h64f-5h5j-jqjh (aka CVE-2026-44577).\n\nNext.js has a Denial of Service in the Image Optimization API\n\nAliases: CVE-2026-44577\nAdvisory: https://osv.dev/vulnerability/GHSA-h64f-5h5j-jqjh\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-22694e26fad606a0", "name": "Vulnerable dependency next 16.1.6: GHSA-jcc7-9wpm-mj36", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-jcc7-9wpm-mj36"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-jcc7-9wpm-mj36.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jcc7-9wpm-mj36\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-12024fcd1d5adec4", "name": "Vulnerable dependency next 16.1.6: GHSA-m99w-x7hq-7vfj", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-m99w-x7hq-7vfj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-m99w-x7hq-7vfj (aka CVE-2026-64641).\n\nNext.js: Denial of Service in App Router using Server Actions\n\nAliases: CVE-2026-64641\nAdvisory: https://osv.dev/vulnerability/GHSA-m99w-x7hq-7vfj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-212c62b5914af9eb", "name": "Vulnerable dependency next 16.1.6: GHSA-mg66-mrh9-m8jx", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-mg66-mrh9-m8jx"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-mg66-mrh9-m8jx (aka CVE-2026-44579).\n\nNext.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components\n\nAliases: CVE-2026-44579\nAdvisory: https://osv.dev/vulnerability/GHSA-mg66-mrh9-m8jx\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-10ecaa4f345f6c72", "name": "Vulnerable dependency next 16.1.6: GHSA-mq59-m269-xvcx", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-mq59-m269-xvcx"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-mq59-m269-xvcx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mq59-m269-xvcx\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5bd47020777fd274", "name": "Vulnerable dependency next 16.1.6: GHSA-p9j2-gv94-2wf4", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-p9j2-gv94-2wf4"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-p9j2-gv94-2wf4 (aka CVE-2026-64645).\n\nNext.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\nAliases: CVE-2026-64645\nAdvisory: https://osv.dev/vulnerability/GHSA-p9j2-gv94-2wf4\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7cc488b141ba38ac", "name": "Vulnerable dependency next 16.1.6: GHSA-q4gf-8mx6-v5v3", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-q4gf-8mx6-v5v3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-q4gf-8mx6-v5v3.\n\nNext.js has a Denial of Service with Server Components\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q4gf-8mx6-v5v3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6c90b619f8950a47", "name": "Vulnerable dependency next 16.1.6: GHSA-q8wf-6r8g-63ch", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-q8wf-6r8g-63ch"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-q8wf-6r8g-63ch (aka CVE-2026-64644).\n\nNext.js: Denial of Service in the Image Optimization API using SVGs\n\nAliases: CVE-2026-64644\nAdvisory: https://osv.dev/vulnerability/GHSA-q8wf-6r8g-63ch\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a656a4f52ae8cdc2", "name": "Vulnerable dependency next 16.1.6: GHSA-vfv6-92ff-j949", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-vfv6-92ff-j949"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-vfv6-92ff-j949 (aka CVE-2026-44582).\n\nNext.js vulnerable to cache poisoning via collisions in React Server Component cache-busting\n\nAliases: CVE-2026-44582\nAdvisory: https://osv.dev/vulnerability/GHSA-vfv6-92ff-j949\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b857a474fc56e115", "name": "Vulnerable dependency next 16.1.6: GHSA-wfc6-r584-vfw7", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-wfc6-r584-vfw7"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-wfc6-r584-vfw7 (aka CVE-2026-44576).\n\nNext.js vulnerable to cache poisoning in React Server Component responses\n\nAliases: CVE-2026-44576\nAdvisory: https://osv.dev/vulnerability/GHSA-wfc6-r584-vfw7\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9f0ba69a8769a605", "name": "Vulnerable dependency postcss 8.5.8: GHSA-6g55-p6wh-862q", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.8: GHSA-6g55-p6wh-862q"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.8` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-6g55-p6wh-862q (aka CVE-2026-45623).\n\nPostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments\n\nAliases: CVE-2026-45623\nAdvisory: https://osv.dev/vulnerability/GHSA-6g55-p6wh-862q\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-d0332d5e3c05fd58", "name": "Vulnerable dependency postcss 8.5.8: GHSA-qx2v-qp2m-jg93", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.8: GHSA-qx2v-qp2m-jg93"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.8` (resolved in `advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json`) is affected by GHSA-qx2v-qp2m-jg93 (aka CVE-2026-41305).\n\nPostCSS has XSS via Unescaped </style> in its CSS Stringify Output\n\nAliases: CVE-2026-41305\nAdvisory: https://osv.dev/vulnerability/GHSA-qx2v-qp2m-jg93\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-08f2e05e22ce335a", "name": "Vulnerable dependency axios 1.11.0: GHSA-35jp-ww65-95wh", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-35jp-ww65-95wh"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-35jp-ww65-95wh.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-35jp-ww65-95wh\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-814d66d9828c04e2", "name": "Vulnerable dependency axios 1.11.0: GHSA-3g43-6gmg-66jw", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-3g43-6gmg-66jw"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-3g43-6gmg-66jw.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-3g43-6gmg-66jw\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-009520a68cce8704", "name": "Vulnerable dependency axios 1.11.0: GHSA-3p68-rc4w-qgx5", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-3p68-rc4w-qgx5"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-3p68-rc4w-qgx5.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-3p68-rc4w-qgx5\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9c2af18b7ae2af4c", "name": "Vulnerable dependency axios 1.11.0: GHSA-3w6x-2g7m-8v23", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-3w6x-2g7m-8v23"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-3w6x-2g7m-8v23.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-3w6x-2g7m-8v23\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f7bbea57b4997075", "name": "Vulnerable dependency axios 1.11.0: GHSA-42h9-826w-cgv3", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-42h9-826w-cgv3"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-42h9-826w-cgv3.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-42h9-826w-cgv3\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b67dd38387904a47", "name": "Vulnerable dependency axios 1.11.0: GHSA-43fc-jf86-j433", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-43fc-jf86-j433"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-43fc-jf86-j433.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-43fc-jf86-j433\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ee8a1ff2ca8cf6fc", "name": "Vulnerable dependency axios 1.11.0: GHSA-445q-vr5w-6q77", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-445q-vr5w-6q77"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-445q-vr5w-6q77.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-445q-vr5w-6q77\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2db2cd3055a4a2f4", "name": "Vulnerable dependency axios 1.11.0: GHSA-4hjh-wcwx-xvwj", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-4hjh-wcwx-xvwj"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-4hjh-wcwx-xvwj.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-4hjh-wcwx-xvwj\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a039c0af076a3735", "name": "Vulnerable dependency axios 1.11.0: GHSA-5c9x-8gcm-mpgx", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-5c9x-8gcm-mpgx"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-5c9x-8gcm-mpgx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-5c9x-8gcm-mpgx\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-727cc8c4f75187a6", "name": "Vulnerable dependency axios 1.11.0: GHSA-62hf-57xw-28j9", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-62hf-57xw-28j9"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-62hf-57xw-28j9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-62hf-57xw-28j9\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c46b95e5477d197e", "name": "Vulnerable dependency axios 1.11.0: GHSA-6chq-wfr3-2hj9", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-6chq-wfr3-2hj9"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-6chq-wfr3-2hj9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6chq-wfr3-2hj9\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-979e3ad812a60b83", "name": "Vulnerable dependency axios 1.11.0: GHSA-777c-7fjr-54vf", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-777c-7fjr-54vf"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-777c-7fjr-54vf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-777c-7fjr-54vf\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1a1634914cd42338", "name": "Vulnerable dependency axios 1.11.0: GHSA-7q8q-rj6j-mhjq", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-7q8q-rj6j-mhjq"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-7q8q-rj6j-mhjq.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-7q8q-rj6j-mhjq\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-78a436ac5b83b90b", "name": "Vulnerable dependency axios 1.11.0: GHSA-898c-q2cr-xwhg", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-898c-q2cr-xwhg"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-898c-q2cr-xwhg.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-898c-q2cr-xwhg\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-77088e97ede35190", "name": "Vulnerable dependency axios 1.11.0: GHSA-fvcv-3m26-pcqx", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-fvcv-3m26-pcqx"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-fvcv-3m26-pcqx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fvcv-3m26-pcqx\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3dcf07308fdb2db9", "name": "Vulnerable dependency axios 1.11.0: GHSA-hfxv-24rg-xrqf", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-hfxv-24rg-xrqf"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-hfxv-24rg-xrqf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hfxv-24rg-xrqf\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0c8ff34925117e3b", "name": "Vulnerable dependency axios 1.11.0: GHSA-j5f8-grm9-p9fc", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-j5f8-grm9-p9fc"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-j5f8-grm9-p9fc.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-j5f8-grm9-p9fc\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9316dbce0158f716", "name": "Vulnerable dependency axios 1.11.0: GHSA-jqh4-m9w3-8hp9", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-jqh4-m9w3-8hp9"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-jqh4-m9w3-8hp9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jqh4-m9w3-8hp9\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-481559b4320de4e5", "name": "Vulnerable dependency axios 1.11.0: GHSA-m7pr-hjqh-92cm", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-m7pr-hjqh-92cm"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-m7pr-hjqh-92cm.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-m7pr-hjqh-92cm\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-65bc0a2f855dd091", "name": "Vulnerable dependency axios 1.11.0: GHSA-mmx7-hfxf-jppx", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-mmx7-hfxf-jppx"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-mmx7-hfxf-jppx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mmx7-hfxf-jppx\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eb1106c0a41f4c26", "name": "Vulnerable dependency axios 1.11.0: GHSA-p92q-9vqr-4j8v", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-p92q-9vqr-4j8v"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-p92q-9vqr-4j8v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p92q-9vqr-4j8v\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-61ee42081c14aaca", "name": "Vulnerable dependency axios 1.11.0: GHSA-pf86-5x62-jrwf", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-pf86-5x62-jrwf"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-pf86-5x62-jrwf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pf86-5x62-jrwf\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-02f049c4cda80be7", "name": "Vulnerable dependency axios 1.11.0: GHSA-pmv8-rq9r-6j72", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-pmv8-rq9r-6j72"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-pmv8-rq9r-6j72.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pmv8-rq9r-6j72\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e21c6a708b8f31bc", "name": "Vulnerable dependency axios 1.11.0: GHSA-pmwg-cvhr-8vh7", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-pmwg-cvhr-8vh7"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-pmwg-cvhr-8vh7.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pmwg-cvhr-8vh7\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-40c06b29d7b10796", "name": "Vulnerable dependency axios 1.11.0: GHSA-q8qp-cvcw-x6jj", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-q8qp-cvcw-x6jj"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-q8qp-cvcw-x6jj.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q8qp-cvcw-x6jj\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-beed1dee6387c1bc", "name": "Vulnerable dependency axios 1.11.0: GHSA-vf2m-468p-8v99", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-vf2m-468p-8v99"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-vf2m-468p-8v99.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vf2m-468p-8v99\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2ba5d37e9ebb7ead", "name": "Vulnerable dependency axios 1.11.0: GHSA-w9j2-pvgh-6h63", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-w9j2-pvgh-6h63"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-w9j2-pvgh-6h63.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w9j2-pvgh-6h63\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-147489be53febd4a", "name": "Vulnerable dependency axios 1.11.0: GHSA-xhjh-pmcv-23jw", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-xhjh-pmcv-23jw"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-xhjh-pmcv-23jw.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xhjh-pmcv-23jw\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-10d203c8f2340363", "name": "Vulnerable dependency axios 1.11.0: GHSA-xx6v-rp6x-q39c", "shortDescription": {"text": "Vulnerable dependency axios 1.11.0: GHSA-xx6v-rp6x-q39c"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.11.0` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-xx6v-rp6x-q39c.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xx6v-rp6x-q39c\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cf338cf76f24b16e", "name": "Vulnerable dependency electron 37.2.6: GHSA-3c8v-cfp5-9885", "shortDescription": {"text": "Vulnerable dependency electron 37.2.6: GHSA-3c8v-cfp5-9885"}, "fullDescription": {"text": "OSV.dev reports `electron` at version `37.2.6` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-3c8v-cfp5-9885.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-3c8v-cfp5-9885\nFix: upgrade `electron` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7b922335d976f42d", "name": "Vulnerable dependency electron 37.2.6: GHSA-4p4r-m79c-wq3v", "shortDescription": {"text": "Vulnerable dependency electron 37.2.6: GHSA-4p4r-m79c-wq3v"}, "fullDescription": {"text": "OSV.dev reports `electron` at version `37.2.6` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-4p4r-m79c-wq3v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-4p4r-m79c-wq3v\nFix: upgrade `electron` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-05845fc98881bc91", "name": "Vulnerable dependency electron 37.2.6: GHSA-532v-xpq5-8h95", "shortDescription": {"text": "Vulnerable dependency electron 37.2.6: GHSA-532v-xpq5-8h95"}, "fullDescription": {"text": "OSV.dev reports `electron` at version `37.2.6` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-532v-xpq5-8h95.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-532v-xpq5-8h95\nFix: upgrade `electron` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-72d3dc0676c330f9", "name": "Vulnerable dependency electron 37.2.6: GHSA-5rqw-r77c-jp79", "shortDescription": {"text": "Vulnerable dependency electron 37.2.6: GHSA-5rqw-r77c-jp79"}, "fullDescription": {"text": "OSV.dev reports `electron` at version `37.2.6` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-5rqw-r77c-jp79.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-5rqw-r77c-jp79\nFix: upgrade `electron` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ed6e709c4ef2db22", "name": "Vulnerable dependency electron 37.2.6: GHSA-8337-3p73-46f4", "shortDescription": {"text": "Vulnerable dependency electron 37.2.6: GHSA-8337-3p73-46f4"}, "fullDescription": {"text": "OSV.dev reports `electron` at version `37.2.6` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-8337-3p73-46f4.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8337-3p73-46f4\nFix: upgrade `electron` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fcccb2bf78bb2654", "name": "Vulnerable dependency electron 37.2.6: GHSA-8x5q-pvf5-64mp", "shortDescription": {"text": "Vulnerable dependency electron 37.2.6: GHSA-8x5q-pvf5-64mp"}, "fullDescription": {"text": "OSV.dev reports `electron` at version `37.2.6` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-8x5q-pvf5-64mp.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8x5q-pvf5-64mp\nFix: upgrade `electron` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5dcca1137d36e6e2", "name": "Vulnerable dependency electron 37.2.6: GHSA-9899-m83m-qhpj", "shortDescription": {"text": "Vulnerable dependency electron 37.2.6: GHSA-9899-m83m-qhpj"}, "fullDescription": {"text": "OSV.dev reports `electron` at version `37.2.6` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-9899-m83m-qhpj.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9899-m83m-qhpj\nFix: upgrade `electron` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3ef164b37ae427f0", "name": "Vulnerable dependency electron 37.2.6: GHSA-9w97-2464-8783", "shortDescription": {"text": "Vulnerable dependency electron 37.2.6: GHSA-9w97-2464-8783"}, "fullDescription": {"text": "OSV.dev reports `electron` at version `37.2.6` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-9w97-2464-8783.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9w97-2464-8783\nFix: upgrade `electron` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9445fb1dda7e7af6", "name": "Vulnerable dependency electron 37.2.6: GHSA-9wfr-w7mm-pc7f", "shortDescription": {"text": "Vulnerable dependency electron 37.2.6: GHSA-9wfr-w7mm-pc7f"}, "fullDescription": {"text": "OSV.dev reports `electron` at version `37.2.6` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-9wfr-w7mm-pc7f.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9wfr-w7mm-pc7f\nFix: upgrade `electron` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a001199030d427fb", "name": "Vulnerable dependency electron 37.2.6: GHSA-f37v-82c4-4x64", "shortDescription": {"text": "Vulnerable dependency electron 37.2.6: GHSA-f37v-82c4-4x64"}, "fullDescription": {"text": "OSV.dev reports `electron` at version `37.2.6` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-f37v-82c4-4x64.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-f37v-82c4-4x64\nFix: upgrade `electron` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fbf30e166decc37a", "name": "Vulnerable dependency electron 37.2.6: GHSA-f3pv-wv63-48x8", "shortDescription": {"text": "Vulnerable dependency electron 37.2.6: GHSA-f3pv-wv63-48x8"}, "fullDescription": {"text": "OSV.dev reports `electron` at version `37.2.6` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-f3pv-wv63-48x8.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-f3pv-wv63-48x8\nFix: upgrade `electron` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aa6674f9c21315da", "name": "Vulnerable dependency electron 37.2.6: GHSA-jfqx-fxh3-c62j", "shortDescription": {"text": "Vulnerable dependency electron 37.2.6: GHSA-jfqx-fxh3-c62j"}, "fullDescription": {"text": "OSV.dev reports `electron` at version `37.2.6` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-jfqx-fxh3-c62j.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jfqx-fxh3-c62j\nFix: upgrade `electron` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6e1c503e26bf4c7d", "name": "Vulnerable dependency electron 37.2.6: GHSA-jjp3-mq3x-295m", "shortDescription": {"text": "Vulnerable dependency electron 37.2.6: GHSA-jjp3-mq3x-295m"}, "fullDescription": {"text": "OSV.dev reports `electron` at version `37.2.6` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-jjp3-mq3x-295m.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jjp3-mq3x-295m\nFix: upgrade `electron` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9223eb674152033d", "name": "Vulnerable dependency electron 37.2.6: GHSA-mwmh-mq4g-g6gr", "shortDescription": {"text": "Vulnerable dependency electron 37.2.6: GHSA-mwmh-mq4g-g6gr"}, "fullDescription": {"text": "OSV.dev reports `electron` at version `37.2.6` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-mwmh-mq4g-g6gr.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mwmh-mq4g-g6gr\nFix: upgrade `electron` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b30c98cbe425cd39", "name": "Vulnerable dependency electron 37.2.6: GHSA-r5p7-gp4j-qhrx", "shortDescription": {"text": "Vulnerable dependency electron 37.2.6: GHSA-r5p7-gp4j-qhrx"}, "fullDescription": {"text": "OSV.dev reports `electron` at version `37.2.6` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-r5p7-gp4j-qhrx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r5p7-gp4j-qhrx\nFix: upgrade `electron` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f82610ea891284b2", "name": "Vulnerable dependency electron 37.2.6: GHSA-vmqv-hx8q-j7mg", "shortDescription": {"text": "Vulnerable dependency electron 37.2.6: GHSA-vmqv-hx8q-j7mg"}, "fullDescription": {"text": "OSV.dev reports `electron` at version `37.2.6` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-vmqv-hx8q-j7mg.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vmqv-hx8q-j7mg\nFix: upgrade `electron` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-667d4d0061362efe", "name": "Vulnerable dependency electron 37.2.6: GHSA-xj5x-m3f3-5x3h", "shortDescription": {"text": "Vulnerable dependency electron 37.2.6: GHSA-xj5x-m3f3-5x3h"}, "fullDescription": {"text": "OSV.dev reports `electron` at version `37.2.6` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-xj5x-m3f3-5x3h.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xj5x-m3f3-5x3h\nFix: upgrade `electron` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fd8aae660189773f", "name": "Vulnerable dependency electron 37.2.6: GHSA-xwr5-m59h-vwqr", "shortDescription": {"text": "Vulnerable dependency electron 37.2.6: GHSA-xwr5-m59h-vwqr"}, "fullDescription": {"text": "OSV.dev reports `electron` at version `37.2.6` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-xwr5-m59h-vwqr.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xwr5-m59h-vwqr\nFix: upgrade `electron` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-484b4abf758a1ed3", "name": "Vulnerable dependency tar 6.2.1: GHSA-23hp-3jrh-7fpw", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-23hp-3jrh-7fpw"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-23hp-3jrh-7fpw.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-23hp-3jrh-7fpw\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ae463d5502621523", "name": "Vulnerable dependency tar 6.2.1: GHSA-34x7-hfp2-rc4v", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-34x7-hfp2-rc4v"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-34x7-hfp2-rc4v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-34x7-hfp2-rc4v\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-a080bbceacea5120", "name": "Vulnerable dependency tar 6.2.1: GHSA-83g3-92jg-28cx", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-83g3-92jg-28cx"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-83g3-92jg-28cx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-83g3-92jg-28cx\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-d4b5b3167bbd41b3", "name": "Vulnerable dependency tar 6.2.1: GHSA-8qq5-rm4j-mr97", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-8qq5-rm4j-mr97"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-8qq5-rm4j-mr97.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8qq5-rm4j-mr97\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ba49b5fdb33775e0", "name": "Vulnerable dependency tar 6.2.1: GHSA-8x88-c5mf-7j5w", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-8x88-c5mf-7j5w"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-8x88-c5mf-7j5w.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8x88-c5mf-7j5w\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4b87004a76c96813", "name": "Vulnerable dependency tar 6.2.1: GHSA-9ppj-qmqm-q256", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-9ppj-qmqm-q256"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-9ppj-qmqm-q256.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9ppj-qmqm-q256\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-fa0048609ee5f671", "name": "Vulnerable dependency tar 6.2.1: GHSA-gvwx-54wh-qm9j", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-gvwx-54wh-qm9j"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-gvwx-54wh-qm9j.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gvwx-54wh-qm9j\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-79efca9486942718", "name": "Vulnerable dependency tar 6.2.1: GHSA-qffp-2rhf-9h96", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-qffp-2rhf-9h96"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-qffp-2rhf-9h96.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qffp-2rhf-9h96\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-a87c61d1deaea113", "name": "Vulnerable dependency tar 6.2.1: GHSA-r6q2-hw4h-h46w", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-r6q2-hw4h-h46w"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-r6q2-hw4h-h46w.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r6q2-hw4h-h46w\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-205ec9c81e3c2f29", "name": "Vulnerable dependency tar 6.2.1: GHSA-vmf3-w455-68vh", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-vmf3-w455-68vh"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-vmf3-w455-68vh.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vmf3-w455-68vh\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-84c5084dfe1cc645", "name": "Vulnerable dependency tar 6.2.1: GHSA-w8wr-v893-vjvp", "shortDescription": {"text": "Vulnerable dependency tar 6.2.1: GHSA-w8wr-v893-vjvp"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `6.2.1` (resolved in `advanced_llm_apps/thinkpath_chatbot_app/package-lock.json`) is affected by GHSA-w8wr-v893-vjvp.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w8wr-v893-vjvp\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-259e1b236aedc2e2", "name": "Vulnerable dependency diff 7.0.0: GHSA-73rr-hh4g-fpgx", "shortDescription": {"text": "Vulnerable dependency diff 7.0.0: GHSA-73rr-hh4g-fpgx"}, "fullDescription": {"text": "OSV.dev reports `diff` at version `7.0.0` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-73rr-hh4g-fpgx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-73rr-hh4g-fpgx\nFix: upgrade `diff` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ec6e06b5a2bb6dca", "name": "Vulnerable dependency next 15.5.15: GHSA-267c-6grr-h53f", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-267c-6grr-h53f"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-267c-6grr-h53f (aka CVE-2026-44575).\n\nNext.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes\n\nAliases: CVE-2026-44575\nAdvisory: https://osv.dev/vulnerability/GHSA-267c-6grr-h53f\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2e37d7b45eeccb19", "name": "Vulnerable dependency next 15.5.15: GHSA-26hh-7cqf-hhc6", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-26hh-7cqf-hhc6"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-26hh-7cqf-hhc6 (aka CVE-2026-45109).\n\nNext.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up\n\nAliases: CVE-2026-45109\nAdvisory: https://osv.dev/vulnerability/GHSA-26hh-7cqf-hhc6\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-07c2e77581cf82eb", "name": "Vulnerable dependency next 15.5.15: GHSA-36qx-fr4f-26g5", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-36qx-fr4f-26g5"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-36qx-fr4f-26g5 (aka CVE-2026-44573).\n\nNext.js has a Middleware / Proxy bypass in Pages Router applications using i18n\n\nAliases: CVE-2026-44573\nAdvisory: https://osv.dev/vulnerability/GHSA-36qx-fr4f-26g5\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dccf6217737c52d3", "name": "Vulnerable dependency next 15.5.15: GHSA-3g8h-86w9-wvmq", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-3g8h-86w9-wvmq"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-3g8h-86w9-wvmq (aka CVE-2026-44572).\n\nNext.js's Middleware / Proxy redirects can be cache-poisoned\n\nAliases: CVE-2026-44572\nAdvisory: https://osv.dev/vulnerability/GHSA-3g8h-86w9-wvmq\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d8d9b315e2d99de8", "name": "Vulnerable dependency next 15.5.15: GHSA-4633-3j49-mh5q", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-4633-3j49-mh5q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-4633-3j49-mh5q (aka CVE-2026-64647).\n\nNext.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\nAliases: CVE-2026-64647\nAdvisory: https://osv.dev/vulnerability/GHSA-4633-3j49-mh5q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4c1fcf92142bf910", "name": "Vulnerable dependency next 15.5.15: GHSA-492v-c6pp-mqqv", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-492v-c6pp-mqqv"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-492v-c6pp-mqqv (aka CVE-2026-44574).\n\nNext.js has a Middleware / Proxy bypass through dynamic route parameter injection\n\nAliases: CVE-2026-44574\nAdvisory: https://osv.dev/vulnerability/GHSA-492v-c6pp-mqqv\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1fe0ff76651e32c2", "name": "Vulnerable dependency next 15.5.15: GHSA-4c39-4ccg-62r3", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-4c39-4ccg-62r3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-4c39-4ccg-62r3 (aka CVE-2026-64646).\n\nNext.js: Unbounded Server Action payload in Edge runtime\n\nAliases: CVE-2026-64646\nAdvisory: https://osv.dev/vulnerability/GHSA-4c39-4ccg-62r3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b41c312612d72b3c", "name": "Vulnerable dependency next 15.5.15: GHSA-68g3-v927-f742", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-68g3-v927-f742"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-68g3-v927-f742 (aka CVE-2026-64648).\n\nNext.js: Cache confusion of response bodies for requests with bodies\n\nAliases: CVE-2026-64648\nAdvisory: https://osv.dev/vulnerability/GHSA-68g3-v927-f742\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-397895e88fab637b", "name": "Vulnerable dependency next 15.5.15: GHSA-89xv-2m56-2m9x", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-89xv-2m56-2m9x"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-89xv-2m56-2m9x (aka CVE-2026-64649).\n\nNext.js: Server-Side Request Forgery in Server Actions on custom servers\n\nAliases: CVE-2026-64649\nAdvisory: https://osv.dev/vulnerability/GHSA-89xv-2m56-2m9x\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-aa4d5644b78da3f6", "name": "Vulnerable dependency next 15.5.15: GHSA-8h8q-6873-q5fj", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-8h8q-6873-q5fj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-8h8q-6873-q5fj.\n\nNext.js Vulnerable to Denial of Service with Server Components\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8h8q-6873-q5fj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-45d1a5030ad52858", "name": "Vulnerable dependency next 15.5.15: GHSA-955p-x3mx-jcvp", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-955p-x3mx-jcvp"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-955p-x3mx-jcvp (aka CVE-2026-64643).\n\nNext.js: Unauthenticated disclosure of internal Server Function endpoints\n\nAliases: CVE-2026-64643\nAdvisory: https://osv.dev/vulnerability/GHSA-955p-x3mx-jcvp\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dfec36d14bdd6cf5", "name": "Vulnerable dependency next 15.5.15: GHSA-c4j6-fc7j-m34r", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-c4j6-fc7j-m34r"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-c4j6-fc7j-m34r (aka CVE-2026-44578).\n\nNext.js vulnerable to server-side request forgery in applications using WebSocket upgrades\n\nAliases: CVE-2026-44578\nAdvisory: https://osv.dev/vulnerability/GHSA-c4j6-fc7j-m34r\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e7b3644dbac20632", "name": "Vulnerable dependency next 15.5.15: GHSA-ffhc-5mcf-pf4q", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-ffhc-5mcf-pf4q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-ffhc-5mcf-pf4q (aka CVE-2026-44581).\n\nNext.js vulnerable to cross-site scripting in App Router applications using CSP nonces\n\nAliases: CVE-2026-44581\nAdvisory: https://osv.dev/vulnerability/GHSA-ffhc-5mcf-pf4q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8542f6b49da8ca39", "name": "Vulnerable dependency next 15.5.15: GHSA-gx5p-jg67-6x7h", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-gx5p-jg67-6x7h"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-gx5p-jg67-6x7h (aka CVE-2026-44580).\n\nNext.js has cross-site scripting in beforeInteractive scripts with untrusted input\n\nAliases: CVE-2026-44580\nAdvisory: https://osv.dev/vulnerability/GHSA-gx5p-jg67-6x7h\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c4cecc82edb7e0b7", "name": "Vulnerable dependency next 15.5.15: GHSA-h64f-5h5j-jqjh", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-h64f-5h5j-jqjh"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-h64f-5h5j-jqjh (aka CVE-2026-44577).\n\nNext.js has a Denial of Service in the Image Optimization API\n\nAliases: CVE-2026-44577\nAdvisory: https://osv.dev/vulnerability/GHSA-h64f-5h5j-jqjh\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4e1f7bd2146ab61e", "name": "Vulnerable dependency next 15.5.15: GHSA-m99w-x7hq-7vfj", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-m99w-x7hq-7vfj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-m99w-x7hq-7vfj (aka CVE-2026-64641).\n\nNext.js: Denial of Service in App Router using Server Actions\n\nAliases: CVE-2026-64641\nAdvisory: https://osv.dev/vulnerability/GHSA-m99w-x7hq-7vfj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9ba598575c89d0aa", "name": "Vulnerable dependency next 15.5.15: GHSA-mg66-mrh9-m8jx", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-mg66-mrh9-m8jx"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-mg66-mrh9-m8jx (aka CVE-2026-44579).\n\nNext.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components\n\nAliases: CVE-2026-44579\nAdvisory: https://osv.dev/vulnerability/GHSA-mg66-mrh9-m8jx\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-03de3249db0bc70e", "name": "Vulnerable dependency next 15.5.15: GHSA-p9j2-gv94-2wf4", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-p9j2-gv94-2wf4"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-p9j2-gv94-2wf4 (aka CVE-2026-64645).\n\nNext.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\nAliases: CVE-2026-64645\nAdvisory: https://osv.dev/vulnerability/GHSA-p9j2-gv94-2wf4\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-436157ebeb5eff82", "name": "Vulnerable dependency next 15.5.15: GHSA-q8wf-6r8g-63ch", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-q8wf-6r8g-63ch"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-q8wf-6r8g-63ch (aka CVE-2026-64644).\n\nNext.js: Denial of Service in the Image Optimization API using SVGs\n\nAliases: CVE-2026-64644\nAdvisory: https://osv.dev/vulnerability/GHSA-q8wf-6r8g-63ch\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-456aeb6bc5b13608", "name": "Vulnerable dependency next 15.5.15: GHSA-vfv6-92ff-j949", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-vfv6-92ff-j949"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-vfv6-92ff-j949 (aka CVE-2026-44582).\n\nNext.js vulnerable to cache poisoning via collisions in React Server Component cache-busting\n\nAliases: CVE-2026-44582\nAdvisory: https://osv.dev/vulnerability/GHSA-vfv6-92ff-j949\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f876bfd6ecd99389", "name": "Vulnerable dependency next 15.5.15: GHSA-wfc6-r584-vfw7", "shortDescription": {"text": "Vulnerable dependency next 15.5.15: GHSA-wfc6-r584-vfw7"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.5.15` (resolved in `agent_skills/self-improving-agent-skills/frontend/package-lock.json`) is affected by GHSA-wfc6-r584-vfw7 (aka CVE-2026-44576).\n\nNext.js vulnerable to cache poisoning in React Server Component responses\n\nAliases: CVE-2026-44576\nAdvisory: https://osv.dev/vulnerability/GHSA-wfc6-r584-vfw7\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6de55bf6b59e6511", "name": "Vulnerable dependency @hono/node-server 1.19.14: GHSA-frvp-7c67-39w9", "shortDescription": {"text": "Vulnerable dependency @hono/node-server 1.19.14: GHSA-frvp-7c67-39w9"}, "fullDescription": {"text": "OSV.dev reports `@hono/node-server` at version `1.19.14` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-frvp-7c67-39w9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-frvp-7c67-39w9\nFix: upgrade `@hono/node-server` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ad8cae985e6d5f59", "name": "Vulnerable dependency diff 5.2.0: GHSA-73rr-hh4g-fpgx", "shortDescription": {"text": "Vulnerable dependency diff 5.2.0: GHSA-73rr-hh4g-fpgx"}, "fullDescription": {"text": "OSV.dev reports `diff` at version `5.2.0` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-73rr-hh4g-fpgx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-73rr-hh4g-fpgx\nFix: upgrade `diff` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5abf71efbf6ffec5", "name": "Vulnerable dependency hono 4.12.23: GHSA-88fw-hqm2-52qc", "shortDescription": {"text": "Vulnerable dependency hono 4.12.23: GHSA-88fw-hqm2-52qc"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.23` (resolved in `generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml`) is affected by GHSA-88fw-hqm2-52qc (aka CVE-2026-54290).\n\nhono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nAliases: CVE-2026-54290\nAdvisory: https://osv.dev/vulnerability/GHSA-88fw-hqm2-52qc\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d71dade93d23d920", "name": "Vulnerable dependency hono 4.12.23: GHSA-hvrm-45r6-mjfj", "shortDescription": {"text": "Vulnerable dependency hono 4.12.23: GHSA-hvrm-45r6-mjfj"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.23` (resolved in `generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml`) is affected by GHSA-hvrm-45r6-mjfj.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hvrm-45r6-mjfj\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1484299770f3d114", "name": "Vulnerable dependency hono 4.12.23: GHSA-j6c9-x7qj-28xf", "shortDescription": {"text": "Vulnerable dependency hono 4.12.23: GHSA-j6c9-x7qj-28xf"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.23` (resolved in `generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml`) is affected by GHSA-j6c9-x7qj-28xf (aka CVE-2026-54287).\n\nhono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nAliases: CVE-2026-54287\nAdvisory: https://osv.dev/vulnerability/GHSA-j6c9-x7qj-28xf\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c3686711b6b8f4f1", "name": "Vulnerable dependency hono 4.12.23: GHSA-rv63-4mwf-qqc2", "shortDescription": {"text": "Vulnerable dependency hono 4.12.23: GHSA-rv63-4mwf-qqc2"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.23` (resolved in `generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml`) is affected by GHSA-rv63-4mwf-qqc2 (aka CVE-2026-54288).\n\nhono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`\n\nAliases: CVE-2026-54288\nAdvisory: https://osv.dev/vulnerability/GHSA-rv63-4mwf-qqc2\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5b147445e8285cad", "name": "Vulnerable dependency hono 4.12.23: GHSA-w62v-xxxg-mg59", "shortDescription": {"text": "Vulnerable dependency hono 4.12.23: GHSA-w62v-xxxg-mg59"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.23` (resolved in `generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml`) is affected by GHSA-w62v-xxxg-mg59 (aka CVE-2026-59895).\n\nHono: Server-Side XSS via JSX Escaping Bypass in cx() Utility\n\nAliases: CVE-2026-59895\nAdvisory: https://osv.dev/vulnerability/GHSA-w62v-xxxg-mg59\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6af05213761f2a52", "name": "Vulnerable dependency hono 4.12.23: GHSA-wgpf-jwqj-8h8p", "shortDescription": {"text": "Vulnerable dependency hono 4.12.23: GHSA-wgpf-jwqj-8h8p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.23` (resolved in `generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml`) is affected by GHSA-wgpf-jwqj-8h8p (aka CVE-2026-54289).\n\nhono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest\n\nAliases: CVE-2026-54289\nAdvisory: https://osv.dev/vulnerability/GHSA-wgpf-jwqj-8h8p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8113b565ce825d3e", "name": "Vulnerable dependency hono 4.12.23: GHSA-wwfh-h76j-fc44", "shortDescription": {"text": "Vulnerable dependency hono 4.12.23: GHSA-wwfh-h76j-fc44"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.23` (resolved in `generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml`) is affected by GHSA-wwfh-h76j-fc44 (aka CVE-2026-54286).\n\nhono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nAliases: CVE-2026-54286\nAdvisory: https://osv.dev/vulnerability/GHSA-wwfh-h76j-fc44\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c9ef7ab0cc2d7115", "name": "Vulnerable dependency hono 4.12.23: GHSA-xgm2-5f3f-mvvc", "shortDescription": {"text": "Vulnerable dependency hono 4.12.23: GHSA-xgm2-5f3f-mvvc"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.23` (resolved in `generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml`) is affected by GHSA-xgm2-5f3f-mvvc (aka CVE-2026-59897).\n\nHono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication\n\nAliases: CVE-2026-59897\nAdvisory: https://osv.dev/vulnerability/GHSA-xgm2-5f3f-mvvc\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-25983bfdb03dc630", "name": "Vulnerable dependency next 15.3.2: GHSA-267c-6grr-h53f", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-267c-6grr-h53f"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-267c-6grr-h53f (aka CVE-2026-44575).\n\nNext.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes\n\nAliases: CVE-2026-44575\nAdvisory: https://osv.dev/vulnerability/GHSA-267c-6grr-h53f\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4643287facd07c9a", "name": "Vulnerable dependency next 15.3.2: GHSA-26hh-7cqf-hhc6", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-26hh-7cqf-hhc6"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-26hh-7cqf-hhc6 (aka CVE-2026-45109).\n\nNext.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up\n\nAliases: CVE-2026-45109\nAdvisory: https://osv.dev/vulnerability/GHSA-26hh-7cqf-hhc6\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-86595941c3e52307", "name": "Vulnerable dependency next 15.3.2: GHSA-36qx-fr4f-26g5", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-36qx-fr4f-26g5"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-36qx-fr4f-26g5 (aka CVE-2026-44573).\n\nNext.js has a Middleware / Proxy bypass in Pages Router applications using i18n\n\nAliases: CVE-2026-44573\nAdvisory: https://osv.dev/vulnerability/GHSA-36qx-fr4f-26g5\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-89c13578f103dcb3", "name": "Vulnerable dependency next 15.3.2: GHSA-3g8h-86w9-wvmq", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-3g8h-86w9-wvmq"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-3g8h-86w9-wvmq (aka CVE-2026-44572).\n\nNext.js's Middleware / Proxy redirects can be cache-poisoned\n\nAliases: CVE-2026-44572\nAdvisory: https://osv.dev/vulnerability/GHSA-3g8h-86w9-wvmq\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ee3cff0dd5336778", "name": "Vulnerable dependency next 15.3.2: GHSA-3x4c-7xq6-9pq8", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-3x4c-7xq6-9pq8"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-3x4c-7xq6-9pq8 (aka CVE-2026-27980).\n\nNext.js: Unbounded next/image disk cache growth can exhaust storage\n\nAliases: CVE-2026-27980\nAdvisory: https://osv.dev/vulnerability/GHSA-3x4c-7xq6-9pq8\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0ad8097e4830c737", "name": "Vulnerable dependency next 15.3.2: GHSA-4342-x723-ch2f", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-4342-x723-ch2f"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-4342-x723-ch2f.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-4342-x723-ch2f\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a0acf591b774bcf4", "name": "Vulnerable dependency next 15.3.2: GHSA-4633-3j49-mh5q", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-4633-3j49-mh5q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-4633-3j49-mh5q (aka CVE-2026-64647).\n\nNext.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\nAliases: CVE-2026-64647\nAdvisory: https://osv.dev/vulnerability/GHSA-4633-3j49-mh5q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e7ef30a54ca634be", "name": "Vulnerable dependency next 15.3.2: GHSA-4c39-4ccg-62r3", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-4c39-4ccg-62r3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-4c39-4ccg-62r3 (aka CVE-2026-64646).\n\nNext.js: Unbounded Server Action payload in Edge runtime\n\nAliases: CVE-2026-64646\nAdvisory: https://osv.dev/vulnerability/GHSA-4c39-4ccg-62r3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-40fa9286d5bac9bb", "name": "Vulnerable dependency next 15.3.2: GHSA-68g3-v927-f742", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-68g3-v927-f742"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-68g3-v927-f742 (aka CVE-2026-64648).\n\nNext.js: Cache confusion of response bodies for requests with bodies\n\nAliases: CVE-2026-64648\nAdvisory: https://osv.dev/vulnerability/GHSA-68g3-v927-f742\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7a793187280e314f", "name": "Vulnerable dependency next 15.3.2: GHSA-89xv-2m56-2m9x", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-89xv-2m56-2m9x"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-89xv-2m56-2m9x (aka CVE-2026-64649).\n\nNext.js: Server-Side Request Forgery in Server Actions on custom servers\n\nAliases: CVE-2026-64649\nAdvisory: https://osv.dev/vulnerability/GHSA-89xv-2m56-2m9x\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2c6ceb7c946c512b", "name": "Vulnerable dependency next 15.3.2: GHSA-8h8q-6873-q5fj", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-8h8q-6873-q5fj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-8h8q-6873-q5fj.\n\nNext.js Vulnerable to Denial of Service with Server Components\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8h8q-6873-q5fj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e369fa0a3e8694c6", "name": "Vulnerable dependency next 15.3.2: GHSA-955p-x3mx-jcvp", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-955p-x3mx-jcvp"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-955p-x3mx-jcvp (aka CVE-2026-64643).\n\nNext.js: Unauthenticated disclosure of internal Server Function endpoints\n\nAliases: CVE-2026-64643\nAdvisory: https://osv.dev/vulnerability/GHSA-955p-x3mx-jcvp\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5f93c684bd08aec1", "name": "Vulnerable dependency next 15.3.2: GHSA-9g9p-9gw9-jx7f", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-9g9p-9gw9-jx7f"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-9g9p-9gw9-jx7f.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9g9p-9gw9-jx7f\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-413499a6eae2a1cf", "name": "Vulnerable dependency next 15.3.2: GHSA-9qr9-h5gf-34mp", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-9qr9-h5gf-34mp"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-9qr9-h5gf-34mp.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9qr9-h5gf-34mp\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9a6cd8de9dd1ff92", "name": "Vulnerable dependency next 15.3.2: GHSA-c4j6-fc7j-m34r", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-c4j6-fc7j-m34r"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-c4j6-fc7j-m34r (aka CVE-2026-44578).\n\nNext.js vulnerable to server-side request forgery in applications using WebSocket upgrades\n\nAliases: CVE-2026-44578\nAdvisory: https://osv.dev/vulnerability/GHSA-c4j6-fc7j-m34r\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-356a382fdace0846", "name": "Vulnerable dependency next 15.3.2: GHSA-ffhc-5mcf-pf4q", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-ffhc-5mcf-pf4q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-ffhc-5mcf-pf4q (aka CVE-2026-44581).\n\nNext.js vulnerable to cross-site scripting in App Router applications using CSP nonces\n\nAliases: CVE-2026-44581\nAdvisory: https://osv.dev/vulnerability/GHSA-ffhc-5mcf-pf4q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f5b29dabeb303a21", "name": "Vulnerable dependency next 15.3.2: GHSA-g5qg-72qw-gw5v", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-g5qg-72qw-gw5v"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-g5qg-72qw-gw5v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-g5qg-72qw-gw5v\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c925a7c6c1bb3db4", "name": "Vulnerable dependency next 15.3.2: GHSA-ggv3-7p47-pfv8", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-ggv3-7p47-pfv8"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-ggv3-7p47-pfv8 (aka CVE-2026-29057).\n\nNext.js: HTTP request smuggling in rewrites\n\nAliases: CVE-2026-29057\nAdvisory: https://osv.dev/vulnerability/GHSA-ggv3-7p47-pfv8\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ce59df6e344bde19", "name": "Vulnerable dependency next 15.3.2: GHSA-gx5p-jg67-6x7h", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-gx5p-jg67-6x7h"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-gx5p-jg67-6x7h (aka CVE-2026-44580).\n\nNext.js has cross-site scripting in beforeInteractive scripts with untrusted input\n\nAliases: CVE-2026-44580\nAdvisory: https://osv.dev/vulnerability/GHSA-gx5p-jg67-6x7h\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f52b3ffd4202b015", "name": "Vulnerable dependency next 15.3.2: GHSA-h25m-26qc-wcjf", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-h25m-26qc-wcjf"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-h25m-26qc-wcjf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-h25m-26qc-wcjf\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-efd6e9382523c7ee", "name": "Vulnerable dependency next 15.3.2: GHSA-h64f-5h5j-jqjh", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-h64f-5h5j-jqjh"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-h64f-5h5j-jqjh (aka CVE-2026-44577).\n\nNext.js has a Denial of Service in the Image Optimization API\n\nAliases: CVE-2026-44577\nAdvisory: https://osv.dev/vulnerability/GHSA-h64f-5h5j-jqjh\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d079a2ebf88c49c0", "name": "Vulnerable dependency next 15.3.2: GHSA-m99w-x7hq-7vfj", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-m99w-x7hq-7vfj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-m99w-x7hq-7vfj (aka CVE-2026-64641).\n\nNext.js: Denial of Service in App Router using Server Actions\n\nAliases: CVE-2026-64641\nAdvisory: https://osv.dev/vulnerability/GHSA-m99w-x7hq-7vfj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-915d7df90dd95828", "name": "Vulnerable dependency next 15.3.2: GHSA-mg66-mrh9-m8jx", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-mg66-mrh9-m8jx"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-mg66-mrh9-m8jx (aka CVE-2026-44579).\n\nNext.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components\n\nAliases: CVE-2026-44579\nAdvisory: https://osv.dev/vulnerability/GHSA-mg66-mrh9-m8jx\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-55a19d3270c227a9", "name": "Vulnerable dependency next 15.3.2: GHSA-mwv6-3258-q52c", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-mwv6-3258-q52c"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-mwv6-3258-q52c.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mwv6-3258-q52c\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5d58cf137fb608fd", "name": "Vulnerable dependency next 15.3.2: GHSA-p9j2-gv94-2wf4", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-p9j2-gv94-2wf4"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-p9j2-gv94-2wf4 (aka CVE-2026-64645).\n\nNext.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\nAliases: CVE-2026-64645\nAdvisory: https://osv.dev/vulnerability/GHSA-p9j2-gv94-2wf4\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9ad402be7a7bdba1", "name": "Vulnerable dependency next 15.3.2: GHSA-q4gf-8mx6-v5v3", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-q4gf-8mx6-v5v3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-q4gf-8mx6-v5v3.\n\nNext.js has a Denial of Service with Server Components\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q4gf-8mx6-v5v3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ac4f9b871930f97d", "name": "Vulnerable dependency next 15.3.2: GHSA-r2fc-ccr8-96c4", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-r2fc-ccr8-96c4"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-r2fc-ccr8-96c4.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r2fc-ccr8-96c4\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-750353a4077ee998", "name": "Vulnerable dependency next 15.3.2: GHSA-vfv6-92ff-j949", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-vfv6-92ff-j949"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-vfv6-92ff-j949 (aka CVE-2026-44582).\n\nNext.js vulnerable to cache poisoning via collisions in React Server Component cache-busting\n\nAliases: CVE-2026-44582\nAdvisory: https://osv.dev/vulnerability/GHSA-vfv6-92ff-j949\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b56e0397208d028b", "name": "Vulnerable dependency next 15.3.2: GHSA-w37m-7fhw-fmv9", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-w37m-7fhw-fmv9"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-w37m-7fhw-fmv9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w37m-7fhw-fmv9\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-12a6a41cc333fdd0", "name": "Vulnerable dependency next 15.3.2: GHSA-wfc6-r584-vfw7", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-wfc6-r584-vfw7"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-wfc6-r584-vfw7 (aka CVE-2026-44576).\n\nNext.js vulnerable to cache poisoning in React Server Component responses\n\nAliases: CVE-2026-44576\nAdvisory: https://osv.dev/vulnerability/GHSA-wfc6-r584-vfw7\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-79e4fa34b1d2c1ab", "name": "Vulnerable dependency next 15.3.2: GHSA-xv57-4mr9-wg8v", "shortDescription": {"text": "Vulnerable dependency next 15.3.2: GHSA-xv57-4mr9-wg8v"}, "fullDescription": {"text": "OSV.dev reports `next` at version `15.3.2` (resolved in `generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml`) is affected by GHSA-xv57-4mr9-wg8v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xv57-4mr9-wg8v\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f2c05d08eb4007c6", "name": "Vulnerable dependency click 8.3.1: PYSEC-2026-2132", "shortDescription": {"text": "Vulnerable dependency click 8.3.1: PYSEC-2026-2132"}, "fullDescription": {"text": "OSV.dev reports `click` at version `8.3.1` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by PYSEC-2026-2132.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2132\nFix: upgrade `click` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2320582a958fc949", "name": "Vulnerable dependency idna 3.11: GHSA-65pc-fj4g-8rjx", "shortDescription": {"text": "Vulnerable dependency idna 3.11: GHSA-65pc-fj4g-8rjx"}, "fullDescription": {"text": "OSV.dev reports `idna` at version `3.11` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-65pc-fj4g-8rjx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-65pc-fj4g-8rjx\nFix: upgrade `idna` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0dbf50da30592d7e", "name": "Vulnerable dependency idna 3.11: PYSEC-2026-215", "shortDescription": {"text": "Vulnerable dependency idna 3.11: PYSEC-2026-215"}, "fullDescription": {"text": "OSV.dev reports `idna` at version `3.11` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by PYSEC-2026-215.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-215\nFix: upgrade `idna` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5c337cecea05467e", "name": "Vulnerable dependency langchain 1.2.7: GHSA-gr75-jv2w-4656", "shortDescription": {"text": "Vulnerable dependency langchain 1.2.7: GHSA-gr75-jv2w-4656"}, "fullDescription": {"text": "OSV.dev reports `langchain` at version `1.2.7` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-gr75-jv2w-4656 (aka CVE-2026-55443).\n\nLangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nAliases: CVE-2026-55443, PYSEC-2026-2192, PYSEC-2026-2556\nAdvisory: https://osv.dev/vulnerability/GHSA-gr75-jv2w-4656\nFix: upgrade `langchain` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-10c5f19c31c89afc", "name": "Vulnerable dependency langchain-anthropic 1.3.1: GHSA-gr75-jv2w-4656", "shortDescription": {"text": "Vulnerable dependency langchain-anthropic 1.3.1: GHSA-gr75-jv2w-4656"}, "fullDescription": {"text": "OSV.dev reports `langchain-anthropic` at version `1.3.1` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-gr75-jv2w-4656 (aka CVE-2026-55443).\n\nLangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nAliases: CVE-2026-55443, PYSEC-2026-2192, PYSEC-2026-2556\nAdvisory: https://osv.dev/vulnerability/GHSA-gr75-jv2w-4656\nFix: upgrade `langchain-anthropic` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-71cfe576975d031e", "name": "Vulnerable dependency langchain-core 1.2.7: GHSA-2g6r-c272-w58r", "shortDescription": {"text": "Vulnerable dependency langchain-core 1.2.7: GHSA-2g6r-c272-w58r"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `1.2.7` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-2g6r-c272-w58r.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-2g6r-c272-w58r\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-050540da2643e9cb", "name": "Vulnerable dependency langchain-core 1.2.7: GHSA-926x-3r5x-gfhw", "shortDescription": {"text": "Vulnerable dependency langchain-core 1.2.7: GHSA-926x-3r5x-gfhw"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `1.2.7` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-926x-3r5x-gfhw.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-926x-3r5x-gfhw\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d094f6c72f5899a7", "name": "Vulnerable dependency langchain-core 1.2.7: GHSA-pjwx-r37v-7724", "shortDescription": {"text": "Vulnerable dependency langchain-core 1.2.7: GHSA-pjwx-r37v-7724"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `1.2.7` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-pjwx-r37v-7724.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pjwx-r37v-7724\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-62b4c0ba4f336c45", "name": "Vulnerable dependency langchain-core 1.2.7: GHSA-qh6h-p6c9-ff54", "shortDescription": {"text": "Vulnerable dependency langchain-core 1.2.7: GHSA-qh6h-p6c9-ff54"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `1.2.7` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-qh6h-p6c9-ff54.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qh6h-p6c9-ff54\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7a25856b17d8f18c", "name": "Vulnerable dependency langchain-core 1.2.7: PYSEC-2026-2193", "shortDescription": {"text": "Vulnerable dependency langchain-core 1.2.7: PYSEC-2026-2193"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `1.2.7` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by PYSEC-2026-2193.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2193\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-579d801a66d6c0c2", "name": "Vulnerable dependency langchain-core 1.2.7: PYSEC-2026-2562", "shortDescription": {"text": "Vulnerable dependency langchain-core 1.2.7: PYSEC-2026-2562"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `1.2.7` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by PYSEC-2026-2562.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2562\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0fe42e0906b76391", "name": "Vulnerable dependency langchain-core 1.2.7: PYSEC-2026-2563", "shortDescription": {"text": "Vulnerable dependency langchain-core 1.2.7: PYSEC-2026-2563"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `1.2.7` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by PYSEC-2026-2563.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2563\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5737bc2d6fad5a43", "name": "Vulnerable dependency langchain-core 1.2.7: PYSEC-2026-2564", "shortDescription": {"text": "Vulnerable dependency langchain-core 1.2.7: PYSEC-2026-2564"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `1.2.7` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by PYSEC-2026-2564.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2564\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c640af3794f656da", "name": "Vulnerable dependency langchain-openai 1.1.7: GHSA-r7w7-9xr2-qq2r", "shortDescription": {"text": "Vulnerable dependency langchain-openai 1.1.7: GHSA-r7w7-9xr2-qq2r"}, "fullDescription": {"text": "OSV.dev reports `langchain-openai` at version `1.1.7` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-r7w7-9xr2-qq2r.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r7w7-9xr2-qq2r\nFix: upgrade `langchain-openai` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-55126f1d03233dc2", "name": "Vulnerable dependency langchain-openai 1.1.7: PYSEC-2026-76", "shortDescription": {"text": "Vulnerable dependency langchain-openai 1.1.7: PYSEC-2026-76"}, "fullDescription": {"text": "OSV.dev reports `langchain-openai` at version `1.1.7` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by PYSEC-2026-76.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-76\nFix: upgrade `langchain-openai` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0f48de024d48fad5", "name": "Vulnerable dependency langgraph 1.0.7: GHSA-g48c-2wqr-h844", "shortDescription": {"text": "Vulnerable dependency langgraph 1.0.7: GHSA-g48c-2wqr-h844"}, "fullDescription": {"text": "OSV.dev reports `langgraph` at version `1.0.7` (resolved in `generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock`) is affected by GHSA-g48c-2wqr-h844.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-g48c-2wqr-h844\nFix: upgrade `langgraph` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-781794e3869c37ce", "name": "Vulnerable dependency langgraph 1.0.7: PYSEC-2026-83", "shortDescription": {"text": "Vulnerable dependency langgraph 1.0.7: PYSEC-2026-83"}, "fullDescription": {"text": "OSV.dev reports `langgraph` at version `1.0.7` (resolved in `generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock`) is affected by PYSEC-2026-83.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-83\nFix: upgrade `langgraph` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-54d06dcfc5fe133d", "name": "Vulnerable dependency langsmith 0.6.4: GHSA-3644-q5cj-c5c7", "shortDescription": {"text": "Vulnerable dependency langsmith 0.6.4: GHSA-3644-q5cj-c5c7"}, "fullDescription": {"text": "OSV.dev reports `langsmith` at version `0.6.4` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-3644-q5cj-c5c7 (aka CVE-2026-45134).\n\nLangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nAliases: CVE-2026-45134, PYSEC-2026-2555, PYSEC-2026-2560, PYSEC-2026-2582\nAdvisory: https://osv.dev/vulnerability/GHSA-3644-q5cj-c5c7\nFix: upgrade `langsmith` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-76f3bac0628979a8", "name": "Vulnerable dependency langsmith 0.6.4: GHSA-f4xh-w4cj-qxq8", "shortDescription": {"text": "Vulnerable dependency langsmith 0.6.4: GHSA-f4xh-w4cj-qxq8"}, "fullDescription": {"text": "OSV.dev reports `langsmith` at version `0.6.4` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-f4xh-w4cj-qxq8.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-f4xh-w4cj-qxq8\nFix: upgrade `langsmith` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aca567edde0ca147", "name": "Vulnerable dependency langsmith 0.6.4: GHSA-rr7j-v2q5-chgv", "shortDescription": {"text": "Vulnerable dependency langsmith 0.6.4: GHSA-rr7j-v2q5-chgv"}, "fullDescription": {"text": "OSV.dev reports `langsmith` at version `0.6.4` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-rr7j-v2q5-chgv.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rr7j-v2q5-chgv\nFix: upgrade `langsmith` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea32917d705f8bf3", "name": "Vulnerable dependency langsmith 0.6.4: PYSEC-2026-2583", "shortDescription": {"text": "Vulnerable dependency langsmith 0.6.4: PYSEC-2026-2583"}, "fullDescription": {"text": "OSV.dev reports `langsmith` at version `0.6.4` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by PYSEC-2026-2583.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2583\nFix: upgrade `langsmith` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dfc9e364167fac5e", "name": "Vulnerable dependency orjson 3.11.5: GHSA-hx9q-6w63-j58v", "shortDescription": {"text": "Vulnerable dependency orjson 3.11.5: GHSA-hx9q-6w63-j58v"}, "fullDescription": {"text": "OSV.dev reports `orjson` at version `3.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-hx9q-6w63-j58v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hx9q-6w63-j58v\nFix: upgrade `orjson` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a4e664a075331610", "name": "Vulnerable dependency pyasn1 0.6.2: GHSA-8ppf-4f7h-5ppj", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.2: GHSA-8ppf-4f7h-5ppj"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.2` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-8ppf-4f7h-5ppj.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8ppf-4f7h-5ppj\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d3f661eb004a9b93", "name": "Vulnerable dependency pyasn1 0.6.2: GHSA-hm4w-wwcw-mr6r", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.2: GHSA-hm4w-wwcw-mr6r"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.2` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-hm4w-wwcw-mr6r.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hm4w-wwcw-mr6r\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-de288bf4685518ef", "name": "Vulnerable dependency pyasn1 0.6.2: GHSA-jr27-m4p2-rc6r", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.2: GHSA-jr27-m4p2-rc6r"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.2` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-jr27-m4p2-rc6r.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jr27-m4p2-rc6r\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-52e7d2602bd9b5d2", "name": "Vulnerable dependency pyasn1 0.6.2: PYSEC-2026-2263", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.2: PYSEC-2026-2263"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.2` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by PYSEC-2026-2263.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2263\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-86a2796b63900a1a", "name": "Vulnerable dependency pyasn1 0.6.2: PYSEC-2026-3455", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.2: PYSEC-2026-3455"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.2` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by PYSEC-2026-3455.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3455\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9c49da643885aa4e", "name": "Vulnerable dependency pyasn1 0.6.2: PYSEC-2026-3456", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.2: PYSEC-2026-3456"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.2` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by PYSEC-2026-3456.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3456\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-63a30e5b9f08e00c", "name": "Vulnerable dependency pyasn1 0.6.2: PYSEC-2026-3457", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.2: PYSEC-2026-3457"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.2` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by PYSEC-2026-3457.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3457\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a0f7a4c12507b244", "name": "Vulnerable dependency python-dotenv 1.2.1: GHSA-mf9w-mj56-hr94", "shortDescription": {"text": "Vulnerable dependency python-dotenv 1.2.1: GHSA-mf9w-mj56-hr94"}, "fullDescription": {"text": "OSV.dev reports `python-dotenv` at version `1.2.1` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-mf9w-mj56-hr94.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mf9w-mj56-hr94\nFix: upgrade `python-dotenv` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aca15b04e9a933e8", "name": "Vulnerable dependency python-dotenv 1.2.1: PYSEC-2026-2270", "shortDescription": {"text": "Vulnerable dependency python-dotenv 1.2.1: PYSEC-2026-2270"}, "fullDescription": {"text": "OSV.dev reports `python-dotenv` at version `1.2.1` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by PYSEC-2026-2270.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2270\nFix: upgrade `python-dotenv` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-675101e200c7bceb", "name": "Vulnerable dependency requests 2.32.5: GHSA-gc5v-m9x4-r6x2", "shortDescription": {"text": "Vulnerable dependency requests 2.32.5: GHSA-gc5v-m9x4-r6x2"}, "fullDescription": {"text": "OSV.dev reports `requests` at version `2.32.5` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-gc5v-m9x4-r6x2.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gc5v-m9x4-r6x2\nFix: upgrade `requests` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-14c979f9d47ba2d0", "name": "Vulnerable dependency requests 2.32.5: PYSEC-2026-2275", "shortDescription": {"text": "Vulnerable dependency requests 2.32.5: PYSEC-2026-2275"}, "fullDescription": {"text": "OSV.dev reports `requests` at version `2.32.5` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by PYSEC-2026-2275.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2275\nFix: upgrade `requests` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f4a150bfe9984abd", "name": "Vulnerable dependency urllib3 2.6.3: GHSA-mf9v-mfxr-j63j", "shortDescription": {"text": "Vulnerable dependency urllib3 2.6.3: GHSA-mf9v-mfxr-j63j"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.6.3` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-mf9v-mfxr-j63j.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mf9v-mfxr-j63j\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ab01730b729b428d", "name": "Vulnerable dependency urllib3 2.6.3: GHSA-qccp-gfcp-xxvc", "shortDescription": {"text": "Vulnerable dependency urllib3 2.6.3: GHSA-qccp-gfcp-xxvc"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.6.3` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by GHSA-qccp-gfcp-xxvc.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qccp-gfcp-xxvc\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-360c72c25a1bd03d", "name": "Vulnerable dependency urllib3 2.6.3: PYSEC-2026-141", "shortDescription": {"text": "Vulnerable dependency urllib3 2.6.3: PYSEC-2026-141"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.6.3` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by PYSEC-2026-141.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-141\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-611eb46eafe539c6", "name": "Vulnerable dependency urllib3 2.6.3: PYSEC-2026-142", "shortDescription": {"text": "Vulnerable dependency urllib3 2.6.3: PYSEC-2026-142"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.6.3` (resolved in `generative_ui_agents/ai-deep-research-agent/agent/uv.lock`) is affected by PYSEC-2026-142.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-142\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ba1c9689d1e4e42c", "name": "Vulnerable dependency @modelcontextprotocol/sdk 1.25.3: GHSA-345p-7cg4-v4c7", "shortDescription": {"text": "Vulnerable dependency @modelcontextprotocol/sdk 1.25.3: GHSA-345p-7cg4-v4c7"}, "fullDescription": {"text": "OSV.dev reports `@modelcontextprotocol/sdk` at version `1.25.3` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-345p-7cg4-v4c7.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-345p-7cg4-v4c7\nFix: upgrade `@modelcontextprotocol/sdk` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5aa35d30bda80ae5", "name": "Vulnerable dependency hono 4.11.5: GHSA-26pp-8wgv-hjvm", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-26pp-8wgv-hjvm"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-26pp-8wgv-hjvm.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-26pp-8wgv-hjvm\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-79d20d86634355d4", "name": "Vulnerable dependency hono 4.11.5: GHSA-2gcr-mfcq-wcc3", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-2gcr-mfcq-wcc3"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-2gcr-mfcq-wcc3.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-2gcr-mfcq-wcc3\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4928c7b6e6ec8143", "name": "Vulnerable dependency hono 4.11.5: GHSA-3hrh-pfw6-9m5x", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-3hrh-pfw6-9m5x"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-3hrh-pfw6-9m5x.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-3hrh-pfw6-9m5x\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0659973ada00c6d2", "name": "Vulnerable dependency hono 4.11.5: GHSA-458j-xx4x-4375", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-458j-xx4x-4375"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-458j-xx4x-4375.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-458j-xx4x-4375\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3fc4925e2f26ba5a", "name": "Vulnerable dependency hono 4.11.5: GHSA-5pq2-9x2x-5p6w", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-5pq2-9x2x-5p6w"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-5pq2-9x2x-5p6w.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-5pq2-9x2x-5p6w\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fadb65be81d590d2", "name": "Vulnerable dependency hono 4.11.5: GHSA-69xw-7hcm-h432", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-69xw-7hcm-h432"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-69xw-7hcm-h432.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-69xw-7hcm-h432\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-94561469639a0cd5", "name": "Vulnerable dependency hono 4.11.5: GHSA-6wqw-2p9w-4vw4", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-6wqw-2p9w-4vw4"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-6wqw-2p9w-4vw4.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6wqw-2p9w-4vw4\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-802e7e7c4f82590d", "name": "Vulnerable dependency hono 4.11.5: GHSA-88fw-hqm2-52qc", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-88fw-hqm2-52qc"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-88fw-hqm2-52qc (aka CVE-2026-54290).\n\nhono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nAliases: CVE-2026-54290\nAdvisory: https://osv.dev/vulnerability/GHSA-88fw-hqm2-52qc\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bd4f532bf6e2474a", "name": "Vulnerable dependency hono 4.11.5: GHSA-9r54-q6cx-xmh5", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-9r54-q6cx-xmh5"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-9r54-q6cx-xmh5.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9r54-q6cx-xmh5\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b682b3f7e271aafe", "name": "Vulnerable dependency hono 4.11.5: GHSA-9vqf-7f2p-gf9v", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-9vqf-7f2p-gf9v"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-9vqf-7f2p-gf9v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9vqf-7f2p-gf9v\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2bf01df89831bb75", "name": "Vulnerable dependency hono 4.11.5: GHSA-f577-qrjj-4474", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-f577-qrjj-4474"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-f577-qrjj-4474.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-f577-qrjj-4474\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c1bb9969e3d766b1", "name": "Vulnerable dependency hono 4.11.5: GHSA-gq3j-xvxp-8hrf", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-gq3j-xvxp-8hrf"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-gq3j-xvxp-8hrf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gq3j-xvxp-8hrf\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dafca213b5e14498", "name": "Vulnerable dependency hono 4.11.5: GHSA-hm8q-7f3q-5f36", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-hm8q-7f3q-5f36"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-hm8q-7f3q-5f36.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hm8q-7f3q-5f36\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b26b185dc16cf4e0", "name": "Vulnerable dependency hono 4.11.5: GHSA-j6c9-x7qj-28xf", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-j6c9-x7qj-28xf"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-j6c9-x7qj-28xf (aka CVE-2026-54287).\n\nhono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nAliases: CVE-2026-54287\nAdvisory: https://osv.dev/vulnerability/GHSA-j6c9-x7qj-28xf\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-75d86c488bf95c88", "name": "Vulnerable dependency hono 4.11.5: GHSA-p6xx-57qc-3wxr", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-p6xx-57qc-3wxr"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-p6xx-57qc-3wxr.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p6xx-57qc-3wxr\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d08e2ca22d6db8ca", "name": "Vulnerable dependency hono 4.11.5: GHSA-p77w-8qqv-26rm", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-p77w-8qqv-26rm"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-p77w-8qqv-26rm.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p77w-8qqv-26rm\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-86206b1043dd54c6", "name": "Vulnerable dependency hono 4.11.5: GHSA-q5qw-h33p-qvwr", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-q5qw-h33p-qvwr"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-q5qw-h33p-qvwr.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q5qw-h33p-qvwr\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-576fb0a0772b27ff", "name": "Vulnerable dependency hono 4.11.5: GHSA-qp7p-654g-cw7p", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-qp7p-654g-cw7p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-qp7p-654g-cw7p.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qp7p-654g-cw7p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d155b61a5712a670", "name": "Vulnerable dependency hono 4.11.5: GHSA-r354-f388-2fhh", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-r354-f388-2fhh"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-r354-f388-2fhh.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r354-f388-2fhh\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-76802254abea2242", "name": "Vulnerable dependency hono 4.11.5: GHSA-r5rp-j6wh-rvv4", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-r5rp-j6wh-rvv4"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-r5rp-j6wh-rvv4.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r5rp-j6wh-rvv4\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-92ab8206a2611a80", "name": "Vulnerable dependency hono 4.11.5: GHSA-rv63-4mwf-qqc2", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-rv63-4mwf-qqc2"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-rv63-4mwf-qqc2 (aka CVE-2026-54288).\n\nhono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`\n\nAliases: CVE-2026-54288\nAdvisory: https://osv.dev/vulnerability/GHSA-rv63-4mwf-qqc2\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cb01d23ebaca84ff", "name": "Vulnerable dependency hono 4.11.5: GHSA-v8w9-8mx6-g223", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-v8w9-8mx6-g223"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-v8w9-8mx6-g223.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v8w9-8mx6-g223\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cbfa6d023199ca3e", "name": "Vulnerable dependency hono 4.11.5: GHSA-w332-q679-j88p", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-w332-q679-j88p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-w332-q679-j88p.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w332-q679-j88p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9a6149dafd72b0c", "name": "Vulnerable dependency hono 4.11.5: GHSA-w62v-xxxg-mg59", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-w62v-xxxg-mg59"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-w62v-xxxg-mg59 (aka CVE-2026-59895).\n\nHono: Server-Side XSS via JSX Escaping Bypass in cx() Utility\n\nAliases: CVE-2026-59895\nAdvisory: https://osv.dev/vulnerability/GHSA-w62v-xxxg-mg59\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-211772ba498d9dcf", "name": "Vulnerable dependency hono 4.11.5: GHSA-wgpf-jwqj-8h8p", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-wgpf-jwqj-8h8p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-wgpf-jwqj-8h8p (aka CVE-2026-54289).\n\nhono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest\n\nAliases: CVE-2026-54289\nAdvisory: https://osv.dev/vulnerability/GHSA-wgpf-jwqj-8h8p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-88e0ec1b07e1c567", "name": "Vulnerable dependency hono 4.11.5: GHSA-wmmm-f939-6g9c", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-wmmm-f939-6g9c"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-wmmm-f939-6g9c.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wmmm-f939-6g9c\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-49b5f6e3686da5e2", "name": "Vulnerable dependency hono 4.11.5: GHSA-wwfh-h76j-fc44", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-wwfh-h76j-fc44"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-wwfh-h76j-fc44 (aka CVE-2026-54286).\n\nhono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nAliases: CVE-2026-54286\nAdvisory: https://osv.dev/vulnerability/GHSA-wwfh-h76j-fc44\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f1bd3adb583a75b7", "name": "Vulnerable dependency hono 4.11.5: GHSA-xf4j-xp2r-rqqx", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-xf4j-xp2r-rqqx"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-xf4j-xp2r-rqqx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xf4j-xp2r-rqqx\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-768d0c2530403f38", "name": "Vulnerable dependency hono 4.11.5: GHSA-xgm2-5f3f-mvvc", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-xgm2-5f3f-mvvc"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-xgm2-5f3f-mvvc (aka CVE-2026-59897).\n\nHono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication\n\nAliases: CVE-2026-59897\nAdvisory: https://osv.dev/vulnerability/GHSA-xgm2-5f3f-mvvc\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6baa4a8054e3fc55", "name": "Vulnerable dependency hono 4.11.5: GHSA-xpcf-pg52-r92g", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-xpcf-pg52-r92g"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-xpcf-pg52-r92g.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xpcf-pg52-r92g\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7131e779dd804266", "name": "Vulnerable dependency hono 4.11.5: GHSA-xrhx-7g5j-rcj5", "shortDescription": {"text": "Vulnerable dependency hono 4.11.5: GHSA-xrhx-7g5j-rcj5"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.11.5` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-xrhx-7g5j-rcj5.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xrhx-7g5j-rcj5\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d41bddbbb65323a7", "name": "Vulnerable dependency next 16.1.1: GHSA-267c-6grr-h53f", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-267c-6grr-h53f"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-267c-6grr-h53f (aka CVE-2026-44575).\n\nNext.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes\n\nAliases: CVE-2026-44575\nAdvisory: https://osv.dev/vulnerability/GHSA-267c-6grr-h53f\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-85ce1969636b9cd3", "name": "Vulnerable dependency next 16.1.1: GHSA-26hh-7cqf-hhc6", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-26hh-7cqf-hhc6"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-26hh-7cqf-hhc6 (aka CVE-2026-45109).\n\nNext.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up\n\nAliases: CVE-2026-45109\nAdvisory: https://osv.dev/vulnerability/GHSA-26hh-7cqf-hhc6\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8805e772e15ebd81", "name": "Vulnerable dependency next 16.1.1: GHSA-36qx-fr4f-26g5", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-36qx-fr4f-26g5"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-36qx-fr4f-26g5 (aka CVE-2026-44573).\n\nNext.js has a Middleware / Proxy bypass in Pages Router applications using i18n\n\nAliases: CVE-2026-44573\nAdvisory: https://osv.dev/vulnerability/GHSA-36qx-fr4f-26g5\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6f56ae3368641f58", "name": "Vulnerable dependency next 16.1.1: GHSA-3g8h-86w9-wvmq", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-3g8h-86w9-wvmq"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-3g8h-86w9-wvmq (aka CVE-2026-44572).\n\nNext.js's Middleware / Proxy redirects can be cache-poisoned\n\nAliases: CVE-2026-44572\nAdvisory: https://osv.dev/vulnerability/GHSA-3g8h-86w9-wvmq\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-532f4dd041a47c6b", "name": "Vulnerable dependency next 16.1.1: GHSA-3x4c-7xq6-9pq8", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-3x4c-7xq6-9pq8"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-3x4c-7xq6-9pq8 (aka CVE-2026-27980).\n\nNext.js: Unbounded next/image disk cache growth can exhaust storage\n\nAliases: CVE-2026-27980\nAdvisory: https://osv.dev/vulnerability/GHSA-3x4c-7xq6-9pq8\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ce8de164097ce37c", "name": "Vulnerable dependency next 16.1.1: GHSA-4633-3j49-mh5q", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-4633-3j49-mh5q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-4633-3j49-mh5q (aka CVE-2026-64647).\n\nNext.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\nAliases: CVE-2026-64647\nAdvisory: https://osv.dev/vulnerability/GHSA-4633-3j49-mh5q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1b4510cb5251a14d", "name": "Vulnerable dependency next 16.1.1: GHSA-492v-c6pp-mqqv", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-492v-c6pp-mqqv"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-492v-c6pp-mqqv (aka CVE-2026-44574).\n\nNext.js has a Middleware / Proxy bypass through dynamic route parameter injection\n\nAliases: CVE-2026-44574\nAdvisory: https://osv.dev/vulnerability/GHSA-492v-c6pp-mqqv\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-40a19a8a573a3309", "name": "Vulnerable dependency next 16.1.1: GHSA-4c39-4ccg-62r3", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-4c39-4ccg-62r3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-4c39-4ccg-62r3 (aka CVE-2026-64646).\n\nNext.js: Unbounded Server Action payload in Edge runtime\n\nAliases: CVE-2026-64646\nAdvisory: https://osv.dev/vulnerability/GHSA-4c39-4ccg-62r3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8d23fcd1d1fa3e3a", "name": "Vulnerable dependency next 16.1.1: GHSA-5f7q-jpqc-wp7h", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-5f7q-jpqc-wp7h"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-5f7q-jpqc-wp7h.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-5f7q-jpqc-wp7h\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-558e2c2d1eab809a", "name": "Vulnerable dependency next 16.1.1: GHSA-68g3-v927-f742", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-68g3-v927-f742"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-68g3-v927-f742 (aka CVE-2026-64648).\n\nNext.js: Cache confusion of response bodies for requests with bodies\n\nAliases: CVE-2026-64648\nAdvisory: https://osv.dev/vulnerability/GHSA-68g3-v927-f742\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-85b7b5b7bf727340", "name": "Vulnerable dependency next 16.1.1: GHSA-6gpp-xcg3-4w24", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-6gpp-xcg3-4w24"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-6gpp-xcg3-4w24 (aka CVE-2026-64642).\n\nNext.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale\n\nAliases: CVE-2026-64642\nAdvisory: https://osv.dev/vulnerability/GHSA-6gpp-xcg3-4w24\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-800a145a5dfd3d17", "name": "Vulnerable dependency next 16.1.1: GHSA-89xv-2m56-2m9x", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-89xv-2m56-2m9x"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-89xv-2m56-2m9x (aka CVE-2026-64649).\n\nNext.js: Server-Side Request Forgery in Server Actions on custom servers\n\nAliases: CVE-2026-64649\nAdvisory: https://osv.dev/vulnerability/GHSA-89xv-2m56-2m9x\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-84abeb606a544a28", "name": "Vulnerable dependency next 16.1.1: GHSA-8h8q-6873-q5fj", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-8h8q-6873-q5fj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-8h8q-6873-q5fj.\n\nNext.js Vulnerable to Denial of Service with Server Components\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8h8q-6873-q5fj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a9db58c2f17ea3bd", "name": "Vulnerable dependency next 16.1.1: GHSA-955p-x3mx-jcvp", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-955p-x3mx-jcvp"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-955p-x3mx-jcvp (aka CVE-2026-64643).\n\nNext.js: Unauthenticated disclosure of internal Server Function endpoints\n\nAliases: CVE-2026-64643\nAdvisory: https://osv.dev/vulnerability/GHSA-955p-x3mx-jcvp\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3e9ade4b18616679", "name": "Vulnerable dependency next 16.1.1: GHSA-9g9p-9gw9-jx7f", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-9g9p-9gw9-jx7f"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-9g9p-9gw9-jx7f.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9g9p-9gw9-jx7f\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2ed41bfc316bae99", "name": "Vulnerable dependency next 16.1.1: GHSA-c4j6-fc7j-m34r", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-c4j6-fc7j-m34r"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-c4j6-fc7j-m34r (aka CVE-2026-44578).\n\nNext.js vulnerable to server-side request forgery in applications using WebSocket upgrades\n\nAliases: CVE-2026-44578\nAdvisory: https://osv.dev/vulnerability/GHSA-c4j6-fc7j-m34r\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-38a19468485405a7", "name": "Vulnerable dependency next 16.1.1: GHSA-ffhc-5mcf-pf4q", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-ffhc-5mcf-pf4q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-ffhc-5mcf-pf4q (aka CVE-2026-44581).\n\nNext.js vulnerable to cross-site scripting in App Router applications using CSP nonces\n\nAliases: CVE-2026-44581\nAdvisory: https://osv.dev/vulnerability/GHSA-ffhc-5mcf-pf4q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a48357eea14b0e8f", "name": "Vulnerable dependency next 16.1.1: GHSA-ggv3-7p47-pfv8", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-ggv3-7p47-pfv8"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-ggv3-7p47-pfv8 (aka CVE-2026-29057).\n\nNext.js: HTTP request smuggling in rewrites\n\nAliases: CVE-2026-29057\nAdvisory: https://osv.dev/vulnerability/GHSA-ggv3-7p47-pfv8\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f68b684b2806438a", "name": "Vulnerable dependency next 16.1.1: GHSA-gx5p-jg67-6x7h", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-gx5p-jg67-6x7h"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-gx5p-jg67-6x7h (aka CVE-2026-44580).\n\nNext.js has cross-site scripting in beforeInteractive scripts with untrusted input\n\nAliases: CVE-2026-44580\nAdvisory: https://osv.dev/vulnerability/GHSA-gx5p-jg67-6x7h\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-df7ce90f795ef7da", "name": "Vulnerable dependency next 16.1.1: GHSA-h25m-26qc-wcjf", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-h25m-26qc-wcjf"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-h25m-26qc-wcjf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-h25m-26qc-wcjf\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d785890a396f91d", "name": "Vulnerable dependency next 16.1.1: GHSA-h27x-g6w4-24gq", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-h27x-g6w4-24gq"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-h27x-g6w4-24gq.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-h27x-g6w4-24gq\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-24684883c5bd1804", "name": "Vulnerable dependency next 16.1.1: GHSA-h64f-5h5j-jqjh", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-h64f-5h5j-jqjh"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-h64f-5h5j-jqjh (aka CVE-2026-44577).\n\nNext.js has a Denial of Service in the Image Optimization API\n\nAliases: CVE-2026-44577\nAdvisory: https://osv.dev/vulnerability/GHSA-h64f-5h5j-jqjh\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a1b44fbf0a39da07", "name": "Vulnerable dependency next 16.1.1: GHSA-jcc7-9wpm-mj36", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-jcc7-9wpm-mj36"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-jcc7-9wpm-mj36.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jcc7-9wpm-mj36\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5c258ee50a4bc414", "name": "Vulnerable dependency next 16.1.1: GHSA-m99w-x7hq-7vfj", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-m99w-x7hq-7vfj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-m99w-x7hq-7vfj (aka CVE-2026-64641).\n\nNext.js: Denial of Service in App Router using Server Actions\n\nAliases: CVE-2026-64641\nAdvisory: https://osv.dev/vulnerability/GHSA-m99w-x7hq-7vfj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ad1de68b26198aea", "name": "Vulnerable dependency next 16.1.1: GHSA-mg66-mrh9-m8jx", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-mg66-mrh9-m8jx"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-mg66-mrh9-m8jx (aka CVE-2026-44579).\n\nNext.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components\n\nAliases: CVE-2026-44579\nAdvisory: https://osv.dev/vulnerability/GHSA-mg66-mrh9-m8jx\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2eae071c558ae957", "name": "Vulnerable dependency next 16.1.1: GHSA-mq59-m269-xvcx", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-mq59-m269-xvcx"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-mq59-m269-xvcx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mq59-m269-xvcx\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c562a52adc7f4206", "name": "Vulnerable dependency next 16.1.1: GHSA-p9j2-gv94-2wf4", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-p9j2-gv94-2wf4"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-p9j2-gv94-2wf4 (aka CVE-2026-64645).\n\nNext.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\nAliases: CVE-2026-64645\nAdvisory: https://osv.dev/vulnerability/GHSA-p9j2-gv94-2wf4\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-32e09ad3b5eea58e", "name": "Vulnerable dependency next 16.1.1: GHSA-q4gf-8mx6-v5v3", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-q4gf-8mx6-v5v3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-q4gf-8mx6-v5v3.\n\nNext.js has a Denial of Service with Server Components\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q4gf-8mx6-v5v3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bbe11a8c9880f949", "name": "Vulnerable dependency next 16.1.1: GHSA-q8wf-6r8g-63ch", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-q8wf-6r8g-63ch"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-q8wf-6r8g-63ch (aka CVE-2026-64644).\n\nNext.js: Denial of Service in the Image Optimization API using SVGs\n\nAliases: CVE-2026-64644\nAdvisory: https://osv.dev/vulnerability/GHSA-q8wf-6r8g-63ch\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fba697ec6de59ab7", "name": "Vulnerable dependency next 16.1.1: GHSA-vfv6-92ff-j949", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-vfv6-92ff-j949"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-vfv6-92ff-j949 (aka CVE-2026-44582).\n\nNext.js vulnerable to cache poisoning via collisions in React Server Component cache-busting\n\nAliases: CVE-2026-44582\nAdvisory: https://osv.dev/vulnerability/GHSA-vfv6-92ff-j949\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5d8912b23b8d73e2", "name": "Vulnerable dependency next 16.1.1: GHSA-wfc6-r584-vfw7", "shortDescription": {"text": "Vulnerable dependency next 16.1.1: GHSA-wfc6-r584-vfw7"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.1` (resolved in `generative_ui_agents/ai-deep-research-agent/package-lock.json`) is affected by GHSA-wfc6-r584-vfw7 (aka CVE-2026-44576).\n\nNext.js vulnerable to cache poisoning in React Server Component responses\n\nAliases: CVE-2026-44576\nAdvisory: https://osv.dev/vulnerability/GHSA-wfc6-r584-vfw7\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8fd4338dbb86373e", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-2fqr-mr3j-6wp8", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-2fqr-mr3j-6wp8"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-2fqr-mr3j-6wp8 (aka CVE-2026-54279).\n\naiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence\n\nAliases: CVE-2026-54279, PYSEC-2026-2112\nAdvisory: https://osv.dev/vulnerability/GHSA-2fqr-mr3j-6wp8\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-47b9faecc32b3fc9", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-2vrm-gr82-f7m5", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-2vrm-gr82-f7m5"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-2vrm-gr82-f7m5 (aka CVE-2026-34514).\n\nAIOHTTP has CRLF injection through multipart part content type header construction\n\nAliases: CVE-2026-34514, PYSEC-2026-2096\nAdvisory: https://osv.dev/vulnerability/GHSA-2vrm-gr82-f7m5\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cb9dff6b489714c9", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-3wq7-rqq7-wx6j", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-3wq7-rqq7-wx6j"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-3wq7-rqq7-wx6j (aka CVE-2026-34517).\n\nAIOHTTP has late size enforcement for non-file multipart fields causes memory DoS\n\nAliases: CVE-2026-34517, PYSEC-2026-2099\nAdvisory: https://osv.dev/vulnerability/GHSA-3wq7-rqq7-wx6j\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9815f91b0dbcef73", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-4fvr-rgm6-gqmc", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-4fvr-rgm6-gqmc"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-4fvr-rgm6-gqmc (aka CVE-2026-54273).\n\naiohttp: HTTP/1 Pipelined Requests Queue Without Limit\n\nAliases: CVE-2026-54273, PYSEC-2026-2107\nAdvisory: https://osv.dev/vulnerability/GHSA-4fvr-rgm6-gqmc\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4cb7cbdf9adec549", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-4m7w-qmgq-4wj5", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-4m7w-qmgq-4wj5"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-4m7w-qmgq-4wj5 (aka CVE-2026-54275).\n\naiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections\n\nAliases: CVE-2026-54275, PYSEC-2026-237\nAdvisory: https://osv.dev/vulnerability/GHSA-4m7w-qmgq-4wj5\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b20a1a4198f1b775", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-63hf-3vf5-4wqf", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-63hf-3vf5-4wqf"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-63hf-3vf5-4wqf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-63hf-3vf5-4wqf\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3e26b4a17a098b70", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-63hw-fmq6-xxg2", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-63hw-fmq6-xxg2"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-63hw-fmq6-xxg2.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-63hw-fmq6-xxg2\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-24452b263a79ef8d", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-966j-vmvw-g2g9", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-966j-vmvw-g2g9"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-966j-vmvw-g2g9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-966j-vmvw-g2g9\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c9a33482a88ae1e5", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-9x8q-7h8h-wcw9", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-9x8q-7h8h-wcw9"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-9x8q-7h8h-wcw9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9x8q-7h8h-wcw9\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-95140ede6a0b0b7f", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-c427-h43c-vf67", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-c427-h43c-vf67"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-c427-h43c-vf67.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-c427-h43c-vf67\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fa67ffe5dac3fabf", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-g3cq-j2xw-wf74", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-g3cq-j2xw-wf74"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-g3cq-j2xw-wf74.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-g3cq-j2xw-wf74\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-75807b2c7ee21d0d", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-hcc4-c3v8-rx92", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-hcc4-c3v8-rx92"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-hcc4-c3v8-rx92.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hcc4-c3v8-rx92\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-88a06f9ad7120d7c", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-hg6j-4rv6-33pg", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-hg6j-4rv6-33pg"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-hg6j-4rv6-33pg.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hg6j-4rv6-33pg\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-55026c97311e3a1c", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-hpj7-wq8m-9hgp", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-hpj7-wq8m-9hgp"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-hpj7-wq8m-9hgp.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hpj7-wq8m-9hgp\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2c71a72a4937465d", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-jg22-mg44-37j8", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-jg22-mg44-37j8"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-jg22-mg44-37j8.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jg22-mg44-37j8\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a01eb9b7ba9317dd", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-m5qp-6w8w-w647", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-m5qp-6w8w-w647"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-m5qp-6w8w-w647.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-m5qp-6w8w-w647\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-441e2f24ee8460e6", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-m6qw-4cw2-hm4m", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-m6qw-4cw2-hm4m"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-m6qw-4cw2-hm4m.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-m6qw-4cw2-hm4m\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-61dea895105a6b32", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-mwh4-6h8g-pg8w", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-mwh4-6h8g-pg8w"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-mwh4-6h8g-pg8w.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mwh4-6h8g-pg8w\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e038d7476051bfb", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-p998-jp59-783m", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-p998-jp59-783m"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-p998-jp59-783m.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p998-jp59-783m\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-95aff45a4b2bb736", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-w2fm-2cpv-w7v5", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-w2fm-2cpv-w7v5"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-w2fm-2cpv-w7v5.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w2fm-2cpv-w7v5\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9ac4aaf1c86ec314", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-xcgm-r5h9-7989", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-xcgm-r5h9-7989"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-xcgm-r5h9-7989.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xcgm-r5h9-7989\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-550178420448ef49", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2094", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2094"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-2094.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2094\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6bef4a117fc4d37c", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2095", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2095"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-2095.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2095\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-16bc8d03bf7944ec", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2097", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2097"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-2097.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2097\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-63bf583ec20ebde2", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2098", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2098"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-2098.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2098\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7393b06c11d5980a", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2100", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2100"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-2100.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2100\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6c42f7d4f08eb732", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2101", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2101"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-2101.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2101\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-904cceab0b4fb98a", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2102", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2102"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-2102.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2102\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-787adb5b9cf175d8", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2103", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2103"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-2103.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2103\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9a0562075797fb8d", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2104", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2104"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-2104.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2104\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eee16a45f74568c1", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2105", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2105"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-2105.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2105\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cea4364a0252c5df", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2106", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2106"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-2106.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2106\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-985e1c2857c0c22a", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2108", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2108"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-2108.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2108\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e41706c5f8254bf0", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2109", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2109"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-2109.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2109\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-42b40d518b47d7f9", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2110", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2110"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-2110.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2110\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7fdc6c7acd417e10", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2111", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2111"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-2111.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2111\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a4b816fd7a92ae32", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2113", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2113"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-2113.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2113\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9aee01be5e569ee", "name": "Vulnerable dependency google-adk 1.26.0: GHSA-rg7c-g689-fr3x", "shortDescription": {"text": "Vulnerable dependency google-adk 1.26.0: GHSA-rg7c-g689-fr3x"}, "fullDescription": {"text": "OSV.dev reports `google-adk` at version `1.26.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-rg7c-g689-fr3x.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rg7c-g689-fr3x\nFix: upgrade `google-adk` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d730fb2d5f1adad9", "name": "Vulnerable dependency google-adk 1.26.0: PYSEC-2026-344", "shortDescription": {"text": "Vulnerable dependency google-adk 1.26.0: PYSEC-2026-344"}, "fullDescription": {"text": "OSV.dev reports `google-adk` at version `1.26.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-344.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-344\nFix: upgrade `google-adk` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8035d1da0d628d35", "name": "Vulnerable dependency mcp 1.26.0: GHSA-hvrp-rf83-w775", "shortDescription": {"text": "Vulnerable dependency mcp 1.26.0: GHSA-hvrp-rf83-w775"}, "fullDescription": {"text": "OSV.dev reports `mcp` at version `1.26.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-hvrp-rf83-w775.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hvrp-rf83-w775\nFix: upgrade `mcp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7b2acca52eea176f", "name": "Vulnerable dependency mcp 1.26.0: GHSA-jpw9-pfvf-9f58", "shortDescription": {"text": "Vulnerable dependency mcp 1.26.0: GHSA-jpw9-pfvf-9f58"}, "fullDescription": {"text": "OSV.dev reports `mcp` at version `1.26.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-jpw9-pfvf-9f58.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jpw9-pfvf-9f58\nFix: upgrade `mcp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3c78c4bd934e2905", "name": "Vulnerable dependency mcp 1.26.0: GHSA-vj7q-gjh5-988w", "shortDescription": {"text": "Vulnerable dependency mcp 1.26.0: GHSA-vj7q-gjh5-988w"}, "fullDescription": {"text": "OSV.dev reports `mcp` at version `1.26.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-vj7q-gjh5-988w.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vj7q-gjh5-988w\nFix: upgrade `mcp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f077f322ac920a82", "name": "Vulnerable dependency mcp 1.26.0: PYSEC-2026-3481", "shortDescription": {"text": "Vulnerable dependency mcp 1.26.0: PYSEC-2026-3481"}, "fullDescription": {"text": "OSV.dev reports `mcp` at version `1.26.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-3481.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3481\nFix: upgrade `mcp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8729597f44c3b474", "name": "Vulnerable dependency mcp 1.26.0: PYSEC-2026-3482", "shortDescription": {"text": "Vulnerable dependency mcp 1.26.0: PYSEC-2026-3482"}, "fullDescription": {"text": "OSV.dev reports `mcp` at version `1.26.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-3482.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3482\nFix: upgrade `mcp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b85ef3c7dea87afd", "name": "Vulnerable dependency mcp 1.26.0: PYSEC-2026-3483", "shortDescription": {"text": "Vulnerable dependency mcp 1.26.0: PYSEC-2026-3483"}, "fullDescription": {"text": "OSV.dev reports `mcp` at version `1.26.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-3483.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3483\nFix: upgrade `mcp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-745839925f4f67d5", "name": "Vulnerable dependency pydantic-settings 2.13.1: GHSA-4xgf-cpjx-pc3j", "shortDescription": {"text": "Vulnerable dependency pydantic-settings 2.13.1: GHSA-4xgf-cpjx-pc3j"}, "fullDescription": {"text": "OSV.dev reports `pydantic-settings` at version `2.13.1` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-4xgf-cpjx-pc3j.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-4xgf-cpjx-pc3j\nFix: upgrade `pydantic-settings` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-31f841f0bde645c1", "name": "Vulnerable dependency pyjwt 2.11.0: GHSA-752w-5fwx-jx9f", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.11.0: GHSA-752w-5fwx-jx9f"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.11.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-752w-5fwx-jx9f.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-752w-5fwx-jx9f\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7972c1a4d6858565", "name": "Vulnerable dependency pyjwt 2.11.0: GHSA-993g-76c3-p5m4", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.11.0: GHSA-993g-76c3-p5m4"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.11.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-993g-76c3-p5m4.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-993g-76c3-p5m4\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1173313eb0ea38fc", "name": "Vulnerable dependency pyjwt 2.11.0: GHSA-fhv5-28vv-h8m8", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.11.0: GHSA-fhv5-28vv-h8m8"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.11.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-fhv5-28vv-h8m8.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fhv5-28vv-h8m8\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-23a354813d55c9a6", "name": "Vulnerable dependency pyjwt 2.11.0: GHSA-jq35-7prp-9v3f", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.11.0: GHSA-jq35-7prp-9v3f"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.11.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-jq35-7prp-9v3f.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jq35-7prp-9v3f\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5c4862ac5f376b27", "name": "Vulnerable dependency pyjwt 2.11.0: GHSA-w7vc-732c-9m39", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.11.0: GHSA-w7vc-732c-9m39"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.11.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-w7vc-732c-9m39.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w7vc-732c-9m39\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-145b12fc0d4b238f", "name": "Vulnerable dependency pyjwt 2.11.0: GHSA-xgmm-8j9v-c9wx", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.11.0: GHSA-xgmm-8j9v-c9wx"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.11.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-xgmm-8j9v-c9wx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xgmm-8j9v-c9wx\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7a8681fe269fdc57", "name": "Vulnerable dependency pyjwt 2.11.0: PYSEC-2026-120", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.11.0: PYSEC-2026-120"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.11.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-120.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-120\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e498d38662979e8b", "name": "Vulnerable dependency pyjwt 2.11.0: PYSEC-2026-175", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.11.0: PYSEC-2026-175"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.11.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-175.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-175\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9f3e708cf88f041a", "name": "Vulnerable dependency pyjwt 2.11.0: PYSEC-2026-176", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.11.0: PYSEC-2026-176"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.11.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-176.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-176\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3787d673ec30b79e", "name": "Vulnerable dependency pyjwt 2.11.0: PYSEC-2026-177", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.11.0: PYSEC-2026-177"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.11.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-177.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-177\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c10539dae56a1e86", "name": "Vulnerable dependency pyjwt 2.11.0: PYSEC-2026-178", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.11.0: PYSEC-2026-178"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.11.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-178.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-178\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5ea9b247dca06b54", "name": "Vulnerable dependency pyjwt 2.11.0: PYSEC-2026-179", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.11.0: PYSEC-2026-179"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.11.0` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-179.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-179\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d633118398334767", "name": "Vulnerable dependency python-multipart 0.0.22: GHSA-5rvq-cxj2-64vf", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-5rvq-cxj2-64vf"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-5rvq-cxj2-64vf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-5rvq-cxj2-64vf\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b1e1bfe8ddd857d0", "name": "Vulnerable dependency python-multipart 0.0.22: GHSA-6jv3-5f52-599m", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-6jv3-5f52-599m"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-6jv3-5f52-599m.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6jv3-5f52-599m\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4521384e6357b38f", "name": "Vulnerable dependency python-multipart 0.0.22: GHSA-mj87-hwqh-73pj", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-mj87-hwqh-73pj"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-mj87-hwqh-73pj.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mj87-hwqh-73pj\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0d358ed7a0f4caea", "name": "Vulnerable dependency python-multipart 0.0.22: GHSA-pp6c-gr5w-3c5g", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-pp6c-gr5w-3c5g"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-pp6c-gr5w-3c5g.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pp6c-gr5w-3c5g\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1ce105834d93ecf0", "name": "Vulnerable dependency python-multipart 0.0.22: GHSA-v9pg-7xvm-68hf", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-v9pg-7xvm-68hf"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-v9pg-7xvm-68hf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v9pg-7xvm-68hf\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5471b86ca0edd516", "name": "Vulnerable dependency python-multipart 0.0.22: GHSA-vffw-93wf-4j4q", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-vffw-93wf-4j4q"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-vffw-93wf-4j4q.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vffw-93wf-4j4q\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d1a6c1fb146e5fae", "name": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3036", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3036"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-3036.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3036\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a76f7ef58018cbab", "name": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3037", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3037"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-3037.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3037\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4bb95bc19c7e2c9f", "name": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3038", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3038"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-3038.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3038\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-25f015baaa07ca74", "name": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3039", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3039"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-3039.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3039\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-60bb6d47a0b91df7", "name": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3040", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3040"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-3040.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3040\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bb3c0bd145de12b5", "name": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3041", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3041"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-3041.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3041\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-956f9f7464d669cb", "name": "Vulnerable dependency starlette 0.52.1: GHSA-82w8-qh3p-5jfq", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-82w8-qh3p-5jfq"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-82w8-qh3p-5jfq.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-82w8-qh3p-5jfq\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8f275ecbd53fe568", "name": "Vulnerable dependency starlette 0.52.1: GHSA-86qp-5c8j-p5mr", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-86qp-5c8j-p5mr"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-86qp-5c8j-p5mr.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-86qp-5c8j-p5mr\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fd666f835a1605d1", "name": "Vulnerable dependency starlette 0.52.1: GHSA-jp82-jpqv-5vv3", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-jp82-jpqv-5vv3"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-jp82-jpqv-5vv3.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jp82-jpqv-5vv3\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e85042c94c74cbc2", "name": "Vulnerable dependency starlette 0.52.1: GHSA-wqp7-x3pw-xc5r", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-wqp7-x3pw-xc5r"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-wqp7-x3pw-xc5r.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wqp7-x3pw-xc5r\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-89cfcbd7b744abc8", "name": "Vulnerable dependency starlette 0.52.1: GHSA-x746-7m8f-x49c", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-x746-7m8f-x49c"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by GHSA-x746-7m8f-x49c.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-x746-7m8f-x49c\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a3ea3f2ae21103ff", "name": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-161", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-161"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-161.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-161\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-62b2226a96e2a6e2", "name": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-2280", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-2280"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-2280.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2280\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-13c486807da6e154", "name": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-2281", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-2281"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-2281.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2281\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2928f42662458d7b", "name": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-248", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-248"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-248.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-248\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bad9ff1f92bf9711", "name": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-249", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-249"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `generative_ui_agents/ai-financial-coach-agent/agent/uv.lock`) is affected by PYSEC-2026-249.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-249\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-58e034301bb6b7a2", "name": "Vulnerable dependency hono 4.12.15: GHSA-2gcr-mfcq-wcc3", "shortDescription": {"text": "Vulnerable dependency hono 4.12.15: GHSA-2gcr-mfcq-wcc3"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.15` (resolved in `generative_ui_agents/ai-financial-coach-agent/package-lock.json`) is affected by GHSA-2gcr-mfcq-wcc3.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-2gcr-mfcq-wcc3\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-697a17e86702153a", "name": "Vulnerable dependency hono 4.12.15: GHSA-3hrh-pfw6-9m5x", "shortDescription": {"text": "Vulnerable dependency hono 4.12.15: GHSA-3hrh-pfw6-9m5x"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.15` (resolved in `generative_ui_agents/ai-financial-coach-agent/package-lock.json`) is affected by GHSA-3hrh-pfw6-9m5x.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-3hrh-pfw6-9m5x\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8229a20596fddede", "name": "Vulnerable dependency hono 4.12.15: GHSA-69xw-7hcm-h432", "shortDescription": {"text": "Vulnerable dependency hono 4.12.15: GHSA-69xw-7hcm-h432"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.15` (resolved in `generative_ui_agents/ai-financial-coach-agent/package-lock.json`) is affected by GHSA-69xw-7hcm-h432.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-69xw-7hcm-h432\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d52702fa48f98dc7", "name": "Vulnerable dependency hono 4.12.15: GHSA-88fw-hqm2-52qc", "shortDescription": {"text": "Vulnerable dependency hono 4.12.15: GHSA-88fw-hqm2-52qc"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.15` (resolved in `generative_ui_agents/ai-financial-coach-agent/package-lock.json`) is affected by GHSA-88fw-hqm2-52qc (aka CVE-2026-54290).\n\nhono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nAliases: CVE-2026-54290\nAdvisory: https://osv.dev/vulnerability/GHSA-88fw-hqm2-52qc\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-db7d569aaf434a4e", "name": "Vulnerable dependency hono 4.12.15: GHSA-9vqf-7f2p-gf9v", "shortDescription": {"text": "Vulnerable dependency hono 4.12.15: GHSA-9vqf-7f2p-gf9v"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.15` (resolved in `generative_ui_agents/ai-financial-coach-agent/package-lock.json`) is affected by GHSA-9vqf-7f2p-gf9v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9vqf-7f2p-gf9v\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ba225b4f735b0a57", "name": "Vulnerable dependency hono 4.12.15: GHSA-f577-qrjj-4474", "shortDescription": {"text": "Vulnerable dependency hono 4.12.15: GHSA-f577-qrjj-4474"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.15` (resolved in `generative_ui_agents/ai-financial-coach-agent/package-lock.json`) is affected by GHSA-f577-qrjj-4474.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-f577-qrjj-4474\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f67c1369aeec7a9d", "name": "Vulnerable dependency hono 4.12.15: GHSA-hm8q-7f3q-5f36", "shortDescription": {"text": "Vulnerable dependency hono 4.12.15: GHSA-hm8q-7f3q-5f36"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.15` (resolved in `generative_ui_agents/ai-financial-coach-agent/package-lock.json`) is affected by GHSA-hm8q-7f3q-5f36.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hm8q-7f3q-5f36\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-583a72baba1ddc59", "name": "Vulnerable dependency hono 4.12.15: GHSA-hvrm-45r6-mjfj", "shortDescription": {"text": "Vulnerable dependency hono 4.12.15: GHSA-hvrm-45r6-mjfj"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.15` (resolved in `generative_ui_agents/ai-financial-coach-agent/package-lock.json`) is affected by GHSA-hvrm-45r6-mjfj.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hvrm-45r6-mjfj\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-da3f313e5ac0042e", "name": "Vulnerable dependency hono 4.12.15: GHSA-j6c9-x7qj-28xf", "shortDescription": {"text": "Vulnerable dependency hono 4.12.15: GHSA-j6c9-x7qj-28xf"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.15` (resolved in `generative_ui_agents/ai-financial-coach-agent/package-lock.json`) is affected by GHSA-j6c9-x7qj-28xf (aka CVE-2026-54287).\n\nhono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nAliases: CVE-2026-54287\nAdvisory: https://osv.dev/vulnerability/GHSA-j6c9-x7qj-28xf\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c8251f9a60cc37f9", "name": "Vulnerable dependency hono 4.12.15: GHSA-p77w-8qqv-26rm", "shortDescription": {"text": "Vulnerable dependency hono 4.12.15: GHSA-p77w-8qqv-26rm"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.15` (resolved in `generative_ui_agents/ai-financial-coach-agent/package-lock.json`) is affected by GHSA-p77w-8qqv-26rm.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p77w-8qqv-26rm\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9cf7e7a8cae054b", "name": "Vulnerable dependency hono 4.12.15: GHSA-qp7p-654g-cw7p", "shortDescription": {"text": "Vulnerable dependency hono 4.12.15: GHSA-qp7p-654g-cw7p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.15` (resolved in `generative_ui_agents/ai-financial-coach-agent/package-lock.json`) is affected by GHSA-qp7p-654g-cw7p.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qp7p-654g-cw7p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bf97e3f99543ed7b", "name": "Vulnerable dependency hono 4.12.15: GHSA-rv63-4mwf-qqc2", "shortDescription": {"text": "Vulnerable dependency hono 4.12.15: GHSA-rv63-4mwf-qqc2"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.15` (resolved in `generative_ui_agents/ai-financial-coach-agent/package-lock.json`) is affected by GHSA-rv63-4mwf-qqc2 (aka CVE-2026-54288).\n\nhono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`\n\nAliases: CVE-2026-54288\nAdvisory: https://osv.dev/vulnerability/GHSA-rv63-4mwf-qqc2\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7c499a56010c10c7", "name": "Vulnerable dependency hono 4.12.15: GHSA-w62v-xxxg-mg59", "shortDescription": {"text": "Vulnerable dependency hono 4.12.15: GHSA-w62v-xxxg-mg59"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.15` (resolved in `generative_ui_agents/ai-financial-coach-agent/package-lock.json`) is affected by GHSA-w62v-xxxg-mg59 (aka CVE-2026-59895).\n\nHono: Server-Side XSS via JSX Escaping Bypass in cx() Utility\n\nAliases: CVE-2026-59895\nAdvisory: https://osv.dev/vulnerability/GHSA-w62v-xxxg-mg59\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-717b45e6f55370c8", "name": "Vulnerable dependency hono 4.12.15: GHSA-wgpf-jwqj-8h8p", "shortDescription": {"text": "Vulnerable dependency hono 4.12.15: GHSA-wgpf-jwqj-8h8p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.15` (resolved in `generative_ui_agents/ai-financial-coach-agent/package-lock.json`) is affected by GHSA-wgpf-jwqj-8h8p (aka CVE-2026-54289).\n\nhono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest\n\nAliases: CVE-2026-54289\nAdvisory: https://osv.dev/vulnerability/GHSA-wgpf-jwqj-8h8p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-33d3f42fd34e9a22", "name": "Vulnerable dependency hono 4.12.15: GHSA-wwfh-h76j-fc44", "shortDescription": {"text": "Vulnerable dependency hono 4.12.15: GHSA-wwfh-h76j-fc44"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.15` (resolved in `generative_ui_agents/ai-financial-coach-agent/package-lock.json`) is affected by GHSA-wwfh-h76j-fc44 (aka CVE-2026-54286).\n\nhono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nAliases: CVE-2026-54286\nAdvisory: https://osv.dev/vulnerability/GHSA-wwfh-h76j-fc44\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ced3f5815208fac0", "name": "Vulnerable dependency hono 4.12.15: GHSA-xgm2-5f3f-mvvc", "shortDescription": {"text": "Vulnerable dependency hono 4.12.15: GHSA-xgm2-5f3f-mvvc"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.15` (resolved in `generative_ui_agents/ai-financial-coach-agent/package-lock.json`) is affected by GHSA-xgm2-5f3f-mvvc (aka CVE-2026-59897).\n\nHono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication\n\nAliases: CVE-2026-59897\nAdvisory: https://osv.dev/vulnerability/GHSA-xgm2-5f3f-mvvc\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e64aae9278b014d", "name": "Vulnerable dependency hono 4.12.15: GHSA-xrhx-7g5j-rcj5", "shortDescription": {"text": "Vulnerable dependency hono 4.12.15: GHSA-xrhx-7g5j-rcj5"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.15` (resolved in `generative_ui_agents/ai-financial-coach-agent/package-lock.json`) is affected by GHSA-xrhx-7g5j-rcj5.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xrhx-7g5j-rcj5\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-568ce6b423d45050", "name": "Vulnerable dependency postcss 8.5.10: GHSA-6g55-p6wh-862q", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.10: GHSA-6g55-p6wh-862q"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.10` (resolved in `generative_ui_agents/ai-financial-coach-agent/package-lock.json`) is affected by GHSA-6g55-p6wh-862q (aka CVE-2026-45623).\n\nPostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments\n\nAliases: CVE-2026-45623\nAdvisory: https://osv.dev/vulnerability/GHSA-6g55-p6wh-862q\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2874d809b800a08c", "name": "Vulnerable dependency @hono/node-server 1.19.12: GHSA-92pp-h63x-v22m", "shortDescription": {"text": "Vulnerable dependency @hono/node-server 1.19.12: GHSA-92pp-h63x-v22m"}, "fullDescription": {"text": "OSV.dev reports `@hono/node-server` at version `1.19.12` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-92pp-h63x-v22m.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-92pp-h63x-v22m\nFix: upgrade `@hono/node-server` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-24a923395b6fd4e4", "name": "Vulnerable dependency @hono/node-server 1.19.12: GHSA-frvp-7c67-39w9", "shortDescription": {"text": "Vulnerable dependency @hono/node-server 1.19.12: GHSA-frvp-7c67-39w9"}, "fullDescription": {"text": "OSV.dev reports `@hono/node-server` at version `1.19.12` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-frvp-7c67-39w9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-frvp-7c67-39w9\nFix: upgrade `@hono/node-server` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a2a43f4761a7d43a", "name": "Vulnerable dependency hono 4.12.10: GHSA-26pp-8wgv-hjvm", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-26pp-8wgv-hjvm"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-26pp-8wgv-hjvm.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-26pp-8wgv-hjvm\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7c93c1bb4145ab84", "name": "Vulnerable dependency hono 4.12.10: GHSA-2gcr-mfcq-wcc3", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-2gcr-mfcq-wcc3"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-2gcr-mfcq-wcc3.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-2gcr-mfcq-wcc3\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b8243515b69714f2", "name": "Vulnerable dependency hono 4.12.10: GHSA-3hrh-pfw6-9m5x", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-3hrh-pfw6-9m5x"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-3hrh-pfw6-9m5x.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-3hrh-pfw6-9m5x\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f09bb2f1e967c866", "name": "Vulnerable dependency hono 4.12.10: GHSA-458j-xx4x-4375", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-458j-xx4x-4375"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-458j-xx4x-4375.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-458j-xx4x-4375\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b040d4c49be64bd8", "name": "Vulnerable dependency hono 4.12.10: GHSA-69xw-7hcm-h432", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-69xw-7hcm-h432"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-69xw-7hcm-h432.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-69xw-7hcm-h432\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-73659387e6d5d876", "name": "Vulnerable dependency hono 4.12.10: GHSA-88fw-hqm2-52qc", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-88fw-hqm2-52qc"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-88fw-hqm2-52qc (aka CVE-2026-54290).\n\nhono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nAliases: CVE-2026-54290\nAdvisory: https://osv.dev/vulnerability/GHSA-88fw-hqm2-52qc\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-22bb42ab1decb8f2", "name": "Vulnerable dependency hono 4.12.10: GHSA-9vqf-7f2p-gf9v", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-9vqf-7f2p-gf9v"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-9vqf-7f2p-gf9v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9vqf-7f2p-gf9v\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-076ee3761af5ccf7", "name": "Vulnerable dependency hono 4.12.10: GHSA-f577-qrjj-4474", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-f577-qrjj-4474"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-f577-qrjj-4474.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-f577-qrjj-4474\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-36225fc773f92027", "name": "Vulnerable dependency hono 4.12.10: GHSA-hm8q-7f3q-5f36", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-hm8q-7f3q-5f36"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-hm8q-7f3q-5f36.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hm8q-7f3q-5f36\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-64989c2663acb2f4", "name": "Vulnerable dependency hono 4.12.10: GHSA-hvrm-45r6-mjfj", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-hvrm-45r6-mjfj"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-hvrm-45r6-mjfj.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hvrm-45r6-mjfj\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-95c6c63d803133b3", "name": "Vulnerable dependency hono 4.12.10: GHSA-j6c9-x7qj-28xf", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-j6c9-x7qj-28xf"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-j6c9-x7qj-28xf (aka CVE-2026-54287).\n\nhono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nAliases: CVE-2026-54287\nAdvisory: https://osv.dev/vulnerability/GHSA-j6c9-x7qj-28xf\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f0270ba1a88a0044", "name": "Vulnerable dependency hono 4.12.10: GHSA-p77w-8qqv-26rm", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-p77w-8qqv-26rm"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-p77w-8qqv-26rm.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p77w-8qqv-26rm\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-817793ddd6b7bab8", "name": "Vulnerable dependency hono 4.12.10: GHSA-qp7p-654g-cw7p", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-qp7p-654g-cw7p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-qp7p-654g-cw7p.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qp7p-654g-cw7p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-57f205be7d1af9c7", "name": "Vulnerable dependency hono 4.12.10: GHSA-r5rp-j6wh-rvv4", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-r5rp-j6wh-rvv4"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-r5rp-j6wh-rvv4.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r5rp-j6wh-rvv4\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-172c646fbd10afd0", "name": "Vulnerable dependency hono 4.12.10: GHSA-rv63-4mwf-qqc2", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-rv63-4mwf-qqc2"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-rv63-4mwf-qqc2 (aka CVE-2026-54288).\n\nhono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`\n\nAliases: CVE-2026-54288\nAdvisory: https://osv.dev/vulnerability/GHSA-rv63-4mwf-qqc2\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a98a3064d5c0c0c0", "name": "Vulnerable dependency hono 4.12.10: GHSA-w62v-xxxg-mg59", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-w62v-xxxg-mg59"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-w62v-xxxg-mg59 (aka CVE-2026-59895).\n\nHono: Server-Side XSS via JSX Escaping Bypass in cx() Utility\n\nAliases: CVE-2026-59895\nAdvisory: https://osv.dev/vulnerability/GHSA-w62v-xxxg-mg59\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cfd21471f070f1c7", "name": "Vulnerable dependency hono 4.12.10: GHSA-wgpf-jwqj-8h8p", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-wgpf-jwqj-8h8p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-wgpf-jwqj-8h8p (aka CVE-2026-54289).\n\nhono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest\n\nAliases: CVE-2026-54289\nAdvisory: https://osv.dev/vulnerability/GHSA-wgpf-jwqj-8h8p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a7838f3db70d31ae", "name": "Vulnerable dependency hono 4.12.10: GHSA-wmmm-f939-6g9c", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-wmmm-f939-6g9c"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-wmmm-f939-6g9c.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wmmm-f939-6g9c\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8f57ec7fe70a3d90", "name": "Vulnerable dependency hono 4.12.10: GHSA-wwfh-h76j-fc44", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-wwfh-h76j-fc44"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-wwfh-h76j-fc44 (aka CVE-2026-54286).\n\nhono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nAliases: CVE-2026-54286\nAdvisory: https://osv.dev/vulnerability/GHSA-wwfh-h76j-fc44\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b3d16eff6f338c5d", "name": "Vulnerable dependency hono 4.12.10: GHSA-xf4j-xp2r-rqqx", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-xf4j-xp2r-rqqx"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-xf4j-xp2r-rqqx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xf4j-xp2r-rqqx\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3fb489bf61e2a18b", "name": "Vulnerable dependency hono 4.12.10: GHSA-xgm2-5f3f-mvvc", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-xgm2-5f3f-mvvc"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-xgm2-5f3f-mvvc (aka CVE-2026-59897).\n\nHono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication\n\nAliases: CVE-2026-59897\nAdvisory: https://osv.dev/vulnerability/GHSA-xgm2-5f3f-mvvc\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-24031c5fd7928f08", "name": "Vulnerable dependency hono 4.12.10: GHSA-xpcf-pg52-r92g", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-xpcf-pg52-r92g"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-xpcf-pg52-r92g.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xpcf-pg52-r92g\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3acf580738d9cc80", "name": "Vulnerable dependency hono 4.12.10: GHSA-xrhx-7g5j-rcj5", "shortDescription": {"text": "Vulnerable dependency hono 4.12.10: GHSA-xrhx-7g5j-rcj5"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.10` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-xrhx-7g5j-rcj5.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xrhx-7g5j-rcj5\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-89090f8f96dfc666", "name": "Vulnerable dependency react-router 7.13.2: GHSA-2j2x-hqr9-3h42", "shortDescription": {"text": "Vulnerable dependency react-router 7.13.2: GHSA-2j2x-hqr9-3h42"}, "fullDescription": {"text": "OSV.dev reports `react-router` at version `7.13.2` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-2j2x-hqr9-3h42.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-2j2x-hqr9-3h42\nFix: upgrade `react-router` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-067d42057ee42daf", "name": "Vulnerable dependency react-router 7.13.2: GHSA-49rj-9fvp-4h2h", "shortDescription": {"text": "Vulnerable dependency react-router 7.13.2: GHSA-49rj-9fvp-4h2h"}, "fullDescription": {"text": "OSV.dev reports `react-router` at version `7.13.2` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-49rj-9fvp-4h2h.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-49rj-9fvp-4h2h\nFix: upgrade `react-router` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bfdba2fcd1520066", "name": "Vulnerable dependency react-router 7.13.2: GHSA-84g9-w2xq-vcv6", "shortDescription": {"text": "Vulnerable dependency react-router 7.13.2: GHSA-84g9-w2xq-vcv6"}, "fullDescription": {"text": "OSV.dev reports `react-router` at version `7.13.2` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-84g9-w2xq-vcv6.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-84g9-w2xq-vcv6\nFix: upgrade `react-router` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-387d31ca3007ba59", "name": "Vulnerable dependency react-router 7.13.2: GHSA-8x6r-g9mw-2r78", "shortDescription": {"text": "Vulnerable dependency react-router 7.13.2: GHSA-8x6r-g9mw-2r78"}, "fullDescription": {"text": "OSV.dev reports `react-router` at version `7.13.2` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-8x6r-g9mw-2r78.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8x6r-g9mw-2r78\nFix: upgrade `react-router` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3f1e6d65c8420dfe", "name": "Vulnerable dependency react-router 7.13.2: GHSA-rxv8-25v2-qmq8", "shortDescription": {"text": "Vulnerable dependency react-router 7.13.2: GHSA-rxv8-25v2-qmq8"}, "fullDescription": {"text": "OSV.dev reports `react-router` at version `7.13.2` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-rxv8-25v2-qmq8.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rxv8-25v2-qmq8\nFix: upgrade `react-router` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3036b17119b14f5c", "name": "Vulnerable dependency tar 7.5.13: GHSA-23hp-3jrh-7fpw", "shortDescription": {"text": "Vulnerable dependency tar 7.5.13: GHSA-23hp-3jrh-7fpw"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `7.5.13` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-23hp-3jrh-7fpw.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-23hp-3jrh-7fpw\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-29d3a9a0d1a09910", "name": "Vulnerable dependency tar 7.5.13: GHSA-8x88-c5mf-7j5w", "shortDescription": {"text": "Vulnerable dependency tar 7.5.13: GHSA-8x88-c5mf-7j5w"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `7.5.13` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-8x88-c5mf-7j5w.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8x88-c5mf-7j5w\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2691a591eb730179", "name": "Vulnerable dependency tar 7.5.13: GHSA-gvwx-54wh-qm9j", "shortDescription": {"text": "Vulnerable dependency tar 7.5.13: GHSA-gvwx-54wh-qm9j"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `7.5.13` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-gvwx-54wh-qm9j.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gvwx-54wh-qm9j\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ada0255315465195", "name": "Vulnerable dependency tar 7.5.13: GHSA-vmf3-w455-68vh", "shortDescription": {"text": "Vulnerable dependency tar 7.5.13: GHSA-vmf3-w455-68vh"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `7.5.13` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-vmf3-w455-68vh.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vmf3-w455-68vh\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a0632063ac3c3c87", "name": "Vulnerable dependency tar 7.5.13: GHSA-w8wr-v893-vjvp", "shortDescription": {"text": "Vulnerable dependency tar 7.5.13: GHSA-w8wr-v893-vjvp"}, "fullDescription": {"text": "OSV.dev reports `tar` at version `7.5.13` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-w8wr-v893-vjvp.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w8wr-v893-vjvp\nFix: upgrade `tar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d2d41f95c6ed075d", "name": "Vulnerable dependency turbo 2.9.3: GHSA-3qcw-2rhx-2726", "shortDescription": {"text": "Vulnerable dependency turbo 2.9.3: GHSA-3qcw-2rhx-2726"}, "fullDescription": {"text": "OSV.dev reports `turbo` at version `2.9.3` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-3qcw-2rhx-2726.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-3qcw-2rhx-2726\nFix: upgrade `turbo` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-488eab4f4db3a2cb", "name": "Vulnerable dependency turbo 2.9.3: GHSA-hcf7-66rw-9f5r", "shortDescription": {"text": "Vulnerable dependency turbo 2.9.3: GHSA-hcf7-66rw-9f5r"}, "fullDescription": {"text": "OSV.dev reports `turbo` at version `2.9.3` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-hcf7-66rw-9f5r.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hcf7-66rw-9f5r\nFix: upgrade `turbo` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-257f0c0e8b5306fe", "name": "Vulnerable dependency vite 6.4.1: GHSA-4w7w-66w2-5vf9", "shortDescription": {"text": "Vulnerable dependency vite 6.4.1: GHSA-4w7w-66w2-5vf9"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `6.4.1` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-4w7w-66w2-5vf9 (aka CVE-2026-39365).\n\nVite Vulnerable to Path Traversal in Optimized Deps `.map` Handling\n\nAliases: CVE-2026-39365\nAdvisory: https://osv.dev/vulnerability/GHSA-4w7w-66w2-5vf9\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e61d6a281d32426a", "name": "Vulnerable dependency vite 6.4.1: GHSA-fx2h-pf6j-xcff", "shortDescription": {"text": "Vulnerable dependency vite 6.4.1: GHSA-fx2h-pf6j-xcff"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `6.4.1` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-fx2h-pf6j-xcff (aka CVE-2026-53571).\n\nvite: `server.fs.deny` bypass on Windows alternate paths\n\nAliases: CVE-2026-53571\nAdvisory: https://osv.dev/vulnerability/GHSA-fx2h-pf6j-xcff\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c352ec90ac235ffb", "name": "Vulnerable dependency vite 6.4.1: GHSA-p9ff-h696-f583", "shortDescription": {"text": "Vulnerable dependency vite 6.4.1: GHSA-p9ff-h696-f583"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `6.4.1` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-p9ff-h696-f583 (aka CVE-2026-39363).\n\nVite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket\n\nAliases: CVE-2026-39363\nAdvisory: https://osv.dev/vulnerability/GHSA-p9ff-h696-f583\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-f569b2fecd6a84cd", "name": "Vulnerable dependency vite 6.4.1: GHSA-v6wh-96g9-6wx3", "shortDescription": {"text": "Vulnerable dependency vite 6.4.1: GHSA-v6wh-96g9-6wx3"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `6.4.1` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-v6wh-96g9-6wx3 (aka CVE-2026-53632).\n\nlaunch-editor: NTLMv2 hash disclosure via UNC path handling on Windows\n\nAliases: CVE-2026-53632\nAdvisory: https://osv.dev/vulnerability/GHSA-v6wh-96g9-6wx3\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ab60190dbbccf0af", "name": "Vulnerable dependency vite 7.3.1: GHSA-4w7w-66w2-5vf9", "shortDescription": {"text": "Vulnerable dependency vite 7.3.1: GHSA-4w7w-66w2-5vf9"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `7.3.1` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-4w7w-66w2-5vf9 (aka CVE-2026-39365).\n\nVite Vulnerable to Path Traversal in Optimized Deps `.map` Handling\n\nAliases: CVE-2026-39365\nAdvisory: https://osv.dev/vulnerability/GHSA-4w7w-66w2-5vf9\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-eb1e41517cb3b9b7", "name": "Vulnerable dependency vite 7.3.1: GHSA-fx2h-pf6j-xcff", "shortDescription": {"text": "Vulnerable dependency vite 7.3.1: GHSA-fx2h-pf6j-xcff"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `7.3.1` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-fx2h-pf6j-xcff (aka CVE-2026-53571).\n\nvite: `server.fs.deny` bypass on Windows alternate paths\n\nAliases: CVE-2026-53571\nAdvisory: https://osv.dev/vulnerability/GHSA-fx2h-pf6j-xcff\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c658c26bcf996874", "name": "Vulnerable dependency vite 7.3.1: GHSA-p9ff-h696-f583", "shortDescription": {"text": "Vulnerable dependency vite 7.3.1: GHSA-p9ff-h696-f583"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `7.3.1` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-p9ff-h696-f583 (aka CVE-2026-39363).\n\nVite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket\n\nAliases: CVE-2026-39363\nAdvisory: https://osv.dev/vulnerability/GHSA-p9ff-h696-f583\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-75f5d8336c1c0c78", "name": "Vulnerable dependency vite 7.3.1: GHSA-v2wj-q39q-566r", "shortDescription": {"text": "Vulnerable dependency vite 7.3.1: GHSA-v2wj-q39q-566r"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `7.3.1` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-v2wj-q39q-566r.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v2wj-q39q-566r\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-dd33842e657a5b7c", "name": "Vulnerable dependency vite 7.3.1: GHSA-v6wh-96g9-6wx3", "shortDescription": {"text": "Vulnerable dependency vite 7.3.1: GHSA-v6wh-96g9-6wx3"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `7.3.1` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-v6wh-96g9-6wx3 (aka CVE-2026-53632).\n\nlaunch-editor: NTLMv2 hash disclosure via UNC path handling on Windows\n\nAliases: CVE-2026-53632\nAdvisory: https://osv.dev/vulnerability/GHSA-v6wh-96g9-6wx3\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-dbd130a5ba53241f", "name": "Vulnerable dependency vite 8.0.3: GHSA-4w7w-66w2-5vf9", "shortDescription": {"text": "Vulnerable dependency vite 8.0.3: GHSA-4w7w-66w2-5vf9"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `8.0.3` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-4w7w-66w2-5vf9 (aka CVE-2026-39365).\n\nVite Vulnerable to Path Traversal in Optimized Deps `.map` Handling\n\nAliases: CVE-2026-39365\nAdvisory: https://osv.dev/vulnerability/GHSA-4w7w-66w2-5vf9\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea793561b342c075", "name": "Vulnerable dependency vite 8.0.3: GHSA-fx2h-pf6j-xcff", "shortDescription": {"text": "Vulnerable dependency vite 8.0.3: GHSA-fx2h-pf6j-xcff"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `8.0.3` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-fx2h-pf6j-xcff (aka CVE-2026-53571).\n\nvite: `server.fs.deny` bypass on Windows alternate paths\n\nAliases: CVE-2026-53571\nAdvisory: https://osv.dev/vulnerability/GHSA-fx2h-pf6j-xcff\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b20e9c473a2067f7", "name": "Vulnerable dependency vite 8.0.3: GHSA-p9ff-h696-f583", "shortDescription": {"text": "Vulnerable dependency vite 8.0.3: GHSA-p9ff-h696-f583"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `8.0.3` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-p9ff-h696-f583 (aka CVE-2026-39363).\n\nVite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket\n\nAliases: CVE-2026-39363\nAdvisory: https://osv.dev/vulnerability/GHSA-p9ff-h696-f583\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-743cefa6d647197e", "name": "Vulnerable dependency vite 8.0.3: GHSA-v2wj-q39q-566r", "shortDescription": {"text": "Vulnerable dependency vite 8.0.3: GHSA-v2wj-q39q-566r"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `8.0.3` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-v2wj-q39q-566r.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v2wj-q39q-566r\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ceaaaff01ad6ebc2", "name": "Vulnerable dependency vite 8.0.3: GHSA-v6wh-96g9-6wx3", "shortDescription": {"text": "Vulnerable dependency vite 8.0.3: GHSA-v6wh-96g9-6wx3"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `8.0.3` (resolved in `generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml`) is affected by GHSA-v6wh-96g9-6wx3 (aka CVE-2026-53632).\n\nlaunch-editor: NTLMv2 hash disclosure via UNC path handling on Windows\n\nAliases: CVE-2026-53632\nAdvisory: https://osv.dev/vulnerability/GHSA-v6wh-96g9-6wx3\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2524fda4bc7e9aba", "name": "Vulnerable dependency langchain 1.2.0: GHSA-gr75-jv2w-4656", "shortDescription": {"text": "Vulnerable dependency langchain 1.2.0: GHSA-gr75-jv2w-4656"}, "fullDescription": {"text": "OSV.dev reports `langchain` at version `1.2.0` (resolved in `generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock`) is affected by GHSA-gr75-jv2w-4656 (aka CVE-2026-55443).\n\nLangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nAliases: CVE-2026-55443, PYSEC-2026-2192, PYSEC-2026-2556\nAdvisory: https://osv.dev/vulnerability/GHSA-gr75-jv2w-4656\nFix: upgrade `langchain` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-07d55afd5f6f7200", "name": "Vulnerable dependency langchain-core 1.2.16: GHSA-926x-3r5x-gfhw", "shortDescription": {"text": "Vulnerable dependency langchain-core 1.2.16: GHSA-926x-3r5x-gfhw"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `1.2.16` (resolved in `generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock`) is affected by GHSA-926x-3r5x-gfhw.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-926x-3r5x-gfhw\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fbd048ac41ed90e9", "name": "Vulnerable dependency langchain-core 1.2.16: GHSA-pjwx-r37v-7724", "shortDescription": {"text": "Vulnerable dependency langchain-core 1.2.16: GHSA-pjwx-r37v-7724"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `1.2.16` (resolved in `generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock`) is affected by GHSA-pjwx-r37v-7724.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pjwx-r37v-7724\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f76e564dc7eadece", "name": "Vulnerable dependency langchain-core 1.2.16: GHSA-qh6h-p6c9-ff54", "shortDescription": {"text": "Vulnerable dependency langchain-core 1.2.16: GHSA-qh6h-p6c9-ff54"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `1.2.16` (resolved in `generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock`) is affected by GHSA-qh6h-p6c9-ff54.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qh6h-p6c9-ff54\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2ab60797b4508d2e", "name": "Vulnerable dependency langchain-core 1.2.16: PYSEC-2026-2193", "shortDescription": {"text": "Vulnerable dependency langchain-core 1.2.16: PYSEC-2026-2193"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `1.2.16` (resolved in `generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock`) is affected by PYSEC-2026-2193.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2193\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6de7f58fca8fdb46", "name": "Vulnerable dependency langchain-core 1.2.16: PYSEC-2026-2563", "shortDescription": {"text": "Vulnerable dependency langchain-core 1.2.16: PYSEC-2026-2563"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `1.2.16` (resolved in `generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock`) is affected by PYSEC-2026-2563.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2563\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b5c9716a00053954", "name": "Vulnerable dependency langchain-core 1.2.16: PYSEC-2026-2564", "shortDescription": {"text": "Vulnerable dependency langchain-core 1.2.16: PYSEC-2026-2564"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `1.2.16` (resolved in `generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock`) is affected by PYSEC-2026-2564.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2564\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-63fd260abd1047ec", "name": "Vulnerable dependency langchain-openai 1.1.9: GHSA-r7w7-9xr2-qq2r", "shortDescription": {"text": "Vulnerable dependency langchain-openai 1.1.9: GHSA-r7w7-9xr2-qq2r"}, "fullDescription": {"text": "OSV.dev reports `langchain-openai` at version `1.1.9` (resolved in `generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock`) is affected by GHSA-r7w7-9xr2-qq2r.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r7w7-9xr2-qq2r\nFix: upgrade `langchain-openai` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4954ac89b0e3becf", "name": "Vulnerable dependency langchain-openai 1.1.9: PYSEC-2026-76", "shortDescription": {"text": "Vulnerable dependency langchain-openai 1.1.9: PYSEC-2026-76"}, "fullDescription": {"text": "OSV.dev reports `langchain-openai` at version `1.1.9` (resolved in `generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock`) is affected by PYSEC-2026-76.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-76\nFix: upgrade `langchain-openai` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-37ef992c979b02fd", "name": "Vulnerable dependency langsmith 0.6.6: GHSA-3644-q5cj-c5c7", "shortDescription": {"text": "Vulnerable dependency langsmith 0.6.6: GHSA-3644-q5cj-c5c7"}, "fullDescription": {"text": "OSV.dev reports `langsmith` at version `0.6.6` (resolved in `generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock`) is affected by GHSA-3644-q5cj-c5c7 (aka CVE-2026-45134).\n\nLangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nAliases: CVE-2026-45134, PYSEC-2026-2555, PYSEC-2026-2560, PYSEC-2026-2582\nAdvisory: https://osv.dev/vulnerability/GHSA-3644-q5cj-c5c7\nFix: upgrade `langsmith` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d1a391a57e2ede2c", "name": "Vulnerable dependency langsmith 0.6.6: GHSA-f4xh-w4cj-qxq8", "shortDescription": {"text": "Vulnerable dependency langsmith 0.6.6: GHSA-f4xh-w4cj-qxq8"}, "fullDescription": {"text": "OSV.dev reports `langsmith` at version `0.6.6` (resolved in `generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock`) is affected by GHSA-f4xh-w4cj-qxq8.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-f4xh-w4cj-qxq8\nFix: upgrade `langsmith` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7cbce9f5f206fd7f", "name": "Vulnerable dependency langsmith 0.6.6: GHSA-rr7j-v2q5-chgv", "shortDescription": {"text": "Vulnerable dependency langsmith 0.6.6: GHSA-rr7j-v2q5-chgv"}, "fullDescription": {"text": "OSV.dev reports `langsmith` at version `0.6.6` (resolved in `generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock`) is affected by GHSA-rr7j-v2q5-chgv.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rr7j-v2q5-chgv\nFix: upgrade `langsmith` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cf37968f1572ae8a", "name": "Vulnerable dependency langsmith 0.6.6: PYSEC-2026-2583", "shortDescription": {"text": "Vulnerable dependency langsmith 0.6.6: PYSEC-2026-2583"}, "fullDescription": {"text": "OSV.dev reports `langsmith` at version `0.6.6` (resolved in `generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock`) is affected by PYSEC-2026-2583.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2583\nFix: upgrade `langsmith` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-603754b5f32709b3", "name": "Vulnerable dependency click 8.3.2: PYSEC-2026-2132", "shortDescription": {"text": "Vulnerable dependency click 8.3.2: PYSEC-2026-2132"}, "fullDescription": {"text": "OSV.dev reports `click` at version `8.3.2` (resolved in `generative_ui_agents/generative-ui-starter-project/agent/uv.lock`) is affected by PYSEC-2026-2132.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2132\nFix: upgrade `click` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-62a355125ec37cb1", "name": "Vulnerable dependency langchain 1.2.15: GHSA-gr75-jv2w-4656", "shortDescription": {"text": "Vulnerable dependency langchain 1.2.15: GHSA-gr75-jv2w-4656"}, "fullDescription": {"text": "OSV.dev reports `langchain` at version `1.2.15` (resolved in `generative_ui_agents/generative-ui-starter-project/agent/uv.lock`) is affected by GHSA-gr75-jv2w-4656 (aka CVE-2026-55443).\n\nLangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nAliases: CVE-2026-55443, PYSEC-2026-2192, PYSEC-2026-2556\nAdvisory: https://osv.dev/vulnerability/GHSA-gr75-jv2w-4656\nFix: upgrade `langchain` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-873041286d84052a", "name": "Vulnerable dependency langchain-anthropic 1.4.0: GHSA-gr75-jv2w-4656", "shortDescription": {"text": "Vulnerable dependency langchain-anthropic 1.4.0: GHSA-gr75-jv2w-4656"}, "fullDescription": {"text": "OSV.dev reports `langchain-anthropic` at version `1.4.0` (resolved in `generative_ui_agents/generative-ui-starter-project/agent/uv.lock`) is affected by GHSA-gr75-jv2w-4656 (aka CVE-2026-55443).\n\nLangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders\n\nAliases: CVE-2026-55443, PYSEC-2026-2192, PYSEC-2026-2556\nAdvisory: https://osv.dev/vulnerability/GHSA-gr75-jv2w-4656\nFix: upgrade `langchain-anthropic` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8ad122675f99df3c", "name": "Vulnerable dependency langchain-core 1.2.29: GHSA-pjwx-r37v-7724", "shortDescription": {"text": "Vulnerable dependency langchain-core 1.2.29: GHSA-pjwx-r37v-7724"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `1.2.29` (resolved in `generative_ui_agents/generative-ui-starter-project/agent/uv.lock`) is affected by GHSA-pjwx-r37v-7724.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pjwx-r37v-7724\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1219dc9c152abde6", "name": "Vulnerable dependency langchain-core 1.2.29: PYSEC-2026-2564", "shortDescription": {"text": "Vulnerable dependency langchain-core 1.2.29: PYSEC-2026-2564"}, "fullDescription": {"text": "OSV.dev reports `langchain-core` at version `1.2.29` (resolved in `generative_ui_agents/generative-ui-starter-project/agent/uv.lock`) is affected by PYSEC-2026-2564.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2564\nFix: upgrade `langchain-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-63add6afe5d1e03b", "name": "Vulnerable dependency langsmith 0.7.31: GHSA-3644-q5cj-c5c7", "shortDescription": {"text": "Vulnerable dependency langsmith 0.7.31: GHSA-3644-q5cj-c5c7"}, "fullDescription": {"text": "OSV.dev reports `langsmith` at version `0.7.31` (resolved in `generative_ui_agents/generative-ui-starter-project/agent/uv.lock`) is affected by GHSA-3644-q5cj-c5c7 (aka CVE-2026-45134).\n\nLangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning\n\nAliases: CVE-2026-45134, PYSEC-2026-2555, PYSEC-2026-2560, PYSEC-2026-2582\nAdvisory: https://osv.dev/vulnerability/GHSA-3644-q5cj-c5c7\nFix: upgrade `langsmith` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3dbfe11eaeebbda8", "name": "Vulnerable dependency langsmith 0.7.31: GHSA-f4xh-w4cj-qxq8", "shortDescription": {"text": "Vulnerable dependency langsmith 0.7.31: GHSA-f4xh-w4cj-qxq8"}, "fullDescription": {"text": "OSV.dev reports `langsmith` at version `0.7.31` (resolved in `generative_ui_agents/generative-ui-starter-project/agent/uv.lock`) is affected by GHSA-f4xh-w4cj-qxq8.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-f4xh-w4cj-qxq8\nFix: upgrade `langsmith` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a8356a4e96f23267", "name": "Vulnerable dependency pip 26.0.1: GHSA-58qw-9mgm-455v", "shortDescription": {"text": "Vulnerable dependency pip 26.0.1: GHSA-58qw-9mgm-455v"}, "fullDescription": {"text": "OSV.dev reports `pip` at version `26.0.1` (resolved in `generative_ui_agents/generative-ui-starter-project/agent/uv.lock`) is affected by GHSA-58qw-9mgm-455v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-58qw-9mgm-455v\nFix: upgrade `pip` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c0f3702558ebe4cb", "name": "Vulnerable dependency pip 26.0.1: GHSA-jp4c-xjxw-mgf9", "shortDescription": {"text": "Vulnerable dependency pip 26.0.1: GHSA-jp4c-xjxw-mgf9"}, "fullDescription": {"text": "OSV.dev reports `pip` at version `26.0.1` (resolved in `generative_ui_agents/generative-ui-starter-project/agent/uv.lock`) is affected by GHSA-jp4c-xjxw-mgf9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jp4c-xjxw-mgf9\nFix: upgrade `pip` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fcbd008b42fa53ea", "name": "Vulnerable dependency pip 26.0.1: GHSA-wf93-45jw-7689", "shortDescription": {"text": "Vulnerable dependency pip 26.0.1: GHSA-wf93-45jw-7689"}, "fullDescription": {"text": "OSV.dev reports `pip` at version `26.0.1` (resolved in `generative_ui_agents/generative-ui-starter-project/agent/uv.lock`) is affected by GHSA-wf93-45jw-7689.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wf93-45jw-7689\nFix: upgrade `pip` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ca3021d1de9eae0d", "name": "Vulnerable dependency pip 26.0.1: PYSEC-2026-196", "shortDescription": {"text": "Vulnerable dependency pip 26.0.1: PYSEC-2026-196"}, "fullDescription": {"text": "OSV.dev reports `pip` at version `26.0.1` (resolved in `generative_ui_agents/generative-ui-starter-project/agent/uv.lock`) is affected by PYSEC-2026-196.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-196\nFix: upgrade `pip` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9607ee11b13a72cd", "name": "Vulnerable dependency pip 26.0.1: PYSEC-2026-2875", "shortDescription": {"text": "Vulnerable dependency pip 26.0.1: PYSEC-2026-2875"}, "fullDescription": {"text": "OSV.dev reports `pip` at version `26.0.1` (resolved in `generative_ui_agents/generative-ui-starter-project/agent/uv.lock`) is affected by PYSEC-2026-2875.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2875\nFix: upgrade `pip` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ed1450e28dd608d7", "name": "Vulnerable dependency pip 26.0.1: PYSEC-2026-2876", "shortDescription": {"text": "Vulnerable dependency pip 26.0.1: PYSEC-2026-2876"}, "fullDescription": {"text": "OSV.dev reports `pip` at version `26.0.1` (resolved in `generative_ui_agents/generative-ui-starter-project/agent/uv.lock`) is affected by PYSEC-2026-2876.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2876\nFix: upgrade `pip` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cdb994d1530edf58", "name": "Dependency @ai-sdk/openai is two or more major versions behind", "shortDescription": {"text": "Dependency @ai-sdk/openai is two or more major versions behind"}, "fullDescription": {"text": "`@ai-sdk/openai` is pinned at `1.3.22` in `generative_ui_agents/ai-dashboard-canvas-agent/package.json` while the latest release on the npm registry is `4.0.19` \u2014 3 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@ai-sdk/openai` to `4.0.19`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-fcac91b6db817f4f", "name": "Dependency @ai-sdk/openai is a major version behind", "shortDescription": {"text": "Dependency @ai-sdk/openai is a major version behind"}, "fullDescription": {"text": "`@ai-sdk/openai` is pinned at `3.0.33` in `generative_ui_agents/ai-mcp-app-builder/apps/web/package.json` while the latest release on the npm registry is `4.0.19` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@ai-sdk/openai` to `4.0.19`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-2fda694469daaf64", "name": "124 backend endpoints not called by scanned frontend", "shortDescription": {"text": "124 backend endpoints not called by scanned frontend"}, "fullDescription": {"text": "No scanned frontend call matched these backend routes. Sample: GET /release-radar/dry-run, POST /release-radar/trigger, POST /release-radar/pubsub, GET /agent-scout/dry-run, POST /agent-scout/trigger, POST /agent-scout/pubsub, POST /api/upload, POST /api/upload-files + 116 more. This is fine when endpoints serve external clients (mobile apps, SDKs, third-party integrations, server-side webhooks). Otherwise document consumers or remove dead routes."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/30767"}, "properties": {"repository": "Shubhamsaboo/awesome-llm-apps", "repoUrl": "https://github.com/Shubhamsaboo/awesome-llm-apps", "branch": "main"}, "results": [{"ruleId": "scanner-bba7087fd4421d03", "level": "note", "message": {"text": "Possibly dead Python function: preview_dependency_brief"}, "properties": {"repobilityId": "9bf34f7a374d5fbc", "scanner": "scanner-primary", "fingerprint": "bba7087fd4421d03", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "always_on_agents/release_radar_agent/agent.py:10"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5c01c136a8507d50", "level": "note", "message": {"text": "Possibly dead Python function: fetch_github_releases"}, "properties": {"repobilityId": "8217762ad8d4b14f", "scanner": "scanner-primary", "fingerprint": "5c01c136a8507d50", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "always_on_agents/release_radar_agent/radar.py:253"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-86c19a78733a4474", "level": "note", "message": {"text": "Possibly dead Python function: handle_starttag"}, "properties": {"repobilityId": "3bf216d149959ebf", "scanner": "scanner-primary", "fingerprint": "86c19a78733a4474", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "always_on_agents/always_on_hn_briefing_agent/scout.py:83"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2e4618a760678aec", "level": "note", "message": {"text": "Possibly dead Python function: handle_endtag"}, "properties": {"repobilityId": "7eb6f3decafc1766", "scanner": "scanner-primary", "fingerprint": "2e4618a760678aec", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "always_on_agents/always_on_hn_briefing_agent/scout.py:101"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-18c327cb7ab58508", "level": "note", "message": {"text": "Possibly dead Python function: handle_data"}, "properties": {"repobilityId": "3a673a278f4fc1e6", "scanner": "scanner-primary", "fingerprint": "18c327cb7ab58508", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "always_on_agents/always_on_hn_briefing_agent/scout.py:133"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-180fdc7696023a26", "level": "note", "message": {"text": "Possibly dead Python function: preview_agent_builder_brief"}, "properties": {"repobilityId": "186d7118a6d51157", "scanner": "scanner-primary", "fingerprint": "180fdc7696023a26", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "always_on_agents/always_on_hn_briefing_agent/agent.py:10"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8a4c1a4ddd27139b", "level": "note", "message": {"text": "Possibly dead Python function: handle_starttag"}, "properties": {"repobilityId": "3bf216d149959ebf", "scanner": "scanner-primary", "fingerprint": "8a4c1a4ddd27139b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/agentic_typed_rag_pydanticai/rag.py:386"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-06c31757855e354b", "level": "note", "message": {"text": "Possibly dead Python function: handle_endtag"}, "properties": {"repobilityId": "7eb6f3decafc1766", "scanner": "scanner-primary", "fingerprint": "06c31757855e354b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/agentic_typed_rag_pydanticai/rag.py:392"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-09f03e050de1efc2", "level": "note", "message": {"text": "Possibly dead Python function: handle_data"}, "properties": {"repobilityId": "3a673a278f4fc1e6", "scanner": "scanner-primary", "fingerprint": "09f03e050de1efc2", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/agentic_typed_rag_pydanticai/rag.py:398"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4c7d76ebb141b9bf", "level": "note", "message": {"text": "Possibly dead Python function: add_text_source"}, "properties": {"repobilityId": "b6255692a94adcfd", "scanner": "scanner-primary", "fingerprint": "4c7d76ebb141b9bf", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/multimodal_agentic_rag/backend/rag_store.py:297"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7f96d096db38fb59", "level": "note", "message": {"text": "Possibly dead Python function: add_file_source"}, "properties": {"repobilityId": "03469858d73586e8", "scanner": "scanner-primary", "fingerprint": "7f96d096db38fb59", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/multimodal_agentic_rag/backend/rag_store.py:330"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ad5ec8a6bda97ecb", "level": "note", "message": {"text": "Possibly dead Python function: remove_source"}, "properties": {"repobilityId": "61cd86ce5ab0675b", "scanner": "scanner-primary", "fingerprint": "ad5ec8a6bda97ecb", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/multimodal_agentic_rag/backend/rag_store.py:372"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4ce4bb78cf8a74f9", "level": "note", "message": {"text": "Possibly dead Python function: retrieve_relevant_context"}, "properties": {"repobilityId": "f720d27427e66e90", "scanner": "scanner-primary", "fingerprint": "4ce4bb78cf8a74f9", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/multimodal_agentic_rag/backend/server.py:116"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-56ab387595ad1bc0", "level": "note", "message": {"text": "Possibly dead Python function: retrieve_relevant_context"}, "properties": {"repobilityId": "f720d27427e66e90", "scanner": "scanner-primary", "fingerprint": "56ab387595ad1bc0", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/multimodal_agentic_rag/backend/agentic_rag_agent/agent.py:7"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6f1deb2f14ab8e51", "level": "note", "message": {"text": "Possibly dead Python function: inspect_embedding_space"}, "properties": {"repobilityId": "1c7444cbc04002e8", "scanner": "scanner-primary", "fingerprint": "6f1deb2f14ab8e51", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/multimodal_agentic_rag/backend/agentic_rag_agent/agent.py:12"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-413926232ab742b5", "level": "note", "message": {"text": "Possibly dead Python function: web_research"}, "properties": {"repobilityId": "24218c5b364e7d72", "scanner": "scanner-primary", "fingerprint": "413926232ab742b5", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/rag_database_routing/rag_database_routing.py:211"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b41ced5bd8a51027", "level": "note", "message": {"text": "Possibly dead Python function: grade_documents"}, "properties": {"repobilityId": "c879fc1be9dbee14", "scanner": "scanner-primary", "fingerprint": "b41ced5bd8a51027", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/ai_blog_search/app.py:94"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7042eeda14acffdb", "level": "note", "message": {"text": "Possibly dead Python function: rewrite"}, "properties": {"repobilityId": "b5937c294869f30f", "scanner": "scanner-primary", "fingerprint": "7042eeda14acffdb", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/ai_blog_search/app.py:174"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-58a4f22d951c1cbb", "level": "note", "message": {"text": "Possibly dead Python function: check_document_relevance"}, "properties": {"repobilityId": "0e181ad1573eb2b3", "scanner": "scanner-primary", "fingerprint": "58a4f22d951c1cbb", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/gemini_agentic_rag/agentic_rag_gemini.py:296"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-39c88b16e704565e", "level": "note", "message": {"text": "Possibly dead Python function: web_research"}, "properties": {"repobilityId": "24218c5b364e7d72", "scanner": "scanner-primary", "fingerprint": "39c88b16e704565e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/rag_agent_cohere/rag_agent_cohere.py:164"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5d5302c5cdf78401", "level": "note", "message": {"text": "Possibly dead Python function: post_process"}, "properties": {"repobilityId": "e7898e0fc487aecf", "scanner": "scanner-primary", "fingerprint": "5d5302c5cdf78401", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/rag_agent_cohere/rag_agent_cohere.py:234"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ace5b37c8bc128e2", "level": "note", "message": {"text": "Possibly dead Python function: check_document_relevance"}, "properties": {"repobilityId": "0e181ad1573eb2b3", "scanner": "scanner-primary", "fingerprint": "ace5b37c8bc128e2", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/qwen_local_rag/qwen_local_rag_agent.py:289"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ec6a7e4b3d678716", "level": "note", "message": {"text": "Possibly dead Python function: format_docs"}, "properties": {"repobilityId": "1a58e8d1ae9ceec3", "scanner": "scanner-primary", "fingerprint": "ec6a7e4b3d678716", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/rag_chain/app.py:22"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-260f3fb9197de879", "level": "note", "message": {"text": "Possibly dead Python function: check_document_relevance"}, "properties": {"repobilityId": "0e181ad1573eb2b3", "scanner": "scanner-primary", "fingerprint": "260f3fb9197de879", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/deepseek_local_rag_agent/deepseek_rag_agent.py:306"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9f2e1fb12b8b057a", "level": "note", "message": {"text": "Possibly dead Python function: web_search"}, "properties": {"repobilityId": "f152b965664ac716", "scanner": "scanner-primary", "fingerprint": "9f2e1fb12b8b057a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/corrective_rag/corrective_rag.py:84"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6da5b28065159d0b", "level": "note", "message": {"text": "Possibly dead Python function: grade_documents"}, "properties": {"repobilityId": "c879fc1be9dbee14", "scanner": "scanner-primary", "fingerprint": "6da5b28065159d0b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/corrective_rag/corrective_rag.py:280"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1e6111f6b840a866", "level": "note", "message": {"text": "Possibly dead Python function: transform_query"}, "properties": {"repobilityId": "4c6798ae5bf1be57", "scanner": "scanner-primary", "fingerprint": "1e6111f6b840a866", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/corrective_rag/corrective_rag.py:339"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b1ac5d9b9f150dbf", "level": "note", "message": {"text": "Possibly dead Python function: decide_to_generate"}, "properties": {"repobilityId": "fd34859701d56481", "scanner": "scanner-primary", "fingerprint": "b1ac5d9b9f150dbf", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/corrective_rag/corrective_rag.py:374"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-179e9be40d669bd8", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 agent_skills/self-improving-agent-skills/frontend/src/app/layout.tsx:21"}, "properties": {"repobilityId": "70fac89864d4a857", "scanner": "scanner-primary", "fingerprint": "179e9be40d669bd8", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/src/app/layout.tsx"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-b6809c56954a4679", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/page.tsx:298"}, "properties": {"repobilityId": "0e7672ed554d217d", "scanner": "scanner-primary", "fingerprint": "b6809c56954a4679", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/app/page.tsx"}, "region": {"startLine": 298}}}]}, {"ruleId": "scanner-888244d0beab35e0", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/api/copilotkit/route.ts:28"}, "properties": {"repobilityId": "4f96bd9232c10dae", "scanner": "scanner-primary", "fingerprint": "888244d0beab35e0", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/app/api/copilotkit/route.ts"}, "region": {"startLine": 28}}}]}, {"ruleId": "scanner-34a21b761817c78e", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/api/mcp-introspect/route.ts:22"}, "properties": {"repobilityId": "88aa1b8a8d0e444c", "scanner": "scanner-primary", "fingerprint": "34a21b761817c78e", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/app/api/mcp-introspect/route.ts"}, "region": {"startLine": 22}}}]}, {"ruleId": "scanner-60913a09d8d76065", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/api/mastra-agent/route.ts:25"}, "properties": {"repobilityId": "2b495af7292d395c", "scanner": "scanner-primary", "fingerprint": "60913a09d8d76065", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/app/api/mastra-agent/route.ts"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-8f131a20039851aa", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/components/CopilotKitProvider.tsx:57"}, "properties": {"repobilityId": "8c8641f8247cbd83", "scanner": "scanner-primary", "fingerprint": "8f131a20039851aa", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/app/components/CopilotKitProvider.tsx"}, "region": {"startLine": 57}}}]}, {"ruleId": "scanner-c4b3f742ac3509b9", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/components/ToolDetail.tsx:109"}, "properties": {"repobilityId": "b73fc0f2de6f1abd", "scanner": "scanner-primary", "fingerprint": "c4b3f742ac3509b9", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/app/components/ToolDetail.tsx"}, "region": {"startLine": 109}}}]}, {"ruleId": "scanner-f4d3f185f3902aea", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/components/McpServerManager.tsx:96"}, "properties": {"repobilityId": "aa154a04f7e2b112", "scanner": "scanner-primary", "fingerprint": "f4d3f185f3902aea", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/app/components/McpServerManager.tsx"}, "region": {"startLine": 96}}}]}, {"ruleId": "scanner-683919c6d833c5fa", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/hooks/useToolConfigStore.ts:250"}, "properties": {"repobilityId": "236c99535dddff02", "scanner": "scanner-primary", "fingerprint": "683919c6d833c5fa", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/app/hooks/useToolConfigStore.ts"}, "region": {"startLine": 250}}}]}, {"ruleId": "scanner-bd0078a746a2b9af", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/hooks/useMcpIntrospect.ts:52"}, "properties": {"repobilityId": "e90d06dee2b5aead", "scanner": "scanner-primary", "fingerprint": "bd0078a746a2b9af", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/app/hooks/useMcpIntrospect.ts"}, "region": {"startLine": 52}}}]}, {"ruleId": "scanner-06f9f823672f0565", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/generative-ui-starter-project/src/components/tool-rendering.tsx:63"}, "properties": {"repobilityId": "56605454f8350a62", "scanner": "scanner-primary", "fingerprint": "06f9f823672f0565", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/src/components/tool-rendering.tsx"}, "region": {"startLine": 63}}}]}, {"ruleId": "scanner-bbe7166a6036a6ed", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/generative-ui-starter-project/src/components/generative-ui/charts/pie-chart.tsx:139"}, "properties": {"repobilityId": "bbb63ce95ff82709", "scanner": "scanner-primary", "fingerprint": "bbe7166a6036a6ed", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/src/components/generative-ui/charts/pie-chart.tsx"}, "region": {"startLine": 139}}}]}, {"ruleId": "scanner-65d98b0470ee410f", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/ui/src/components/ui/chart.tsx:75"}, "properties": {"repobilityId": "3d5b56cc58b7e7fc", "scanner": "scanner-primary", "fingerprint": "65d98b0470ee410f", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/ui/src/components/ui/chart.tsx"}, "region": {"startLine": 75}}}]}, {"ruleId": "scanner-61143edfa6bd6acc", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 generative_ui_agents/ai-dashboard-canvas-agent/src/components/ui/chart.tsx:83"}, "properties": {"repobilityId": "2a95efba1708c223", "scanner": "scanner-primary", "fingerprint": "61143edfa6bd6acc", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/src/components/ui/chart.tsx"}, "region": {"startLine": 83}}}]}, {"ruleId": "scanner-9fa067d230488315", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/ai-dashboard-canvas-agent/src/components/dashboard/metrics/pinnedMetrics.tsx:82"}, "properties": {"repobilityId": "8b806b7e5c9e0bb3", "scanner": "scanner-primary", "fingerprint": "9fa067d230488315", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/src/components/dashboard/metrics/pinnedMetrics.tsx"}, "region": {"startLine": 82}}}]}, {"ruleId": "scanner-432429b55cbfb655", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/ai-dashboard-canvas-agent/src/components/chat/actions/search.tsx:18"}, "properties": {"repobilityId": "6494cdee166c2c8c", "scanner": "scanner-primary", "fingerprint": "432429b55cbfb655", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/src/components/chat/actions/search.tsx"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-454a3dc69dcf33a0", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/ai-deep-research-agent/src/components/Workspace.tsx:284"}, "properties": {"repobilityId": "4e04c759a1cf0bfa", "scanner": "scanner-primary", "fingerprint": "454a3dc69dcf33a0", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/src/components/Workspace.tsx"}, "region": {"startLine": 284}}}]}, {"ruleId": "scanner-4f75437abd9e08a4", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 generative_ui_agents/ai-deep-research-agent/src/components/Workspace.tsx:89"}, "properties": {"repobilityId": "dfa361c8ca3c4d26", "scanner": "scanner-primary", "fingerprint": "4f75437abd9e08a4", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/src/components/Workspace.tsx"}, "region": {"startLine": 89}}}]}, {"ruleId": "scanner-a6e9bca015593811", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 generative_ui_agents/ai-deep-research-agent/src/components/FileViewerModal.tsx:114"}, "properties": {"repobilityId": "323b350e1a9f37bc", "scanner": "scanner-primary", "fingerprint": "a6e9bca015593811", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/src/components/FileViewerModal.tsx"}, "region": {"startLine": 114}}}]}, {"ruleId": "scanner-0f658eb5d3eb6dc0", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 generative_ui_agents/ai-deep-research-agent/src/app/page.tsx:53"}, "properties": {"repobilityId": "0fcfa52565f28c23", "scanner": "scanner-primary", "fingerprint": "0f658eb5d3eb6dc0", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/src/app/page.tsx"}, "region": {"startLine": 53}}}]}, {"ruleId": "scanner-691086a6b4a7c34a", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/middleware.ts:7"}, "properties": {"repobilityId": "8c75810473d04943", "scanner": "scanner-primary", "fingerprint": "691086a6b4a7c34a", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/middleware.ts"}, "region": {"startLine": 7}}}]}, {"ruleId": "scanner-3eb0d152e4f10e84", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/app/api/plans/[id]/retry/route.ts:106"}, "properties": {"repobilityId": "1936e9bf2c7e5a55", "scanner": "scanner-primary", "fingerprint": "3eb0d152e4f10e84", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/app/api/plans/[id]/retry/route.ts"}, "region": {"startLine": 106}}}]}, {"ruleId": "scanner-81eaa720ee6359e9", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/app/api/plan/submit/route.ts:34"}, "properties": {"repobilityId": "16347acdad18c47a", "scanner": "scanner-primary", "fingerprint": "81eaa720ee6359e9", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/app/api/plan/submit/route.ts"}, "region": {"startLine": 34}}}]}, {"ruleId": "scanner-2ff81f242157225a", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/app/plan/page.tsx:286"}, "properties": {"repobilityId": "fe85209cdaa76e03", "scanner": "scanner-primary", "fingerprint": "2ff81f242157225a", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/app/plan/page.tsx"}, "region": {"startLine": 286}}}]}, {"ruleId": "scanner-b03bed969c46952f", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/app/plan/[id]/page.tsx:229"}, "properties": {"repobilityId": "5eb331fab907adaf", "scanner": "scanner-primary", "fingerprint": "b03bed969c46952f", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/app/plan/[id]/page.tsx"}, "region": {"startLine": 229}}}]}, {"ruleId": "scanner-88621956d0d56c36", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ScriptConfirmation.js:279"}, "properties": {"repobilityId": "b20bc256869b4afa", "scanner": "scanner-primary", "fingerprint": "88621956d0d56c36", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ScriptConfirmation.js"}, "region": {"startLine": 279}}}]}, {"ruleId": "scanner-3db911dcddadb5a3", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ScriptConfirmation.js:116"}, "properties": {"repobilityId": "15269c08f7b276a6", "scanner": "scanner-primary", "fingerprint": "3db911dcddadb5a3", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ScriptConfirmation.js"}, "region": {"startLine": 116}}}]}, {"ruleId": "scanner-b3608f3d2bd2b53f", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/Sidebar.js:529"}, "properties": {"repobilityId": "be0793b2518a98ad", "scanner": "scanner-primary", "fingerprint": "b3608f3d2bd2b53f", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/Sidebar.js"}, "region": {"startLine": 529}}}]}, {"ruleId": "scanner-37262d32e58e89c5", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ActivePodcastPreview.js:260"}, "properties": {"repobilityId": "5ef0b6a1fefbf975", "scanner": "scanner-primary", "fingerprint": "37262d32e58e89c5", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ActivePodcastPreview.js"}, "region": {"startLine": 260}}}]}, {"ruleId": "scanner-680e4b024e3226c9", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ChatMessage.js:320"}, "properties": {"repobilityId": "c72b1f07f792c7fc", "scanner": "scanner-primary", "fingerprint": "680e4b024e3226c9", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ChatMessage.js"}, "region": {"startLine": 320}}}]}, {"ruleId": "scanner-19143002a9841dbe", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/social/PostItem.js:180"}, "properties": {"repobilityId": "35b655ffbdf5697c", "scanner": "scanner-primary", "fingerprint": "19143002a9841dbe", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/social/PostItem.js"}, "region": {"startLine": 180}}}]}, {"ruleId": "scanner-804788381737ff14", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/social/AnalyticsCards.js:177"}, "properties": {"repobilityId": "1b97b9616e2cf07c", "scanner": "scanner-primary", "fingerprint": "804788381737ff14", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/social/AnalyticsCards.js"}, "region": {"startLine": 177}}}]}, {"ruleId": "scanner-e1105076cdfcc139", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/social/StatsTab.js:614"}, "properties": {"repobilityId": "bf98b91830dd7267", "scanner": "scanner-primary", "fingerprint": "e1105076cdfcc139", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/social/StatsTab.js"}, "region": {"startLine": 614}}}]}, {"ruleId": "scanner-4ad55f79229e8f9a", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/SourceDetail.js:381"}, "properties": {"repobilityId": "743db0a90fd5ee49", "scanner": "scanner-primary", "fingerprint": "4ad55f79229e8f9a", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/SourceDetail.js"}, "region": {"startLine": 381}}}]}, {"ruleId": "scanner-12ae5487b0d91e8b", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/Sources.js:545"}, "properties": {"repobilityId": "3e7fceb360d8fd86", "scanner": "scanner-primary", "fingerprint": "12ae5487b0d91e8b", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/Sources.js"}, "region": {"startLine": 545}}}]}, {"ruleId": "scanner-650522f022f48c9e", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/StudioChat.js:726"}, "properties": {"repobilityId": "22fb99f8cf443d60", "scanner": "scanner-primary", "fingerprint": "650522f022f48c9e", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/StudioChat.js"}, "region": {"startLine": 726}}}]}, {"ruleId": "scanner-ada5b7b4d2420b51", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/StudioChat.js:40"}, "properties": {"repobilityId": "3de963554bc6a6ee", "scanner": "scanner-primary", "fingerprint": "ada5b7b4d2420b51", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/StudioChat.js"}, "region": {"startLine": 40}}}]}, {"ruleId": "scanner-9a6b2c79c7a351a7", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/ArticleDetail.js:217"}, "properties": {"repobilityId": "5ce04bef86e1e993", "scanner": "scanner-primary", "fingerprint": "9a6b2c79c7a351a7", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/ArticleDetail.js"}, "region": {"startLine": 217}}}]}, {"ruleId": "scanner-933951cc42aecfff", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/Voyager.js:441"}, "properties": {"repobilityId": "b41e39a79b61078e", "scanner": "scanner-primary", "fingerprint": "933951cc42aecfff", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/Voyager.js"}, "region": {"startLine": 441}}}]}, {"ruleId": "scanner-d4835bdecbfb6f5e", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/PodcastDetail.js:503"}, "properties": {"repobilityId": "c940970832465248", "scanner": "scanner-primary", "fingerprint": "d4835bdecbfb6f5e", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/PodcastDetail.js"}, "region": {"startLine": 503}}}]}, {"ruleId": "scanner-8c31c58cc4369879", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/src/app/page.tsx:283"}, "properties": {"repobilityId": "f91fcb96a1395d9f", "scanner": "scanner-primary", "fingerprint": "8c31c58cc4369879", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/src/app/page.tsx"}, "region": {"startLine": 283}}}]}, {"ruleId": "scanner-d98d9ba5f7924c7f", "level": "error", "message": {"text": "subprocess shell true \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/scheduler.py:99"}, "properties": {"repobilityId": "85b3122c2c325425", "scanner": "scanner-primary", "fingerprint": "d98d9ba5f7924c7f", "layer": "security", "severity": "high", "confidence": 0.7, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/scheduler.py"}, "region": {"startLine": 99}}}]}, {"ruleId": "scanner-f89eebcbfcf07ed2", "level": "warning", "message": {"text": "react dangerouslysetinnerhtml \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ChatMessage.js:320"}, "properties": {"repobilityId": "5ea54901f245505b", "scanner": "scanner-primary", "fingerprint": "f89eebcbfcf07ed2", "layer": "security", "severity": "medium", "confidence": 0.7, "tags": ["semgrep", "security", "react"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ChatMessage.js"}, "region": {"startLine": 320}}}]}, {"ruleId": "scanner-11ee1db73659aee7", "level": "warning", "message": {"text": "react dangerouslysetinnerhtml \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ScriptConfirmation.js:117"}, "properties": {"repobilityId": "2e6b05a11786ff78", "scanner": "scanner-primary", "fingerprint": "11ee1db73659aee7", "layer": "security", "severity": "medium", "confidence": 0.7, "tags": ["semgrep", "security", "react"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ScriptConfirmation.js"}, "region": {"startLine": 117}}}]}, {"ruleId": "scanner-a2bfa3597bd731e8", "level": "warning", "message": {"text": "use defused xml \u2014 advanced_ai_agents/multi_agent_apps/devpulse_ai/adapters/arxiv.py:9"}, "properties": {"repobilityId": "76253f630a8de569", "scanner": "scanner-primary", "fingerprint": "a2bfa3597bd731e8", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/devpulse_ai/adapters/arxiv.py"}, "region": {"startLine": 9}}}]}, {"ruleId": "scanner-4c24056072eadb40", "level": "warning", "message": {"text": "insecure hash algorithm sha1 \u2014 advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent/agent.py:212"}, "properties": {"repobilityId": "306159f67f0e0015", "scanner": "scanner-primary", "fingerprint": "4c24056072eadb40", "layer": "security", "severity": "medium", "confidence": 0.75, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent/agent.py"}, "region": {"startLine": 212}}}]}, {"ruleId": "scanner-e5d7ddfba8509e57", "level": "warning", "message": {"text": "eval detected \u2014 ai_agent_framework_crash_course/google_adk_crash_course/4_tool_using_agent/4_2_function_tools/calculator_agent/tools.py:30"}, "properties": {"repobilityId": "9ab36e9358339b33", "scanner": "scanner-primary", "fingerprint": "e5d7ddfba8509e57", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "ai_agent_framework_crash_course/google_adk_crash_course/4_tool_using_agent/4_2_function_tools/calculator_agent/tools.py"}, "region": {"startLine": 30}}}]}, {"ruleId": "scanner-9c294554701f421c", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 always_on_agents/always_on_hn_briefing_agent/delivery.py:73"}, "properties": {"repobilityId": "c282e98de6561ab4", "scanner": "scanner-primary", "fingerprint": "9c294554701f421c", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "always_on_agents/always_on_hn_briefing_agent/delivery.py"}, "region": {"startLine": 73}}}]}, {"ruleId": "scanner-66060256a17bb798", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 always_on_agents/always_on_hn_briefing_agent/scout.py:239"}, "properties": {"repobilityId": "b9b3d552a1af6c8b", "scanner": "scanner-primary", "fingerprint": "66060256a17bb798", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "always_on_agents/always_on_hn_briefing_agent/scout.py"}, "region": {"startLine": 239}}}]}, {"ruleId": "scanner-ce482863b0d41788", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 always_on_agents/release_radar_agent/delivery.py:196"}, "properties": {"repobilityId": "3156e99b7a862d4f", "scanner": "scanner-primary", "fingerprint": "ce482863b0d41788", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "always_on_agents/release_radar_agent/delivery.py"}, "region": {"startLine": 196}}}]}, {"ruleId": "scanner-cecb2ce6c7d930d1", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 always_on_agents/release_radar_agent/radar.py:270"}, "properties": {"repobilityId": "7c1d04ef908e9ca8", "scanner": "scanner-primary", "fingerprint": "cecb2ce6c7d930d1", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "always_on_agents/release_radar_agent/radar.py"}, "region": {"startLine": 270}}}]}, {"ruleId": "scanner-f994bb697401c428", "level": "error", "message": {"text": "CVE-2026-42215: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "7744c4f60935f769", "scanner": "scanner-primary", "fingerprint": "f994bb697401c428", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42215"]}}, {"ruleId": "scanner-ab8c23027e464eb8", "level": "error", "message": {"text": "CVE-2026-42284: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "c9841297cc832ed4", "scanner": "scanner-primary", "fingerprint": "ab8c23027e464eb8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42284"]}}, {"ruleId": "scanner-95cdc6a1a275a6bc", "level": "error", "message": {"text": "CVE-2026-44243: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "d1f6619fffc45adc", "scanner": "scanner-primary", "fingerprint": "95cdc6a1a275a6bc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44243"]}}, {"ruleId": "scanner-0110e35afb3d7cee", "level": "error", "message": {"text": "CVE-2026-44244: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "22a69f559c6a9608", "scanner": "scanner-primary", "fingerprint": "0110e35afb3d7cee", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44244"]}}, {"ruleId": "scanner-efeabb24fb1ba4b8", "level": "error", "message": {"text": "GHSA-2f96-g7mh-g2hx: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "feed2e63861acf69", "scanner": "scanner-primary", "fingerprint": "efeabb24fb1ba4b8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-2f96-g7mh-g2hx"]}}, {"ruleId": "scanner-cacd18fcc6e94ca2", "level": "error", "message": {"text": "GHSA-956x-8gvw-wg5v: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "f43553c778bd36ef", "scanner": "scanner-primary", "fingerprint": "cacd18fcc6e94ca2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-956x-8gvw-wg5v"]}}, {"ruleId": "scanner-7f32f3f8258b7db7", "level": "error", "message": {"text": "GHSA-mv93-w799-cj2w: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "45828372ebf2f4b7", "scanner": "scanner-primary", "fingerprint": "7f32f3f8258b7db7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-mv93-w799-cj2w"]}}, {"ruleId": "scanner-a02f30d6bb516284", "level": "error", "message": {"text": "GHSA-rwj8-pgh3-r573: gitpython 3.1.44 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "7bdf50a874fc078a", "scanner": "scanner-primary", "fingerprint": "a02f30d6bb516284", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-rwj8-pgh3-r573"]}}, {"ruleId": "scanner-26a070528d22225b", "level": "error", "message": {"text": "CVE-2025-43859: h11 0.14.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "9e42b66fdbc74db0", "scanner": "scanner-primary", "fingerprint": "26a070528d22225b", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-43859"]}}, {"ruleId": "scanner-badc8117fe004997", "level": "warning", "message": {"text": "CVE-2026-45409: idna 3.10 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "54ff3ee559d008c2", "scanner": "scanner-primary", "fingerprint": "badc8117fe004997", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45409"]}}, {"ruleId": "scanner-0e9363d965ae91b5", "level": "warning", "message": {"text": "CVE-2025-27516: jinja2 3.1.5 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "71cf2bc5b1dbd654", "scanner": "scanner-primary", "fingerprint": "0e9363d965ae91b5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-27516"]}}, {"ruleId": "scanner-98c3eab0fb1cbdaa", "level": "error", "message": {"text": "CVE-2026-25990: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "e42c23095ffac4d1", "scanner": "scanner-primary", "fingerprint": "98c3eab0fb1cbdaa", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25990"]}}, {"ruleId": "scanner-893c85b8249e8eec", "level": "error", "message": {"text": "CVE-2026-40192: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "740c6692eacd7f42", "scanner": "scanner-primary", "fingerprint": "893c85b8249e8eec", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40192"]}}, {"ruleId": "scanner-84711fadc86eb3a4", "level": "error", "message": {"text": "CVE-2026-42311: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "8b1c2c1d6a4319eb", "scanner": "scanner-primary", "fingerprint": "84711fadc86eb3a4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42311"]}}, {"ruleId": "scanner-50ae30223e7d0d9c", "level": "error", "message": {"text": "CVE-2026-54058: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "7edd59140fb04b9c", "scanner": "scanner-primary", "fingerprint": "50ae30223e7d0d9c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54058"]}}, {"ruleId": "scanner-7d3d692483592c76", "level": "error", "message": {"text": "CVE-2026-54059: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "c2d28d5b05fb798f", "scanner": "scanner-primary", "fingerprint": "7d3d692483592c76", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54059"]}}, {"ruleId": "scanner-7e09a96b8ab967db", "level": "error", "message": {"text": "CVE-2026-54060: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "0c5c3f333053f903", "scanner": "scanner-primary", "fingerprint": "7e09a96b8ab967db", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54060"]}}, {"ruleId": "scanner-e6e7e3cabee106fd", "level": "error", "message": {"text": "CVE-2026-55379: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "ef7b20b6cdd0f61c", "scanner": "scanner-primary", "fingerprint": "e6e7e3cabee106fd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55379"]}}, {"ruleId": "scanner-91149532c47915ea", "level": "error", "message": {"text": "CVE-2026-55380: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "17b539c4ccc0e211", "scanner": "scanner-primary", "fingerprint": "91149532c47915ea", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55380"]}}, {"ruleId": "scanner-dfbb75f819056c32", "level": "error", "message": {"text": "CVE-2026-59197: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "0adfdd187e07bfac", "scanner": "scanner-primary", "fingerprint": "dfbb75f819056c32", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59197"]}}, {"ruleId": "scanner-36c13625493bc341", "level": "error", "message": {"text": "CVE-2026-59199: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "18d426ce32b3e4fc", "scanner": "scanner-primary", "fingerprint": "36c13625493bc341", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59199"]}}, {"ruleId": "scanner-0d45ee505a37afb7", "level": "error", "message": {"text": "CVE-2026-59200: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "99607ff894bc35cb", "scanner": "scanner-primary", "fingerprint": "0d45ee505a37afb7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59200"]}}, {"ruleId": "scanner-38ebd50f4fc57afd", "level": "error", "message": {"text": "CVE-2026-59204: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "715d91243a271b69", "scanner": "scanner-primary", "fingerprint": "38ebd50f4fc57afd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59204"]}}, {"ruleId": "scanner-1e36c8d8e7fcf10f", "level": "error", "message": {"text": "CVE-2026-59205: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "1f00bd614a2f6a5a", "scanner": "scanner-primary", "fingerprint": "1e36c8d8e7fcf10f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59205"]}}, {"ruleId": "scanner-46bf61be261a799c", "level": "warning", "message": {"text": "CVE-2026-42308: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "99d3c2c5545ee747", "scanner": "scanner-primary", "fingerprint": "46bf61be261a799c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42308"]}}, {"ruleId": "scanner-842a2d8b246ee9fa", "level": "warning", "message": {"text": "CVE-2026-42310: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "b091c347bc885fbc", "scanner": "scanner-primary", "fingerprint": "842a2d8b246ee9fa", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42310"]}}, {"ruleId": "scanner-9cd4a825f01e53ca", "level": "warning", "message": {"text": "CVE-2026-55798: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "41efd60b323d2732", "scanner": "scanner-primary", "fingerprint": "9cd4a825f01e53ca", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55798"]}}, {"ruleId": "scanner-878c29e7792f130b", "level": "warning", "message": {"text": "CVE-2026-59198: pillow 11.1.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "e48512a42df151c5", "scanner": "scanner-primary", "fingerprint": "878c29e7792f130b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59198"]}}, {"ruleId": "scanner-53652323d3acd0b0", "level": "warning", "message": {"text": "CVE-2025-8869: pip 25.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "000b71728cffe2b2", "scanner": "scanner-primary", "fingerprint": "53652323d3acd0b0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-8869"]}}, {"ruleId": "scanner-efa4460d948511aa", "level": "warning", "message": {"text": "CVE-2026-3219: pip 25.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "a27db339f877aac9", "scanner": "scanner-primary", "fingerprint": "efa4460d948511aa", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-3219"]}}, {"ruleId": "scanner-b30b30a425c9a4a4", "level": "warning", "message": {"text": "CVE-2026-6357: pip 25.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "ee46b95108db2ef7", "scanner": "scanner-primary", "fingerprint": "b30b30a425c9a4a4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6357"]}}, {"ruleId": "scanner-815d906057c4af44", "level": "warning", "message": {"text": "CVE-2026-8643: pip 25.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "b0803d99c58b622c", "scanner": "scanner-primary", "fingerprint": "815d906057c4af44", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8643"]}}, {"ruleId": "scanner-2c6cb61c1d658d0e", "level": "note", "message": {"text": "CVE-2026-1703: pip 25.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "2a5bf1e25775646a", "scanner": "scanner-primary", "fingerprint": "2c6cb61c1d658d0e", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-1703"]}}, {"ruleId": "scanner-165beb0deb0ad2d3", "level": "error", "message": {"text": "CVE-2025-4565: protobuf 5.29.3 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "f782bfd2450d3ec3", "scanner": "scanner-primary", "fingerprint": "165beb0deb0ad2d3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-4565"]}}, {"ruleId": "scanner-59c73b64e081cdc8", "level": "error", "message": {"text": "CVE-2026-0994: protobuf 5.29.3 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "2f8078f34946cf97", "scanner": "scanner-primary", "fingerprint": "59c73b64e081cdc8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-0994"]}}, {"ruleId": "scanner-1c03f4c89ad36e6a", "level": "error", "message": {"text": "CVE-2026-25087: pyarrow 19.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "14117f561722a778", "scanner": "scanner-primary", "fingerprint": "1c03f4c89ad36e6a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25087"]}}, {"ruleId": "scanner-58545354f7bfcb8b", "level": "error", "message": {"text": "CVE-2026-23490: pyasn1 0.6.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "08671efc7721023a", "scanner": "scanner-primary", "fingerprint": "58545354f7bfcb8b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-23490"]}}, {"ruleId": "scanner-77e8f2a819b07175", "level": "error", "message": {"text": "CVE-2026-30922: pyasn1 0.6.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "f84d48aaa3d4521d", "scanner": "scanner-primary", "fingerprint": "77e8f2a819b07175", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-30922"]}}, {"ruleId": "scanner-4e9008472c4f55df", "level": "error", "message": {"text": "CVE-2026-59885: pyasn1 0.6.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "0f354f5d1655a263", "scanner": "scanner-primary", "fingerprint": "4e9008472c4f55df", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59885"]}}, {"ruleId": "scanner-464b62309026d71a", "level": "error", "message": {"text": "CVE-2026-59886: pyasn1 0.6.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "88010021a3b73eb9", "scanner": "scanner-primary", "fingerprint": "464b62309026d71a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59886"]}}, {"ruleId": "scanner-c0ca5e597fce152a", "level": "note", "message": {"text": "CVE-2026-4539: pygments 2.19.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "2c78e7595fa7d5b7", "scanner": "scanner-primary", "fingerprint": "c0ca5e597fce152a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4539"]}}, {"ruleId": "scanner-6653bafa3c9f8119", "level": "warning", "message": {"text": "CVE-2026-28684: python-dotenv 1.0.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "c366c1fc0bf497aa", "scanner": "scanner-primary", "fingerprint": "6653bafa3c9f8119", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28684"]}}, {"ruleId": "scanner-31e9f85019784c93", "level": "error", "message": {"text": "CVE-2026-24486: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "5ad05c5dc9c95dd6", "scanner": "scanner-primary", "fingerprint": "31e9f85019784c93", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24486"]}}, {"ruleId": "scanner-b83893534e90508d", "level": "error", "message": {"text": "CVE-2026-42561: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "9f9c0fcc13578798", "scanner": "scanner-primary", "fingerprint": "b83893534e90508d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42561"]}}, {"ruleId": "scanner-87601c7c2d832a86", "level": "error", "message": {"text": "CVE-2026-53539: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "25a114de03651c06", "scanner": "scanner-primary", "fingerprint": "87601c7c2d832a86", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53539"]}}, {"ruleId": "scanner-951ae750292179d4", "level": "warning", "message": {"text": "CVE-2026-40347: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "e18035afd788e9e1", "scanner": "scanner-primary", "fingerprint": "951ae750292179d4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40347"]}}, {"ruleId": "scanner-7e9337670943e85e", "level": "note", "message": {"text": "CVE-2026-53537: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "33aaab784cae4811", "scanner": "scanner-primary", "fingerprint": "7e9337670943e85e", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53537"]}}, {"ruleId": "scanner-127bccbcb604a22d", "level": "note", "message": {"text": "CVE-2026-53538: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "d5c7c3e95bf58d1a", "scanner": "scanner-primary", "fingerprint": "127bccbcb604a22d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53538"]}}, {"ruleId": "scanner-e1d0edbed10262bd", "level": "note", "message": {"text": "CVE-2026-53540: python-multipart 0.0.20 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "d92b5516b445916f", "scanner": "scanner-primary", "fingerprint": "e1d0edbed10262bd", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53540"]}}, {"ruleId": "scanner-5ce6899171c9a270", "level": "warning", "message": {"text": "CVE-2024-47081: requests 2.32.3 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "df71a695bd37b786", "scanner": "scanner-primary", "fingerprint": "5ce6899171c9a270", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-47081"]}}, {"ruleId": "scanner-6abb67f2cd74ae0f", "level": "warning", "message": {"text": "CVE-2026-25645: requests 2.32.3 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "0229c80a9a1bc865", "scanner": "scanner-primary", "fingerprint": "6abb67f2cd74ae0f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25645"]}}, {"ruleId": "scanner-c9fa3b95cc82f9c1", "level": "error", "message": {"text": "CVE-2025-47273: setuptools 75.8.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "0989727ca9aab1cd", "scanner": "scanner-primary", "fingerprint": "c9fa3b95cc82f9c1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-47273"]}}, {"ruleId": "scanner-67385b65da3eb88f", "level": "warning", "message": {"text": "CVE-2026-59890: setuptools 75.8.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "967f2f8e196712ee", "scanner": "scanner-primary", "fingerprint": "67385b65da3eb88f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59890"]}}, {"ruleId": "scanner-15604435eb6989ae", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.42.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "a5fa8503114d8054", "scanner": "scanner-primary", "fingerprint": "15604435eb6989ae", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-6ef582ba768dc289", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.42.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "5fc85c3d8dae443e", "scanner": "scanner-primary", "fingerprint": "6ef582ba768dc289", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-ee3d599ceb8f88ca", "level": "error", "message": {"text": "CVE-2025-47287: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "85196da34a013e4b", "scanner": "scanner-primary", "fingerprint": "ee3d599ceb8f88ca", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-47287"]}}, {"ruleId": "scanner-170bb0a8d70a7334", "level": "error", "message": {"text": "CVE-2025-67725: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "2a46213baeb4e62c", "scanner": "scanner-primary", "fingerprint": "170bb0a8d70a7334", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-67725"]}}, {"ruleId": "scanner-f4c2fbb33b0c02d0", "level": "error", "message": {"text": "CVE-2025-67726: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "f0ab2daef3f4d539", "scanner": "scanner-primary", "fingerprint": "f4c2fbb33b0c02d0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-67726"]}}, {"ruleId": "scanner-10619e73478030c1", "level": "error", "message": {"text": "CVE-2026-31958: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "7fdfa8bdbd6da462", "scanner": "scanner-primary", "fingerprint": "10619e73478030c1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31958"]}}, {"ruleId": "scanner-8e3decac588f7788", "level": "error", "message": {"text": "CVE-2026-35536: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "ca4c5b4640ffbc80", "scanner": "scanner-primary", "fingerprint": "8e3decac588f7788", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-35536"]}}, {"ruleId": "scanner-817e8344c4b1e8e7", "level": "error", "message": {"text": "CVE-2026-49853: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "e8af248f5c4eb399", "scanner": "scanner-primary", "fingerprint": "817e8344c4b1e8e7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49853"]}}, {"ruleId": "scanner-14a50c38e805d8ab", "level": "error", "message": {"text": "CVE-2026-49855: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "237e0ba0d9054339", "scanner": "scanner-primary", "fingerprint": "14a50c38e805d8ab", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49855"]}}, {"ruleId": "scanner-48c697cd6cf8b3e8", "level": "warning", "message": {"text": "CVE-2025-67724: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "3e761a72565a9733", "scanner": "scanner-primary", "fingerprint": "48c697cd6cf8b3e8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-67724"]}}, {"ruleId": "scanner-b4da03a8726512c0", "level": "warning", "message": {"text": "GHSA-78cv-mqj4-43f7: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "7592c4e202ddeb30", "scanner": "scanner-primary", "fingerprint": "b4da03a8726512c0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-78cv-mqj4-43f7"]}}, {"ruleId": "scanner-09459af5cf2352e1", "level": "warning", "message": {"text": "GHSA-pw6j-qg29-8w7f: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "c14fa508d29bbc7b", "scanner": "scanner-primary", "fingerprint": "09459af5cf2352e1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-pw6j-qg29-8w7f"]}}, {"ruleId": "scanner-db8de70b327eb784", "level": "note", "message": {"text": "CVE-2026-49854: tornado 6.4.2 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "84c0bbba19144ec1", "scanner": "scanner-primary", "fingerprint": "db8de70b327eb784", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49854"]}}, {"ruleId": "scanner-dcc12ded09206c0a", "level": "error", "message": {"text": "CVE-2025-66418: urllib3 2.3.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "94fcfc045ae0a9a0", "scanner": "scanner-primary", "fingerprint": "dcc12ded09206c0a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66418"]}}, {"ruleId": "scanner-3e6bbf81eddf9c63", "level": "error", "message": {"text": "CVE-2025-66471: urllib3 2.3.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "bdbdb3134715b5bd", "scanner": "scanner-primary", "fingerprint": "3e6bbf81eddf9c63", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66471"]}}, {"ruleId": "scanner-ebbdd8053e7f6a50", "level": "error", "message": {"text": "CVE-2026-21441: urllib3 2.3.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "4afe9fb6f5f9691e", "scanner": "scanner-primary", "fingerprint": "ebbdd8053e7f6a50", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-21441"]}}, {"ruleId": "scanner-2405f10a982c9287", "level": "error", "message": {"text": "CVE-2026-44431: urllib3 2.3.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "8f19dd9e10fb606e", "scanner": "scanner-primary", "fingerprint": "2405f10a982c9287", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44431"]}}, {"ruleId": "scanner-5d3d7f9fca83e27b", "level": "warning", "message": {"text": "CVE-2025-50181: urllib3 2.3.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "7646bbcb06116e7e", "scanner": "scanner-primary", "fingerprint": "5d3d7f9fca83e27b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-50181"]}}, {"ruleId": "scanner-c07e90c498947808", "level": "warning", "message": {"text": "CVE-2025-50182: urllib3 2.3.0 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "3812f95e84189573", "scanner": "scanner-primary", "fingerprint": "c07e90c498947808", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-50182"]}}, {"ruleId": "scanner-6dbadd36ee0d90f8", "level": "error", "message": {"text": "CVE-2026-24049: wheel 0.45.1 \u2014 advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "properties": {"repobilityId": "eef4cf6ab9f638e1", "scanner": "scanner-primary", "fingerprint": "6dbadd36ee0d90f8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24049"]}}, {"ruleId": "scanner-c23be08978c6b68c", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_competitor_intelligence_agent_team/requirements.txt"}, "properties": {"repobilityId": "00d0bd419a2ef285", "scanner": "scanner-primary", "fingerprint": "c23be08978c6b68c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-33c70811b704cba4", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_competitor_intelligence_agent_team/requirements.txt"}, "properties": {"repobilityId": "1b61c332b538a8b9", "scanner": "scanner-primary", "fingerprint": "33c70811b704cba4", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-de6eba61959ade4a", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_game_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "5aa42335744d9d08", "scanner": "scanner-primary", "fingerprint": "de6eba61959ade4a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-df1e94e9ced407af", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_game_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "081239901d922794", "scanner": "scanner-primary", "fingerprint": "df1e94e9ced407af", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-7fa436897a46e4ed", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.40.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_legal_agent_team/local_ai_legal_agent_team/requirements.txt"}, "properties": {"repobilityId": "5b26fc6d88947341", "scanner": "scanner-primary", "fingerprint": "7fa436897a46e4ed", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-ca1f7bf55c618884", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.40.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_legal_agent_team/local_ai_legal_agent_team/requirements.txt"}, "properties": {"repobilityId": "2d0d357e3e4a5718", "scanner": "scanner-primary", "fingerprint": "ca1f7bf55c618884", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-de65a1150d351ec2", "level": "warning", "message": {"text": "CVE-2023-36464: PyPDF2 3.0.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_recruitment_agent_team/requirements.txt"}, "properties": {"repobilityId": "1ad305e881ecc22e", "scanner": "scanner-primary", "fingerprint": "de65a1150d351ec2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-36464"]}}, {"ruleId": "scanner-07804eb4dcc7b6d3", "level": "warning", "message": {"text": "CVE-2024-47081: requests 2.32.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_recruitment_agent_team/requirements.txt"}, "properties": {"repobilityId": "7e5e1045aa3daf25", "scanner": "scanner-primary", "fingerprint": "07804eb4dcc7b6d3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-47081"]}}, {"ruleId": "scanner-45c647978483485e", "level": "warning", "message": {"text": "CVE-2026-25645: requests 2.32.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_recruitment_agent_team/requirements.txt"}, "properties": {"repobilityId": "fe8cd00d4e84bc2c", "scanner": "scanner-primary", "fingerprint": "45c647978483485e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25645"]}}, {"ruleId": "scanner-ee99cec7f0c8876c", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.40.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_recruitment_agent_team/requirements.txt"}, "properties": {"repobilityId": "4594fdb06eee920d", "scanner": "scanner-primary", "fingerprint": "ee99cec7f0c8876c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-f45025d273af5d6c", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.40.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_recruitment_agent_team/requirements.txt"}, "properties": {"repobilityId": "c7ca1d645486f73a", "scanner": "scanner-primary", "fingerprint": "f45025d273af5d6c", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-5959d960fb5c4919", "level": "warning", "message": {"text": "CVE-2026-28684: python-dotenv 1.1.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_services_agency/requirements.txt"}, "properties": {"repobilityId": "cef236ff4a843261", "scanner": "scanner-primary", "fingerprint": "5959d960fb5c4919", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28684"]}}, {"ruleId": "scanner-225e08d674d93b42", "level": "warning", "message": {"text": "CVE-2025-56427: composio 0.1.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_teaching_agent_team/requirements.txt"}, "properties": {"repobilityId": "20c92d1ceb3c187e", "scanner": "scanner-primary", "fingerprint": "225e08d674d93b42", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-56427"]}}, {"ruleId": "scanner-33b7f6688217c41f", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_teaching_agent_team/requirements.txt"}, "properties": {"repobilityId": "49ad01d6c582934b", "scanner": "scanner-primary", "fingerprint": "33b7f6688217c41f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-369a2c4e656be986", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_teaching_agent_team/requirements.txt"}, "properties": {"repobilityId": "57bb0b4f137d5eed", "scanner": "scanner-primary", "fingerprint": "369a2c4e656be986", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-6ff77703f54db24d", "level": "error", "message": {"text": "CVE-2026-35002: agno 1.5.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "d42d0be25035dadd", "scanner": "scanner-primary", "fingerprint": "6ff77703f54db24d", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-35002"]}}, {"ruleId": "scanner-67e4bd86cdca49c4", "level": "error", "message": {"text": "CVE-2026-10105: agno 1.5.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "45b46d329ae865b3", "scanner": "scanner-primary", "fingerprint": "67e4bd86cdca49c4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10105"]}}, {"ruleId": "scanner-4c33bda89ed6c3ca", "level": "error", "message": {"text": "CVE-2025-69223: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "a98cf106e04923aa", "scanner": "scanner-primary", "fingerprint": "4c33bda89ed6c3ca", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69223"]}}, {"ruleId": "scanner-4a6694bfd514b6ee", "level": "warning", "message": {"text": "CVE-2025-69227: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "e5e061ae5ba48ec1", "scanner": "scanner-primary", "fingerprint": "4a6694bfd514b6ee", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69227"]}}, {"ruleId": "scanner-70484482fae6cbf0", "level": "warning", "message": {"text": "CVE-2025-69228: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "0236d12d9cb8b049", "scanner": "scanner-primary", "fingerprint": "70484482fae6cbf0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69228"]}}, {"ruleId": "scanner-a222ca1abbe9c5ba", "level": "warning", "message": {"text": "CVE-2025-69229: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "746d1ad7b665c721", "scanner": "scanner-primary", "fingerprint": "a222ca1abbe9c5ba", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69229"]}}, {"ruleId": "scanner-32eaca897e9dcf48", "level": "warning", "message": {"text": "CVE-2026-22815: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "f12a020008d6b2b2", "scanner": "scanner-primary", "fingerprint": "32eaca897e9dcf48", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-22815"]}}, {"ruleId": "scanner-62ac2b6a1433ba91", "level": "warning", "message": {"text": "CVE-2026-34515: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "76d4c4fb3c4423d5", "scanner": "scanner-primary", "fingerprint": "62ac2b6a1433ba91", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34515"]}}, {"ruleId": "scanner-434bfb16a22eac55", "level": "warning", "message": {"text": "CVE-2026-34516: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "cac8bf2b2845d7ea", "scanner": "scanner-primary", "fingerprint": "434bfb16a22eac55", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34516"]}}, {"ruleId": "scanner-5c86180485a845b2", "level": "warning", "message": {"text": "CVE-2026-34525: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "fd9e95212b1084ca", "scanner": "scanner-primary", "fingerprint": "5c86180485a845b2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34525"]}}, {"ruleId": "scanner-a11f6b05338ffa8d", "level": "warning", "message": {"text": "CVE-2026-34993: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "46c3c7dce10a7802", "scanner": "scanner-primary", "fingerprint": "a11f6b05338ffa8d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34993"]}}, {"ruleId": "scanner-e0d9233daebe392b", "level": "warning", "message": {"text": "CVE-2026-47265: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "ed6d6ff7382e781d", "scanner": "scanner-primary", "fingerprint": "e0d9233daebe392b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47265"]}}, {"ruleId": "scanner-175bef58967cceae", "level": "warning", "message": {"text": "CVE-2026-54273: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "98b3d4e559cc0c20", "scanner": "scanner-primary", "fingerprint": "175bef58967cceae", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54273"]}}, {"ruleId": "scanner-99d7e8662c9f9b2f", "level": "warning", "message": {"text": "CVE-2026-54274: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "339af00bfdfa81fd", "scanner": "scanner-primary", "fingerprint": "99d7e8662c9f9b2f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54274"]}}, {"ruleId": "scanner-4dc7ad98b515a22e", "level": "warning", "message": {"text": "CVE-2026-54276: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "09b08f7e394f6e91", "scanner": "scanner-primary", "fingerprint": "4dc7ad98b515a22e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54276"]}}, {"ruleId": "scanner-da9af0261d30e082", "level": "warning", "message": {"text": "CVE-2026-54277: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "ad1ca1db4395a192", "scanner": "scanner-primary", "fingerprint": "da9af0261d30e082", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54277"]}}, {"ruleId": "scanner-1481c995edfa6a31", "level": "warning", "message": {"text": "CVE-2026-54278: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "dcb39688fcc3f4cb", "scanner": "scanner-primary", "fingerprint": "1481c995edfa6a31", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54278"]}}, {"ruleId": "scanner-595497baed9ef17c", "level": "note", "message": {"text": "CVE-2025-53643: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "8f8848b5d497a7b9", "scanner": "scanner-primary", "fingerprint": "595497baed9ef17c", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-53643"]}}, {"ruleId": "scanner-49aaa60399d891e6", "level": "note", "message": {"text": "CVE-2025-69224: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "01a93e9ccbf2dbc3", "scanner": "scanner-primary", "fingerprint": "49aaa60399d891e6", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69224"]}}, {"ruleId": "scanner-87696374ad9fe8b4", "level": "note", "message": {"text": "CVE-2025-69225: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "d27eadd9b355407b", "scanner": "scanner-primary", "fingerprint": "87696374ad9fe8b4", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69225"]}}, {"ruleId": "scanner-9d3c494ede67fb6d", "level": "note", "message": {"text": "CVE-2025-69226: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "9303b2b77e7e004d", "scanner": "scanner-primary", "fingerprint": "9d3c494ede67fb6d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69226"]}}, {"ruleId": "scanner-41d59b66526625b2", "level": "note", "message": {"text": "CVE-2025-69230: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "cc681590a3deab13", "scanner": "scanner-primary", "fingerprint": "41d59b66526625b2", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69230"]}}, {"ruleId": "scanner-1967d656156d029e", "level": "note", "message": {"text": "CVE-2026-34513: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "6d20bee675f56bad", "scanner": "scanner-primary", "fingerprint": "1967d656156d029e", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34513"]}}, {"ruleId": "scanner-820cd23fede41311", "level": "note", "message": {"text": "CVE-2026-34514: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "cff502bbfefac6e1", "scanner": "scanner-primary", "fingerprint": "820cd23fede41311", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34514"]}}, {"ruleId": "scanner-f69d3ed248fc2a1a", "level": "note", "message": {"text": "CVE-2026-34517: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "ca468eeeed774131", "scanner": "scanner-primary", "fingerprint": "f69d3ed248fc2a1a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34517"]}}, {"ruleId": "scanner-c33ccff139d68a9b", "level": "note", "message": {"text": "CVE-2026-34518: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "d61fdc893dcfc282", "scanner": "scanner-primary", "fingerprint": "c33ccff139d68a9b", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34518"]}}, {"ruleId": "scanner-ba2f82a6e54a02ad", "level": "note", "message": {"text": "CVE-2026-34519: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "2d80f2c6df3813ff", "scanner": "scanner-primary", "fingerprint": "ba2f82a6e54a02ad", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34519"]}}, {"ruleId": "scanner-62c604a3902f3c83", "level": "note", "message": {"text": "CVE-2026-34520: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "d5e006a172fead0c", "scanner": "scanner-primary", "fingerprint": "62c604a3902f3c83", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34520"]}}, {"ruleId": "scanner-9889f056296bb0f8", "level": "note", "message": {"text": "CVE-2026-50269: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "2d961a54b01cd346", "scanner": "scanner-primary", "fingerprint": "9889f056296bb0f8", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-50269"]}}, {"ruleId": "scanner-de8ef3ed04e6117b", "level": "note", "message": {"text": "CVE-2026-54275: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "f69458f15948bbda", "scanner": "scanner-primary", "fingerprint": "de8ef3ed04e6117b", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54275"]}}, {"ruleId": "scanner-d422e3cf9949cda1", "level": "note", "message": {"text": "CVE-2026-54279: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "1328da2f3f10e828", "scanner": "scanner-primary", "fingerprint": "d422e3cf9949cda1", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54279"]}}, {"ruleId": "scanner-2dc3eead15bd773a", "level": "note", "message": {"text": "CVE-2026-54280: aiohttp 3.12.6 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "6dc16ccd40f1d23e", "scanner": "scanner-primary", "fingerprint": "2dc3eead15bd773a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54280"]}}, {"ruleId": "scanner-1caadde6c5f8b666", "level": "error", "message": {"text": "CVE-2026-42215: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "efdb4b9129b7d792", "scanner": "scanner-primary", "fingerprint": "1caadde6c5f8b666", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42215"]}}, {"ruleId": "scanner-d7dd9d5eecfab0d8", "level": "error", "message": {"text": "CVE-2026-42284: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "fa7c388139192409", "scanner": "scanner-primary", "fingerprint": "d7dd9d5eecfab0d8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42284"]}}, {"ruleId": "scanner-bc0d2f4f0ea34362", "level": "error", "message": {"text": "CVE-2026-44243: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "642e6d7eec21b8df", "scanner": "scanner-primary", "fingerprint": "bc0d2f4f0ea34362", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44243"]}}, {"ruleId": "scanner-c274de8ed08eb46b", "level": "error", "message": {"text": "CVE-2026-44244: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "254414b1c58015fe", "scanner": "scanner-primary", "fingerprint": "c274de8ed08eb46b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44244"]}}, {"ruleId": "scanner-028af81833b92cf2", "level": "error", "message": {"text": "GHSA-2f96-g7mh-g2hx: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "0af215317a142578", "scanner": "scanner-primary", "fingerprint": "028af81833b92cf2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-2f96-g7mh-g2hx"]}}, {"ruleId": "scanner-4bc751500e3588f3", "level": "error", "message": {"text": "GHSA-956x-8gvw-wg5v: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "91fdbeb18a56fd76", "scanner": "scanner-primary", "fingerprint": "4bc751500e3588f3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-956x-8gvw-wg5v"]}}, {"ruleId": "scanner-f1cc9c705bceea92", "level": "error", "message": {"text": "GHSA-mv93-w799-cj2w: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "902fe60a7c309b2c", "scanner": "scanner-primary", "fingerprint": "f1cc9c705bceea92", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-mv93-w799-cj2w"]}}, {"ruleId": "scanner-df268f25bfea14d3", "level": "error", "message": {"text": "GHSA-rwj8-pgh3-r573: gitpython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "6e6a5d53b0ed7190", "scanner": "scanner-primary", "fingerprint": "df268f25bfea14d3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-rwj8-pgh3-r573"]}}, {"ruleId": "scanner-43da8ca3e353d6dc", "level": "warning", "message": {"text": "CVE-2025-57804: h2 4.2.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "ef936a737983418f", "scanner": "scanner-primary", "fingerprint": "43da8ca3e353d6dc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-57804"]}}, {"ruleId": "scanner-342377025a41a82b", "level": "warning", "message": {"text": "CVE-2026-45409: idna 3.10 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "345db5bce0f69e0b", "scanner": "scanner-primary", "fingerprint": "342377025a41a82b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45409"]}}, {"ruleId": "scanner-0db441e713754e1b", "level": "error", "message": {"text": "CVE-2026-31240: mem0ai 0.1.102 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "dd7fb8d6aa65f704", "scanner": "scanner-primary", "fingerprint": "0db441e713754e1b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31240"]}}, {"ruleId": "scanner-084be3b1db8ab3e1", "level": "warning", "message": {"text": "CVE-2026-31241: mem0ai 0.1.102 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "4a31fb6561e0d1d3", "scanner": "scanner-primary", "fingerprint": "084be3b1db8ab3e1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31241"]}}, {"ruleId": "scanner-e3aeb2fef11dc3e1", "level": "warning", "message": {"text": "CVE-2026-31245: mem0ai 0.1.102 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "114f8105fd256fd1", "scanner": "scanner-primary", "fingerprint": "e3aeb2fef11dc3e1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31245"]}}, {"ruleId": "scanner-6229792054c09829", "level": "note", "message": {"text": "CVE-2026-7597: mem0ai 0.1.102 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "5915eb358c46c899", "scanner": "scanner-primary", "fingerprint": "6229792054c09829", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-7597"]}}, {"ruleId": "scanner-55a2832ec566db2c", "level": "error", "message": {"text": "CVE-2026-0994: protobuf 6.31.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "8a11c7ef76a20917", "scanner": "scanner-primary", "fingerprint": "55a2832ec566db2c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-0994"]}}, {"ruleId": "scanner-c3f1dd55ad918c62", "level": "error", "message": {"text": "CVE-2026-23490: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "1a7d896530300491", "scanner": "scanner-primary", "fingerprint": "c3f1dd55ad918c62", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-23490"]}}, {"ruleId": "scanner-d559408a1a115f70", "level": "error", "message": {"text": "CVE-2026-30922: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "f26363bf40b01a77", "scanner": "scanner-primary", "fingerprint": "d559408a1a115f70", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-30922"]}}, {"ruleId": "scanner-e30e23c3f46dd2da", "level": "error", "message": {"text": "CVE-2026-59885: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "98e4b6b63bcb9014", "scanner": "scanner-primary", "fingerprint": "e30e23c3f46dd2da", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59885"]}}, {"ruleId": "scanner-16e948d5ea8b0d47", "level": "error", "message": {"text": "CVE-2026-59886: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "fbe0635ce200b430", "scanner": "scanner-primary", "fingerprint": "16e948d5ea8b0d47", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59886"]}}, {"ruleId": "scanner-66a63c03a37911ef", "level": "note", "message": {"text": "CVE-2026-4539: pygments 2.19.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "c4d8a791d2b1787c", "scanner": "scanner-primary", "fingerprint": "66a63c03a37911ef", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4539"]}}, {"ruleId": "scanner-2f78e95530b59592", "level": "warning", "message": {"text": "CVE-2025-71176: pytest 8.3.5 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "cef008618c060c4e", "scanner": "scanner-primary", "fingerprint": "2f78e95530b59592", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-71176"]}}, {"ruleId": "scanner-d9641f282c39073f", "level": "warning", "message": {"text": "CVE-2026-28684: python-dotenv 1.1.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "9c1af395726a38a3", "scanner": "scanner-primary", "fingerprint": "d9641f282c39073f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28684"]}}, {"ruleId": "scanner-92e9bfe1ecfb19df", "level": "error", "message": {"text": "CVE-2026-24486: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "d296da7383467c14", "scanner": "scanner-primary", "fingerprint": "92e9bfe1ecfb19df", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24486"]}}, {"ruleId": "scanner-c2535a55acb31d50", "level": "error", "message": {"text": "CVE-2026-42561: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "8e225342a47d818d", "scanner": "scanner-primary", "fingerprint": "c2535a55acb31d50", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42561"]}}, {"ruleId": "scanner-876c287bfd6e2639", "level": "error", "message": {"text": "CVE-2026-53539: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "900d2039a56a1e26", "scanner": "scanner-primary", "fingerprint": "876c287bfd6e2639", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53539"]}}, {"ruleId": "scanner-f43255590e1c21a1", "level": "warning", "message": {"text": "CVE-2026-40347: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "39947f2e6a66fc45", "scanner": "scanner-primary", "fingerprint": "f43255590e1c21a1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40347"]}}, {"ruleId": "scanner-a64c848fe6c0d709", "level": "note", "message": {"text": "CVE-2026-53537: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "f3ef933ca9facd7e", "scanner": "scanner-primary", "fingerprint": "a64c848fe6c0d709", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53537"]}}, {"ruleId": "scanner-7a1236deaf1ef997", "level": "note", "message": {"text": "CVE-2026-53538: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "3c69f5ac6c369a33", "scanner": "scanner-primary", "fingerprint": "7a1236deaf1ef997", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53538"]}}, {"ruleId": "scanner-b810e5aecdc4b92a", "level": "note", "message": {"text": "CVE-2026-53540: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "028afd5ca79c71c8", "scanner": "scanner-primary", "fingerprint": "b810e5aecdc4b92a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53540"]}}, {"ruleId": "scanner-0b203871a3974878", "level": "warning", "message": {"text": "CVE-2024-47081: requests 2.32.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "4e1bb8054115bd81", "scanner": "scanner-primary", "fingerprint": "0b203871a3974878", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-47081"]}}, {"ruleId": "scanner-9fdea612cd195d1c", "level": "warning", "message": {"text": "CVE-2026-25645: requests 2.32.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "3f232a52b12e7f69", "scanner": "scanner-primary", "fingerprint": "9fdea612cd195d1c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25645"]}}, {"ruleId": "scanner-86f4935868342d0e", "level": "error", "message": {"text": "CVE-2025-62727: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "ac6969c2fc1a21fa", "scanner": "scanner-primary", "fingerprint": "86f4935868342d0e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-62727"]}}, {"ruleId": "scanner-45c78b00191568df", "level": "error", "message": {"text": "CVE-2026-48818: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "5d66936486d4fa6c", "scanner": "scanner-primary", "fingerprint": "45c78b00191568df", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48818"]}}, {"ruleId": "scanner-f6be8609a2a6ba96", "level": "error", "message": {"text": "CVE-2026-54283: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "93b2c85fc0efc4d5", "scanner": "scanner-primary", "fingerprint": "f6be8609a2a6ba96", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54283"]}}, {"ruleId": "scanner-798b3720452930a8", "level": "warning", "message": {"text": "CVE-2025-54121: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "136e2c2bc3705d0e", "scanner": "scanner-primary", "fingerprint": "798b3720452930a8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-54121"]}}, {"ruleId": "scanner-db9bab7abb7157c6", "level": "warning", "message": {"text": "CVE-2026-48710: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "3fd9ad63f38c8a56", "scanner": "scanner-primary", "fingerprint": "db9bab7abb7157c6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48710"]}}, {"ruleId": "scanner-1d4677b47b244bae", "level": "warning", "message": {"text": "CVE-2026-48817: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "390bf0a0b80757da", "scanner": "scanner-primary", "fingerprint": "1d4677b47b244bae", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48817"]}}, {"ruleId": "scanner-758eb6ec50042ff4", "level": "note", "message": {"text": "CVE-2026-54282: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "07fc5a5ebb93ae84", "scanner": "scanner-primary", "fingerprint": "758eb6ec50042ff4", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54282"]}}, {"ruleId": "scanner-a5b47f3d55f203cf", "level": "error", "message": {"text": "CVE-2025-66418: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "d132d914d870347a", "scanner": "scanner-primary", "fingerprint": "a5b47f3d55f203cf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66418"]}}, {"ruleId": "scanner-699d2df981b913c6", "level": "error", "message": {"text": "CVE-2025-66471: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "1a3cdf0e75f9c2ed", "scanner": "scanner-primary", "fingerprint": "699d2df981b913c6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66471"]}}, {"ruleId": "scanner-eaf45dd96f79c169", "level": "error", "message": {"text": "CVE-2026-21441: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "b04adf6ddb08f816", "scanner": "scanner-primary", "fingerprint": "eaf45dd96f79c169", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-21441"]}}, {"ruleId": "scanner-be980db29bafa8de", "level": "error", "message": {"text": "CVE-2026-44431: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "c0269d12a3cd9d95", "scanner": "scanner-primary", "fingerprint": "be980db29bafa8de", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44431"]}}, {"ruleId": "scanner-36341deafaff9827", "level": "warning", "message": {"text": "CVE-2025-50181: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "d42ed9ba18f39bb8", "scanner": "scanner-primary", "fingerprint": "36341deafaff9827", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-50181"]}}, {"ruleId": "scanner-f5ac93ee23269a0c", "level": "warning", "message": {"text": "CVE-2025-50182: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "properties": {"repobilityId": "9b0a1fa928186ef7", "scanner": "scanner-primary", "fingerprint": "f5ac93ee23269a0c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-50182"]}}, {"ruleId": "scanner-e9dda8f6602a2279", "level": "error", "message": {"text": "CVE-2026-53512: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "a76820c9e566701d", "scanner": "scanner-primary", "fingerprint": "e9dda8f6602a2279", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53512"]}}, {"ruleId": "scanner-ac44eb029689d7af", "level": "error", "message": {"text": "GHSA-xg6x-h9c9-2m83: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "55717ae5281d8954", "scanner": "scanner-primary", "fingerprint": "ac44eb029689d7af", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-xg6x-h9c9-2m83"]}}, {"ruleId": "scanner-eb6dfa6bda9a3570", "level": "error", "message": {"text": "CVE-2025-61928: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "d36eab9fa2e0e803", "scanner": "scanner-primary", "fingerprint": "eb6dfa6bda9a3570", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-61928"]}}, {"ruleId": "scanner-cea750ea258006ca", "level": "error", "message": {"text": "CVE-2026-45364: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "77a6202cde0831a3", "scanner": "scanner-primary", "fingerprint": "cea750ea258006ca", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45364"]}}, {"ruleId": "scanner-c234a6693fb091e5", "level": "error", "message": {"text": "CVE-2026-53514: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "be984b40f798b30d", "scanner": "scanner-primary", "fingerprint": "c234a6693fb091e5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53514"]}}, {"ruleId": "scanner-82e99eac1bc26009", "level": "error", "message": {"text": "CVE-2026-53516: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "097876dd84bc62aa", "scanner": "scanner-primary", "fingerprint": "82e99eac1bc26009", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53516"]}}, {"ruleId": "scanner-022619e1c6c20e65", "level": "error", "message": {"text": "CVE-2026-53518: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "0c460b46525d9f79", "scanner": "scanner-primary", "fingerprint": "022619e1c6c20e65", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53518"]}}, {"ruleId": "scanner-541c96bb724b4451", "level": "error", "message": {"text": "GHSA-86j7-9j95-vpqj: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "feeccdeabc0b1573", "scanner": "scanner-primary", "fingerprint": "541c96bb724b4451", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-86j7-9j95-vpqj"]}}, {"ruleId": "scanner-e320ff95e41c4c92", "level": "error", "message": {"text": "GHSA-9h47-pqcx-hjr4: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "6a1fc3b8f11cef5a", "scanner": "scanner-primary", "fingerprint": "e320ff95e41c4c92", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-9h47-pqcx-hjr4"]}}, {"ruleId": "scanner-c249ca8e69031ec7", "level": "error", "message": {"text": "GHSA-x732-6j76-qmhm: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "9319d7e39cdaf2da", "scanner": "scanner-primary", "fingerprint": "c249ca8e69031ec7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-x732-6j76-qmhm"]}}, {"ruleId": "scanner-bba0752afc67556a", "level": "warning", "message": {"text": "GHSA-wxw3-q3m9-c3jr: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "73725690900acbd9", "scanner": "scanner-primary", "fingerprint": "bba0752afc67556a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-wxw3-q3m9-c3jr"]}}, {"ruleId": "scanner-d198b3d7804b82e7", "level": "note", "message": {"text": "CVE-2025-53535: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "e41cc5b6d8695527", "scanner": "scanner-primary", "fingerprint": "d198b3d7804b82e7", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-53535"]}}, {"ruleId": "scanner-53b6b5b0e8df56bd", "level": "note", "message": {"text": "GHSA-2vg6-77g8-24mp: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "5bc34aa7979efec8", "scanner": "scanner-primary", "fingerprint": "53b6b5b0e8df56bd", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-2vg6-77g8-24mp"]}}, {"ruleId": "scanner-71c337a7b99c3ed8", "level": "note", "message": {"text": "GHSA-569q-mpph-wgww: better-auth 1.2.8 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "780aa72a5439df10", "scanner": "scanner-primary", "fingerprint": "71c337a7b99c3ed8", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-569q-mpph-wgww"]}}, {"ruleId": "scanner-fe6af4614f163486", "level": "warning", "message": {"text": "GHSA-hq75-xg7r-rx6c: better-call 1.0.9 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "4d2a7303d988e639", "scanner": "scanner-primary", "fingerprint": "fe6af4614f163486", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-hq75-xg7r-rx6c"]}}, {"ruleId": "scanner-5b6eda0b6fd52ce1", "level": "error", "message": {"text": "CVE-2026-35209: defu 6.1.4 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "460150f65f04670e", "scanner": "scanner-primary", "fingerprint": "5b6eda0b6fd52ce1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-35209"]}}, {"ruleId": "scanner-3467653acdca23df", "level": "error", "message": {"text": "CVE-2026-32763: kysely 0.28.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "2c820fd6f670c577", "scanner": "scanner-primary", "fingerprint": "3467653acdca23df", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-32763"]}}, {"ruleId": "scanner-517427c8f7143719", "level": "error", "message": {"text": "CVE-2026-33468: kysely 0.28.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "d88cfd8245f31527", "scanner": "scanner-primary", "fingerprint": "517427c8f7143719", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33468"]}}, {"ruleId": "scanner-972e7bf95d3c2000", "level": "error", "message": {"text": "CVE-2026-44635: kysely 0.28.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "2ae60d703ebf6c29", "scanner": "scanner-primary", "fingerprint": "972e7bf95d3c2000", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44635"]}}, {"ruleId": "scanner-3f319f53538105c0", "level": "warning", "message": {"text": "CVE-2025-66400: mdast-util-to-hast 13.2.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "e7dbadc65bca6ead", "scanner": "scanner-primary", "fingerprint": "3f319f53538105c0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66400"]}}, {"ruleId": "scanner-0f69df9d9287111c", "level": "error", "message": {"text": "CVE-2025-55182: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "301170942d358058", "scanner": "scanner-primary", "fingerprint": "0f69df9d9287111c", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-55182"]}}, {"ruleId": "scanner-136722a9b063a679", "level": "error", "message": {"text": "CVE-2026-44573: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "336eb53f953ca892", "scanner": "scanner-primary", "fingerprint": "136722a9b063a679", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44573"]}}, {"ruleId": "scanner-64c6837499e85121", "level": "error", "message": {"text": "CVE-2026-44575: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "e3c7c4fe9ff42f79", "scanner": "scanner-primary", "fingerprint": "64c6837499e85121", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44575"]}}, {"ruleId": "scanner-0ec85a0a6ebff72f", "level": "error", "message": {"text": "CVE-2026-44578: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "9ec6e146477acb53", "scanner": "scanner-primary", "fingerprint": "0ec85a0a6ebff72f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44578"]}}, {"ruleId": "scanner-e051a587d0342800", "level": "error", "message": {"text": "CVE-2026-44579: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "6ee5690055d2eb61", "scanner": "scanner-primary", "fingerprint": "e051a587d0342800", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44579"]}}, {"ruleId": "scanner-958e623d5bd39c18", "level": "error", "message": {"text": "CVE-2026-45109: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "f36ba24a1dafe02a", "scanner": "scanner-primary", "fingerprint": "958e623d5bd39c18", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45109"]}}, {"ruleId": "scanner-ac7118bf3809d56c", "level": "error", "message": {"text": "CVE-2026-64641: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "dd7da3053796d224", "scanner": "scanner-primary", "fingerprint": "ac7118bf3809d56c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64641"]}}, {"ruleId": "scanner-922ef0d990b639ee", "level": "error", "message": {"text": "CVE-2026-64645: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "74c1e4c00c0c10a5", "scanner": "scanner-primary", "fingerprint": "922ef0d990b639ee", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64645"]}}, {"ruleId": "scanner-b5842c5d8170fe44", "level": "error", "message": {"text": "CVE-2026-64649: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "e7b5f551ee0e21d3", "scanner": "scanner-primary", "fingerprint": "b5842c5d8170fe44", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64649"]}}, {"ruleId": "scanner-8e0feea1dafefb44", "level": "error", "message": {"text": "GHSA-8h8q-6873-q5fj: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "0f98c59dcdb9ae43", "scanner": "scanner-primary", "fingerprint": "8e0feea1dafefb44", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-8h8q-6873-q5fj"]}}, {"ruleId": "scanner-62de401c9b41c06f", "level": "error", "message": {"text": "GHSA-h25m-26qc-wcjf: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "aaea1ddaeb07f9a7", "scanner": "scanner-primary", "fingerprint": "62de401c9b41c06f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-h25m-26qc-wcjf"]}}, {"ruleId": "scanner-f9e0f2ccc6937d3e", "level": "error", "message": {"text": "GHSA-mwv6-3258-q52c: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "0ded5f4cd3e2e766", "scanner": "scanner-primary", "fingerprint": "f9e0f2ccc6937d3e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-mwv6-3258-q52c"]}}, {"ruleId": "scanner-4dedeb93526b1974", "level": "error", "message": {"text": "GHSA-q4gf-8mx6-v5v3: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "7e24095dd869329b", "scanner": "scanner-primary", "fingerprint": "4dedeb93526b1974", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-q4gf-8mx6-v5v3"]}}, {"ruleId": "scanner-cc04fa964b712808", "level": "warning", "message": {"text": "CVE-2025-55173: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "4e886bade0089170", "scanner": "scanner-primary", "fingerprint": "cc04fa964b712808", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-55173"]}}, {"ruleId": "scanner-c994336b8eacec63", "level": "warning", "message": {"text": "CVE-2025-57752: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "5c02647d8984fb54", "scanner": "scanner-primary", "fingerprint": "c994336b8eacec63", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-57752"]}}, {"ruleId": "scanner-f1ef6af7f14d662b", "level": "warning", "message": {"text": "CVE-2025-57822: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "66044e57a54a502c", "scanner": "scanner-primary", "fingerprint": "f1ef6af7f14d662b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-57822"]}}, {"ruleId": "scanner-7753263f01550694", "level": "warning", "message": {"text": "CVE-2025-59471: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "1942563a3f4b1bfe", "scanner": "scanner-primary", "fingerprint": "7753263f01550694", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-59471"]}}, {"ruleId": "scanner-d9ca5e51cc6d5c5c", "level": "warning", "message": {"text": "CVE-2026-27980: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "9b6a31f5b9010f39", "scanner": "scanner-primary", "fingerprint": "d9ca5e51cc6d5c5c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27980"]}}, {"ruleId": "scanner-1f671a796c8e215c", "level": "warning", "message": {"text": "CVE-2026-29057: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "bbe5ad82d0b43c5a", "scanner": "scanner-primary", "fingerprint": "1f671a796c8e215c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29057"]}}, {"ruleId": "scanner-4c11570196486e50", "level": "warning", "message": {"text": "CVE-2026-44576: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "0dea2112423f0f23", "scanner": "scanner-primary", "fingerprint": "4c11570196486e50", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44576"]}}, {"ruleId": "scanner-687c647bafcf038a", "level": "warning", "message": {"text": "CVE-2026-44577: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "f3bae6ad06684bfd", "scanner": "scanner-primary", "fingerprint": "687c647bafcf038a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44577"]}}, {"ruleId": "scanner-03746ff066ba0fbd", "level": "warning", "message": {"text": "CVE-2026-44580: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "0b458c59da4d5af7", "scanner": "scanner-primary", "fingerprint": "03746ff066ba0fbd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44580"]}}, {"ruleId": "scanner-35b81c45c491dd42", "level": "warning", "message": {"text": "CVE-2026-44581: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "f00eced62df95645", "scanner": "scanner-primary", "fingerprint": "35b81c45c491dd42", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44581"]}}, {"ruleId": "scanner-010f6ee5f61eabea", "level": "warning", "message": {"text": "CVE-2026-64643: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "d81bdfa3d5e2b8ee", "scanner": "scanner-primary", "fingerprint": "010f6ee5f61eabea", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64643"]}}, {"ruleId": "scanner-a5fe0b38e0133e37", "level": "warning", "message": {"text": "CVE-2026-64646: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "0c5389adbe5ae32a", "scanner": "scanner-primary", "fingerprint": "a5fe0b38e0133e37", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64646"]}}, {"ruleId": "scanner-7fd0187ad045fd28", "level": "warning", "message": {"text": "CVE-2026-64647: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "57448e2f297bc904", "scanner": "scanner-primary", "fingerprint": "7fd0187ad045fd28", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64647"]}}, {"ruleId": "scanner-0ce9cca10d5db591", "level": "warning", "message": {"text": "CVE-2026-64648: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "bd040a6158f59d5c", "scanner": "scanner-primary", "fingerprint": "0ce9cca10d5db591", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64648"]}}, {"ruleId": "scanner-a168d5703332d720", "level": "warning", "message": {"text": "GHSA-w37m-7fhw-fmv9: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "bc98684d63d28d6b", "scanner": "scanner-primary", "fingerprint": "a168d5703332d720", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-w37m-7fhw-fmv9"]}}, {"ruleId": "scanner-13b3d89d695c0453", "level": "note", "message": {"text": "CVE-2026-44572: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "82cc165451b8658a", "scanner": "scanner-primary", "fingerprint": "13b3d89d695c0453", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44572"]}}, {"ruleId": "scanner-ddaeb8e8b60471aa", "level": "note", "message": {"text": "CVE-2026-44582: next 15.3.3 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "90a361abf8730f42", "scanner": "scanner-primary", "fingerprint": "ddaeb8e8b60471aa", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44582"]}}, {"ruleId": "scanner-9c0383b9b9deded4", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "6bd8c442371a66ef", "scanner": "scanner-primary", "fingerprint": "9c0383b9b9deded4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-152e2df0884d5fea", "level": "error", "message": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.2 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "properties": {"repobilityId": "53b1d6243aa58b4a", "scanner": "scanner-primary", "fingerprint": "152e2df0884d5fea", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f88m-g3jw-g9cj"]}}, {"ruleId": "scanner-b284b438af2d83f7", "level": "error", "message": {"text": "CVE-2026-25990: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "62fed6404c6781fc", "scanner": "scanner-primary", "fingerprint": "b284b438af2d83f7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25990"]}}, {"ruleId": "scanner-0b68eabc267cb64f", "level": "error", "message": {"text": "CVE-2026-40192: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "86cc40d865d0a29c", "scanner": "scanner-primary", "fingerprint": "0b68eabc267cb64f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40192"]}}, {"ruleId": "scanner-99042a9b27c1b0d9", "level": "error", "message": {"text": "CVE-2026-42311: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "2a935d9daf1a4704", "scanner": "scanner-primary", "fingerprint": "99042a9b27c1b0d9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42311"]}}, {"ruleId": "scanner-384f85180eb38b8f", "level": "error", "message": {"text": "CVE-2026-54058: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "dbafac06b2933709", "scanner": "scanner-primary", "fingerprint": "384f85180eb38b8f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54058"]}}, {"ruleId": "scanner-8828c24d1ce23950", "level": "error", "message": {"text": "CVE-2026-54059: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "a3c440f7e6f556ae", "scanner": "scanner-primary", "fingerprint": "8828c24d1ce23950", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54059"]}}, {"ruleId": "scanner-5d8eba57144e1df9", "level": "error", "message": {"text": "CVE-2026-54060: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "75f8b72b9b61fed4", "scanner": "scanner-primary", "fingerprint": "5d8eba57144e1df9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54060"]}}, {"ruleId": "scanner-5c8821e7d78f3cad", "level": "error", "message": {"text": "CVE-2026-55379: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "a0e55afc91300a77", "scanner": "scanner-primary", "fingerprint": "5c8821e7d78f3cad", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55379"]}}, {"ruleId": "scanner-4374165d8ee4d2b2", "level": "error", "message": {"text": "CVE-2026-55380: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "d905a65715651f9e", "scanner": "scanner-primary", "fingerprint": "4374165d8ee4d2b2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55380"]}}, {"ruleId": "scanner-c18844ba62ec8581", "level": "error", "message": {"text": "CVE-2026-59197: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "dc7e4bdefeed83c9", "scanner": "scanner-primary", "fingerprint": "c18844ba62ec8581", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59197"]}}, {"ruleId": "scanner-ee9cc4e961429b59", "level": "error", "message": {"text": "CVE-2026-59199: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "13d85ae6e611d8cd", "scanner": "scanner-primary", "fingerprint": "ee9cc4e961429b59", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59199"]}}, {"ruleId": "scanner-4d7f4c1d3d9287a3", "level": "error", "message": {"text": "CVE-2026-59200: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "e79d072322982493", "scanner": "scanner-primary", "fingerprint": "4d7f4c1d3d9287a3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59200"]}}, {"ruleId": "scanner-3e31950c41a31c57", "level": "error", "message": {"text": "CVE-2026-59204: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "c8e08dcc8793890e", "scanner": "scanner-primary", "fingerprint": "3e31950c41a31c57", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59204"]}}, {"ruleId": "scanner-ae98da7bfccf9262", "level": "error", "message": {"text": "CVE-2026-59205: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "03a784c4e9cfbcf1", "scanner": "scanner-primary", "fingerprint": "ae98da7bfccf9262", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59205"]}}, {"ruleId": "scanner-c29d3f28ae4d6786", "level": "warning", "message": {"text": "CVE-2026-42308: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "0c9e478716dc984d", "scanner": "scanner-primary", "fingerprint": "c29d3f28ae4d6786", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42308"]}}, {"ruleId": "scanner-b9a548f2db0e7e2e", "level": "warning", "message": {"text": "CVE-2026-42310: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "ab12186d0942dc62", "scanner": "scanner-primary", "fingerprint": "b9a548f2db0e7e2e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42310"]}}, {"ruleId": "scanner-4d40d6ebb4f42e24", "level": "warning", "message": {"text": "CVE-2026-55798: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "e1c973f2b17df0e9", "scanner": "scanner-primary", "fingerprint": "4d40d6ebb4f42e24", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55798"]}}, {"ruleId": "scanner-48aed6213adcd445", "level": "warning", "message": {"text": "CVE-2026-59198: Pillow 11.0.0 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "fcaeb42860a9b771", "scanner": "scanner-primary", "fingerprint": "48aed6213adcd445", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59198"]}}, {"ruleId": "scanner-90a869230c010e8e", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "0010ccd9ba99e6b9", "scanner": "scanner-primary", "fingerprint": "90a869230c010e8e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-3f96abcaed2b1d79", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.41.1 \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt"}, "properties": {"repobilityId": "38498fae4c6ae6a7", "scanner": "scanner-primary", "fingerprint": "3f96abcaed2b1d79", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-ec4723df0a71f7d3", "level": "error", "message": {"text": "CVE-2025-23042: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "properties": {"repobilityId": "1229757d07709f37", "scanner": "scanner-primary", "fingerprint": "ec4723df0a71f7d3", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-23042"]}}, {"ruleId": "scanner-dd5afac30f18a0a8", "level": "error", "message": {"text": "CVE-2024-8966: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "properties": {"repobilityId": "859b510babe55311", "scanner": "scanner-primary", "fingerprint": "dd5afac30f18a0a8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-8966"]}}, {"ruleId": "scanner-9a1619d7cf7d2deb", "level": "error", "message": {"text": "CVE-2026-28414: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "properties": {"repobilityId": "6012b4138c3e7d40", "scanner": "scanner-primary", "fingerprint": "9a1619d7cf7d2deb", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28414"]}}, {"ruleId": "scanner-d48fe973b4124192", "level": "error", "message": {"text": "CVE-2026-28416: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "properties": {"repobilityId": "f075d8b664d0a6d0", "scanner": "scanner-primary", "fingerprint": "d48fe973b4124192", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28416"]}}, {"ruleId": "scanner-ebfdb5ace0ed16ed", "level": "error", "message": {"text": "CVE-2026-48545: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "properties": {"repobilityId": "99d6efb10d507a8b", "scanner": "scanner-primary", "fingerprint": "ebfdb5ace0ed16ed", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48545"]}}, {"ruleId": "scanner-bef903ecddb7b7df", "level": "warning", "message": {"text": "CVE-2025-48889: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "properties": {"repobilityId": "e29072c34b709b21", "scanner": "scanner-primary", "fingerprint": "bef903ecddb7b7df", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-48889"]}}, {"ruleId": "scanner-819b8680765bfbdc", "level": "warning", "message": {"text": "CVE-2026-28415: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "properties": {"repobilityId": "b4187e6040aa30f8", "scanner": "scanner-primary", "fingerprint": "819b8680765bfbdc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28415"]}}, {"ruleId": "scanner-a473ea2ac3f4f18c", "level": "note", "message": {"text": "CVE-2025-5320: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "properties": {"repobilityId": "e3c835796ed847c4", "scanner": "scanner-primary", "fingerprint": "a473ea2ac3f4f18c", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-5320"]}}, {"ruleId": "scanner-83c4c67c8c0d0437", "level": "note", "message": {"text": "CVE-2026-10783: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "properties": {"repobilityId": "085691e2d3c4f084", "scanner": "scanner-primary", "fingerprint": "83c4c67c8c0d0437", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10783"]}}, {"ruleId": "scanner-751f7ab8a91586fa", "level": "note", "message": {"text": "CVE-2026-27167: gradio 5.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt"}, "properties": {"repobilityId": "15343d6ea01b103d", "scanner": "scanner-primary", "fingerprint": "751f7ab8a91586fa", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27167"]}}, {"ruleId": "scanner-636187c0f2dcda4d", "level": "note", "message": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.17 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "a8943ad2da998bb6", "scanner": "scanner-primary", "fingerprint": "636187c0f2dcda4d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8769"]}}, {"ruleId": "scanner-db8c44758d337afe", "level": "note", "message": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "a8943ad2da998bb6", "scanner": "scanner-primary", "fingerprint": "db8c44758d337afe", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8769"]}}, {"ruleId": "scanner-c70f349c41aabbe4", "level": "error", "message": {"text": "CVE-2026-29087: @hono/node-server 1.19.9 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "048f1c8c8e0ca6b4", "scanner": "scanner-primary", "fingerprint": "c70f349c41aabbe4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29087"]}}, {"ruleId": "scanner-2a5531e0d3abcd42", "level": "warning", "message": {"text": "CVE-2026-39406: @hono/node-server 1.19.9 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "693bf5df20b06564", "scanner": "scanner-primary", "fingerprint": "2a5531e0d3abcd42", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39406"]}}, {"ruleId": "scanner-201838826ab72974", "level": "warning", "message": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.9 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "9511f3a92a13631f", "scanner": "scanner-primary", "fingerprint": "201838826ab72974", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-frvp-7c67-39w9"]}}, {"ruleId": "scanner-3d3016100b5d0cf2", "level": "warning", "message": {"text": "CVE-2025-69873: ajv 8.17.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "77db0df35d2fb417", "scanner": "scanner-primary", "fingerprint": "3d3016100b5d0cf2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69873"]}}, {"ruleId": "scanner-5722e3250ec31f53", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 1.20.4 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "1a8d77074c6ee0d8", "scanner": "scanner-primary", "fingerprint": "5722e3250ec31f53", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-0b9ac68b40cdbc89", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "1a8d77074c6ee0d8", "scanner": "scanner-primary", "fingerprint": "0b9ac68b40cdbc89", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-12f16d87e7f39415", "level": "warning", "message": {"text": "CVE-2026-0540: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "5afa0392809b5d62", "scanner": "scanner-primary", "fingerprint": "12f16d87e7f39415", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-0540"]}}, {"ruleId": "scanner-06a6e51816e1a362", "level": "warning", "message": {"text": "CVE-2026-41238: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "4847485ac974330e", "scanner": "scanner-primary", "fingerprint": "06a6e51816e1a362", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41238"]}}, {"ruleId": "scanner-b3d89cfefd72ce42", "level": "warning", "message": {"text": "CVE-2026-41239: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "60ee8238e9e275d2", "scanner": "scanner-primary", "fingerprint": "b3d89cfefd72ce42", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41239"]}}, {"ruleId": "scanner-6f9980c5aa6a9092", "level": "warning", "message": {"text": "CVE-2026-41240: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "ca9bf8d979432a9c", "scanner": "scanner-primary", "fingerprint": "6f9980c5aa6a9092", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41240"]}}, {"ruleId": "scanner-80cc29f5676ba1fb", "level": "warning", "message": {"text": "CVE-2026-49458: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "39521e4423e80605", "scanner": "scanner-primary", "fingerprint": "80cc29f5676ba1fb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49458"]}}, {"ruleId": "scanner-946fdac9bca2346e", "level": "warning", "message": {"text": "CVE-2026-49459: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "069b73ce98646122", "scanner": "scanner-primary", "fingerprint": "946fdac9bca2346e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49459"]}}, {"ruleId": "scanner-dc8dd834ff2dadd5", "level": "warning", "message": {"text": "CVE-2026-49978: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "e823d545012d12f8", "scanner": "scanner-primary", "fingerprint": "dc8dd834ff2dadd5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49978"]}}, {"ruleId": "scanner-dee754c5def4efbe", "level": "warning", "message": {"text": "GHSA-39q2-94rc-95cp: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "72554917fff9b204", "scanner": "scanner-primary", "fingerprint": "dee754c5def4efbe", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-39q2-94rc-95cp"]}}, {"ruleId": "scanner-5ca2b63bacfeb4c4", "level": "warning", "message": {"text": "GHSA-76mc-f452-cxcm: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "7fe55bc126309d39", "scanner": "scanner-primary", "fingerprint": "5ca2b63bacfeb4c4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-76mc-f452-cxcm"]}}, {"ruleId": "scanner-672c6cb2ba190925", "level": "warning", "message": {"text": "GHSA-cj63-jhhr-wcxv: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "75dcc58a725d1202", "scanner": "scanner-primary", "fingerprint": "672c6cb2ba190925", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cj63-jhhr-wcxv"]}}, {"ruleId": "scanner-91590914d91aaa5f", "level": "warning", "message": {"text": "GHSA-cjmm-f4jc-qw8r: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "1834dcadbb1ff36d", "scanner": "scanner-primary", "fingerprint": "91590914d91aaa5f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cjmm-f4jc-qw8r"]}}, {"ruleId": "scanner-1f6f3b64bb7a5cf3", "level": "warning", "message": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "5e4e2691c98138fd", "scanner": "scanner-primary", "fingerprint": "1f6f3b64bb7a5cf3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cmwh-pvxp-8882"]}}, {"ruleId": "scanner-a7617ec97280f293", "level": "warning", "message": {"text": "GHSA-h8r8-wccr-v5f2: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "a268577a9f48c12e", "scanner": "scanner-primary", "fingerprint": "a7617ec97280f293", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-h8r8-wccr-v5f2"]}}, {"ruleId": "scanner-b90b5d43abc83696", "level": "note", "message": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "d2fe3ea6741c19eb", "scanner": "scanner-primary", "fingerprint": "b90b5d43abc83696", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-c2j3-45gr-mqc4"]}}, {"ruleId": "scanner-59d9b4dcd9bdde4d", "level": "note", "message": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "1086b3644c5ba094", "scanner": "scanner-primary", "fingerprint": "59d9b4dcd9bdde4d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-gvmj-g25r-r7wr"]}}, {"ruleId": "scanner-78a7a9ad120cceda", "level": "note", "message": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "75a755a6fae8d91e", "scanner": "scanner-primary", "fingerprint": "78a7a9ad120cceda", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-vxr8-fq34-vvx9"]}}, {"ruleId": "scanner-51c5a14152f1f386", "level": "note", "message": {"text": "GHSA-x4vx-rjvf-j5p4: dompurify 3.3.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "7c83b229d5d46f3f", "scanner": "scanner-primary", "fingerprint": "51c5a14152f1f386", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-x4vx-rjvf-j5p4"]}}, {"ruleId": "scanner-09a1ec27fbd0be31", "level": "error", "message": {"text": "CVE-2026-30827: express-rate-limit 8.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "90b7efa4950f282e", "scanner": "scanner-primary", "fingerprint": "09a1ec27fbd0be31", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-30827"]}}, {"ruleId": "scanner-4700b2ac38538a67", "level": "error", "message": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "c77ddd15a4ae3d48", "scanner": "scanner-primary", "fingerprint": "4700b2ac38538a67", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13676"]}}, {"ruleId": "scanner-2b8ad42d65df83fa", "level": "error", "message": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "ed761bb00f47f866", "scanner": "scanner-primary", "fingerprint": "2b8ad42d65df83fa", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-16221"]}}, {"ruleId": "scanner-64abaa25a1a452ee", "level": "error", "message": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "4f8039f81f895260", "scanner": "scanner-primary", "fingerprint": "64abaa25a1a452ee", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6321"]}}, {"ruleId": "scanner-e138671ae9eb6f45", "level": "error", "message": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "6f486fa4183bb614", "scanner": "scanner-primary", "fingerprint": "e138671ae9eb6f45", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6322"]}}, {"ruleId": "scanner-f1dbced56b9c6cb6", "level": "error", "message": {"text": "CVE-2026-12143: form-data 4.0.5 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "a79eb82070cecf8a", "scanner": "scanner-primary", "fingerprint": "f1dbced56b9c6cb6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12143"]}}, {"ruleId": "scanner-e578bbc6dd70f8c0", "level": "error", "message": {"text": "CVE-2026-29045: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "e8cf164ef9537c06", "scanner": "scanner-primary", "fingerprint": "e578bbc6dd70f8c0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29045"]}}, {"ruleId": "scanner-558ec2e5fbb3503e", "level": "error", "message": {"text": "CVE-2026-54290: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "37053ea9066f7dff", "scanner": "scanner-primary", "fingerprint": "558ec2e5fbb3503e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54290"]}}, {"ruleId": "scanner-5cb6621a27615a2a", "level": "warning", "message": {"text": "CVE-2026-29085: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "69147ca5eaabb29a", "scanner": "scanner-primary", "fingerprint": "5cb6621a27615a2a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29085"]}}, {"ruleId": "scanner-a44845fcb3d08791", "level": "warning", "message": {"text": "CVE-2026-29086: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "734d03f92989555e", "scanner": "scanner-primary", "fingerprint": "a44845fcb3d08791", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29086"]}}, {"ruleId": "scanner-649fc7533507f3a8", "level": "warning", "message": {"text": "CVE-2026-39407: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "0dfeeafebf4df9dc", "scanner": "scanner-primary", "fingerprint": "649fc7533507f3a8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39407"]}}, {"ruleId": "scanner-b8d5ea5de13c20f6", "level": "warning", "message": {"text": "CVE-2026-39408: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "4ac8290aee9479c0", "scanner": "scanner-primary", "fingerprint": "b8d5ea5de13c20f6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39408"]}}, {"ruleId": "scanner-78bd25e4cf84f806", "level": "warning", "message": {"text": "CVE-2026-39409: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "5e8e6222dc619bc1", "scanner": "scanner-primary", "fingerprint": "78bd25e4cf84f806", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39409"]}}, {"ruleId": "scanner-143775611dddfbb9", "level": "warning", "message": {"text": "CVE-2026-39410: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "8e7848c8e34d0275", "scanner": "scanner-primary", "fingerprint": "143775611dddfbb9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39410"]}}, {"ruleId": "scanner-fd4e91b72bbdc3ea", "level": "warning", "message": {"text": "CVE-2026-44455: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "2a1175b5a7d7a085", "scanner": "scanner-primary", "fingerprint": "fd4e91b72bbdc3ea", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44455"]}}, {"ruleId": "scanner-aa3ba9fed688dfb9", "level": "warning", "message": {"text": "CVE-2026-44456: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "234e693d4c7a1e8a", "scanner": "scanner-primary", "fingerprint": "aa3ba9fed688dfb9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44456"]}}, {"ruleId": "scanner-98a698dfabb82853", "level": "warning", "message": {"text": "CVE-2026-44457: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "58b3034485f8ea6d", "scanner": "scanner-primary", "fingerprint": "98a698dfabb82853", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44457"]}}, {"ruleId": "scanner-65d222a1f0af4579", "level": "warning", "message": {"text": "CVE-2026-44458: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "76dc3d69ad9c5f63", "scanner": "scanner-primary", "fingerprint": "65d222a1f0af4579", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44458"]}}, {"ruleId": "scanner-dbdf701762255f5c", "level": "warning", "message": {"text": "CVE-2026-47673: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "42cf9259c8bcf985", "scanner": "scanner-primary", "fingerprint": "dbdf701762255f5c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47673"]}}, {"ruleId": "scanner-bd9a14f41c388060", "level": "warning", "message": {"text": "CVE-2026-47674: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "65611253fb6275d0", "scanner": "scanner-primary", "fingerprint": "bd9a14f41c388060", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47674"]}}, {"ruleId": "scanner-564efecff5e6a8af", "level": "warning", "message": {"text": "CVE-2026-47675: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "0f8ea210d77686d3", "scanner": "scanner-primary", "fingerprint": "564efecff5e6a8af", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47675"]}}, {"ruleId": "scanner-6f6e620af582b36a", "level": "warning", "message": {"text": "CVE-2026-47676: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "9b91dde460c3a51a", "scanner": "scanner-primary", "fingerprint": "6f6e620af582b36a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47676"]}}, {"ruleId": "scanner-e9d6fb809fc0ed9a", "level": "warning", "message": {"text": "CVE-2026-54286: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "c9555bc9de792c9d", "scanner": "scanner-primary", "fingerprint": "e9d6fb809fc0ed9a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54286"]}}, {"ruleId": "scanner-6eeceb13118d32b5", "level": "warning", "message": {"text": "CVE-2026-54287: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "6233ff55ff923e7e", "scanner": "scanner-primary", "fingerprint": "6eeceb13118d32b5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54287"]}}, {"ruleId": "scanner-3423605970184af7", "level": "warning", "message": {"text": "CVE-2026-54288: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "84feaf6ade557e68", "scanner": "scanner-primary", "fingerprint": "3423605970184af7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54288"]}}, {"ruleId": "scanner-1846d0a1eb32b0a5", "level": "warning", "message": {"text": "CVE-2026-54289: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "21752c181c0e1108", "scanner": "scanner-primary", "fingerprint": "1846d0a1eb32b0a5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54289"]}}, {"ruleId": "scanner-8b266f72c6094302", "level": "warning", "message": {"text": "CVE-2026-56761: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "0d2a31b9cbc9a8f2", "scanner": "scanner-primary", "fingerprint": "8b266f72c6094302", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-56761"]}}, {"ruleId": "scanner-538b6db3ba39304c", "level": "warning", "message": {"text": "CVE-2026-59895: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "73c8b72eda3e6be0", "scanner": "scanner-primary", "fingerprint": "538b6db3ba39304c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59895"]}}, {"ruleId": "scanner-39ffc16de1c2d93d", "level": "warning", "message": {"text": "CVE-2026-59897: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "0f56842dabcc682f", "scanner": "scanner-primary", "fingerprint": "39ffc16de1c2d93d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59897"]}}, {"ruleId": "scanner-f1011ebab4706351", "level": "warning", "message": {"text": "GHSA-26pp-8wgv-hjvm: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "383b097d34d0b7d2", "scanner": "scanner-primary", "fingerprint": "f1011ebab4706351", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-26pp-8wgv-hjvm"]}}, {"ruleId": "scanner-8d2953e43796d98b", "level": "warning", "message": {"text": "GHSA-v8w9-8mx6-g223: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "99f5550abada0ff7", "scanner": "scanner-primary", "fingerprint": "8d2953e43796d98b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-v8w9-8mx6-g223"]}}, {"ruleId": "scanner-f207eb2e4f4fd17e", "level": "note", "message": {"text": "CVE-2026-44459: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "1a6ad5b885108c84", "scanner": "scanner-primary", "fingerprint": "f207eb2e4f4fd17e", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44459"]}}, {"ruleId": "scanner-a2ebcc4490c9637c", "level": "note", "message": {"text": "GHSA-gq3j-xvxp-8hrf: hono 4.11.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "eec553fcd68c28e8", "scanner": "scanner-primary", "fingerprint": "a2ebcc4490c9637c", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-gq3j-xvxp-8hrf"]}}, {"ruleId": "scanner-e8860a21d7738ee4", "level": "warning", "message": {"text": "CVE-2026-42338: ip-address 10.0.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "957437f9171811cf", "scanner": "scanner-primary", "fingerprint": "e8860a21d7738ee4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42338"]}}, {"ruleId": "scanner-8903203942e78afd", "level": "error", "message": {"text": "CVE-2026-45134: langsmith 0.3.87 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "5933fd3a130872e2", "scanner": "scanner-primary", "fingerprint": "8903203942e78afd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45134"]}}, {"ruleId": "scanner-2b54cba2c19863ec", "level": "warning", "message": {"text": "CVE-2026-25528: langsmith 0.3.87 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "7992ce6e4bcc90eb", "scanner": "scanner-primary", "fingerprint": "2b54cba2c19863ec", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25528"]}}, {"ruleId": "scanner-0cecc4d2d7ab9ebb", "level": "warning", "message": {"text": "CVE-2026-40190: langsmith 0.3.87 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "9b57bb11e2282427", "scanner": "scanner-primary", "fingerprint": "0cecc4d2d7ab9ebb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40190"]}}, {"ruleId": "scanner-6af4ca37c5b3264c", "level": "warning", "message": {"text": "CVE-2026-41182: langsmith 0.3.87 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "06fcb62c56176a48", "scanner": "scanner-primary", "fingerprint": "6af4ca37c5b3264c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41182"]}}, {"ruleId": "scanner-1c215766c6e5ed64", "level": "error", "message": {"text": "CVE-2026-45134: langsmith 0.4.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "5933fd3a130872e2", "scanner": "scanner-primary", "fingerprint": "1c215766c6e5ed64", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45134"]}}, {"ruleId": "scanner-ce89f4499f7a5149", "level": "warning", "message": {"text": "CVE-2026-40190: langsmith 0.4.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "9b57bb11e2282427", "scanner": "scanner-primary", "fingerprint": "ce89f4499f7a5149", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40190"]}}, {"ruleId": "scanner-1e9cbaf34d8c8c24", "level": "warning", "message": {"text": "CVE-2026-41182: langsmith 0.4.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "06fcb62c56176a48", "scanner": "scanner-primary", "fingerprint": "1e9cbaf34d8c8c24", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41182"]}}, {"ruleId": "scanner-3b03d9e9b7c8f7c3", "level": "error", "message": {"text": "CVE-2026-4800: lodash-es 4.17.21 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "8501f521d84ec66f", "scanner": "scanner-primary", "fingerprint": "3b03d9e9b7c8f7c3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-21ccd52ea6c0e24d", "level": "warning", "message": {"text": "CVE-2025-13465: lodash-es 4.17.21 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "b26097d61c6ebcd0", "scanner": "scanner-primary", "fingerprint": "21ccd52ea6c0e24d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-13465"]}}, {"ruleId": "scanner-4fdd70b4163141cf", "level": "warning", "message": {"text": "CVE-2026-2950: lodash-es 4.17.21 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "26c687ee5a32e671", "scanner": "scanner-primary", "fingerprint": "4fdd70b4163141cf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-e5650daced229e03", "level": "error", "message": {"text": "CVE-2026-4800: lodash-es 4.17.23 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "8501f521d84ec66f", "scanner": "scanner-primary", "fingerprint": "e5650daced229e03", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-a8c97ccb937af6e3", "level": "warning", "message": {"text": "CVE-2026-2950: lodash-es 4.17.23 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "26c687ee5a32e671", "scanner": "scanner-primary", "fingerprint": "a8c97ccb937af6e3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-546576b656ca40e1", "level": "warning", "message": {"text": "CVE-2026-41148: mermaid 11.12.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "e63ef6eb2d01c82e", "scanner": "scanner-primary", "fingerprint": "546576b656ca40e1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41148"]}}, {"ruleId": "scanner-7333aee0dc0726d9", "level": "warning", "message": {"text": "CVE-2026-41149: mermaid 11.12.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "3c8db78b85f12ba9", "scanner": "scanner-primary", "fingerprint": "7333aee0dc0726d9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41149"]}}, {"ruleId": "scanner-fc1297f01e1e5536", "level": "warning", "message": {"text": "CVE-2026-41150: mermaid 11.12.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "6b225a396e39bdb0", "scanner": "scanner-primary", "fingerprint": "fc1297f01e1e5536", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41150"]}}, {"ruleId": "scanner-c5b2560b3eed31e4", "level": "warning", "message": {"text": "CVE-2026-41159: mermaid 11.12.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "5b1298f0c6e765a2", "scanner": "scanner-primary", "fingerprint": "c5b2560b3eed31e4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41159"]}}, {"ruleId": "scanner-6ba4a8936a687578", "level": "error", "message": {"text": "CVE-2026-44573: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "be8cf7105af30930", "scanner": "scanner-primary", "fingerprint": "6ba4a8936a687578", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44573"]}}, {"ruleId": "scanner-572c88e998ed2b6a", "level": "error", "message": {"text": "CVE-2026-44574: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "7482de7f908bca7f", "scanner": "scanner-primary", "fingerprint": "572c88e998ed2b6a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44574"]}}, {"ruleId": "scanner-3c2407d45afe92c0", "level": "error", "message": {"text": "CVE-2026-44575: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "b6d287b0b6be6ecd", "scanner": "scanner-primary", "fingerprint": "3c2407d45afe92c0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44575"]}}, {"ruleId": "scanner-59123f9faef96283", "level": "error", "message": {"text": "CVE-2026-44578: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "2d0e204ffe41f123", "scanner": "scanner-primary", "fingerprint": "59123f9faef96283", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44578"]}}, {"ruleId": "scanner-49a15067c230c5cd", "level": "error", "message": {"text": "CVE-2026-44579: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "370237edc9e5f01e", "scanner": "scanner-primary", "fingerprint": "49a15067c230c5cd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44579"]}}, {"ruleId": "scanner-57055106f5091843", "level": "error", "message": {"text": "CVE-2026-45109: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "2091d8c2f943d925", "scanner": "scanner-primary", "fingerprint": "57055106f5091843", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45109"]}}, {"ruleId": "scanner-66def54f256524e7", "level": "error", "message": {"text": "CVE-2026-64641: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "6f807899f5730401", "scanner": "scanner-primary", "fingerprint": "66def54f256524e7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64641"]}}, {"ruleId": "scanner-7b0159511c88f106", "level": "error", "message": {"text": "CVE-2026-64645: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "62b8af4512d34cab", "scanner": "scanner-primary", "fingerprint": "7b0159511c88f106", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64645"]}}, {"ruleId": "scanner-3939689077bb3d81", "level": "error", "message": {"text": "CVE-2026-64649: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "8f8ee19735fe991b", "scanner": "scanner-primary", "fingerprint": "3939689077bb3d81", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64649"]}}, {"ruleId": "scanner-18363ad3488d0594", "level": "error", "message": {"text": "GHSA-8h8q-6873-q5fj: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "305230be17dd40f7", "scanner": "scanner-primary", "fingerprint": "18363ad3488d0594", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-8h8q-6873-q5fj"]}}, {"ruleId": "scanner-70b5879c8780215d", "level": "error", "message": {"text": "GHSA-q4gf-8mx6-v5v3: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "1693fee4af618fc2", "scanner": "scanner-primary", "fingerprint": "70b5879c8780215d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-q4gf-8mx6-v5v3"]}}, {"ruleId": "scanner-1ad94e91d85cd2e8", "level": "warning", "message": {"text": "CVE-2026-27980: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "bd45b521efd1d4a7", "scanner": "scanner-primary", "fingerprint": "1ad94e91d85cd2e8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27980"]}}, {"ruleId": "scanner-60d90e42162542e1", "level": "warning", "message": {"text": "CVE-2026-29057: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "7d7e90ffc97084fd", "scanner": "scanner-primary", "fingerprint": "60d90e42162542e1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29057"]}}, {"ruleId": "scanner-a1fbef8ada1f4030", "level": "warning", "message": {"text": "CVE-2026-44576: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "4c2caf7c44efb1f2", "scanner": "scanner-primary", "fingerprint": "a1fbef8ada1f4030", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44576"]}}, {"ruleId": "scanner-54e1c8df43a8b33e", "level": "warning", "message": {"text": "CVE-2026-44577: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "64c6cfc6013c1b11", "scanner": "scanner-primary", "fingerprint": "54e1c8df43a8b33e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44577"]}}, {"ruleId": "scanner-4944832c1504511e", "level": "warning", "message": {"text": "CVE-2026-44580: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "ab77a2c896e828f2", "scanner": "scanner-primary", "fingerprint": "4944832c1504511e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44580"]}}, {"ruleId": "scanner-d97017abc20d069e", "level": "warning", "message": {"text": "CVE-2026-44581: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "2658bff21f320c8a", "scanner": "scanner-primary", "fingerprint": "d97017abc20d069e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44581"]}}, {"ruleId": "scanner-7ea8f94cba2b99a3", "level": "warning", "message": {"text": "CVE-2026-64643: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "9cbbbbd4d1e726bc", "scanner": "scanner-primary", "fingerprint": "7ea8f94cba2b99a3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64643"]}}, {"ruleId": "scanner-3d594779be44f06e", "level": "warning", "message": {"text": "CVE-2026-64644: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "2a034e9550a3b881", "scanner": "scanner-primary", "fingerprint": "3d594779be44f06e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64644"]}}, {"ruleId": "scanner-fcbf2122b30a6b33", "level": "warning", "message": {"text": "CVE-2026-64646: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "ada07efcf8491b8b", "scanner": "scanner-primary", "fingerprint": "fcbf2122b30a6b33", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64646"]}}, {"ruleId": "scanner-1d5de215ac0caa59", "level": "warning", "message": {"text": "CVE-2026-64647: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "fd7a195d7ca2105f", "scanner": "scanner-primary", "fingerprint": "1d5de215ac0caa59", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64647"]}}, {"ruleId": "scanner-809deb7b5a65dd62", "level": "warning", "message": {"text": "CVE-2026-64648: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "c8f48fff63ffde6d", "scanner": "scanner-primary", "fingerprint": "809deb7b5a65dd62", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64648"]}}, {"ruleId": "scanner-28e95206c9eb0e5a", "level": "note", "message": {"text": "CVE-2026-44572: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "59e67bd159a477e5", "scanner": "scanner-primary", "fingerprint": "28e95206c9eb0e5a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44572"]}}, {"ruleId": "scanner-f272bd5d444dcc95", "level": "note", "message": {"text": "CVE-2026-44582: next 15.5.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "15fc29f7ea500817", "scanner": "scanner-primary", "fingerprint": "f272bd5d444dcc95", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44582"]}}, {"ruleId": "scanner-cae3aac321982f7c", "level": "error", "message": {"text": "CVE-2026-4867: path-to-regexp 0.1.12 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "a6129ad13e6699f4", "scanner": "scanner-primary", "fingerprint": "cae3aac321982f7c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4867"]}}, {"ruleId": "scanner-faaa24656d99af42", "level": "error", "message": {"text": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "51b593dca6f3eed7", "scanner": "scanner-primary", "fingerprint": "faaa24656d99af42", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4926"]}}, {"ruleId": "scanner-8a610f3bc8f5d389", "level": "warning", "message": {"text": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "b3eba0d7e07440b7", "scanner": "scanner-primary", "fingerprint": "8a610f3bc8f5d389", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4923"]}}, {"ruleId": "scanner-93e571be4ac9192e", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "43ef584ca62395f9", "scanner": "scanner-primary", "fingerprint": "93e571be4ac9192e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-b504a83ffd8fe86a", "level": "warning", "message": {"text": "CVE-2024-53382: prismjs 1.27.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "77709b1901a271bf", "scanner": "scanner-primary", "fingerprint": "b504a83ffd8fe86a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-53382"]}}, {"ruleId": "scanner-3a5ef3d999d5f39c", "level": "warning", "message": {"text": "CVE-2026-8723: qs 6.14.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "66223e1258b01e84", "scanner": "scanner-primary", "fingerprint": "3a5ef3d999d5f39c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8723"]}}, {"ruleId": "scanner-200577ee81beacad", "level": "note", "message": {"text": "CVE-2026-2391: qs 6.14.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "51db6682df1934c0", "scanner": "scanner-primary", "fingerprint": "200577ee81beacad", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2391"]}}, {"ruleId": "scanner-62072bb95abe2e48", "level": "error", "message": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "ddb9d427d393ea12", "scanner": "scanner-primary", "fingerprint": "62072bb95abe2e48", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f88m-g3jw-g9cj"]}}, {"ruleId": "scanner-68c660fa1a677893", "level": "warning", "message": {"text": "CVE-2026-12644: ts-deepmerge 7.0.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "f65c0491d45c82f5", "scanner": "scanner-primary", "fingerprint": "68c660fa1a677893", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12644"]}}, {"ruleId": "scanner-13571d85a3d33dd9", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 10.0.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "a3c886caa3979f72", "scanner": "scanner-primary", "fingerprint": "13571d85a3d33dd9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-b7cca058a9d08df6", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "a3c886caa3979f72", "scanner": "scanner-primary", "fingerprint": "b7cca058a9d08df6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-c8d4c108cf54aa10", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "properties": {"repobilityId": "a3c886caa3979f72", "scanner": "scanner-primary", "fingerprint": "c8d4c108cf54aa10", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-42d70e9df5cf1203", "level": "error", "message": {"text": "CVE-2026-42215: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "c82419d89c36715e", "scanner": "scanner-primary", "fingerprint": "42d70e9df5cf1203", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42215"]}}, {"ruleId": "scanner-64576949139b64ac", "level": "error", "message": {"text": "CVE-2026-42284: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "2512f302e961ce40", "scanner": "scanner-primary", "fingerprint": "64576949139b64ac", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42284"]}}, {"ruleId": "scanner-b9d09896fc702722", "level": "error", "message": {"text": "CVE-2026-44243: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "673085f7907515bd", "scanner": "scanner-primary", "fingerprint": "b9d09896fc702722", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44243"]}}, {"ruleId": "scanner-1e2c04be9c8b640c", "level": "error", "message": {"text": "CVE-2026-44244: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "378ef612a5f7d60c", "scanner": "scanner-primary", "fingerprint": "1e2c04be9c8b640c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44244"]}}, {"ruleId": "scanner-e8fda51dd3353d0c", "level": "error", "message": {"text": "GHSA-2f96-g7mh-g2hx: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "f941a14d16270115", "scanner": "scanner-primary", "fingerprint": "e8fda51dd3353d0c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-2f96-g7mh-g2hx"]}}, {"ruleId": "scanner-ea1fdd012bbf8555", "level": "error", "message": {"text": "GHSA-956x-8gvw-wg5v: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "3e9a1fa82e2d45e0", "scanner": "scanner-primary", "fingerprint": "ea1fdd012bbf8555", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-956x-8gvw-wg5v"]}}, {"ruleId": "scanner-4c50187873096d50", "level": "error", "message": {"text": "GHSA-mv93-w799-cj2w: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "68f894650c00d690", "scanner": "scanner-primary", "fingerprint": "4c50187873096d50", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-mv93-w799-cj2w"]}}, {"ruleId": "scanner-bd525d32ce409f0e", "level": "error", "message": {"text": "GHSA-rwj8-pgh3-r573: GitPython 3.1.44 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "9977346d4499e2df", "scanner": "scanner-primary", "fingerprint": "bd525d32ce409f0e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-rwj8-pgh3-r573"]}}, {"ruleId": "scanner-38e516be504806a3", "level": "error", "message": {"text": "CVE-2026-32597: PyJWT 2.9.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "4bbc082c4275f622", "scanner": "scanner-primary", "fingerprint": "38e516be504806a3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-32597"]}}, {"ruleId": "scanner-282ad11b28f5348a", "level": "error", "message": {"text": "CVE-2026-48526: PyJWT 2.9.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "ab8a58d1764478a8", "scanner": "scanner-primary", "fingerprint": "282ad11b28f5348a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48526"]}}, {"ruleId": "scanner-7c053f33dac36498", "level": "warning", "message": {"text": "CVE-2026-48522: PyJWT 2.9.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "360f1f664b5cc1ba", "scanner": "scanner-primary", "fingerprint": "7c053f33dac36498", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48522"]}}, {"ruleId": "scanner-e4e189f23b847a5f", "level": "warning", "message": {"text": "CVE-2026-48523: PyJWT 2.9.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "24d4972a547fad4e", "scanner": "scanner-primary", "fingerprint": "e4e189f23b847a5f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48523"]}}, {"ruleId": "scanner-4b8b21124eb507d4", "level": "warning", "message": {"text": "CVE-2026-48525: PyJWT 2.9.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "88687edcb231c9c1", "scanner": "scanner-primary", "fingerprint": "4b8b21124eb507d4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48525"]}}, {"ruleId": "scanner-651aa47f1fac0967", "level": "note", "message": {"text": "CVE-2026-48524: PyJWT 2.9.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "5512eec1afe991ec", "scanner": "scanner-primary", "fingerprint": "651aa47f1fac0967", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48524"]}}, {"ruleId": "scanner-9d46ffc5a02564c9", "level": "error", "message": {"text": "CVE-2026-35002: agno 1.4.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "71be21bd6814f323", "scanner": "scanner-primary", "fingerprint": "9d46ffc5a02564c9", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-35002"]}}, {"ruleId": "scanner-d84772eba72837fb", "level": "error", "message": {"text": "CVE-2026-10105: agno 1.4.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "fdaf31a6f88cf2a9", "scanner": "scanner-primary", "fingerprint": "d84772eba72837fb", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10105"]}}, {"ruleId": "scanner-f6675bd101780315", "level": "error", "message": {"text": "CVE-2025-69223: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "da9917fa15b521a8", "scanner": "scanner-primary", "fingerprint": "f6675bd101780315", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69223"]}}, {"ruleId": "scanner-918c370c332d0340", "level": "warning", "message": {"text": "CVE-2025-69227: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "28e6c0bb9c946efc", "scanner": "scanner-primary", "fingerprint": "918c370c332d0340", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69227"]}}, {"ruleId": "scanner-f0007d8396211c43", "level": "warning", "message": {"text": "CVE-2025-69228: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "0f7c2df0949de1e2", "scanner": "scanner-primary", "fingerprint": "f0007d8396211c43", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69228"]}}, {"ruleId": "scanner-46461deb497f99ca", "level": "warning", "message": {"text": "CVE-2025-69229: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "6f39e67446eab6ff", "scanner": "scanner-primary", "fingerprint": "46461deb497f99ca", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69229"]}}, {"ruleId": "scanner-1166cccac204bf63", "level": "warning", "message": {"text": "CVE-2026-22815: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "406850f7f6bd9079", "scanner": "scanner-primary", "fingerprint": "1166cccac204bf63", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-22815"]}}, {"ruleId": "scanner-c5c2606bfc725d67", "level": "warning", "message": {"text": "CVE-2026-34515: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "5acff615bd570e5b", "scanner": "scanner-primary", "fingerprint": "c5c2606bfc725d67", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34515"]}}, {"ruleId": "scanner-658f6ac22bc43c9e", "level": "warning", "message": {"text": "CVE-2026-34516: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "5b81c5a85357d2a3", "scanner": "scanner-primary", "fingerprint": "658f6ac22bc43c9e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34516"]}}, {"ruleId": "scanner-cf397fcb3ab04513", "level": "warning", "message": {"text": "CVE-2026-34525: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "3839636bbc795397", "scanner": "scanner-primary", "fingerprint": "cf397fcb3ab04513", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34525"]}}, {"ruleId": "scanner-612a030398ac1d2d", "level": "warning", "message": {"text": "CVE-2026-34993: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "669ee6d5679f5119", "scanner": "scanner-primary", "fingerprint": "612a030398ac1d2d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34993"]}}, {"ruleId": "scanner-101132809b2c64f2", "level": "warning", "message": {"text": "CVE-2026-47265: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "36266941b9921d9b", "scanner": "scanner-primary", "fingerprint": "101132809b2c64f2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47265"]}}, {"ruleId": "scanner-f9201f2e76c706d4", "level": "warning", "message": {"text": "CVE-2026-54273: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "afd593e44b26e95e", "scanner": "scanner-primary", "fingerprint": "f9201f2e76c706d4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54273"]}}, {"ruleId": "scanner-88acfb41e1b85d13", "level": "warning", "message": {"text": "CVE-2026-54274: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "5ea2159311ccf284", "scanner": "scanner-primary", "fingerprint": "88acfb41e1b85d13", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54274"]}}, {"ruleId": "scanner-dd92f414f9ecf07d", "level": "warning", "message": {"text": "CVE-2026-54276: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "66384b2c8c643dc9", "scanner": "scanner-primary", "fingerprint": "dd92f414f9ecf07d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54276"]}}, {"ruleId": "scanner-c9c242f90888d3b9", "level": "warning", "message": {"text": "CVE-2026-54277: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "8608237ee1222757", "scanner": "scanner-primary", "fingerprint": "c9c242f90888d3b9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54277"]}}, {"ruleId": "scanner-148cb76d5849e6c3", "level": "warning", "message": {"text": "CVE-2026-54278: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "f13c431d763c31f2", "scanner": "scanner-primary", "fingerprint": "148cb76d5849e6c3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54278"]}}, {"ruleId": "scanner-f4162eb745914132", "level": "note", "message": {"text": "CVE-2025-53643: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "484fce031d33985a", "scanner": "scanner-primary", "fingerprint": "f4162eb745914132", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-53643"]}}, {"ruleId": "scanner-e8b14ce34ab9e9c8", "level": "note", "message": {"text": "CVE-2025-69224: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "ec9f27124675ff91", "scanner": "scanner-primary", "fingerprint": "e8b14ce34ab9e9c8", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69224"]}}, {"ruleId": "scanner-fff138aac2d0e148", "level": "note", "message": {"text": "CVE-2025-69225: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "8050d4ca0cf69cd8", "scanner": "scanner-primary", "fingerprint": "fff138aac2d0e148", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69225"]}}, {"ruleId": "scanner-7ac1ec805423f930", "level": "note", "message": {"text": "CVE-2025-69226: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "c70bcc82ec33bb29", "scanner": "scanner-primary", "fingerprint": "7ac1ec805423f930", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69226"]}}, {"ruleId": "scanner-c9b121bf0ef27989", "level": "note", "message": {"text": "CVE-2025-69230: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "36dce6f4cb2f62bf", "scanner": "scanner-primary", "fingerprint": "c9b121bf0ef27989", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69230"]}}, {"ruleId": "scanner-e2e0004d51f857a8", "level": "note", "message": {"text": "CVE-2026-34513: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "424ebd251123fe30", "scanner": "scanner-primary", "fingerprint": "e2e0004d51f857a8", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34513"]}}, {"ruleId": "scanner-04e3129a40024a81", "level": "note", "message": {"text": "CVE-2026-34514: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "71b77b7a9bc21509", "scanner": "scanner-primary", "fingerprint": "04e3129a40024a81", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34514"]}}, {"ruleId": "scanner-f18902e12cd7ba32", "level": "note", "message": {"text": "CVE-2026-34517: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "849151bf89ff6cab", "scanner": "scanner-primary", "fingerprint": "f18902e12cd7ba32", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34517"]}}, {"ruleId": "scanner-0c4c07ef6a0881c8", "level": "note", "message": {"text": "CVE-2026-34518: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "32bd01dfd9a665e2", "scanner": "scanner-primary", "fingerprint": "0c4c07ef6a0881c8", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34518"]}}, {"ruleId": "scanner-13b3297ae42deafe", "level": "note", "message": {"text": "CVE-2026-34519: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "aadb14a075b9f8d4", "scanner": "scanner-primary", "fingerprint": "13b3297ae42deafe", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34519"]}}, {"ruleId": "scanner-aebd205be4735b22", "level": "note", "message": {"text": "CVE-2026-34520: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "f0e6bcdfa18cecee", "scanner": "scanner-primary", "fingerprint": "aebd205be4735b22", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34520"]}}, {"ruleId": "scanner-a92f8fb17c7752c0", "level": "note", "message": {"text": "CVE-2026-50269: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "1d827b8e420a29f6", "scanner": "scanner-primary", "fingerprint": "a92f8fb17c7752c0", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-50269"]}}, {"ruleId": "scanner-b034a92a9d658711", "level": "note", "message": {"text": "CVE-2026-54275: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "c6b1f2734d0e9661", "scanner": "scanner-primary", "fingerprint": "b034a92a9d658711", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54275"]}}, {"ruleId": "scanner-c24191b4c16d3aef", "level": "note", "message": {"text": "CVE-2026-54279: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "069700a54005d560", "scanner": "scanner-primary", "fingerprint": "c24191b4c16d3aef", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54279"]}}, {"ruleId": "scanner-27beaad0a4732854", "level": "note", "message": {"text": "CVE-2026-54280: aiohttp 3.11.18 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "607277b18e052364", "scanner": "scanner-primary", "fingerprint": "27beaad0a4732854", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54280"]}}, {"ruleId": "scanner-286823c8e27e6a84", "level": "note", "message": {"text": "CVE-2025-64481: datasette 0.65.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "7ecee9dab90dc2e5", "scanner": "scanner-primary", "fingerprint": "286823c8e27e6a84", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-64481"]}}, {"ruleId": "scanner-ce6379c5690e2eee", "level": "warning", "message": {"text": "CVE-2025-68146: filelock 3.18.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "115651f4b0b6927f", "scanner": "scanner-primary", "fingerprint": "ce6379c5690e2eee", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-68146"]}}, {"ruleId": "scanner-96f8fc9dcd9caadc", "level": "warning", "message": {"text": "CVE-2026-22701: filelock 3.18.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "28f9cfb5189b619f", "scanner": "scanner-primary", "fingerprint": "96f8fc9dcd9caadc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-22701"]}}, {"ruleId": "scanner-efdf0bdbbd843fed", "level": "error", "message": {"text": "CVE-2025-43859: h11 0.14.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "dd424364a9b3b339", "scanner": "scanner-primary", "fingerprint": "efdf0bdbbd843fed", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-43859"]}}, {"ruleId": "scanner-0ca121337f50b2ec", "level": "warning", "message": {"text": "CVE-2025-57804: h2 4.2.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "2d4116d4cc550d9b", "scanner": "scanner-primary", "fingerprint": "0ca121337f50b2ec", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-57804"]}}, {"ruleId": "scanner-1807dc42a079a244", "level": "warning", "message": {"text": "CVE-2026-45409: idna 3.10 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "c94e3c921c9b2b2f", "scanner": "scanner-primary", "fingerprint": "1807dc42a079a244", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45409"]}}, {"ruleId": "scanner-c66fc5fab98040ad", "level": "error", "message": {"text": "CVE-2026-45134: langchain 0.3.22 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "0110c1b941765e91", "scanner": "scanner-primary", "fingerprint": "c66fc5fab98040ad", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45134"]}}, {"ruleId": "scanner-e4b2a1ea38f4fd80", "level": "warning", "message": {"text": "CVE-2026-55443: langchain 0.3.22 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "fa517886c9664c1e", "scanner": "scanner-primary", "fingerprint": "e4b2a1ea38f4fd80", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55443"]}}, {"ruleId": "scanner-fa749df17a65f322", "level": "warning", "message": {"text": "CVE-2026-55443: langchain-anthropic 0.3.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "37fd847a80ea0cfe", "scanner": "scanner-primary", "fingerprint": "fa749df17a65f322", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55443"]}}, {"ruleId": "scanner-eea8ae764d431f78", "level": "error", "message": {"text": "CVE-2025-68664: langchain-core 0.3.49 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "e8c46e242c170066", "scanner": "scanner-primary", "fingerprint": "eea8ae764d431f78", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-68664"]}}, {"ruleId": "scanner-aa1f680438f06863", "level": "error", "message": {"text": "CVE-2025-65106: langchain-core 0.3.49 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "67a8823c49c70ab4", "scanner": "scanner-primary", "fingerprint": "aa1f680438f06863", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-65106"]}}, {"ruleId": "scanner-a98ac1a49cf77ea4", "level": "error", "message": {"text": "CVE-2026-34070: langchain-core 0.3.49 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "abc86a0a69d2bb6e", "scanner": "scanner-primary", "fingerprint": "a98ac1a49cf77ea4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34070"]}}, {"ruleId": "scanner-4d43da82e6d1cdca", "level": "error", "message": {"text": "CVE-2026-44843: langchain-core 0.3.49 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "89ab933b212c719d", "scanner": "scanner-primary", "fingerprint": "4d43da82e6d1cdca", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44843"]}}, {"ruleId": "scanner-4fbfe3edcf5e759b", "level": "warning", "message": {"text": "CVE-2026-40087: langchain-core 0.3.49 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "73561b07809dde33", "scanner": "scanner-primary", "fingerprint": "4fbfe3edcf5e759b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40087"]}}, {"ruleId": "scanner-5b8a1b96dbb92de4", "level": "note", "message": {"text": "CVE-2026-26013: langchain-core 0.3.49 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "ddeac01b200a6859", "scanner": "scanner-primary", "fingerprint": "5b8a1b96dbb92de4", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26013"]}}, {"ruleId": "scanner-250aea46b9dc58db", "level": "note", "message": {"text": "CVE-2026-41488: langchain-openai 0.3.11 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "f5cf081037d3698d", "scanner": "scanner-primary", "fingerprint": "250aea46b9dc58db", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41488"]}}, {"ruleId": "scanner-774416b44f1dabe1", "level": "error", "message": {"text": "CVE-2025-6985: langchain-text-splitters 0.3.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "5fd3ba95c15bfe17", "scanner": "scanner-primary", "fingerprint": "774416b44f1dabe1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6985"]}}, {"ruleId": "scanner-134350120b55ec15", "level": "warning", "message": {"text": "CVE-2026-41481: langchain-text-splitters 0.3.7 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "12c799b886acf630", "scanner": "scanner-primary", "fingerprint": "134350120b55ec15", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41481"]}}, {"ruleId": "scanner-0d3db040e359b227", "level": "error", "message": {"text": "CVE-2026-45134: langsmith 0.3.31 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "6e01891f4c69ee81", "scanner": "scanner-primary", "fingerprint": "0d3db040e359b227", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45134"]}}, {"ruleId": "scanner-0ded2f1935a804f0", "level": "error", "message": {"text": "GHSA-f4xh-w4cj-qxq8: langsmith 0.3.31 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "c247a0732e1885a1", "scanner": "scanner-primary", "fingerprint": "0ded2f1935a804f0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f4xh-w4cj-qxq8"]}}, {"ruleId": "scanner-1881f0d87c6e1e90", "level": "warning", "message": {"text": "CVE-2026-41182: langsmith 0.3.31 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "95ffa1f5ea47a333", "scanner": "scanner-primary", "fingerprint": "1881f0d87c6e1e90", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41182"]}}, {"ruleId": "scanner-ccb27d4f9cde9fa6", "level": "error", "message": {"text": "CVE-2026-41066: lxml 5.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "5b07e39dc4d51856", "scanner": "scanner-primary", "fingerprint": "ccb27d4f9cde9fa6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41066"]}}, {"ruleId": "scanner-b4823e1ec8ba013e", "level": "error", "message": {"text": "CVE-2026-49825: lxml_html_clean 0.4.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "989c50c8c00c0512", "scanner": "scanner-primary", "fingerprint": "b4823e1ec8ba013e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49825"]}}, {"ruleId": "scanner-e7c22a4f6becea54", "level": "warning", "message": {"text": "CVE-2026-28348: lxml_html_clean 0.4.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "84bbe46e3781312f", "scanner": "scanner-primary", "fingerprint": "e7c22a4f6becea54", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28348"]}}, {"ruleId": "scanner-4c9898c71ee4af49", "level": "warning", "message": {"text": "CVE-2026-28350: lxml_html_clean 0.4.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "02e753740333d702", "scanner": "scanner-primary", "fingerprint": "4c9898c71ee4af49", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28350"]}}, {"ruleId": "scanner-7c382b8c008cd64f", "level": "error", "message": {"text": "CVE-2026-31240: mem0ai 0.1.93 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "74f476859d4ec1e8", "scanner": "scanner-primary", "fingerprint": "7c382b8c008cd64f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31240"]}}, {"ruleId": "scanner-bd6a865cc63a86a2", "level": "warning", "message": {"text": "CVE-2026-31241: mem0ai 0.1.93 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "052473619782e270", "scanner": "scanner-primary", "fingerprint": "bd6a865cc63a86a2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31241"]}}, {"ruleId": "scanner-508c6ab5c59295ca", "level": "warning", "message": {"text": "CVE-2026-31245: mem0ai 0.1.93 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "844e92de5564e551", "scanner": "scanner-primary", "fingerprint": "508c6ab5c59295ca", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31245"]}}, {"ruleId": "scanner-8fd35460689aeeab", "level": "note", "message": {"text": "CVE-2026-7597: mem0ai 0.1.93 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "d0560ae533f02647", "scanner": "scanner-primary", "fingerprint": "8fd35460689aeeab", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-7597"]}}, {"ruleId": "scanner-e577dfd46645672b", "level": "error", "message": {"text": "GHSA-6v7p-g79w-8964: msgpack 1.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "09fabb1da26cc4a1", "scanner": "scanner-primary", "fingerprint": "e577dfd46645672b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-6v7p-g79w-8964"]}}, {"ruleId": "scanner-e1cdf9f23a540946", "level": "error", "message": {"text": "CVE-2025-14009: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "2a15d18ff76b1e36", "scanner": "scanner-primary", "fingerprint": "e1cdf9f23a540946", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-14009"]}}, {"ruleId": "scanner-7204ade5dbb26d38", "level": "error", "message": {"text": "CVE-2026-0846: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "5bd6a74a8f3bb235", "scanner": "scanner-primary", "fingerprint": "7204ade5dbb26d38", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-0846"]}}, {"ruleId": "scanner-0a3f74ef126f2a22", "level": "error", "message": {"text": "CVE-2026-0847: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "41c89f71cbe57403", "scanner": "scanner-primary", "fingerprint": "0a3f74ef126f2a22", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-0847"]}}, {"ruleId": "scanner-7eac932676a25e73", "level": "error", "message": {"text": "CVE-2026-33231: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "66dc883adfef7b94", "scanner": "scanner-primary", "fingerprint": "7eac932676a25e73", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33231"]}}, {"ruleId": "scanner-53dd9e1f6851e1f0", "level": "error", "message": {"text": "CVE-2026-33236: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "809f899a5d45a385", "scanner": "scanner-primary", "fingerprint": "53dd9e1f6851e1f0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33236"]}}, {"ruleId": "scanner-5f1280b20678b747", "level": "error", "message": {"text": "CVE-2026-54293: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "d58eb5cfd804d9e3", "scanner": "scanner-primary", "fingerprint": "5f1280b20678b747", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54293"]}}, {"ruleId": "scanner-3ca02038d3122528", "level": "warning", "message": {"text": "CVE-2026-33230: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "182b53055ed3e8f5", "scanner": "scanner-primary", "fingerprint": "3ca02038d3122528", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33230"]}}, {"ruleId": "scanner-e9f2e78f7aa53d61", "level": "warning", "message": {"text": "GHSA-rf74-v2fm-23pw: nltk 3.9.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "7e4c8c7d0865d051", "scanner": "scanner-primary", "fingerprint": "e9f2e78f7aa53d61", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-rf74-v2fm-23pw"]}}, {"ruleId": "scanner-f766bf2c505b2f2b", "level": "error", "message": {"text": "CVE-2025-67221: orjson 3.10.16 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "9fd002038926f9ff", "scanner": "scanner-primary", "fingerprint": "f766bf2c505b2f2b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-67221"]}}, {"ruleId": "scanner-c1b769fd0c9d0c2d", "level": "error", "message": {"text": "CVE-2025-48379: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "c577878f82cfba83", "scanner": "scanner-primary", "fingerprint": "c1b769fd0c9d0c2d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-48379"]}}, {"ruleId": "scanner-868629d4b617ce05", "level": "error", "message": {"text": "CVE-2026-25990: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "fd5f1518da3ce177", "scanner": "scanner-primary", "fingerprint": "868629d4b617ce05", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25990"]}}, {"ruleId": "scanner-75fd122a4fb0b593", "level": "error", "message": {"text": "CVE-2026-40192: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "96155780f63ffbfa", "scanner": "scanner-primary", "fingerprint": "75fd122a4fb0b593", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40192"]}}, {"ruleId": "scanner-85cb3b2ba8a4c9da", "level": "error", "message": {"text": "CVE-2026-42311: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "7149ae9342d02253", "scanner": "scanner-primary", "fingerprint": "85cb3b2ba8a4c9da", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42311"]}}, {"ruleId": "scanner-86fa88d96844ec27", "level": "error", "message": {"text": "CVE-2026-54058: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "72eb4b302e217cee", "scanner": "scanner-primary", "fingerprint": "86fa88d96844ec27", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54058"]}}, {"ruleId": "scanner-eee97bb5016a65fa", "level": "error", "message": {"text": "CVE-2026-54059: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "c60f9c4ad5ef61d6", "scanner": "scanner-primary", "fingerprint": "eee97bb5016a65fa", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54059"]}}, {"ruleId": "scanner-c8486c8694238962", "level": "error", "message": {"text": "CVE-2026-54060: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "dd7b94a5a47b48bf", "scanner": "scanner-primary", "fingerprint": "c8486c8694238962", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54060"]}}, {"ruleId": "scanner-63227222f2a507d8", "level": "error", "message": {"text": "CVE-2026-55379: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "d07b4e4c75a93bdc", "scanner": "scanner-primary", "fingerprint": "63227222f2a507d8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55379"]}}, {"ruleId": "scanner-6e7e4917108edd6c", "level": "error", "message": {"text": "CVE-2026-55380: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "3aa8966213219664", "scanner": "scanner-primary", "fingerprint": "6e7e4917108edd6c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55380"]}}, {"ruleId": "scanner-fbd870123e07a43f", "level": "error", "message": {"text": "CVE-2026-59197: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "bcbd0b145d6a6fa5", "scanner": "scanner-primary", "fingerprint": "fbd870123e07a43f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59197"]}}, {"ruleId": "scanner-1dc5b9862b69da4b", "level": "error", "message": {"text": "CVE-2026-59199: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "9f765c3bbf1bef72", "scanner": "scanner-primary", "fingerprint": "1dc5b9862b69da4b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59199"]}}, {"ruleId": "scanner-29ca42f167f97ac7", "level": "error", "message": {"text": "CVE-2026-59200: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "165ccc1523695f69", "scanner": "scanner-primary", "fingerprint": "29ca42f167f97ac7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59200"]}}, {"ruleId": "scanner-775e13f760cf5079", "level": "error", "message": {"text": "CVE-2026-59204: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "df94c32d9301a3d5", "scanner": "scanner-primary", "fingerprint": "775e13f760cf5079", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59204"]}}, {"ruleId": "scanner-c5b79b9708c6de43", "level": "error", "message": {"text": "CVE-2026-59205: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "7c046d4f8d72f891", "scanner": "scanner-primary", "fingerprint": "c5b79b9708c6de43", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59205"]}}, {"ruleId": "scanner-ff74de4af1b61344", "level": "warning", "message": {"text": "CVE-2026-42308: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "f5e7af8ad79d4f31", "scanner": "scanner-primary", "fingerprint": "ff74de4af1b61344", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42308"]}}, {"ruleId": "scanner-9821e076016b442a", "level": "warning", "message": {"text": "CVE-2026-42309: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "d7169add6746c0de", "scanner": "scanner-primary", "fingerprint": "9821e076016b442a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42309"]}}, {"ruleId": "scanner-649990f9c6f33185", "level": "warning", "message": {"text": "CVE-2026-42310: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "166c762c5d0cbde7", "scanner": "scanner-primary", "fingerprint": "649990f9c6f33185", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42310"]}}, {"ruleId": "scanner-f9c83181e1630a86", "level": "warning", "message": {"text": "CVE-2026-55798: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "fd4cda7c5897a334", "scanner": "scanner-primary", "fingerprint": "f9c83181e1630a86", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55798"]}}, {"ruleId": "scanner-4677c9e613c253bb", "level": "warning", "message": {"text": "CVE-2026-59198: pillow 11.2.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "3b9db6a8edefe4a2", "scanner": "scanner-primary", "fingerprint": "4677c9e613c253bb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59198"]}}, {"ruleId": "scanner-93902e96288aec4a", "level": "error", "message": {"text": "CVE-2025-4565: protobuf 6.30.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "171ed684bed18477", "scanner": "scanner-primary", "fingerprint": "93902e96288aec4a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-4565"]}}, {"ruleId": "scanner-89241c57518bf84c", "level": "error", "message": {"text": "CVE-2026-0994: protobuf 6.30.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "82d6f98b2b79f0d6", "scanner": "scanner-primary", "fingerprint": "89241c57518bf84c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-0994"]}}, {"ruleId": "scanner-af033e6895a0c43d", "level": "error", "message": {"text": "CVE-2026-23490: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "858e247cb1554a39", "scanner": "scanner-primary", "fingerprint": "af033e6895a0c43d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-23490"]}}, {"ruleId": "scanner-42e80a6aa75f6458", "level": "error", "message": {"text": "CVE-2026-30922: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "734e966c9f08ba1d", "scanner": "scanner-primary", "fingerprint": "42e80a6aa75f6458", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-30922"]}}, {"ruleId": "scanner-cdd8852fb0fa8505", "level": "error", "message": {"text": "CVE-2026-59885: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "e8637c9838637f38", "scanner": "scanner-primary", "fingerprint": "cdd8852fb0fa8505", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59885"]}}, {"ruleId": "scanner-68aa894255d14e88", "level": "error", "message": {"text": "CVE-2026-59886: pyasn1 0.6.1 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "642095ca9ec59454", "scanner": "scanner-primary", "fingerprint": "68aa894255d14e88", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59886"]}}, {"ruleId": "scanner-e49a0640168722d8", "level": "warning", "message": {"text": "CVE-2026-28684: python-dotenv 1.1.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "01d6c91c18e4b20b", "scanner": "scanner-primary", "fingerprint": "e49a0640168722d8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28684"]}}, {"ruleId": "scanner-9c0e85a77fc11b6d", "level": "error", "message": {"text": "CVE-2026-24486: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "ba3cd40e071c203e", "scanner": "scanner-primary", "fingerprint": "9c0e85a77fc11b6d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24486"]}}, {"ruleId": "scanner-28b005542446d4bd", "level": "error", "message": {"text": "CVE-2026-42561: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "4d58c4dfb412c9f0", "scanner": "scanner-primary", "fingerprint": "28b005542446d4bd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42561"]}}, {"ruleId": "scanner-ab30ae632c5554bf", "level": "error", "message": {"text": "CVE-2026-53539: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "09b7e2c893cae79a", "scanner": "scanner-primary", "fingerprint": "ab30ae632c5554bf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53539"]}}, {"ruleId": "scanner-e14d3deacd4cc3a3", "level": "warning", "message": {"text": "CVE-2026-40347: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "3fc378197a63c59a", "scanner": "scanner-primary", "fingerprint": "e14d3deacd4cc3a3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40347"]}}, {"ruleId": "scanner-45b455ce1f3b8347", "level": "note", "message": {"text": "CVE-2026-53537: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "efc779f9d8864f9a", "scanner": "scanner-primary", "fingerprint": "45b455ce1f3b8347", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53537"]}}, {"ruleId": "scanner-610dc7a83341787b", "level": "note", "message": {"text": "CVE-2026-53538: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "8d2591cda566e0ff", "scanner": "scanner-primary", "fingerprint": "610dc7a83341787b", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53538"]}}, {"ruleId": "scanner-ce5852c9e8b9b53b", "level": "note", "message": {"text": "CVE-2026-53540: python-multipart 0.0.20 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "d9680bc9b6da0108", "scanner": "scanner-primary", "fingerprint": "ce5852c9e8b9b53b", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53540"]}}, {"ruleId": "scanner-c4668254ddf73039", "level": "warning", "message": {"text": "CVE-2024-47081: requests 2.32.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "8cf058316e2cf982", "scanner": "scanner-primary", "fingerprint": "c4668254ddf73039", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-47081"]}}, {"ruleId": "scanner-f17acefc3e1037a1", "level": "warning", "message": {"text": "CVE-2026-25645: requests 2.32.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "d7e06f23b381e7ae", "scanner": "scanner-primary", "fingerprint": "f17acefc3e1037a1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25645"]}}, {"ruleId": "scanner-e03f26eecc749785", "level": "error", "message": {"text": "CVE-2026-49476: soupsieve 2.6 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "231b7a0f2cca6c9b", "scanner": "scanner-primary", "fingerprint": "e03f26eecc749785", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49476"]}}, {"ruleId": "scanner-f9319b5a1ff37e78", "level": "error", "message": {"text": "CVE-2026-49477: soupsieve 2.6 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "8587112bca3c28b2", "scanner": "scanner-primary", "fingerprint": "f9319b5a1ff37e78", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49477"]}}, {"ruleId": "scanner-821c4be6c60ebb65", "level": "error", "message": {"text": "CVE-2025-62727: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "b21b8d8056007bf5", "scanner": "scanner-primary", "fingerprint": "821c4be6c60ebb65", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-62727"]}}, {"ruleId": "scanner-5e7f3c744eb57071", "level": "error", "message": {"text": "CVE-2026-48818: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "82fcbe06835a9a46", "scanner": "scanner-primary", "fingerprint": "5e7f3c744eb57071", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48818"]}}, {"ruleId": "scanner-e7453059c6f53505", "level": "error", "message": {"text": "CVE-2026-54283: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "e78ddd3a5ac9f59c", "scanner": "scanner-primary", "fingerprint": "e7453059c6f53505", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54283"]}}, {"ruleId": "scanner-711590fc06028dfc", "level": "warning", "message": {"text": "CVE-2025-54121: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "23e33776211c6da6", "scanner": "scanner-primary", "fingerprint": "711590fc06028dfc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-54121"]}}, {"ruleId": "scanner-6835ee5d538db915", "level": "warning", "message": {"text": "CVE-2026-48710: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "9901ae3235572e2a", "scanner": "scanner-primary", "fingerprint": "6835ee5d538db915", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48710"]}}, {"ruleId": "scanner-97459d2b0f6f6f21", "level": "warning", "message": {"text": "CVE-2026-48817: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "7447147970aea276", "scanner": "scanner-primary", "fingerprint": "97459d2b0f6f6f21", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48817"]}}, {"ruleId": "scanner-85aecfbd41ece92b", "level": "note", "message": {"text": "CVE-2026-54282: starlette 0.46.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "39d3b95a418aeaaa", "scanner": "scanner-primary", "fingerprint": "85aecfbd41ece92b", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54282"]}}, {"ruleId": "scanner-1f75384419f6763a", "level": "error", "message": {"text": "CVE-2025-32434: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "aedf8486541196ae", "scanner": "scanner-primary", "fingerprint": "1f75384419f6763a", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-32434"]}}, {"ruleId": "scanner-64e337c1a58db837", "level": "warning", "message": {"text": "CVE-2025-2998: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "61a694f68e59412b", "scanner": "scanner-primary", "fingerprint": "64e337c1a58db837", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-2998"]}}, {"ruleId": "scanner-a020b8d7c9c71073", "level": "warning", "message": {"text": "CVE-2025-2999: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "78bdfdf441a92b12", "scanner": "scanner-primary", "fingerprint": "a020b8d7c9c71073", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-2999"]}}, {"ruleId": "scanner-2991a51995372545", "level": "warning", "message": {"text": "CVE-2025-3730: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "b6156ec277411f96", "scanner": "scanner-primary", "fingerprint": "2991a51995372545", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3730"]}}, {"ruleId": "scanner-4651de99293353ba", "level": "note", "message": {"text": "CVE-2025-2148: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "7d477d3da92a5ee7", "scanner": "scanner-primary", "fingerprint": "4651de99293353ba", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-2148"]}}, {"ruleId": "scanner-b561637a9fe3c34a", "level": "note", "message": {"text": "CVE-2025-2149: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "21c35de060425dea", "scanner": "scanner-primary", "fingerprint": "b561637a9fe3c34a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-2149"]}}, {"ruleId": "scanner-536e958df6ece688", "level": "note", "message": {"text": "CVE-2025-2953: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "73d24bc5ce5f90a3", "scanner": "scanner-primary", "fingerprint": "536e958df6ece688", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-2953"]}}, {"ruleId": "scanner-dca48a65041f20e0", "level": "note", "message": {"text": "CVE-2025-3000: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "eb05e55731bdbb05", "scanner": "scanner-primary", "fingerprint": "dca48a65041f20e0", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3000"]}}, {"ruleId": "scanner-b7bdc2d4715e0f9e", "level": "note", "message": {"text": "CVE-2025-3001: torch 2.2.2 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "ca58cbdf7a683a22", "scanner": "scanner-primary", "fingerprint": "b7bdc2d4715e0f9e", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3001"]}}, {"ruleId": "scanner-649040017770a165", "level": "error", "message": {"text": "CVE-2026-4372: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "6075400e78772f97", "scanner": "scanner-primary", "fingerprint": "649040017770a165", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4372"]}}, {"ruleId": "scanner-e170dccdbfa32a27", "level": "error", "message": {"text": "CVE-2026-5241: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "2ebaa953d95b7a79", "scanner": "scanner-primary", "fingerprint": "e170dccdbfa32a27", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-5241"]}}, {"ruleId": "scanner-6a669b0ffe380ff0", "level": "warning", "message": {"text": "CVE-2025-3933: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "c29e8f9d94c5423b", "scanner": "scanner-primary", "fingerprint": "6a669b0ffe380ff0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3933"]}}, {"ruleId": "scanner-082df0a7738030b4", "level": "warning", "message": {"text": "CVE-2025-5197: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "1bb51bb4712cdce0", "scanner": "scanner-primary", "fingerprint": "082df0a7738030b4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-5197"]}}, {"ruleId": "scanner-12759909e7b13e13", "level": "warning", "message": {"text": "CVE-2025-6051: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "4e3ca382d1e39df9", "scanner": "scanner-primary", "fingerprint": "12759909e7b13e13", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6051"]}}, {"ruleId": "scanner-42b16f7009057df9", "level": "warning", "message": {"text": "CVE-2025-6638: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "907b3952238c011b", "scanner": "scanner-primary", "fingerprint": "42b16f7009057df9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6638"]}}, {"ruleId": "scanner-d2192c9bbd6366d8", "level": "warning", "message": {"text": "CVE-2025-6921: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "b1027407c8f44598", "scanner": "scanner-primary", "fingerprint": "d2192c9bbd6366d8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6921"]}}, {"ruleId": "scanner-513576f3f83ee355", "level": "warning", "message": {"text": "CVE-2026-1839: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "baa9e751eb10c705", "scanner": "scanner-primary", "fingerprint": "513576f3f83ee355", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-1839"]}}, {"ruleId": "scanner-dfb0688847655c9f", "level": "note", "message": {"text": "CVE-2025-3777: transformers 4.51.3 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "809f90c0afe8de9b", "scanner": "scanner-primary", "fingerprint": "dfb0688847655c9f", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3777"]}}, {"ruleId": "scanner-bdff4c39aa7b542e", "level": "error", "message": {"text": "CVE-2025-66418: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "17fd2c7feed110ac", "scanner": "scanner-primary", "fingerprint": "bdff4c39aa7b542e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66418"]}}, {"ruleId": "scanner-772dea63be5596f6", "level": "error", "message": {"text": "CVE-2025-66471: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "0d7c2738fdaf4000", "scanner": "scanner-primary", "fingerprint": "772dea63be5596f6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66471"]}}, {"ruleId": "scanner-0f06340f58aad3a1", "level": "error", "message": {"text": "CVE-2026-21441: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "f8c5cdafcea77ed6", "scanner": "scanner-primary", "fingerprint": "0f06340f58aad3a1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-21441"]}}, {"ruleId": "scanner-6434fcc50febe87d", "level": "error", "message": {"text": "CVE-2026-44431: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "e43099dbee4ca41e", "scanner": "scanner-primary", "fingerprint": "6434fcc50febe87d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44431"]}}, {"ruleId": "scanner-a00e0cf02c59cec1", "level": "warning", "message": {"text": "CVE-2025-50181: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "feaca772603ac9b0", "scanner": "scanner-primary", "fingerprint": "a00e0cf02c59cec1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-50181"]}}, {"ruleId": "scanner-f284203f7489f65d", "level": "warning", "message": {"text": "CVE-2025-50182: urllib3 2.4.0 \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "properties": {"repobilityId": "94e9752dfc78011e", "scanner": "scanner-primary", "fingerprint": "f284203f7489f65d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-50182"]}}, {"ruleId": "scanner-220df06f1f5f55d2", "level": "error", "message": {"text": "CVE-2026-31240: mem0ai 0.1.29 \u2014 advanced_ai_agents/single_agent_apps/ai_customer_support_agent/requirements.txt"}, "properties": {"repobilityId": "03c92afe04874894", "scanner": "scanner-primary", "fingerprint": "220df06f1f5f55d2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31240"]}}, {"ruleId": "scanner-0fc46f49469983ac", "level": "warning", "message": {"text": "CVE-2026-31241: mem0ai 0.1.29 \u2014 advanced_ai_agents/single_agent_apps/ai_customer_support_agent/requirements.txt"}, "properties": {"repobilityId": "345f157e6aec5ef9", "scanner": "scanner-primary", "fingerprint": "0fc46f49469983ac", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31241"]}}, {"ruleId": "scanner-c18f61ca17f45f1a", "level": "warning", "message": {"text": "CVE-2026-31245: mem0ai 0.1.29 \u2014 advanced_ai_agents/single_agent_apps/ai_customer_support_agent/requirements.txt"}, "properties": {"repobilityId": "439d536eb2222402", "scanner": "scanner-primary", "fingerprint": "c18f61ca17f45f1a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31245"]}}, {"ruleId": "scanner-f875124eb8b678b9", "level": "note", "message": {"text": "CVE-2026-7597: mem0ai 0.1.29 \u2014 advanced_ai_agents/single_agent_apps/ai_customer_support_agent/requirements.txt"}, "properties": {"repobilityId": "91d71ec66f7d8f23", "scanner": "scanner-primary", "fingerprint": "f875124eb8b678b9", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-7597"]}}, {"ruleId": "scanner-d836defd2af2f7bc", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.40.2 \u2014 advanced_ai_agents/single_agent_apps/ai_health_fitness_agent/requirements.txt"}, "properties": {"repobilityId": "0d9828ac0de690fc", "scanner": "scanner-primary", "fingerprint": "d836defd2af2f7bc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-18ffb810d8d50efb", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.40.2 \u2014 advanced_ai_agents/single_agent_apps/ai_health_fitness_agent/requirements.txt"}, "properties": {"repobilityId": "047aed85a34b0b9c", "scanner": "scanner-primary", "fingerprint": "18ffb810d8d50efb", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-9402e870d5e74334", "level": "error", "message": {"text": "CVE-2025-69223: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "b41747601d9585da", "scanner": "scanner-primary", "fingerprint": "9402e870d5e74334", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69223"]}}, {"ruleId": "scanner-6b46b3d9dad5ea81", "level": "warning", "message": {"text": "CVE-2025-69227: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "963680f79a378d03", "scanner": "scanner-primary", "fingerprint": "6b46b3d9dad5ea81", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69227"]}}, {"ruleId": "scanner-721b9ec9c985a7a0", "level": "warning", "message": {"text": "CVE-2025-69228: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "1ac6c7b92dc41adb", "scanner": "scanner-primary", "fingerprint": "721b9ec9c985a7a0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69228"]}}, {"ruleId": "scanner-79675ef3e3ba56ca", "level": "warning", "message": {"text": "CVE-2025-69229: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "549f765aff4f714f", "scanner": "scanner-primary", "fingerprint": "79675ef3e3ba56ca", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69229"]}}, {"ruleId": "scanner-6143d9b12ae4358b", "level": "warning", "message": {"text": "CVE-2026-22815: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "2e17ac666065d97e", "scanner": "scanner-primary", "fingerprint": "6143d9b12ae4358b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-22815"]}}, {"ruleId": "scanner-ac8d00b0f7c992b9", "level": "warning", "message": {"text": "CVE-2026-34515: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "7de7fa73d4386c60", "scanner": "scanner-primary", "fingerprint": "ac8d00b0f7c992b9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34515"]}}, {"ruleId": "scanner-5bf48de2f19823ff", "level": "warning", "message": {"text": "CVE-2026-34516: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "175ade5a73a682f4", "scanner": "scanner-primary", "fingerprint": "5bf48de2f19823ff", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34516"]}}, {"ruleId": "scanner-76178d4410c48ffd", "level": "warning", "message": {"text": "CVE-2026-34525: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "d6aabcc5d6f5fca0", "scanner": "scanner-primary", "fingerprint": "76178d4410c48ffd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34525"]}}, {"ruleId": "scanner-6fb848581cc81d47", "level": "warning", "message": {"text": "CVE-2026-34993: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "9dd581571d4be01f", "scanner": "scanner-primary", "fingerprint": "6fb848581cc81d47", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34993"]}}, {"ruleId": "scanner-dcc1adac586e1f06", "level": "warning", "message": {"text": "CVE-2026-47265: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "baad4bcf543fdc62", "scanner": "scanner-primary", "fingerprint": "dcc1adac586e1f06", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47265"]}}, {"ruleId": "scanner-19ad3dcb4dffcf1f", "level": "warning", "message": {"text": "CVE-2026-54273: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "b0dc75f54d7a31ae", "scanner": "scanner-primary", "fingerprint": "19ad3dcb4dffcf1f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54273"]}}, {"ruleId": "scanner-8a3dfed1576ddea2", "level": "warning", "message": {"text": "CVE-2026-54274: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "09fea5879033fa17", "scanner": "scanner-primary", "fingerprint": "8a3dfed1576ddea2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54274"]}}, {"ruleId": "scanner-01ca8a221f18161e", "level": "warning", "message": {"text": "CVE-2026-54276: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "a67bb99673375531", "scanner": "scanner-primary", "fingerprint": "01ca8a221f18161e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54276"]}}, {"ruleId": "scanner-32951b353791b75b", "level": "warning", "message": {"text": "CVE-2026-54277: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "3317bdcbb08c7d5a", "scanner": "scanner-primary", "fingerprint": "32951b353791b75b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54277"]}}, {"ruleId": "scanner-7f7bf5da41847c4d", "level": "warning", "message": {"text": "CVE-2026-54278: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "38ed459584dda591", "scanner": "scanner-primary", "fingerprint": "7f7bf5da41847c4d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54278"]}}, {"ruleId": "scanner-89dbe9e452890258", "level": "note", "message": {"text": "CVE-2025-53643: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "56f842d36690415c", "scanner": "scanner-primary", "fingerprint": "89dbe9e452890258", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-53643"]}}, {"ruleId": "scanner-02fe326588dbcab2", "level": "note", "message": {"text": "CVE-2025-69224: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "96d7253afcfeb972", "scanner": "scanner-primary", "fingerprint": "02fe326588dbcab2", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69224"]}}, {"ruleId": "scanner-6ad504bbd8dc3fe2", "level": "note", "message": {"text": "CVE-2025-69225: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "38e481e3aeb149e1", "scanner": "scanner-primary", "fingerprint": "6ad504bbd8dc3fe2", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69225"]}}, {"ruleId": "scanner-88024ffbdd99c6ea", "level": "note", "message": {"text": "CVE-2025-69226: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "7fba2df1ca91ed1d", "scanner": "scanner-primary", "fingerprint": "88024ffbdd99c6ea", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69226"]}}, {"ruleId": "scanner-d0f127913e262833", "level": "note", "message": {"text": "CVE-2025-69230: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "3b46d6563540faa5", "scanner": "scanner-primary", "fingerprint": "d0f127913e262833", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69230"]}}, {"ruleId": "scanner-c2d3c9f07a15a300", "level": "note", "message": {"text": "CVE-2026-34513: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "6f3faf069feeb3d9", "scanner": "scanner-primary", "fingerprint": "c2d3c9f07a15a300", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34513"]}}, {"ruleId": "scanner-2680dc97791c616a", "level": "note", "message": {"text": "CVE-2026-34514: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "9211fe6532a6e969", "scanner": "scanner-primary", "fingerprint": "2680dc97791c616a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34514"]}}, {"ruleId": "scanner-5b15888a9122125a", "level": "note", "message": {"text": "CVE-2026-34517: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "8abcd2a4f83b3b63", "scanner": "scanner-primary", "fingerprint": "5b15888a9122125a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34517"]}}, {"ruleId": "scanner-b0ad098edb08a39b", "level": "note", "message": {"text": "CVE-2026-34518: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "62b67fa0a5eb9e0f", "scanner": "scanner-primary", "fingerprint": "b0ad098edb08a39b", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34518"]}}, {"ruleId": "scanner-8eb981584f93a3c7", "level": "note", "message": {"text": "CVE-2026-34519: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "cf04bb81965c94db", "scanner": "scanner-primary", "fingerprint": "8eb981584f93a3c7", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34519"]}}, {"ruleId": "scanner-894e65a41d29c69c", "level": "note", "message": {"text": "CVE-2026-34520: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "c6f099de4be7bb3d", "scanner": "scanner-primary", "fingerprint": "894e65a41d29c69c", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34520"]}}, {"ruleId": "scanner-c720d8ac9ffb0575", "level": "note", "message": {"text": "CVE-2026-50269: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "7caaaaebdd2998e5", "scanner": "scanner-primary", "fingerprint": "c720d8ac9ffb0575", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-50269"]}}, {"ruleId": "scanner-04cbf53ec8088abb", "level": "note", "message": {"text": "CVE-2026-54275: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "57db1270cda7a447", "scanner": "scanner-primary", "fingerprint": "04cbf53ec8088abb", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54275"]}}, {"ruleId": "scanner-4dc122be14f7a7d1", "level": "note", "message": {"text": "CVE-2026-54279: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "7ef6658f7ce0107c", "scanner": "scanner-primary", "fingerprint": "4dc122be14f7a7d1", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54279"]}}, {"ruleId": "scanner-8ebc54ed8ee364e9", "level": "note", "message": {"text": "CVE-2026-54280: aiohttp 3.12.12 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "ba0be9666a0c66f4", "scanner": "scanner-primary", "fingerprint": "8ebc54ed8ee364e9", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54280"]}}, {"ruleId": "scanner-d651449de50155a7", "level": "error", "message": {"text": "CVE-2026-26007: cryptography 45.0.4 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "bdb73e47041281bc", "scanner": "scanner-primary", "fingerprint": "d651449de50155a7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26007"]}}, {"ruleId": "scanner-aa8f829f9e66893b", "level": "error", "message": {"text": "GHSA-537c-gmf6-5ccf: cryptography 45.0.4 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "efbb17afba915fb7", "scanner": "scanner-primary", "fingerprint": "aa8f829f9e66893b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-537c-gmf6-5ccf"]}}, {"ruleId": "scanner-c2afdcbc969914e0", "level": "warning", "message": {"text": "CVE-2026-39892: cryptography 45.0.4 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "23b223be822d481c", "scanner": "scanner-primary", "fingerprint": "c2afdcbc969914e0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39892"]}}, {"ruleId": "scanner-99d7b61abe628114", "level": "note", "message": {"text": "CVE-2026-34073: cryptography 45.0.4 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "b3f10f62233a9457", "scanner": "scanner-primary", "fingerprint": "99d7b61abe628114", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34073"]}}, {"ruleId": "scanner-e1e181c18fecc0a2", "level": "warning", "message": {"text": "CVE-2026-45409: idna 3.10 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "a83a9baa1b08cda6", "scanner": "scanner-primary", "fingerprint": "e1e181c18fecc0a2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45409"]}}, {"ruleId": "scanner-ac30b86e638211f4", "level": "error", "message": {"text": "CVE-2026-45134: langchain 0.3.25 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "e5976fcd2ed5029a", "scanner": "scanner-primary", "fingerprint": "ac30b86e638211f4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45134"]}}, {"ruleId": "scanner-9378ef0c5295354b", "level": "warning", "message": {"text": "CVE-2026-55443: langchain 0.3.25 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "57df6dfb3e2c309f", "scanner": "scanner-primary", "fingerprint": "9378ef0c5295354b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55443"]}}, {"ruleId": "scanner-e6d90b73c3797332", "level": "error", "message": {"text": "CVE-2025-6984: langchain-community 0.3.25 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "8863f68485a4b535", "scanner": "scanner-primary", "fingerprint": "e6d90b73c3797332", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6984"]}}, {"ruleId": "scanner-eac6b982f5ae6b5b", "level": "error", "message": {"text": "CVE-2025-68664: langchain-core 0.3.65 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "6357f899b5f1a010", "scanner": "scanner-primary", "fingerprint": "eac6b982f5ae6b5b", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-68664"]}}, {"ruleId": "scanner-f1cb5aa94662b2f4", "level": "error", "message": {"text": "CVE-2025-65106: langchain-core 0.3.65 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "498f037e67015edd", "scanner": "scanner-primary", "fingerprint": "f1cb5aa94662b2f4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-65106"]}}, {"ruleId": "scanner-f70baea085964f2f", "level": "error", "message": {"text": "CVE-2026-34070: langchain-core 0.3.65 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "16df360ba3f76b9a", "scanner": "scanner-primary", "fingerprint": "f70baea085964f2f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34070"]}}, {"ruleId": "scanner-8de8ea4ce1c378a8", "level": "error", "message": {"text": "CVE-2026-44843: langchain-core 0.3.65 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "274dd184c84bacd8", "scanner": "scanner-primary", "fingerprint": "8de8ea4ce1c378a8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44843"]}}, {"ruleId": "scanner-17cd2a9d20bdd87d", "level": "warning", "message": {"text": "CVE-2026-40087: langchain-core 0.3.65 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "380325362b6213e5", "scanner": "scanner-primary", "fingerprint": "17cd2a9d20bdd87d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40087"]}}, {"ruleId": "scanner-43b1ccd08e3b2fcf", "level": "note", "message": {"text": "CVE-2026-26013: langchain-core 0.3.65 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "ce9fdafbfa9d04e0", "scanner": "scanner-primary", "fingerprint": "43b1ccd08e3b2fcf", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26013"]}}, {"ruleId": "scanner-e76a524cc2268dcd", "level": "error", "message": {"text": "CVE-2025-6985: langchain-text-splitters 0.3.8 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "f95f373630dcf201", "scanner": "scanner-primary", "fingerprint": "e76a524cc2268dcd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6985"]}}, {"ruleId": "scanner-535a1e18437ec0da", "level": "warning", "message": {"text": "CVE-2026-41481: langchain-text-splitters 0.3.8 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "45229974079a9345", "scanner": "scanner-primary", "fingerprint": "535a1e18437ec0da", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41481"]}}, {"ruleId": "scanner-f2b7a8513d8041ec", "level": "error", "message": {"text": "CVE-2026-45134: langsmith 0.3.45 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "950b2f83e3ea618c", "scanner": "scanner-primary", "fingerprint": "f2b7a8513d8041ec", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45134"]}}, {"ruleId": "scanner-d486ff8cd1c386a0", "level": "error", "message": {"text": "GHSA-f4xh-w4cj-qxq8: langsmith 0.3.45 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "5c888c7e55e3e935", "scanner": "scanner-primary", "fingerprint": "d486ff8cd1c386a0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f4xh-w4cj-qxq8"]}}, {"ruleId": "scanner-d2375bc96957e1db", "level": "warning", "message": {"text": "CVE-2026-41182: langsmith 0.3.45 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "b8c5ccd9db4721c0", "scanner": "scanner-primary", "fingerprint": "d2375bc96957e1db", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41182"]}}, {"ruleId": "scanner-a9bbb088e9fdd17e", "level": "warning", "message": {"text": "CVE-2025-68480: marshmallow 3.26.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "103e36431b27f4c0", "scanner": "scanner-primary", "fingerprint": "a9bbb088e9fdd17e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-68480"]}}, {"ruleId": "scanner-5284baa3d495782e", "level": "error", "message": {"text": "CVE-2025-67221: orjson 3.10.18 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "d55c15aad3170027", "scanner": "scanner-primary", "fingerprint": "5284baa3d495782e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-67221"]}}, {"ruleId": "scanner-16c67ceed08d35ac", "level": "error", "message": {"text": "CVE-2025-48379: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "5a78d0fe5f4ea36b", "scanner": "scanner-primary", "fingerprint": "16c67ceed08d35ac", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-48379"]}}, {"ruleId": "scanner-a07baf260297ac45", "level": "error", "message": {"text": "CVE-2026-25990: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "17cd0d645773fced", "scanner": "scanner-primary", "fingerprint": "a07baf260297ac45", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25990"]}}, {"ruleId": "scanner-64ca0fc86ede45ca", "level": "error", "message": {"text": "CVE-2026-40192: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "30fe46fc46ff3e43", "scanner": "scanner-primary", "fingerprint": "64ca0fc86ede45ca", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40192"]}}, {"ruleId": "scanner-f6cdf54be3efd7a1", "level": "error", "message": {"text": "CVE-2026-42311: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "38a0b52f7437c5fa", "scanner": "scanner-primary", "fingerprint": "f6cdf54be3efd7a1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42311"]}}, {"ruleId": "scanner-3e47c01a5018cb19", "level": "error", "message": {"text": "CVE-2026-54058: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "742dbb3ccd410a61", "scanner": "scanner-primary", "fingerprint": "3e47c01a5018cb19", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54058"]}}, {"ruleId": "scanner-c368e1deecd66025", "level": "error", "message": {"text": "CVE-2026-54059: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "3626b2c1c092cd06", "scanner": "scanner-primary", "fingerprint": "c368e1deecd66025", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54059"]}}, {"ruleId": "scanner-fdd258c512792d94", "level": "error", "message": {"text": "CVE-2026-54060: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "4db7394493b29d0b", "scanner": "scanner-primary", "fingerprint": "fdd258c512792d94", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54060"]}}, {"ruleId": "scanner-05baca043731dbf8", "level": "error", "message": {"text": "CVE-2026-55379: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "bdf9ab5c786b5bf4", "scanner": "scanner-primary", "fingerprint": "05baca043731dbf8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55379"]}}, {"ruleId": "scanner-23d1a94f2aeda7f7", "level": "error", "message": {"text": "CVE-2026-55380: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "c915b8923e00304c", "scanner": "scanner-primary", "fingerprint": "23d1a94f2aeda7f7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55380"]}}, {"ruleId": "scanner-0365e8b39bd5cc6a", "level": "error", "message": {"text": "CVE-2026-59197: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "264d1997c0b2e1cf", "scanner": "scanner-primary", "fingerprint": "0365e8b39bd5cc6a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59197"]}}, {"ruleId": "scanner-5e37fb82a7ef5936", "level": "error", "message": {"text": "CVE-2026-59199: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "5be5663a663777b6", "scanner": "scanner-primary", "fingerprint": "5e37fb82a7ef5936", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59199"]}}, {"ruleId": "scanner-7ed704b482d1e181", "level": "error", "message": {"text": "CVE-2026-59200: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "900251307c0dd5da", "scanner": "scanner-primary", "fingerprint": "7ed704b482d1e181", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59200"]}}, {"ruleId": "scanner-8b5c300e3ae1a5a8", "level": "error", "message": {"text": "CVE-2026-59204: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "243d4fbf8d8b34ea", "scanner": "scanner-primary", "fingerprint": "8b5c300e3ae1a5a8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59204"]}}, {"ruleId": "scanner-87c30b9be5567f61", "level": "error", "message": {"text": "CVE-2026-59205: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "20d5ba917c8a159f", "scanner": "scanner-primary", "fingerprint": "87c30b9be5567f61", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59205"]}}, {"ruleId": "scanner-ddc10cba293f1e6b", "level": "warning", "message": {"text": "CVE-2026-42308: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "7df754f7a25a1d1d", "scanner": "scanner-primary", "fingerprint": "ddc10cba293f1e6b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42308"]}}, {"ruleId": "scanner-7ac8fc2a5be28ba2", "level": "warning", "message": {"text": "CVE-2026-42309: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "6184a295ef9fd71f", "scanner": "scanner-primary", "fingerprint": "7ac8fc2a5be28ba2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42309"]}}, {"ruleId": "scanner-7380f6239aab4e47", "level": "warning", "message": {"text": "CVE-2026-42310: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "1a63c7ea221b9f92", "scanner": "scanner-primary", "fingerprint": "7380f6239aab4e47", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42310"]}}, {"ruleId": "scanner-503866edce928c6a", "level": "warning", "message": {"text": "CVE-2026-55798: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "69d77b056e70cc44", "scanner": "scanner-primary", "fingerprint": "503866edce928c6a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55798"]}}, {"ruleId": "scanner-495281d30896d68d", "level": "warning", "message": {"text": "CVE-2026-59198: pillow 11.2.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "fc36cef3587147d3", "scanner": "scanner-primary", "fingerprint": "495281d30896d68d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59198"]}}, {"ruleId": "scanner-df797bd94c0bf972", "level": "note", "message": {"text": "CVE-2026-4539: pygments 2.19.1 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "9ced7483328b4bc7", "scanner": "scanner-primary", "fingerprint": "df797bd94c0bf972", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4539"]}}, {"ruleId": "scanner-7e36590035d25b51", "level": "warning", "message": {"text": "CVE-2026-28684: python-dotenv 1.1.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "d09c682788bf3c49", "scanner": "scanner-primary", "fingerprint": "7e36590035d25b51", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28684"]}}, {"ruleId": "scanner-7a86375de4b92d43", "level": "warning", "message": {"text": "CVE-2026-25645: requests 2.32.4 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "bcbd1936d79707e9", "scanner": "scanner-primary", "fingerprint": "7a86375de4b92d43", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25645"]}}, {"ruleId": "scanner-bd293b9b52b8a62c", "level": "warning", "message": {"text": "CVE-2026-59890: setuptools 80.9.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "6eac897314c173f1", "scanner": "scanner-primary", "fingerprint": "bd293b9b52b8a62c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59890"]}}, {"ruleId": "scanner-ed3705571cce3614", "level": "error", "message": {"text": "CVE-2026-49476: soupsieve 2.7 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "c13d00bda04b8d33", "scanner": "scanner-primary", "fingerprint": "ed3705571cce3614", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49476"]}}, {"ruleId": "scanner-3bab062028ca0037", "level": "error", "message": {"text": "CVE-2026-49477: soupsieve 2.7 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "2f7678a0a368f9cf", "scanner": "scanner-primary", "fingerprint": "3bab062028ca0037", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49477"]}}, {"ruleId": "scanner-4f09e3ee8884d88e", "level": "error", "message": {"text": "CVE-2025-66418: urllib3 2.4.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "1586217308ee6f16", "scanner": "scanner-primary", "fingerprint": "4f09e3ee8884d88e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66418"]}}, {"ruleId": "scanner-5bb7f365e03e551e", "level": "error", "message": {"text": "CVE-2025-66471: urllib3 2.4.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "81965ff7c4e7e248", "scanner": "scanner-primary", "fingerprint": "5bb7f365e03e551e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66471"]}}, {"ruleId": "scanner-0f4cdbf73f988dcf", "level": "error", "message": {"text": "CVE-2026-21441: urllib3 2.4.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "05f9f10b31df2c73", "scanner": "scanner-primary", "fingerprint": "0f4cdbf73f988dcf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-21441"]}}, {"ruleId": "scanner-d06c67096bfd994d", "level": "error", "message": {"text": "CVE-2026-44431: urllib3 2.4.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "32cd57e385374813", "scanner": "scanner-primary", "fingerprint": "d06c67096bfd994d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44431"]}}, {"ruleId": "scanner-cb626db39eb36222", "level": "warning", "message": {"text": "CVE-2025-50181: urllib3 2.4.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "4f006a4ea7fc9a1d", "scanner": "scanner-primary", "fingerprint": "cb626db39eb36222", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-50181"]}}, {"ruleId": "scanner-accc4e9114812943", "level": "warning", "message": {"text": "CVE-2025-50182: urllib3 2.4.0 \u2014 advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "properties": {"repobilityId": "e0411821908c5e5a", "scanner": "scanner-primary", "fingerprint": "accc4e9114812943", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-50182"]}}, {"ruleId": "scanner-2b556dbe3f0fc26f", "level": "error", "message": {"text": "CVE-2026-31240: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/ai_travel_agent_memory/requirements.txt"}, "properties": {"repobilityId": "e52b7d02f1bc7a6e", "scanner": "scanner-primary", "fingerprint": "2b556dbe3f0fc26f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31240"]}}, {"ruleId": "scanner-4c0b0e7228dae96e", "level": "warning", "message": {"text": "CVE-2026-31241: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/ai_travel_agent_memory/requirements.txt"}, "properties": {"repobilityId": "d300ef9ffca13da1", "scanner": "scanner-primary", "fingerprint": "4c0b0e7228dae96e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31241"]}}, {"ruleId": "scanner-8436f2c64e092e75", "level": "warning", "message": {"text": "CVE-2026-31245: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/ai_travel_agent_memory/requirements.txt"}, "properties": {"repobilityId": "92ee39dbb7514a3f", "scanner": "scanner-primary", "fingerprint": "8436f2c64e092e75", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31245"]}}, {"ruleId": "scanner-72503a3e0b2c6082", "level": "note", "message": {"text": "CVE-2026-7597: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/ai_travel_agent_memory/requirements.txt"}, "properties": {"repobilityId": "0d0290f0deafee9f", "scanner": "scanner-primary", "fingerprint": "72503a3e0b2c6082", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-7597"]}}, {"ruleId": "scanner-f8f7396dd61efb02", "level": "error", "message": {"text": "CVE-2026-31240: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/llm_app_personalized_memory/requirements.txt"}, "properties": {"repobilityId": "e6b5d73705f976ec", "scanner": "scanner-primary", "fingerprint": "f8f7396dd61efb02", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31240"]}}, {"ruleId": "scanner-e4073c9a19474c2b", "level": "warning", "message": {"text": "CVE-2026-31241: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/llm_app_personalized_memory/requirements.txt"}, "properties": {"repobilityId": "4e863b18a47f2fe5", "scanner": "scanner-primary", "fingerprint": "e4073c9a19474c2b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31241"]}}, {"ruleId": "scanner-5080deef6205b91b", "level": "warning", "message": {"text": "CVE-2026-31245: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/llm_app_personalized_memory/requirements.txt"}, "properties": {"repobilityId": "afd158c58b5cb17f", "scanner": "scanner-primary", "fingerprint": "5080deef6205b91b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31245"]}}, {"ruleId": "scanner-17fad5649a68d9e4", "level": "note", "message": {"text": "CVE-2026-7597: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/llm_app_personalized_memory/requirements.txt"}, "properties": {"repobilityId": "f989648d05f2e0b1", "scanner": "scanner-primary", "fingerprint": "17fad5649a68d9e4", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-7597"]}}, {"ruleId": "scanner-23811568eae1ff0f", "level": "error", "message": {"text": "CVE-2026-31240: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/local_chatgpt_with_memory/requirements.txt"}, "properties": {"repobilityId": "c1eeea671000deae", "scanner": "scanner-primary", "fingerprint": "23811568eae1ff0f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31240"]}}, {"ruleId": "scanner-17ae306f9a6c1945", "level": "warning", "message": {"text": "CVE-2026-31241: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/local_chatgpt_with_memory/requirements.txt"}, "properties": {"repobilityId": "bb343d15aca041df", "scanner": "scanner-primary", "fingerprint": "17ae306f9a6c1945", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31241"]}}, {"ruleId": "scanner-8345a2494a24f7cd", "level": "warning", "message": {"text": "CVE-2026-31245: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/local_chatgpt_with_memory/requirements.txt"}, "properties": {"repobilityId": "58be54fb8c536671", "scanner": "scanner-primary", "fingerprint": "8345a2494a24f7cd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31245"]}}, {"ruleId": "scanner-8d6751bfe8d8e6ac", "level": "note", "message": {"text": "CVE-2026-7597: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/local_chatgpt_with_memory/requirements.txt"}, "properties": {"repobilityId": "467bde86f6be502f", "scanner": "scanner-primary", "fingerprint": "8d6751bfe8d8e6ac", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-7597"]}}, {"ruleId": "scanner-2e1076f99c8eeddf", "level": "error", "message": {"text": "CVE-2026-31240: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/multi_llm_memory/requirements.txt"}, "properties": {"repobilityId": "11941b095793196a", "scanner": "scanner-primary", "fingerprint": "2e1076f99c8eeddf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31240"]}}, {"ruleId": "scanner-9d05b952d35b47f4", "level": "warning", "message": {"text": "CVE-2026-31241: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/multi_llm_memory/requirements.txt"}, "properties": {"repobilityId": "e35a78b4016b6ffe", "scanner": "scanner-primary", "fingerprint": "9d05b952d35b47f4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31241"]}}, {"ruleId": "scanner-c2445bae45c78221", "level": "warning", "message": {"text": "CVE-2026-31245: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/multi_llm_memory/requirements.txt"}, "properties": {"repobilityId": "9ebf332128064884", "scanner": "scanner-primary", "fingerprint": "c2445bae45c78221", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31245"]}}, {"ruleId": "scanner-11e3f118ba82d34f", "level": "note", "message": {"text": "CVE-2026-7597: mem0ai 0.1.29 \u2014 advanced_llm_apps/llm_apps_with_memory_tutorials/multi_llm_memory/requirements.txt"}, "properties": {"repobilityId": "c286600005782704", "scanner": "scanner-primary", "fingerprint": "11e3f118ba82d34f", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-7597"]}}, {"ruleId": "scanner-8a11f90440ae2bbe", "level": "error", "message": {"text": "CVE-2026-44573: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "5c5f54393dc1ffb1", "scanner": "scanner-primary", "fingerprint": "8a11f90440ae2bbe", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44573"]}}, {"ruleId": "scanner-864c94e0c162973c", "level": "error", "message": {"text": "CVE-2026-44574: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "39baf0f8b7dd9a82", "scanner": "scanner-primary", "fingerprint": "864c94e0c162973c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44574"]}}, {"ruleId": "scanner-23e834cb601b197d", "level": "error", "message": {"text": "CVE-2026-44575: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "290de135685adc06", "scanner": "scanner-primary", "fingerprint": "23e834cb601b197d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44575"]}}, {"ruleId": "scanner-e6a68be8af210ae1", "level": "error", "message": {"text": "CVE-2026-44578: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "431e7888d96a7d9b", "scanner": "scanner-primary", "fingerprint": "e6a68be8af210ae1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44578"]}}, {"ruleId": "scanner-da6bfa426e1d4c24", "level": "error", "message": {"text": "CVE-2026-44579: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "8e9e859789056d2a", "scanner": "scanner-primary", "fingerprint": "da6bfa426e1d4c24", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44579"]}}, {"ruleId": "scanner-5d357be8a71a3aa8", "level": "error", "message": {"text": "CVE-2026-45109: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "0eca38fb9dd5be09", "scanner": "scanner-primary", "fingerprint": "5d357be8a71a3aa8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45109"]}}, {"ruleId": "scanner-28dc9e364afe957f", "level": "error", "message": {"text": "CVE-2026-64641: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "942a87d4ebdd047d", "scanner": "scanner-primary", "fingerprint": "28dc9e364afe957f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64641"]}}, {"ruleId": "scanner-39f148ad58f13d79", "level": "error", "message": {"text": "CVE-2026-64642: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "d9f503499055916e", "scanner": "scanner-primary", "fingerprint": "39f148ad58f13d79", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64642"]}}, {"ruleId": "scanner-2bc820d50b4e0143", "level": "error", "message": {"text": "CVE-2026-64645: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "693d0a165d81edd8", "scanner": "scanner-primary", "fingerprint": "2bc820d50b4e0143", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64645"]}}, {"ruleId": "scanner-4fca12546744e962", "level": "error", "message": {"text": "CVE-2026-64649: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "01b788bddfb8a4cb", "scanner": "scanner-primary", "fingerprint": "4fca12546744e962", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64649"]}}, {"ruleId": "scanner-c9615fa6f8a15461", "level": "error", "message": {"text": "GHSA-8h8q-6873-q5fj: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "f0f5a6559db98950", "scanner": "scanner-primary", "fingerprint": "c9615fa6f8a15461", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-8h8q-6873-q5fj"]}}, {"ruleId": "scanner-8b48486713516c3e", "level": "error", "message": {"text": "GHSA-q4gf-8mx6-v5v3: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "f14f93bf517e83a0", "scanner": "scanner-primary", "fingerprint": "8b48486713516c3e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-q4gf-8mx6-v5v3"]}}, {"ruleId": "scanner-0c14ce8b5b659d11", "level": "warning", "message": {"text": "CVE-2026-27978: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "880df17b031b5bcf", "scanner": "scanner-primary", "fingerprint": "0c14ce8b5b659d11", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27978"]}}, {"ruleId": "scanner-7ef43a4b79e4c619", "level": "warning", "message": {"text": "CVE-2026-27979: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "a8dd0f23a12b9214", "scanner": "scanner-primary", "fingerprint": "7ef43a4b79e4c619", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27979"]}}, {"ruleId": "scanner-1b6265aec4d3cf58", "level": "warning", "message": {"text": "CVE-2026-27980: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "cb502ce16a8fcdb4", "scanner": "scanner-primary", "fingerprint": "1b6265aec4d3cf58", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27980"]}}, {"ruleId": "scanner-d39f3e8b86d44266", "level": "warning", "message": {"text": "CVE-2026-29057: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "e716694618548263", "scanner": "scanner-primary", "fingerprint": "d39f3e8b86d44266", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29057"]}}, {"ruleId": "scanner-046872394d6e413a", "level": "warning", "message": {"text": "CVE-2026-44576: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "35a15ae073785abb", "scanner": "scanner-primary", "fingerprint": "046872394d6e413a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44576"]}}, {"ruleId": "scanner-56f1bd6e0c7505e0", "level": "warning", "message": {"text": "CVE-2026-44577: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "cad97b90a446a1c2", "scanner": "scanner-primary", "fingerprint": "56f1bd6e0c7505e0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44577"]}}, {"ruleId": "scanner-b54af13d8c83e19a", "level": "warning", "message": {"text": "CVE-2026-44580: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "54987c522ea1d6f6", "scanner": "scanner-primary", "fingerprint": "b54af13d8c83e19a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44580"]}}, {"ruleId": "scanner-40e3628ab9a23dcc", "level": "warning", "message": {"text": "CVE-2026-44581: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "404d1c4e9e5151bc", "scanner": "scanner-primary", "fingerprint": "40e3628ab9a23dcc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44581"]}}, {"ruleId": "scanner-46e413729a139427", "level": "warning", "message": {"text": "CVE-2026-64643: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "279053d5b2d8a231", "scanner": "scanner-primary", "fingerprint": "46e413729a139427", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64643"]}}, {"ruleId": "scanner-adfb9f95c5355e35", "level": "warning", "message": {"text": "CVE-2026-64644: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "3912bf51833f672e", "scanner": "scanner-primary", "fingerprint": "adfb9f95c5355e35", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64644"]}}, {"ruleId": "scanner-a1f07d2f536e7c35", "level": "warning", "message": {"text": "CVE-2026-64646: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "407d27b47ae61164", "scanner": "scanner-primary", "fingerprint": "a1f07d2f536e7c35", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64646"]}}, {"ruleId": "scanner-76f99002cabed206", "level": "warning", "message": {"text": "CVE-2026-64647: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "05f6b5a5cff4c482", "scanner": "scanner-primary", "fingerprint": "76f99002cabed206", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64647"]}}, {"ruleId": "scanner-882e13302b26c632", "level": "warning", "message": {"text": "CVE-2026-64648: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "3d963712f466da9d", "scanner": "scanner-primary", "fingerprint": "882e13302b26c632", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64648"]}}, {"ruleId": "scanner-c4f6e28fa224c593", "level": "note", "message": {"text": "CVE-2026-27977: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "b86652a373063cfe", "scanner": "scanner-primary", "fingerprint": "c4f6e28fa224c593", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27977"]}}, {"ruleId": "scanner-0dcd17bd64e5e46d", "level": "note", "message": {"text": "CVE-2026-44572: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "58310f60bd065ef6", "scanner": "scanner-primary", "fingerprint": "0dcd17bd64e5e46d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44572"]}}, {"ruleId": "scanner-cfe2acbcefe904e7", "level": "note", "message": {"text": "CVE-2026-44582: next 16.1.6 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "2933de32b5d1885e", "scanner": "scanner-primary", "fingerprint": "cfe2acbcefe904e7", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44582"]}}, {"ruleId": "scanner-8ea6b3d387573cc3", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "f9904ff71605025a", "scanner": "scanner-primary", "fingerprint": "8ea6b3d387573cc3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-bb375e63f791024b", "level": "error", "message": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "properties": {"repobilityId": "5482286778cddfaf", "scanner": "scanner-primary", "fingerprint": "bb375e63f791024b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f88m-g3jw-g9cj"]}}, {"ruleId": "scanner-8357761e3aca4343", "level": "error", "message": {"text": "CVE-2025-58754: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "ffbcbfc9023f6a37", "scanner": "scanner-primary", "fingerprint": "8357761e3aca4343", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-58754"]}}, {"ruleId": "scanner-47856eb92b31756c", "level": "error", "message": {"text": "CVE-2026-25639: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "c5c5ad0cebc96219", "scanner": "scanner-primary", "fingerprint": "47856eb92b31756c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25639"]}}, {"ruleId": "scanner-0c66927718fb7d64", "level": "error", "message": {"text": "CVE-2026-42033: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "fb63f6503e7d81fe", "scanner": "scanner-primary", "fingerprint": "0c66927718fb7d64", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42033"]}}, {"ruleId": "scanner-75cef56f99b4558f", "level": "error", "message": {"text": "CVE-2026-42035: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "8c025aff6c76133d", "scanner": "scanner-primary", "fingerprint": "75cef56f99b4558f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42035"]}}, {"ruleId": "scanner-9361e36af728cf95", "level": "error", "message": {"text": "CVE-2026-42043: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "d42ec9fa750cb2be", "scanner": "scanner-primary", "fingerprint": "9361e36af728cf95", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42043"]}}, {"ruleId": "scanner-ffa4e055143e0f10", "level": "error", "message": {"text": "CVE-2026-42264: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "65e85c3c18188f64", "scanner": "scanner-primary", "fingerprint": "ffa4e055143e0f10", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42264"]}}, {"ruleId": "scanner-91faa7c3b4c6715d", "level": "error", "message": {"text": "CVE-2026-44486: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "386af6cb8438f41b", "scanner": "scanner-primary", "fingerprint": "91faa7c3b4c6715d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44486"]}}, {"ruleId": "scanner-52d83060249ff34f", "level": "error", "message": {"text": "CVE-2026-44487: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "8b842a32178202c5", "scanner": "scanner-primary", "fingerprint": "52d83060249ff34f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44487"]}}, {"ruleId": "scanner-e5b20a6d125019a6", "level": "error", "message": {"text": "CVE-2026-44488: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "b3a58c2e34b553d3", "scanner": "scanner-primary", "fingerprint": "e5b20a6d125019a6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44488"]}}, {"ruleId": "scanner-706538ce1cd45397", "level": "error", "message": {"text": "CVE-2026-44494: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "2c161dc6f52eb66e", "scanner": "scanner-primary", "fingerprint": "706538ce1cd45397", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44494"]}}, {"ruleId": "scanner-7ff63965ea7f2876", "level": "error", "message": {"text": "CVE-2026-44495: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "2f6c11ba54a7ff53", "scanner": "scanner-primary", "fingerprint": "7ff63965ea7f2876", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44495"]}}, {"ruleId": "scanner-b71c8793b57e2583", "level": "error", "message": {"text": "CVE-2026-44496: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "9a830f50dd7f18b7", "scanner": "scanner-primary", "fingerprint": "b71c8793b57e2583", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44496"]}}, {"ruleId": "scanner-55d06ad407c1338f", "level": "warning", "message": {"text": "CVE-2025-62718: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "0aea792d6363bb62", "scanner": "scanner-primary", "fingerprint": "55d06ad407c1338f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-62718"]}}, {"ruleId": "scanner-778fb3daf7e5b907", "level": "warning", "message": {"text": "CVE-2026-40175: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "5591c5b781150450", "scanner": "scanner-primary", "fingerprint": "778fb3daf7e5b907", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40175"]}}, {"ruleId": "scanner-35cd67467e3864be", "level": "warning", "message": {"text": "CVE-2026-42034: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "f59f5ef76098669f", "scanner": "scanner-primary", "fingerprint": "35cd67467e3864be", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42034"]}}, {"ruleId": "scanner-9a77561fa1637d08", "level": "warning", "message": {"text": "CVE-2026-42036: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "c967410121ba25bf", "scanner": "scanner-primary", "fingerprint": "9a77561fa1637d08", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42036"]}}, {"ruleId": "scanner-1ffa864e8f56590f", "level": "warning", "message": {"text": "CVE-2026-42037: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "07efb1abc917a0e2", "scanner": "scanner-primary", "fingerprint": "1ffa864e8f56590f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42037"]}}, {"ruleId": "scanner-d4a852ffd50d9b4f", "level": "warning", "message": {"text": "CVE-2026-42038: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "7de4f53eecfddb6b", "scanner": "scanner-primary", "fingerprint": "d4a852ffd50d9b4f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42038"]}}, {"ruleId": "scanner-0ebc2dce1af9d400", "level": "warning", "message": {"text": "CVE-2026-42039: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "3af6e174619e56a7", "scanner": "scanner-primary", "fingerprint": "0ebc2dce1af9d400", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42039"]}}, {"ruleId": "scanner-5e59c86be820a179", "level": "warning", "message": {"text": "CVE-2026-42041: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "3cebd13e6771a900", "scanner": "scanner-primary", "fingerprint": "5e59c86be820a179", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42041"]}}, {"ruleId": "scanner-8d2c19e5b4e77c23", "level": "warning", "message": {"text": "CVE-2026-42042: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "528e51730b3b3e5c", "scanner": "scanner-primary", "fingerprint": "8d2c19e5b4e77c23", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42042"]}}, {"ruleId": "scanner-97f95545c730c79d", "level": "warning", "message": {"text": "CVE-2026-42044: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "3a1bb2454165370c", "scanner": "scanner-primary", "fingerprint": "97f95545c730c79d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42044"]}}, {"ruleId": "scanner-edfa93a1f32d0375", "level": "warning", "message": {"text": "CVE-2026-44490: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "8b846c848d4533d2", "scanner": "scanner-primary", "fingerprint": "edfa93a1f32d0375", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44490"]}}, {"ruleId": "scanner-a946177615e8a6d9", "level": "warning", "message": {"text": "GHSA-42h9-826w-cgv3: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "163c5f2501f5ffdf", "scanner": "scanner-primary", "fingerprint": "a946177615e8a6d9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-42h9-826w-cgv3"]}}, {"ruleId": "scanner-ad6aa5d607304df5", "level": "warning", "message": {"text": "GHSA-7q8q-rj6j-mhjq: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "1cd8b4bdc376f5ad", "scanner": "scanner-primary", "fingerprint": "ad6aa5d607304df5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-7q8q-rj6j-mhjq"]}}, {"ruleId": "scanner-033ad7cae7e63c84", "level": "warning", "message": {"text": "GHSA-jqh4-m9w3-8hp9: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "96e933ff1de4a6a0", "scanner": "scanner-primary", "fingerprint": "033ad7cae7e63c84", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-jqh4-m9w3-8hp9"]}}, {"ruleId": "scanner-42027386bfdd7ee6", "level": "warning", "message": {"text": "GHSA-mmx7-hfxf-jppx: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "c69ff56c82078544", "scanner": "scanner-primary", "fingerprint": "42027386bfdd7ee6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-mmx7-hfxf-jppx"]}}, {"ruleId": "scanner-daf0e90cf7e379b4", "level": "warning", "message": {"text": "GHSA-pmv8-rq9r-6j72: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "fb529ad644723b2e", "scanner": "scanner-primary", "fingerprint": "daf0e90cf7e379b4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-pmv8-rq9r-6j72"]}}, {"ruleId": "scanner-1387e8bd61c1a79f", "level": "note", "message": {"text": "CVE-2026-42040: axios 1.11.0 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "d592468652a1bcaa", "scanner": "scanner-primary", "fingerprint": "1387e8bd61c1a79f", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42040"]}}, {"ruleId": "scanner-968cdb29a8cc2611", "level": "error", "message": {"text": "CVE-2026-34769: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "0eb0e1c4cd334f19", "scanner": "scanner-primary", "fingerprint": "968cdb29a8cc2611", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34769"]}}, {"ruleId": "scanner-7b0df819631d02ef", "level": "error", "message": {"text": "CVE-2026-34770: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "eacca04fa7702bac", "scanner": "scanner-primary", "fingerprint": "7b0df819631d02ef", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34770"]}}, {"ruleId": "scanner-5c869c18e2580a27", "level": "error", "message": {"text": "CVE-2026-34771: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "3058926a95419ec1", "scanner": "scanner-primary", "fingerprint": "5c869c18e2580a27", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34771"]}}, {"ruleId": "scanner-f6827d8b25534c77", "level": "error", "message": {"text": "CVE-2026-34774: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "63f82372b14f894e", "scanner": "scanner-primary", "fingerprint": "f6827d8b25534c77", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34774"]}}, {"ruleId": "scanner-082547f0c749b0ff", "level": "warning", "message": {"text": "CVE-2025-55305: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "509b2318bd251695", "scanner": "scanner-primary", "fingerprint": "082547f0c749b0ff", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-55305"]}}, {"ruleId": "scanner-b0e58a3e96b3910c", "level": "warning", "message": {"text": "CVE-2026-34765: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "0dd5056b23e8362a", "scanner": "scanner-primary", "fingerprint": "b0e58a3e96b3910c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34765"]}}, {"ruleId": "scanner-56f313cc5a780094", "level": "warning", "message": {"text": "CVE-2026-34767: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "98173c803c3b995f", "scanner": "scanner-primary", "fingerprint": "56f313cc5a780094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34767"]}}, {"ruleId": "scanner-e44d2960d6168ad4", "level": "warning", "message": {"text": "CVE-2026-34772: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "d5f75f8334cdb5e6", "scanner": "scanner-primary", "fingerprint": "e44d2960d6168ad4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34772"]}}, {"ruleId": "scanner-5c0e5f52c7021461", "level": "warning", "message": {"text": "CVE-2026-34773: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "067e89b0fadcb119", "scanner": "scanner-primary", "fingerprint": "5c0e5f52c7021461", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34773"]}}, {"ruleId": "scanner-a3a4cd47183cc6a5", "level": "warning", "message": {"text": "CVE-2026-34775: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "3717aa5902b5370d", "scanner": "scanner-primary", "fingerprint": "a3a4cd47183cc6a5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34775"]}}, {"ruleId": "scanner-5a5b01efc88e67fe", "level": "warning", "message": {"text": "CVE-2026-34776: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "81f919eefad80c63", "scanner": "scanner-primary", "fingerprint": "5a5b01efc88e67fe", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34776"]}}, {"ruleId": "scanner-b441347c52a5b873", "level": "warning", "message": {"text": "CVE-2026-34777: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "1c779dcd2c230b3f", "scanner": "scanner-primary", "fingerprint": "b441347c52a5b873", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34777"]}}, {"ruleId": "scanner-ff8fc12f7c3c6a35", "level": "warning", "message": {"text": "CVE-2026-34778: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "9a00dca53a8f0440", "scanner": "scanner-primary", "fingerprint": "ff8fc12f7c3c6a35", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34778"]}}, {"ruleId": "scanner-82ad62f1ce4e0992", "level": "warning", "message": {"text": "CVE-2026-34779: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "7d39c831a8a0ee69", "scanner": "scanner-primary", "fingerprint": "82ad62f1ce4e0992", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34779"]}}, {"ruleId": "scanner-0878e27033ca0657", "level": "note", "message": {"text": "CVE-2026-34764: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "ef0887de36155e0f", "scanner": "scanner-primary", "fingerprint": "0878e27033ca0657", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34764"]}}, {"ruleId": "scanner-7cfac469589af530", "level": "note", "message": {"text": "CVE-2026-34766: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "31310af35ffa71c2", "scanner": "scanner-primary", "fingerprint": "7cfac469589af530", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34766"]}}, {"ruleId": "scanner-9206863f2f00d1ee", "level": "note", "message": {"text": "CVE-2026-34768: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "b24654301ec08b9f", "scanner": "scanner-primary", "fingerprint": "9206863f2f00d1ee", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34768"]}}, {"ruleId": "scanner-85e416eaee1dc78f", "level": "note", "message": {"text": "CVE-2026-34781: electron 37.2.6 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "cfa3a79df9760b0e", "scanner": "scanner-primary", "fingerprint": "85e416eaee1dc78f", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34781"]}}, {"ruleId": "scanner-6e591b7093de27e6", "level": "warning", "message": {"text": "GHSA-r4q5-vmmm-2653: follow-redirects 1.15.11 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "db62611198eed349", "scanner": "scanner-primary", "fingerprint": "6e591b7093de27e6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-r4q5-vmmm-2653"]}}, {"ruleId": "scanner-69a6e1af278fdb2d", "level": "error", "message": {"text": "CVE-2026-12143: form-data 4.0.4 \u2014 advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "properties": {"repobilityId": "9f4f5f4997f50cf8", "scanner": "scanner-primary", "fingerprint": "69a6e1af278fdb2d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12143"]}}, {"ruleId": "scanner-7864497877991e7c", "level": "note", "message": {"text": "CVE-2026-24001: diff 7.0.0 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "0e8c6ee8ccbea799", "scanner": "scanner-primary", "fingerprint": "7864497877991e7c", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24001"]}}, {"ruleId": "scanner-0a1c915e7bbe7755", "level": "error", "message": {"text": "CVE-2026-44573: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "93d7f4d1c4420f47", "scanner": "scanner-primary", "fingerprint": "0a1c915e7bbe7755", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44573"]}}, {"ruleId": "scanner-72292f63b82277fa", "level": "error", "message": {"text": "CVE-2026-44574: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "d72e838f1a763aab", "scanner": "scanner-primary", "fingerprint": "72292f63b82277fa", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44574"]}}, {"ruleId": "scanner-80f0afbe2ff50cb1", "level": "error", "message": {"text": "CVE-2026-44575: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "82e3bbb672878920", "scanner": "scanner-primary", "fingerprint": "80f0afbe2ff50cb1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44575"]}}, {"ruleId": "scanner-ceaa67fa8ab5ec1f", "level": "error", "message": {"text": "CVE-2026-44578: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "a0eeb8576b5a5960", "scanner": "scanner-primary", "fingerprint": "ceaa67fa8ab5ec1f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44578"]}}, {"ruleId": "scanner-15b79c877030b69d", "level": "error", "message": {"text": "CVE-2026-44579: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "a678c669ed27ebc4", "scanner": "scanner-primary", "fingerprint": "15b79c877030b69d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44579"]}}, {"ruleId": "scanner-b66b1dbf7678f274", "level": "error", "message": {"text": "CVE-2026-45109: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "e6b7ffb99f5035d4", "scanner": "scanner-primary", "fingerprint": "b66b1dbf7678f274", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45109"]}}, {"ruleId": "scanner-258b464419aa3041", "level": "error", "message": {"text": "CVE-2026-64641: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "6ae8e6536d50ce0e", "scanner": "scanner-primary", "fingerprint": "258b464419aa3041", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64641"]}}, {"ruleId": "scanner-b8abbcf6b1d4b7ed", "level": "error", "message": {"text": "CVE-2026-64645: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "c8fd7e5be37d78a7", "scanner": "scanner-primary", "fingerprint": "b8abbcf6b1d4b7ed", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64645"]}}, {"ruleId": "scanner-e55746e7fc7fac04", "level": "error", "message": {"text": "CVE-2026-64649: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "709e1713e7346d02", "scanner": "scanner-primary", "fingerprint": "e55746e7fc7fac04", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64649"]}}, {"ruleId": "scanner-f3118ba41e6fd416", "level": "error", "message": {"text": "GHSA-8h8q-6873-q5fj: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "255d55a33b77dcb8", "scanner": "scanner-primary", "fingerprint": "f3118ba41e6fd416", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-8h8q-6873-q5fj"]}}, {"ruleId": "scanner-7781245eef7dc8d9", "level": "warning", "message": {"text": "CVE-2026-44576: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "6173ab2e394769bc", "scanner": "scanner-primary", "fingerprint": "7781245eef7dc8d9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44576"]}}, {"ruleId": "scanner-e6567ba27f70dba1", "level": "warning", "message": {"text": "CVE-2026-44577: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "c8340ba010567db5", "scanner": "scanner-primary", "fingerprint": "e6567ba27f70dba1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44577"]}}, {"ruleId": "scanner-b04e65e574c83faf", "level": "warning", "message": {"text": "CVE-2026-44580: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "d389367db1634e28", "scanner": "scanner-primary", "fingerprint": "b04e65e574c83faf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44580"]}}, {"ruleId": "scanner-76b0fdb43b419a09", "level": "warning", "message": {"text": "CVE-2026-44581: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "39c6eef927f09975", "scanner": "scanner-primary", "fingerprint": "76b0fdb43b419a09", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44581"]}}, {"ruleId": "scanner-1c7c4f46d7e9ff57", "level": "warning", "message": {"text": "CVE-2026-64643: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "556337a12cb6581c", "scanner": "scanner-primary", "fingerprint": "1c7c4f46d7e9ff57", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64643"]}}, {"ruleId": "scanner-b49d8564abe6e827", "level": "warning", "message": {"text": "CVE-2026-64644: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "54abfc25bfce07f3", "scanner": "scanner-primary", "fingerprint": "b49d8564abe6e827", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64644"]}}, {"ruleId": "scanner-6823ec5928c419de", "level": "warning", "message": {"text": "CVE-2026-64646: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "e905a6546225b107", "scanner": "scanner-primary", "fingerprint": "6823ec5928c419de", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64646"]}}, {"ruleId": "scanner-67bdd769ea873ab5", "level": "warning", "message": {"text": "CVE-2026-64647: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "f46a31da3f71b96b", "scanner": "scanner-primary", "fingerprint": "67bdd769ea873ab5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64647"]}}, {"ruleId": "scanner-b08be22a49bb9196", "level": "warning", "message": {"text": "CVE-2026-64648: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "45edc8dfd8eec0da", "scanner": "scanner-primary", "fingerprint": "b08be22a49bb9196", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64648"]}}, {"ruleId": "scanner-582a26b2b7663ae4", "level": "note", "message": {"text": "CVE-2026-44572: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "88eaa0598f7f2df2", "scanner": "scanner-primary", "fingerprint": "582a26b2b7663ae4", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44572"]}}, {"ruleId": "scanner-7ea584b1a1ed64a6", "level": "note", "message": {"text": "CVE-2026-44582: next 15.5.15 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "5e2fa9d025b726a4", "scanner": "scanner-primary", "fingerprint": "7ea584b1a1ed64a6", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44582"]}}, {"ruleId": "scanner-70e63851895a24e4", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "598ff98bdf493dc8", "scanner": "scanner-primary", "fingerprint": "70e63851895a24e4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-e5ca2da93c2facc6", "level": "error", "message": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 agent_skills/self-improving-agent-skills/frontend/package-lock.json"}, "properties": {"repobilityId": "63fc22ef0fdd8b58", "scanner": "scanner-primary", "fingerprint": "e5ca2da93c2facc6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f88m-g3jw-g9cj"]}}, {"ruleId": "scanner-b2532895b1591d7a", "level": "error", "message": {"text": "CVE-2026-4810: google-adk 1.9.0 \u2014 always_on_agents/release_radar_agent/requirements.txt"}, "properties": {"repobilityId": "e1c3ee65a790d047", "scanner": "scanner-primary", "fingerprint": "b2532895b1591d7a", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4810"]}}, {"ruleId": "scanner-eb02a5db04fe88b8", "level": "note", "message": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 2.2.8 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "03ea0664573f5b1b", "scanner": "scanner-primary", "fingerprint": "eb02a5db04fe88b8", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8769"]}}, {"ruleId": "scanner-320edb0e675558ed", "level": "note", "message": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.25 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "03ea0664573f5b1b", "scanner": "scanner-primary", "fingerprint": "320edb0e675558ed", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8769"]}}, {"ruleId": "scanner-692f580449fa2d2b", "level": "warning", "message": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.14 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "a306729f09ede34a", "scanner": "scanner-primary", "fingerprint": "692f580449fa2d2b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-frvp-7c67-39w9"]}}, {"ruleId": "scanner-b200a914b2a438b9", "level": "note", "message": {"text": "GHSA-6475-r3vj-m8vf: @smithy/config-resolver 4.2.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "7ecbcbadd91d890b", "scanner": "scanner-primary", "fingerprint": "b200a914b2a438b9", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-6475-r3vj-m8vf"]}}, {"ruleId": "scanner-a6d3aa3763d7a401", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 1.20.3 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "5a21640c94a3bdb0", "scanner": "scanner-primary", "fingerprint": "a6d3aa3763d7a401", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-58c0f96f84d00e1a", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "5a21640c94a3bdb0", "scanner": "scanner-primary", "fingerprint": "58c0f96f84d00e1a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-47af9952ee7d030d", "level": "note", "message": {"text": "CVE-2026-24001: diff 5.2.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "816924c86a781151", "scanner": "scanner-primary", "fingerprint": "47af9952ee7d030d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24001"]}}, {"ruleId": "scanner-1d59f684575194de", "level": "warning", "message": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.4.7 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "d32f5e5b77906da2", "scanner": "scanner-primary", "fingerprint": "1d59f684575194de", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cmwh-pvxp-8882"]}}, {"ruleId": "scanner-85d232377cba56fc", "level": "note", "message": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.4.7 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "5d210de2eb1c554a", "scanner": "scanner-primary", "fingerprint": "85d232377cba56fc", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-c2j3-45gr-mqc4"]}}, {"ruleId": "scanner-28f15a37dd5c1179", "level": "note", "message": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.4.7 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "593930e89193ce06", "scanner": "scanner-primary", "fingerprint": "28f15a37dd5c1179", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-gvmj-g25r-r7wr"]}}, {"ruleId": "scanner-290ae82ab5e1b76b", "level": "note", "message": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.4.7 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "50eb6f27826d99d5", "scanner": "scanner-primary", "fingerprint": "290ae82ab5e1b76b", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-vxr8-fq34-vvx9"]}}, {"ruleId": "scanner-f81574f9babff8df", "level": "error", "message": {"text": "CVE-2026-13676: fast-uri 3.1.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "851ed8a9a9998641", "scanner": "scanner-primary", "fingerprint": "f81574f9babff8df", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13676"]}}, {"ruleId": "scanner-575cc651db0f6125", "level": "error", "message": {"text": "CVE-2026-16221: fast-uri 3.1.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "d4ceda5e58ade4b1", "scanner": "scanner-primary", "fingerprint": "575cc651db0f6125", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-16221"]}}, {"ruleId": "scanner-5e5a80b52dd67a2a", "level": "error", "message": {"text": "CVE-2026-25896: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "6b7b53a1b82ecc9c", "scanner": "scanner-primary", "fingerprint": "5e5a80b52dd67a2a", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25896"]}}, {"ruleId": "scanner-6d66602a2d52d1b8", "level": "error", "message": {"text": "CVE-2026-25128: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "a0265b81702dd278", "scanner": "scanner-primary", "fingerprint": "6d66602a2d52d1b8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25128"]}}, {"ruleId": "scanner-69dcf0919bbb7984", "level": "error", "message": {"text": "CVE-2026-26278: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "489f5f01f7fd1492", "scanner": "scanner-primary", "fingerprint": "69dcf0919bbb7984", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26278"]}}, {"ruleId": "scanner-3a4efe2ab45ba289", "level": "error", "message": {"text": "CVE-2026-33036: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "5f53c24519bc38af", "scanner": "scanner-primary", "fingerprint": "3a4efe2ab45ba289", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33036"]}}, {"ruleId": "scanner-d1994eaab17762b7", "level": "warning", "message": {"text": "CVE-2026-33349: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "ad91ba0838cc9cfd", "scanner": "scanner-primary", "fingerprint": "d1994eaab17762b7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33349"]}}, {"ruleId": "scanner-c8c464f18fb72670", "level": "warning", "message": {"text": "CVE-2026-41650: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "43425205ecf980fb", "scanner": "scanner-primary", "fingerprint": "c8c464f18fb72670", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41650"]}}, {"ruleId": "scanner-426271cd4374c404", "level": "note", "message": {"text": "CVE-2026-27942: fast-xml-parser 5.2.5 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "711eb202cffd5b73", "scanner": "scanner-primary", "fingerprint": "426271cd4374c404", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27942"]}}, {"ruleId": "scanner-dd8f3438c20bd506", "level": "error", "message": {"text": "CVE-2026-12143: form-data 4.0.4 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "4b5760250193d047", "scanner": "scanner-primary", "fingerprint": "dd8f3438c20bd506", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12143"]}}, {"ruleId": "scanner-1348743695a4f817", "level": "error", "message": {"text": "CVE-2026-54290: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "e7bd1480f5258a64", "scanner": "scanner-primary", "fingerprint": "1348743695a4f817", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54290"]}}, {"ruleId": "scanner-e724397e7619c093", "level": "warning", "message": {"text": "CVE-2026-54286: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "c4462d8311b0ce47", "scanner": "scanner-primary", "fingerprint": "e724397e7619c093", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54286"]}}, {"ruleId": "scanner-a45e1883ae0b38f5", "level": "warning", "message": {"text": "CVE-2026-54287: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "77d9cad2e59e31cb", "scanner": "scanner-primary", "fingerprint": "a45e1883ae0b38f5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54287"]}}, {"ruleId": "scanner-5b033b87654ac218", "level": "warning", "message": {"text": "CVE-2026-54288: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "fa52e074f6b6c9ea", "scanner": "scanner-primary", "fingerprint": "5b033b87654ac218", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54288"]}}, {"ruleId": "scanner-ae3d9613fc5dfb08", "level": "warning", "message": {"text": "CVE-2026-54289: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "69a6fbe5b3b4b19a", "scanner": "scanner-primary", "fingerprint": "ae3d9613fc5dfb08", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54289"]}}, {"ruleId": "scanner-703ffa82637537b1", "level": "warning", "message": {"text": "CVE-2026-59895: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "de347a557f7f2adb", "scanner": "scanner-primary", "fingerprint": "703ffa82637537b1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59895"]}}, {"ruleId": "scanner-2f59afe95a306581", "level": "warning", "message": {"text": "CVE-2026-59896: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "212951368909e4e1", "scanner": "scanner-primary", "fingerprint": "2f59afe95a306581", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59896"]}}, {"ruleId": "scanner-eb91f035a94808a3", "level": "warning", "message": {"text": "CVE-2026-59897: hono 4.12.23 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "fd3c791ab737124a", "scanner": "scanner-primary", "fingerprint": "eb91f035a94808a3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59897"]}}, {"ruleId": "scanner-87ea3d009da07611", "level": "error", "message": {"text": "CVE-2025-65945: jws 4.0.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "1034060054390013", "scanner": "scanner-primary", "fingerprint": "87ea3d009da07611", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-65945"]}}, {"ruleId": "scanner-8e08a751d442493b", "level": "error", "message": {"text": "CVE-2026-4800: lodash 4.17.21 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "f835cc837e5a1b8c", "scanner": "scanner-primary", "fingerprint": "8e08a751d442493b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-1571e2350db522e5", "level": "warning", "message": {"text": "CVE-2025-13465: lodash 4.17.21 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "1a570b5351c35017", "scanner": "scanner-primary", "fingerprint": "1571e2350db522e5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-13465"]}}, {"ruleId": "scanner-ac6e43a07303587b", "level": "warning", "message": {"text": "CVE-2026-2950: lodash 4.17.21 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "ef602e3c01c5e1d6", "scanner": "scanner-primary", "fingerprint": "ac6e43a07303587b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-e801d7d0a06470bf", "level": "warning", "message": {"text": "CVE-2025-66400: mdast-util-to-hast 13.2.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "d26eff8a09fafd8c", "scanner": "scanner-primary", "fingerprint": "e801d7d0a06470bf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66400"]}}, {"ruleId": "scanner-0e2e5c4a92721740", "level": "error", "message": {"text": "CVE-2025-55182: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "0c8d91700ed814a7", "scanner": "scanner-primary", "fingerprint": "0e2e5c4a92721740", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-55182"]}}, {"ruleId": "scanner-2b68052ad2262eb5", "level": "error", "message": {"text": "CVE-2026-44573: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "da40169ff3af8e11", "scanner": "scanner-primary", "fingerprint": "2b68052ad2262eb5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44573"]}}, {"ruleId": "scanner-d1ec40d9c1327ecd", "level": "error", "message": {"text": "CVE-2026-44575: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "e6921fedeaa4d437", "scanner": "scanner-primary", "fingerprint": "d1ec40d9c1327ecd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44575"]}}, {"ruleId": "scanner-5f98a2d6dbe93b30", "level": "error", "message": {"text": "CVE-2026-44578: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "1acce5f4058c36d0", "scanner": "scanner-primary", "fingerprint": "5f98a2d6dbe93b30", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44578"]}}, {"ruleId": "scanner-95443fdb07394dfd", "level": "error", "message": {"text": "CVE-2026-44579: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "2cc7f043bf2bda10", "scanner": "scanner-primary", "fingerprint": "95443fdb07394dfd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44579"]}}, {"ruleId": "scanner-09e14aa25645a9f7", "level": "error", "message": {"text": "CVE-2026-45109: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "65d5fccb097fae3a", "scanner": "scanner-primary", "fingerprint": "09e14aa25645a9f7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45109"]}}, {"ruleId": "scanner-3fc29af1c121a014", "level": "error", "message": {"text": "CVE-2026-64641: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "33b6e5b2eac83cb0", "scanner": "scanner-primary", "fingerprint": "3fc29af1c121a014", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64641"]}}, {"ruleId": "scanner-b06fbbaa61ab0f35", "level": "error", "message": {"text": "CVE-2026-64645: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "d4dfc60419cccb6d", "scanner": "scanner-primary", "fingerprint": "b06fbbaa61ab0f35", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64645"]}}, {"ruleId": "scanner-d30a07bc2aa86069", "level": "error", "message": {"text": "CVE-2026-64649: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "00630c7e82ccf97b", "scanner": "scanner-primary", "fingerprint": "d30a07bc2aa86069", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64649"]}}, {"ruleId": "scanner-de5bcc57d1406ee5", "level": "error", "message": {"text": "GHSA-8h8q-6873-q5fj: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "073044054ad5696a", "scanner": "scanner-primary", "fingerprint": "de5bcc57d1406ee5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-8h8q-6873-q5fj"]}}, {"ruleId": "scanner-8ba6970f814b9fef", "level": "error", "message": {"text": "GHSA-h25m-26qc-wcjf: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "6ea9d9fd53855ef0", "scanner": "scanner-primary", "fingerprint": "8ba6970f814b9fef", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-h25m-26qc-wcjf"]}}, {"ruleId": "scanner-0459e427eb1a31ec", "level": "error", "message": {"text": "GHSA-mwv6-3258-q52c: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "54adab3bcab7f536", "scanner": "scanner-primary", "fingerprint": "0459e427eb1a31ec", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-mwv6-3258-q52c"]}}, {"ruleId": "scanner-f77430643d435c19", "level": "error", "message": {"text": "GHSA-q4gf-8mx6-v5v3: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "5d4286f322a71345", "scanner": "scanner-primary", "fingerprint": "f77430643d435c19", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-q4gf-8mx6-v5v3"]}}, {"ruleId": "scanner-4997e740bdb621d2", "level": "warning", "message": {"text": "CVE-2025-55173: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "db38781a11e16d57", "scanner": "scanner-primary", "fingerprint": "4997e740bdb621d2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-55173"]}}, {"ruleId": "scanner-2819da1536e67317", "level": "warning", "message": {"text": "CVE-2025-57752: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "bbe498719aa4eccb", "scanner": "scanner-primary", "fingerprint": "2819da1536e67317", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-57752"]}}, {"ruleId": "scanner-29be2460875677fd", "level": "warning", "message": {"text": "CVE-2025-57822: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "711fb69b60fbc84d", "scanner": "scanner-primary", "fingerprint": "29be2460875677fd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-57822"]}}, {"ruleId": "scanner-65d34bd91059283b", "level": "warning", "message": {"text": "CVE-2025-59471: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "b13d4677a5f28121", "scanner": "scanner-primary", "fingerprint": "65d34bd91059283b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-59471"]}}, {"ruleId": "scanner-f7ede05bf0eda628", "level": "warning", "message": {"text": "CVE-2026-27980: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "cc3d0e906f203529", "scanner": "scanner-primary", "fingerprint": "f7ede05bf0eda628", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27980"]}}, {"ruleId": "scanner-60ba2113c6312508", "level": "warning", "message": {"text": "CVE-2026-29057: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "54f03b24d6e985b4", "scanner": "scanner-primary", "fingerprint": "60ba2113c6312508", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29057"]}}, {"ruleId": "scanner-db1e7c129fe2640a", "level": "warning", "message": {"text": "CVE-2026-44576: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "0b037e1290f066e6", "scanner": "scanner-primary", "fingerprint": "db1e7c129fe2640a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44576"]}}, {"ruleId": "scanner-2d12b228b3d49a57", "level": "warning", "message": {"text": "CVE-2026-44577: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "75669c275b6e2203", "scanner": "scanner-primary", "fingerprint": "2d12b228b3d49a57", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44577"]}}, {"ruleId": "scanner-ace0fa1f6c7c35f0", "level": "warning", "message": {"text": "CVE-2026-44580: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "73bcda04646d43fb", "scanner": "scanner-primary", "fingerprint": "ace0fa1f6c7c35f0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44580"]}}, {"ruleId": "scanner-b5a7ac3c4d0ca4cf", "level": "warning", "message": {"text": "CVE-2026-44581: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "b63125555abe38ec", "scanner": "scanner-primary", "fingerprint": "b5a7ac3c4d0ca4cf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44581"]}}, {"ruleId": "scanner-d4821573718401c2", "level": "warning", "message": {"text": "CVE-2026-64643: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "04e9af82d41d4494", "scanner": "scanner-primary", "fingerprint": "d4821573718401c2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64643"]}}, {"ruleId": "scanner-1aac450d25d5e20d", "level": "warning", "message": {"text": "CVE-2026-64646: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "cef36972e471b0c3", "scanner": "scanner-primary", "fingerprint": "1aac450d25d5e20d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64646"]}}, {"ruleId": "scanner-f26bb2b3ea61ff49", "level": "warning", "message": {"text": "CVE-2026-64647: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "3f915ac191db011d", "scanner": "scanner-primary", "fingerprint": "f26bb2b3ea61ff49", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64647"]}}, {"ruleId": "scanner-be3fe13aee44c504", "level": "warning", "message": {"text": "CVE-2026-64648: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "a13accda73c073c2", "scanner": "scanner-primary", "fingerprint": "be3fe13aee44c504", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64648"]}}, {"ruleId": "scanner-2f0f3d1508d2355e", "level": "warning", "message": {"text": "GHSA-w37m-7fhw-fmv9: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "c2210ea075bd51b1", "scanner": "scanner-primary", "fingerprint": "2f0f3d1508d2355e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-w37m-7fhw-fmv9"]}}, {"ruleId": "scanner-5cc3f463284ab389", "level": "note", "message": {"text": "CVE-2025-49005: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "6fed9d43bd092890", "scanner": "scanner-primary", "fingerprint": "5cc3f463284ab389", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-49005"]}}, {"ruleId": "scanner-58965e41acbac259", "level": "note", "message": {"text": "CVE-2026-44572: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "05b04c8c02d4c5aa", "scanner": "scanner-primary", "fingerprint": "58965e41acbac259", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44572"]}}, {"ruleId": "scanner-276f7bfede241150", "level": "note", "message": {"text": "CVE-2026-44582: next 15.3.2 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "e5ee1fd69cff6f58", "scanner": "scanner-primary", "fingerprint": "276f7bfede241150", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44582"]}}, {"ruleId": "scanner-b3a1ea55eaf10bdb", "level": "error", "message": {"text": "CVE-2025-12816: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "6d6106999b412884", "scanner": "scanner-primary", "fingerprint": "b3a1ea55eaf10bdb", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-12816"]}}, {"ruleId": "scanner-490eddd40d205a51", "level": "error", "message": {"text": "CVE-2025-66031: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "87a4a2227ae21a25", "scanner": "scanner-primary", "fingerprint": "490eddd40d205a51", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66031"]}}, {"ruleId": "scanner-16f407b78644f9a3", "level": "error", "message": {"text": "CVE-2026-33891: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "e00ecfff96247c7a", "scanner": "scanner-primary", "fingerprint": "16f407b78644f9a3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33891"]}}, {"ruleId": "scanner-1b8a7d2951d9ca55", "level": "error", "message": {"text": "CVE-2026-33894: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "83266cb7e070367b", "scanner": "scanner-primary", "fingerprint": "1b8a7d2951d9ca55", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33894"]}}, {"ruleId": "scanner-c80583477f50b6cc", "level": "error", "message": {"text": "CVE-2026-33895: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "5da9e5769c6a161e", "scanner": "scanner-primary", "fingerprint": "c80583477f50b6cc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33895"]}}, {"ruleId": "scanner-789b452727ed01d3", "level": "error", "message": {"text": "CVE-2026-33896: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "f8e55c7008afd7ca", "scanner": "scanner-primary", "fingerprint": "789b452727ed01d3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33896"]}}, {"ruleId": "scanner-fb2675bd8204254d", "level": "warning", "message": {"text": "CVE-2025-66030: node-forge 1.3.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "4e46b1ccda33d136", "scanner": "scanner-primary", "fingerprint": "fb2675bd8204254d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66030"]}}, {"ruleId": "scanner-f9699082ffa30cc2", "level": "error", "message": {"text": "CVE-2026-4867: path-to-regexp 0.1.12 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "c60c67186d55964d", "scanner": "scanner-primary", "fingerprint": "f9699082ffa30cc2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4867"]}}, {"ruleId": "scanner-f827b248f2f245ac", "level": "error", "message": {"text": "CVE-2025-59288: playwright 1.55.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "37c5ef1032d59a00", "scanner": "scanner-primary", "fingerprint": "f827b248f2f245ac", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-59288"]}}, {"ruleId": "scanner-76023393a287362b", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "31c0e3748de49bda", "scanner": "scanner-primary", "fingerprint": "76023393a287362b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-a1cc7072ab98a83e", "level": "warning", "message": {"text": "CVE-2024-53382: prismjs 1.27.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "fc7b9a88b380b645", "scanner": "scanner-primary", "fingerprint": "a1cc7072ab98a83e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-53382"]}}, {"ruleId": "scanner-ad7c60b68832ed6f", "level": "warning", "message": {"text": "CVE-2025-15284: qs 6.13.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "65894ac32dfc1b9b", "scanner": "scanner-primary", "fingerprint": "ad7c60b68832ed6f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-15284"]}}, {"ruleId": "scanner-61269bd3455dde98", "level": "warning", "message": {"text": "CVE-2026-8723: qs 6.13.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "c7664c6ed2b3252c", "scanner": "scanner-primary", "fingerprint": "61269bd3455dde98", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8723"]}}, {"ruleId": "scanner-51f507039a2eb2b7", "level": "note", "message": {"text": "CVE-2026-2391: qs 6.13.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "9c1de6e063ddddc1", "scanner": "scanner-primary", "fingerprint": "51f507039a2eb2b7", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2391"]}}, {"ruleId": "scanner-67492b140d15e686", "level": "error", "message": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.4 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "cd69b190bd2e5f0a", "scanner": "scanner-primary", "fingerprint": "67492b140d15e686", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f88m-g3jw-g9cj"]}}, {"ruleId": "scanner-a54b8ecb28120903", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 10.0.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "bc9b1b865d66c8da", "scanner": "scanner-primary", "fingerprint": "a54b8ecb28120903", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-74cd8f9fb45f438a", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "bc9b1b865d66c8da", "scanner": "scanner-primary", "fingerprint": "74cd8f9fb45f438a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-14dbcbd0d32cbcf6", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "bc9b1b865d66c8da", "scanner": "scanner-primary", "fingerprint": "14dbcbd0d32cbcf6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-14125201359a201d", "level": "error", "message": {"text": "CVE-2025-12758: validator 13.15.15 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "5ac156529c4b7712", "scanner": "scanner-primary", "fingerprint": "14125201359a201d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-12758"]}}, {"ruleId": "scanner-9214ad4fa98dab85", "level": "warning", "message": {"text": "CVE-2025-56200: validator 13.15.15 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "dbfa395f8f851106", "scanner": "scanner-primary", "fingerprint": "9214ad4fa98dab85", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-56200"]}}, {"ruleId": "scanner-76fdcb721fd038aa", "level": "error", "message": {"text": "CVE-2026-48779: ws 8.18.3 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "21ff3728c314a201", "scanner": "scanner-primary", "fingerprint": "76fdcb721fd038aa", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48779"]}}, {"ruleId": "scanner-e19555eefdeda115", "level": "warning", "message": {"text": "CVE-2026-45736: ws 8.18.3 \u2014 generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "properties": {"repobilityId": "9d895102fe533dda", "scanner": "scanner-primary", "fingerprint": "e19555eefdeda115", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45736"]}}, {"ruleId": "scanner-db0e2b5c99e7b780", "level": "warning", "message": {"text": "CVE-2026-45409: idna 3.11 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "909ed1fc0222b934", "scanner": "scanner-primary", "fingerprint": "db0e2b5c99e7b780", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45409"]}}, {"ruleId": "scanner-55297e5c4fbf16ad", "level": "warning", "message": {"text": "CVE-2026-55443: langchain 1.2.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "8e47faaee9f5c8f8", "scanner": "scanner-primary", "fingerprint": "55297e5c4fbf16ad", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55443"]}}, {"ruleId": "scanner-ae7351d9f2bdc3f2", "level": "warning", "message": {"text": "CVE-2026-55443: langchain-anthropic 1.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "0af3463139936c2b", "scanner": "scanner-primary", "fingerprint": "ae7351d9f2bdc3f2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55443"]}}, {"ruleId": "scanner-57a27b91e04e9bcc", "level": "error", "message": {"text": "CVE-2026-34070: langchain-core 1.2.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "77acb048ca1dde30", "scanner": "scanner-primary", "fingerprint": "57a27b91e04e9bcc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34070"]}}, {"ruleId": "scanner-c29b8b20edf7905d", "level": "error", "message": {"text": "CVE-2026-44843: langchain-core 1.2.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "0b30583797536677", "scanner": "scanner-primary", "fingerprint": "c29b8b20edf7905d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44843"]}}, {"ruleId": "scanner-b22b1ddfc3553ec7", "level": "warning", "message": {"text": "CVE-2026-40087: langchain-core 1.2.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "d9fd3379538a9b32", "scanner": "scanner-primary", "fingerprint": "b22b1ddfc3553ec7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40087"]}}, {"ruleId": "scanner-280fc04d59e0b028", "level": "note", "message": {"text": "CVE-2026-26013: langchain-core 1.2.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "f21b4235d9a8d6dc", "scanner": "scanner-primary", "fingerprint": "280fc04d59e0b028", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26013"]}}, {"ruleId": "scanner-f54918a39d9d76c6", "level": "note", "message": {"text": "CVE-2026-41488: langchain-openai 1.1.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "80c8fd97d83ebaaf", "scanner": "scanner-primary", "fingerprint": "f54918a39d9d76c6", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41488"]}}, {"ruleId": "scanner-2c8289719fdf0643", "level": "warning", "message": {"text": "CVE-2026-28277: langgraph 1.0.7 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "f483d0a05f1ab8d2", "scanner": "scanner-primary", "fingerprint": "2c8289719fdf0643", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28277"]}}, {"ruleId": "scanner-423c335761052b47", "level": "warning", "message": {"text": "CVE-2026-48775: langgraph-checkpoint 4.0.0 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "594bbc0e269a7a8e", "scanner": "scanner-primary", "fingerprint": "423c335761052b47", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48775"]}}, {"ruleId": "scanner-04d1e74851653e18", "level": "warning", "message": {"text": "CVE-2026-48776: langgraph-sdk 0.3.3 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "002f40df5ca7dbbe", "scanner": "scanner-primary", "fingerprint": "04d1e74851653e18", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48776"]}}, {"ruleId": "scanner-d74a46da48ac588f", "level": "error", "message": {"text": "CVE-2026-45134: langsmith 0.6.4 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "05e3c4494d2daa5b", "scanner": "scanner-primary", "fingerprint": "d74a46da48ac588f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45134"]}}, {"ruleId": "scanner-00761e873f86a423", "level": "error", "message": {"text": "GHSA-f4xh-w4cj-qxq8: langsmith 0.6.4 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "ea8e6c8ec5e05ba6", "scanner": "scanner-primary", "fingerprint": "00761e873f86a423", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f4xh-w4cj-qxq8"]}}, {"ruleId": "scanner-00919a496da786ba", "level": "warning", "message": {"text": "CVE-2026-41182: langsmith 0.6.4 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "0f241a99ee1add44", "scanner": "scanner-primary", "fingerprint": "00919a496da786ba", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41182"]}}, {"ruleId": "scanner-f1f24a788ce6ba88", "level": "error", "message": {"text": "CVE-2025-67221: orjson 3.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "9e4903beed1f79b6", "scanner": "scanner-primary", "fingerprint": "f1f24a788ce6ba88", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-67221"]}}, {"ruleId": "scanner-8aaaabd4b22515e4", "level": "error", "message": {"text": "CVE-2026-30922: pyasn1 0.6.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "dcae11c78122ce52", "scanner": "scanner-primary", "fingerprint": "8aaaabd4b22515e4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-30922"]}}, {"ruleId": "scanner-0d7e720934582937", "level": "error", "message": {"text": "CVE-2026-59885: pyasn1 0.6.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "ee379675ba334aa5", "scanner": "scanner-primary", "fingerprint": "0d7e720934582937", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59885"]}}, {"ruleId": "scanner-16499d8104b98e43", "level": "error", "message": {"text": "CVE-2026-59886: pyasn1 0.6.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "63b805f46b66a27f", "scanner": "scanner-primary", "fingerprint": "16499d8104b98e43", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59886"]}}, {"ruleId": "scanner-a93632f0556ac42b", "level": "warning", "message": {"text": "CVE-2026-28684: python-dotenv 1.2.1 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "0897b677708ea3af", "scanner": "scanner-primary", "fingerprint": "a93632f0556ac42b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28684"]}}, {"ruleId": "scanner-803bd69be705b713", "level": "warning", "message": {"text": "CVE-2026-25645: requests 2.32.5 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "6f560245d7c7481f", "scanner": "scanner-primary", "fingerprint": "803bd69be705b713", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25645"]}}, {"ruleId": "scanner-8ab9a3f6e485c581", "level": "error", "message": {"text": "CVE-2025-62727: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "e6c05e63b9265db2", "scanner": "scanner-primary", "fingerprint": "8ab9a3f6e485c581", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-62727"]}}, {"ruleId": "scanner-aa188a704d6c73d1", "level": "error", "message": {"text": "CVE-2026-48818: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "8f1aebbb12c946be", "scanner": "scanner-primary", "fingerprint": "aa188a704d6c73d1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48818"]}}, {"ruleId": "scanner-49fb83b93968790c", "level": "error", "message": {"text": "CVE-2026-54283: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "a3d0891ca5049308", "scanner": "scanner-primary", "fingerprint": "49fb83b93968790c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54283"]}}, {"ruleId": "scanner-07156a5dfe5f2eae", "level": "warning", "message": {"text": "CVE-2025-54121: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "88d54481fe2a58c0", "scanner": "scanner-primary", "fingerprint": "07156a5dfe5f2eae", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-54121"]}}, {"ruleId": "scanner-9e8f50909584579a", "level": "warning", "message": {"text": "CVE-2026-48710: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "2148b56a5618ea33", "scanner": "scanner-primary", "fingerprint": "9e8f50909584579a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48710"]}}, {"ruleId": "scanner-dc1d95a21421b23e", "level": "warning", "message": {"text": "CVE-2026-48817: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "1f455aa579ead7bb", "scanner": "scanner-primary", "fingerprint": "dc1d95a21421b23e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48817"]}}, {"ruleId": "scanner-a05cd3c02439e681", "level": "note", "message": {"text": "CVE-2026-54282: starlette 0.46.2 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "13a73dacc00ecad9", "scanner": "scanner-primary", "fingerprint": "a05cd3c02439e681", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54282"]}}, {"ruleId": "scanner-995c89fa3bb1a94f", "level": "error", "message": {"text": "CVE-2026-44431: urllib3 2.6.3 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "f838c166b2ab3004", "scanner": "scanner-primary", "fingerprint": "995c89fa3bb1a94f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44431"]}}, {"ruleId": "scanner-181cad0b9956ed6f", "level": "error", "message": {"text": "CVE-2026-44432: urllib3 2.6.3 \u2014 generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "properties": {"repobilityId": "588f3aa195fac1c8", "scanner": "scanner-primary", "fingerprint": "181cad0b9956ed6f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44432"]}}, {"ruleId": "scanner-fb39ed58889cc9f6", "level": "note", "message": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.17 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "676ec92819e03270", "scanner": "scanner-primary", "fingerprint": "fb39ed58889cc9f6", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8769"]}}, {"ruleId": "scanner-59b1231e478aeb9e", "level": "note", "message": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.20 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "676ec92819e03270", "scanner": "scanner-primary", "fingerprint": "59b1231e478aeb9e", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8769"]}}, {"ruleId": "scanner-12bc393a5a83ef40", "level": "error", "message": {"text": "CVE-2026-29087: @hono/node-server 1.19.9 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "3b75a030fbbd2279", "scanner": "scanner-primary", "fingerprint": "12bc393a5a83ef40", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29087"]}}, {"ruleId": "scanner-1ab98012bb16aae9", "level": "warning", "message": {"text": "CVE-2026-39406: @hono/node-server 1.19.9 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "e99168aa901d3b71", "scanner": "scanner-primary", "fingerprint": "1ab98012bb16aae9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39406"]}}, {"ruleId": "scanner-45f62cb86a07b2ce", "level": "warning", "message": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.9 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "c199fc703e51bff3", "scanner": "scanner-primary", "fingerprint": "45f62cb86a07b2ce", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-frvp-7c67-39w9"]}}, {"ruleId": "scanner-293ba1a70b672312", "level": "error", "message": {"text": "CVE-2026-25536: @modelcontextprotocol/sdk 1.25.3 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "70bd77534428b0dd", "scanner": "scanner-primary", "fingerprint": "293ba1a70b672312", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25536"]}}, {"ruleId": "scanner-fe8acd55462fef0d", "level": "warning", "message": {"text": "CVE-2025-69873: ajv 8.17.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "380f42bf59b9c7ff", "scanner": "scanner-primary", "fingerprint": "fe8acd55462fef0d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69873"]}}, {"ruleId": "scanner-dc1618aeb55bfecd", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 1.20.4 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "43fd5d06e3d1b670", "scanner": "scanner-primary", "fingerprint": "dc1618aeb55bfecd", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-190e23af524f66d6", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "43fd5d06e3d1b670", "scanner": "scanner-primary", "fingerprint": "190e23af524f66d6", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-913c8a5dd55c2c7f", "level": "warning", "message": {"text": "CVE-2026-0540: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "1a5734708300cbfc", "scanner": "scanner-primary", "fingerprint": "913c8a5dd55c2c7f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-0540"]}}, {"ruleId": "scanner-52fc7a4477aa73c4", "level": "warning", "message": {"text": "CVE-2026-41238: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "78d8b61ce20e3f24", "scanner": "scanner-primary", "fingerprint": "52fc7a4477aa73c4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41238"]}}, {"ruleId": "scanner-f5fe58347f9978d8", "level": "warning", "message": {"text": "CVE-2026-41239: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "b0a9c65671b79c8c", "scanner": "scanner-primary", "fingerprint": "f5fe58347f9978d8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41239"]}}, {"ruleId": "scanner-017e5bd64d4ccc26", "level": "warning", "message": {"text": "CVE-2026-41240: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "8435fc6be1b74cbe", "scanner": "scanner-primary", "fingerprint": "017e5bd64d4ccc26", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41240"]}}, {"ruleId": "scanner-95f8d0d3fd15dff0", "level": "warning", "message": {"text": "CVE-2026-49458: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "79955ae1b2581150", "scanner": "scanner-primary", "fingerprint": "95f8d0d3fd15dff0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49458"]}}, {"ruleId": "scanner-0d85e0f237aea9e6", "level": "warning", "message": {"text": "CVE-2026-49459: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "e5a49f4710ae7fe4", "scanner": "scanner-primary", "fingerprint": "0d85e0f237aea9e6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49459"]}}, {"ruleId": "scanner-e405c9188b24d78b", "level": "warning", "message": {"text": "CVE-2026-49978: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "f8e8d9a6afc67455", "scanner": "scanner-primary", "fingerprint": "e405c9188b24d78b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49978"]}}, {"ruleId": "scanner-4a23a28c7146702a", "level": "warning", "message": {"text": "GHSA-39q2-94rc-95cp: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "dd0f19b5c734fd6c", "scanner": "scanner-primary", "fingerprint": "4a23a28c7146702a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-39q2-94rc-95cp"]}}, {"ruleId": "scanner-17f3bb1be445db6f", "level": "warning", "message": {"text": "GHSA-76mc-f452-cxcm: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "23c77949d1387bfe", "scanner": "scanner-primary", "fingerprint": "17f3bb1be445db6f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-76mc-f452-cxcm"]}}, {"ruleId": "scanner-ddb7382b5c810631", "level": "warning", "message": {"text": "GHSA-cj63-jhhr-wcxv: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "11421f65a56d618a", "scanner": "scanner-primary", "fingerprint": "ddb7382b5c810631", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cj63-jhhr-wcxv"]}}, {"ruleId": "scanner-00b1254f03f8ee62", "level": "warning", "message": {"text": "GHSA-cjmm-f4jc-qw8r: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "8f4d49335571f8ad", "scanner": "scanner-primary", "fingerprint": "00b1254f03f8ee62", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cjmm-f4jc-qw8r"]}}, {"ruleId": "scanner-c2e0fd8957d2a221", "level": "warning", "message": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "6d6bf1bace42def2", "scanner": "scanner-primary", "fingerprint": "c2e0fd8957d2a221", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cmwh-pvxp-8882"]}}, {"ruleId": "scanner-6a059b695b102e8e", "level": "warning", "message": {"text": "GHSA-h8r8-wccr-v5f2: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "b3b98d823f1200de", "scanner": "scanner-primary", "fingerprint": "6a059b695b102e8e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-h8r8-wccr-v5f2"]}}, {"ruleId": "scanner-7bb7d1617d2c9ac0", "level": "note", "message": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "aff5fb394f477bc9", "scanner": "scanner-primary", "fingerprint": "7bb7d1617d2c9ac0", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-c2j3-45gr-mqc4"]}}, {"ruleId": "scanner-9094ad9425a3e5dd", "level": "note", "message": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "d0b18db6d1db331d", "scanner": "scanner-primary", "fingerprint": "9094ad9425a3e5dd", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-gvmj-g25r-r7wr"]}}, {"ruleId": "scanner-77fc48313943c59f", "level": "note", "message": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "548de4249373ab78", "scanner": "scanner-primary", "fingerprint": "77fc48313943c59f", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-vxr8-fq34-vvx9"]}}, {"ruleId": "scanner-582324f40b486b59", "level": "note", "message": {"text": "GHSA-x4vx-rjvf-j5p4: dompurify 3.3.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "fb501a655ee07bae", "scanner": "scanner-primary", "fingerprint": "582324f40b486b59", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-x4vx-rjvf-j5p4"]}}, {"ruleId": "scanner-f338522e7d404ad1", "level": "error", "message": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "e14cf547177a73df", "scanner": "scanner-primary", "fingerprint": "f338522e7d404ad1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13676"]}}, {"ruleId": "scanner-43ca655ed127876d", "level": "error", "message": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "e30a4510927ee759", "scanner": "scanner-primary", "fingerprint": "43ca655ed127876d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-16221"]}}, {"ruleId": "scanner-79cfe6b5d4570979", "level": "error", "message": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "9d0592afe0a1787f", "scanner": "scanner-primary", "fingerprint": "79cfe6b5d4570979", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6321"]}}, {"ruleId": "scanner-27538b0f067bb443", "level": "error", "message": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "ea371e754a5d2586", "scanner": "scanner-primary", "fingerprint": "27538b0f067bb443", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6322"]}}, {"ruleId": "scanner-f7fe6a18f9ea9231", "level": "error", "message": {"text": "CVE-2026-12143: form-data 4.0.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "ecc9193602be88d6", "scanner": "scanner-primary", "fingerprint": "f7fe6a18f9ea9231", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12143"]}}, {"ruleId": "scanner-b060b3345fb03f59", "level": "error", "message": {"text": "CVE-2026-29045: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "7e05b67a5ec5bb96", "scanner": "scanner-primary", "fingerprint": "b060b3345fb03f59", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29045"]}}, {"ruleId": "scanner-a4142f549dca8e42", "level": "error", "message": {"text": "CVE-2026-54290: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "d62f00da48932901", "scanner": "scanner-primary", "fingerprint": "a4142f549dca8e42", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54290"]}}, {"ruleId": "scanner-7d2230078ad0fe75", "level": "warning", "message": {"text": "CVE-2026-24398: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "fce0be5889c50ec9", "scanner": "scanner-primary", "fingerprint": "7d2230078ad0fe75", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24398"]}}, {"ruleId": "scanner-3190b383c0bfc454", "level": "warning", "message": {"text": "CVE-2026-24472: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "206519d9883d84f8", "scanner": "scanner-primary", "fingerprint": "3190b383c0bfc454", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24472"]}}, {"ruleId": "scanner-df0ab16938228f95", "level": "warning", "message": {"text": "CVE-2026-24473: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "d3e2bc5902860123", "scanner": "scanner-primary", "fingerprint": "df0ab16938228f95", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24473"]}}, {"ruleId": "scanner-e09a404b949fa2cc", "level": "warning", "message": {"text": "CVE-2026-24771: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "a3a9674525de3fa6", "scanner": "scanner-primary", "fingerprint": "e09a404b949fa2cc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24771"]}}, {"ruleId": "scanner-20a8e19c0a288235", "level": "warning", "message": {"text": "CVE-2026-29085: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "d52b5d3cb30e5ce6", "scanner": "scanner-primary", "fingerprint": "20a8e19c0a288235", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29085"]}}, {"ruleId": "scanner-86ee471158bf3623", "level": "warning", "message": {"text": "CVE-2026-29086: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "25ab42c6ca318169", "scanner": "scanner-primary", "fingerprint": "86ee471158bf3623", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29086"]}}, {"ruleId": "scanner-d57022f0e8e3f390", "level": "warning", "message": {"text": "CVE-2026-39407: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "5490dd4a80778080", "scanner": "scanner-primary", "fingerprint": "d57022f0e8e3f390", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39407"]}}, {"ruleId": "scanner-584f573cacd15d47", "level": "warning", "message": {"text": "CVE-2026-39408: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "1841ab9a5dc953f8", "scanner": "scanner-primary", "fingerprint": "584f573cacd15d47", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39408"]}}, {"ruleId": "scanner-f678a9582ccf30e7", "level": "warning", "message": {"text": "CVE-2026-39409: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "97f8196cd9275d1a", "scanner": "scanner-primary", "fingerprint": "f678a9582ccf30e7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39409"]}}, {"ruleId": "scanner-ab34a189b3e03a21", "level": "warning", "message": {"text": "CVE-2026-39410: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "443bea31ed517d5a", "scanner": "scanner-primary", "fingerprint": "ab34a189b3e03a21", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39410"]}}, {"ruleId": "scanner-57bf89c16ed55d47", "level": "warning", "message": {"text": "CVE-2026-44455: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "f4a1b968d3d4da04", "scanner": "scanner-primary", "fingerprint": "57bf89c16ed55d47", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44455"]}}, {"ruleId": "scanner-7053e25698b6f5e7", "level": "warning", "message": {"text": "CVE-2026-44456: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "b659b7d734387ff7", "scanner": "scanner-primary", "fingerprint": "7053e25698b6f5e7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44456"]}}, {"ruleId": "scanner-c7977e41190df073", "level": "warning", "message": {"text": "CVE-2026-44457: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "94bbd352bc4ea8df", "scanner": "scanner-primary", "fingerprint": "c7977e41190df073", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44457"]}}, {"ruleId": "scanner-a38e2c44f914fb65", "level": "warning", "message": {"text": "CVE-2026-44458: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "ed41ec02afbb4241", "scanner": "scanner-primary", "fingerprint": "a38e2c44f914fb65", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44458"]}}, {"ruleId": "scanner-565870d2fc81539b", "level": "warning", "message": {"text": "CVE-2026-47673: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "69d2f92fd9baf30a", "scanner": "scanner-primary", "fingerprint": "565870d2fc81539b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47673"]}}, {"ruleId": "scanner-3fa2ffc76867e25b", "level": "warning", "message": {"text": "CVE-2026-47674: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "67d1ef5fed28d3ea", "scanner": "scanner-primary", "fingerprint": "3fa2ffc76867e25b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47674"]}}, {"ruleId": "scanner-693f69c730a233dc", "level": "warning", "message": {"text": "CVE-2026-47675: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "022987a6593457a9", "scanner": "scanner-primary", "fingerprint": "693f69c730a233dc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47675"]}}, {"ruleId": "scanner-13df844911bab1d5", "level": "warning", "message": {"text": "CVE-2026-47676: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "aa59023c2b3ad62d", "scanner": "scanner-primary", "fingerprint": "13df844911bab1d5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47676"]}}, {"ruleId": "scanner-5b0fc537468cf4c3", "level": "warning", "message": {"text": "CVE-2026-54286: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "e5a948c5bacce760", "scanner": "scanner-primary", "fingerprint": "5b0fc537468cf4c3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54286"]}}, {"ruleId": "scanner-f6dd9024ec5017d0", "level": "warning", "message": {"text": "CVE-2026-54287: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "eb03c35ade1aae4b", "scanner": "scanner-primary", "fingerprint": "f6dd9024ec5017d0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54287"]}}, {"ruleId": "scanner-c04c0da1e0cdc07c", "level": "warning", "message": {"text": "CVE-2026-54288: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "7425d06bbffef727", "scanner": "scanner-primary", "fingerprint": "c04c0da1e0cdc07c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54288"]}}, {"ruleId": "scanner-002cc9a1cb95ebdf", "level": "warning", "message": {"text": "CVE-2026-54289: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "bc7042187abd99a1", "scanner": "scanner-primary", "fingerprint": "002cc9a1cb95ebdf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54289"]}}, {"ruleId": "scanner-498dd78298655aea", "level": "warning", "message": {"text": "CVE-2026-56761: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "eb933fd05c5c471e", "scanner": "scanner-primary", "fingerprint": "498dd78298655aea", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-56761"]}}, {"ruleId": "scanner-20c57777f5bd0db3", "level": "warning", "message": {"text": "CVE-2026-59895: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "6b9e3e2b998c103f", "scanner": "scanner-primary", "fingerprint": "20c57777f5bd0db3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59895"]}}, {"ruleId": "scanner-83efb7fdba07b4c8", "level": "warning", "message": {"text": "CVE-2026-59897: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "2b8b3f90281a2a2f", "scanner": "scanner-primary", "fingerprint": "83efb7fdba07b4c8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59897"]}}, {"ruleId": "scanner-1216ba17dd8af3e9", "level": "warning", "message": {"text": "GHSA-26pp-8wgv-hjvm: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "b231c6e54a759f38", "scanner": "scanner-primary", "fingerprint": "1216ba17dd8af3e9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-26pp-8wgv-hjvm"]}}, {"ruleId": "scanner-9bef7bf5440c265c", "level": "warning", "message": {"text": "GHSA-v8w9-8mx6-g223: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "d474d1e0f73d2aba", "scanner": "scanner-primary", "fingerprint": "9bef7bf5440c265c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-v8w9-8mx6-g223"]}}, {"ruleId": "scanner-86ef819bf34c42b0", "level": "note", "message": {"text": "CVE-2026-44459: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "ee3df95d6509882b", "scanner": "scanner-primary", "fingerprint": "86ef819bf34c42b0", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44459"]}}, {"ruleId": "scanner-48c7485302317618", "level": "note", "message": {"text": "GHSA-gq3j-xvxp-8hrf: hono 4.11.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "f543f17fa5eab667", "scanner": "scanner-primary", "fingerprint": "48c7485302317618", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-gq3j-xvxp-8hrf"]}}, {"ruleId": "scanner-f8c0cf7ddb3f78b4", "level": "error", "message": {"text": "CVE-2026-45134: langsmith 0.3.87 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "3bac3e84adc56868", "scanner": "scanner-primary", "fingerprint": "f8c0cf7ddb3f78b4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45134"]}}, {"ruleId": "scanner-6c3a5a3dfbf40c67", "level": "warning", "message": {"text": "CVE-2026-25528: langsmith 0.3.87 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "8ceee5c560c397bc", "scanner": "scanner-primary", "fingerprint": "6c3a5a3dfbf40c67", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25528"]}}, {"ruleId": "scanner-3e7bd6fecb5a52a8", "level": "warning", "message": {"text": "CVE-2026-40190: langsmith 0.3.87 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "e8028f98fe335f78", "scanner": "scanner-primary", "fingerprint": "3e7bd6fecb5a52a8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40190"]}}, {"ruleId": "scanner-35e857ca7f1ac496", "level": "warning", "message": {"text": "CVE-2026-41182: langsmith 0.3.87 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "acc6e34f33097089", "scanner": "scanner-primary", "fingerprint": "35e857ca7f1ac496", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41182"]}}, {"ruleId": "scanner-fae51b633a002ba8", "level": "error", "message": {"text": "CVE-2026-45134: langsmith 0.4.8 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "3bac3e84adc56868", "scanner": "scanner-primary", "fingerprint": "fae51b633a002ba8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45134"]}}, {"ruleId": "scanner-737917931f74bb36", "level": "warning", "message": {"text": "CVE-2026-40190: langsmith 0.4.8 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "e8028f98fe335f78", "scanner": "scanner-primary", "fingerprint": "737917931f74bb36", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40190"]}}, {"ruleId": "scanner-7f1b7853209aa4d6", "level": "warning", "message": {"text": "CVE-2026-41182: langsmith 0.4.8 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "acc6e34f33097089", "scanner": "scanner-primary", "fingerprint": "7f1b7853209aa4d6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41182"]}}, {"ruleId": "scanner-be6154a7d56c0119", "level": "error", "message": {"text": "CVE-2026-4800: lodash-es 4.17.21 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "5107e0254598a3e4", "scanner": "scanner-primary", "fingerprint": "be6154a7d56c0119", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-d60c591788e5fde2", "level": "warning", "message": {"text": "CVE-2025-13465: lodash-es 4.17.21 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "6b85d9af87589767", "scanner": "scanner-primary", "fingerprint": "d60c591788e5fde2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-13465"]}}, {"ruleId": "scanner-057c64b00d2db54e", "level": "warning", "message": {"text": "CVE-2026-2950: lodash-es 4.17.21 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "0960be32bcd5a9a9", "scanner": "scanner-primary", "fingerprint": "057c64b00d2db54e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-5ee25e73f85672ce", "level": "error", "message": {"text": "CVE-2026-4800: lodash-es 4.17.23 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "5107e0254598a3e4", "scanner": "scanner-primary", "fingerprint": "5ee25e73f85672ce", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-f17ba385b405e7fc", "level": "warning", "message": {"text": "CVE-2026-2950: lodash-es 4.17.23 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "0960be32bcd5a9a9", "scanner": "scanner-primary", "fingerprint": "f17ba385b405e7fc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-fe8275cb340c2dc1", "level": "warning", "message": {"text": "CVE-2026-41148: mermaid 11.12.2 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "328122ea269018d0", "scanner": "scanner-primary", "fingerprint": "fe8275cb340c2dc1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41148"]}}, {"ruleId": "scanner-f7ef8cb1c948b4ab", "level": "warning", "message": {"text": "CVE-2026-41149: mermaid 11.12.2 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "5f75261948afb470", "scanner": "scanner-primary", "fingerprint": "f7ef8cb1c948b4ab", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41149"]}}, {"ruleId": "scanner-fe79823ba0d4a41f", "level": "warning", "message": {"text": "CVE-2026-41150: mermaid 11.12.2 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "8748d84797961bcf", "scanner": "scanner-primary", "fingerprint": "fe79823ba0d4a41f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41150"]}}, {"ruleId": "scanner-3b37e222a9c60eeb", "level": "warning", "message": {"text": "CVE-2026-41159: mermaid 11.12.2 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "ddd84c3b3d089eb1", "scanner": "scanner-primary", "fingerprint": "3b37e222a9c60eeb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41159"]}}, {"ruleId": "scanner-eb352fed06fe5fd4", "level": "error", "message": {"text": "CVE-2026-44573: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "540dbd9bb7c37985", "scanner": "scanner-primary", "fingerprint": "eb352fed06fe5fd4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44573"]}}, {"ruleId": "scanner-9fa7a25c11c6aee6", "level": "error", "message": {"text": "CVE-2026-44574: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "5584ad409dabc22c", "scanner": "scanner-primary", "fingerprint": "9fa7a25c11c6aee6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44574"]}}, {"ruleId": "scanner-7ea657c7a602700d", "level": "error", "message": {"text": "CVE-2026-44575: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "1d855fa89c1d6f08", "scanner": "scanner-primary", "fingerprint": "7ea657c7a602700d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44575"]}}, {"ruleId": "scanner-a77d13049f721c39", "level": "error", "message": {"text": "CVE-2026-44578: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "eb53877b8e6f2271", "scanner": "scanner-primary", "fingerprint": "a77d13049f721c39", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44578"]}}, {"ruleId": "scanner-6ff613b2e3ee5593", "level": "error", "message": {"text": "CVE-2026-44579: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "1be127913dc794b3", "scanner": "scanner-primary", "fingerprint": "6ff613b2e3ee5593", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44579"]}}, {"ruleId": "scanner-0772cc31a72770d7", "level": "error", "message": {"text": "CVE-2026-45109: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "f8cefcf11b202f8b", "scanner": "scanner-primary", "fingerprint": "0772cc31a72770d7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45109"]}}, {"ruleId": "scanner-0b790afb5fe75c8f", "level": "error", "message": {"text": "CVE-2026-64641: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "206513aab76e445a", "scanner": "scanner-primary", "fingerprint": "0b790afb5fe75c8f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64641"]}}, {"ruleId": "scanner-533b86fd1bbd1556", "level": "error", "message": {"text": "CVE-2026-64642: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "5490d1a04ffed7af", "scanner": "scanner-primary", "fingerprint": "533b86fd1bbd1556", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64642"]}}, {"ruleId": "scanner-bce81a8fc51d6c73", "level": "error", "message": {"text": "CVE-2026-64645: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "77a0c902aa4951ad", "scanner": "scanner-primary", "fingerprint": "bce81a8fc51d6c73", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64645"]}}, {"ruleId": "scanner-beb9d069a4759d28", "level": "error", "message": {"text": "CVE-2026-64649: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "a1ab633315dc31b3", "scanner": "scanner-primary", "fingerprint": "beb9d069a4759d28", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64649"]}}, {"ruleId": "scanner-6ad57425320969a8", "level": "error", "message": {"text": "GHSA-8h8q-6873-q5fj: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "97fdc8f2958260ff", "scanner": "scanner-primary", "fingerprint": "6ad57425320969a8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-8h8q-6873-q5fj"]}}, {"ruleId": "scanner-7a98b5ea98d7553e", "level": "error", "message": {"text": "GHSA-h25m-26qc-wcjf: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "2165e90a2d7707ad", "scanner": "scanner-primary", "fingerprint": "7a98b5ea98d7553e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-h25m-26qc-wcjf"]}}, {"ruleId": "scanner-b632929b6d45ed49", "level": "error", "message": {"text": "GHSA-q4gf-8mx6-v5v3: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "13d712dc1fd5d955", "scanner": "scanner-primary", "fingerprint": "b632929b6d45ed49", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-q4gf-8mx6-v5v3"]}}, {"ruleId": "scanner-2ff184872bbfcb6e", "level": "warning", "message": {"text": "CVE-2025-59471: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "9d94d13b33f3a59c", "scanner": "scanner-primary", "fingerprint": "2ff184872bbfcb6e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-59471"]}}, {"ruleId": "scanner-2dba7962dccae992", "level": "warning", "message": {"text": "CVE-2025-59472: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "839cbdc99426188f", "scanner": "scanner-primary", "fingerprint": "2dba7962dccae992", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-59472"]}}, {"ruleId": "scanner-9c6eb4a4f4a62dc4", "level": "warning", "message": {"text": "CVE-2026-27978: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "5013e7cdef37f3f2", "scanner": "scanner-primary", "fingerprint": "9c6eb4a4f4a62dc4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27978"]}}, {"ruleId": "scanner-497349c8d3b6fceb", "level": "warning", "message": {"text": "CVE-2026-27979: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "447fcdedd8fa19cf", "scanner": "scanner-primary", "fingerprint": "497349c8d3b6fceb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27979"]}}, {"ruleId": "scanner-e446540fbfb35256", "level": "warning", "message": {"text": "CVE-2026-27980: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "c99e385e10b9b426", "scanner": "scanner-primary", "fingerprint": "e446540fbfb35256", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27980"]}}, {"ruleId": "scanner-9790b10edde7fa88", "level": "warning", "message": {"text": "CVE-2026-29057: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "735629e1baa3e964", "scanner": "scanner-primary", "fingerprint": "9790b10edde7fa88", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29057"]}}, {"ruleId": "scanner-8baa115b0e32695b", "level": "warning", "message": {"text": "CVE-2026-44576: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "992c990b2d0565d0", "scanner": "scanner-primary", "fingerprint": "8baa115b0e32695b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44576"]}}, {"ruleId": "scanner-e4f2a9ca59020181", "level": "warning", "message": {"text": "CVE-2026-44577: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "04a27c2300e6bb03", "scanner": "scanner-primary", "fingerprint": "e4f2a9ca59020181", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44577"]}}, {"ruleId": "scanner-2fea8ff19f93297d", "level": "warning", "message": {"text": "CVE-2026-44580: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "329f9b4967e941cf", "scanner": "scanner-primary", "fingerprint": "2fea8ff19f93297d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44580"]}}, {"ruleId": "scanner-e91cbb00f520e9b6", "level": "warning", "message": {"text": "CVE-2026-44581: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "d77469fef98ebf96", "scanner": "scanner-primary", "fingerprint": "e91cbb00f520e9b6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44581"]}}, {"ruleId": "scanner-94428a222ad949c4", "level": "warning", "message": {"text": "CVE-2026-64643: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "6bd9ba133d56d320", "scanner": "scanner-primary", "fingerprint": "94428a222ad949c4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64643"]}}, {"ruleId": "scanner-167334b14655683d", "level": "warning", "message": {"text": "CVE-2026-64644: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "00b25114e3852837", "scanner": "scanner-primary", "fingerprint": "167334b14655683d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64644"]}}, {"ruleId": "scanner-6b1b94ee9d94272b", "level": "warning", "message": {"text": "CVE-2026-64646: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "cc04f7b9ce6da323", "scanner": "scanner-primary", "fingerprint": "6b1b94ee9d94272b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64646"]}}, {"ruleId": "scanner-81cbd2b686a8c515", "level": "warning", "message": {"text": "CVE-2026-64647: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "90c8973137104218", "scanner": "scanner-primary", "fingerprint": "81cbd2b686a8c515", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64647"]}}, {"ruleId": "scanner-e59f915ed9ec917f", "level": "warning", "message": {"text": "CVE-2026-64648: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "1849461d45ec3f31", "scanner": "scanner-primary", "fingerprint": "e59f915ed9ec917f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64648"]}}, {"ruleId": "scanner-9924e36f4ffd8102", "level": "note", "message": {"text": "CVE-2026-27977: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "6e029604408ea369", "scanner": "scanner-primary", "fingerprint": "9924e36f4ffd8102", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27977"]}}, {"ruleId": "scanner-e3a8b0dee9955c3c", "level": "note", "message": {"text": "CVE-2026-44572: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "dccaa887600b5e48", "scanner": "scanner-primary", "fingerprint": "e3a8b0dee9955c3c", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44572"]}}, {"ruleId": "scanner-30a81cf66ca57f16", "level": "note", "message": {"text": "CVE-2026-44582: next 16.1.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "c16fcabd4822ba46", "scanner": "scanner-primary", "fingerprint": "30a81cf66ca57f16", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44582"]}}, {"ruleId": "scanner-86ce9b8335dcca0b", "level": "error", "message": {"text": "CVE-2026-4867: path-to-regexp 0.1.12 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "f2d85d392a6d6b44", "scanner": "scanner-primary", "fingerprint": "86ce9b8335dcca0b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4867"]}}, {"ruleId": "scanner-0222fb556c7a5eff", "level": "error", "message": {"text": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "fd5fc2cda22320d8", "scanner": "scanner-primary", "fingerprint": "0222fb556c7a5eff", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4926"]}}, {"ruleId": "scanner-d4693592e282dc82", "level": "warning", "message": {"text": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "9169e61607f8d1d6", "scanner": "scanner-primary", "fingerprint": "d4693592e282dc82", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4923"]}}, {"ruleId": "scanner-74aa28e1e13081d3", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "82222149eca05450", "scanner": "scanner-primary", "fingerprint": "74aa28e1e13081d3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-af93b96c688d36ed", "level": "warning", "message": {"text": "CVE-2024-53382: prismjs 1.27.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "41d0b9f9153c78b6", "scanner": "scanner-primary", "fingerprint": "af93b96c688d36ed", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-53382"]}}, {"ruleId": "scanner-9fe2f0f13568b9dc", "level": "warning", "message": {"text": "CVE-2026-8723: qs 6.14.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "148ccfaccd9793e5", "scanner": "scanner-primary", "fingerprint": "9fe2f0f13568b9dc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8723"]}}, {"ruleId": "scanner-93eb7cd8ac983eb8", "level": "note", "message": {"text": "CVE-2026-2391: qs 6.14.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "59345ed9f7f9de4a", "scanner": "scanner-primary", "fingerprint": "93eb7cd8ac983eb8", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2391"]}}, {"ruleId": "scanner-4229af95ba177569", "level": "error", "message": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "687d6a26fd055a9d", "scanner": "scanner-primary", "fingerprint": "4229af95ba177569", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f88m-g3jw-g9cj"]}}, {"ruleId": "scanner-e3644a2a1d4665d9", "level": "warning", "message": {"text": "CVE-2026-12644: ts-deepmerge 7.0.3 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "8f48800a4456870b", "scanner": "scanner-primary", "fingerprint": "e3644a2a1d4665d9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12644"]}}, {"ruleId": "scanner-2d482ea60f435961", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 10.0.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "bf73a697df0d3504", "scanner": "scanner-primary", "fingerprint": "2d482ea60f435961", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-70b73452b5db073a", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "bf73a697df0d3504", "scanner": "scanner-primary", "fingerprint": "70b73452b5db073a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-4081e2c7d8d1cfe7", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "properties": {"repobilityId": "bf73a697df0d3504", "scanner": "scanner-primary", "fingerprint": "4081e2c7d8d1cfe7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-467afb15139b2922", "level": "warning", "message": {"text": "CVE-2026-22815: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "ae104cd63e78122e", "scanner": "scanner-primary", "fingerprint": "467afb15139b2922", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-22815"]}}, {"ruleId": "scanner-73aee9721dd8e858", "level": "warning", "message": {"text": "CVE-2026-34515: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "81df6a2eab5315d2", "scanner": "scanner-primary", "fingerprint": "73aee9721dd8e858", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34515"]}}, {"ruleId": "scanner-9ff770951e26e110", "level": "warning", "message": {"text": "CVE-2026-34516: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "9f36581fca9685e2", "scanner": "scanner-primary", "fingerprint": "9ff770951e26e110", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34516"]}}, {"ruleId": "scanner-54f96c902de16125", "level": "warning", "message": {"text": "CVE-2026-34525: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "f5ac1e403789b8ee", "scanner": "scanner-primary", "fingerprint": "54f96c902de16125", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34525"]}}, {"ruleId": "scanner-d5d8618477b6d126", "level": "warning", "message": {"text": "CVE-2026-34993: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "b5e8600dae3610c7", "scanner": "scanner-primary", "fingerprint": "d5d8618477b6d126", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34993"]}}, {"ruleId": "scanner-703fd3ac5e4c0be6", "level": "warning", "message": {"text": "CVE-2026-47265: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "b506da26d5854db4", "scanner": "scanner-primary", "fingerprint": "703fd3ac5e4c0be6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47265"]}}, {"ruleId": "scanner-01c27e0a5aee4775", "level": "warning", "message": {"text": "CVE-2026-54273: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "ddfd33dd92e08fca", "scanner": "scanner-primary", "fingerprint": "01c27e0a5aee4775", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54273"]}}, {"ruleId": "scanner-ee6d2516cbb15479", "level": "warning", "message": {"text": "CVE-2026-54274: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "c61314bbe518bc71", "scanner": "scanner-primary", "fingerprint": "ee6d2516cbb15479", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54274"]}}, {"ruleId": "scanner-b03a654563be231e", "level": "warning", "message": {"text": "CVE-2026-54276: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "06a2e93da055b1c0", "scanner": "scanner-primary", "fingerprint": "b03a654563be231e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54276"]}}, {"ruleId": "scanner-f16b06cc82ae3586", "level": "warning", "message": {"text": "CVE-2026-54277: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "85523169275b40a6", "scanner": "scanner-primary", "fingerprint": "f16b06cc82ae3586", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54277"]}}, {"ruleId": "scanner-0cb5d9b38ecbb0bc", "level": "warning", "message": {"text": "CVE-2026-54278: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "06c69a7960471252", "scanner": "scanner-primary", "fingerprint": "0cb5d9b38ecbb0bc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54278"]}}, {"ruleId": "scanner-015253882b0c945a", "level": "note", "message": {"text": "CVE-2026-34513: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "871f405e041a64ea", "scanner": "scanner-primary", "fingerprint": "015253882b0c945a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34513"]}}, {"ruleId": "scanner-caa08e021651a373", "level": "note", "message": {"text": "CVE-2026-34514: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "a078d23441f2436a", "scanner": "scanner-primary", "fingerprint": "caa08e021651a373", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34514"]}}, {"ruleId": "scanner-f8dd7f2505b701f4", "level": "note", "message": {"text": "CVE-2026-34517: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "24c2e587d3267126", "scanner": "scanner-primary", "fingerprint": "f8dd7f2505b701f4", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34517"]}}, {"ruleId": "scanner-9a65e3e6b727712c", "level": "note", "message": {"text": "CVE-2026-34518: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "613fa7f1005f02d0", "scanner": "scanner-primary", "fingerprint": "9a65e3e6b727712c", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34518"]}}, {"ruleId": "scanner-73564f53c5bad19c", "level": "note", "message": {"text": "CVE-2026-34519: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "cc373ae7d7a669e5", "scanner": "scanner-primary", "fingerprint": "73564f53c5bad19c", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34519"]}}, {"ruleId": "scanner-89f4c3ddbc01e51f", "level": "note", "message": {"text": "CVE-2026-34520: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "85d0d35e3aaf273c", "scanner": "scanner-primary", "fingerprint": "89f4c3ddbc01e51f", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34520"]}}, {"ruleId": "scanner-69cb7214e0b39e47", "level": "note", "message": {"text": "CVE-2026-50269: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "e540f95d2c8f28e9", "scanner": "scanner-primary", "fingerprint": "69cb7214e0b39e47", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-50269"]}}, {"ruleId": "scanner-df40681f5bd4b674", "level": "note", "message": {"text": "CVE-2026-54275: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "63e698fdadb094a9", "scanner": "scanner-primary", "fingerprint": "df40681f5bd4b674", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54275"]}}, {"ruleId": "scanner-79800e06701f2784", "level": "note", "message": {"text": "CVE-2026-54279: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "fec1b982b20d8c79", "scanner": "scanner-primary", "fingerprint": "79800e06701f2784", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54279"]}}, {"ruleId": "scanner-8b438f87801fda4d", "level": "note", "message": {"text": "CVE-2026-54280: aiohttp 3.13.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "4352b530464fefbe", "scanner": "scanner-primary", "fingerprint": "8b438f87801fda4d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54280"]}}, {"ruleId": "scanner-ee6398a00b92ca86", "level": "warning", "message": {"text": "CVE-2026-41425: authlib 1.6.9 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "0a609ed8e32a6297", "scanner": "scanner-primary", "fingerprint": "ee6398a00b92ca86", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41425"]}}, {"ruleId": "scanner-51c09d5b24bd2ac9", "level": "warning", "message": {"text": "CVE-2026-41479: authlib 1.6.9 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "425949d8b2c8172f", "scanner": "scanner-primary", "fingerprint": "51c09d5b24bd2ac9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41479"]}}, {"ruleId": "scanner-912eef5d8d665524", "level": "warning", "message": {"text": "CVE-2026-44681: authlib 1.6.9 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "2c84e79b5919c786", "scanner": "scanner-primary", "fingerprint": "912eef5d8d665524", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44681"]}}, {"ruleId": "scanner-71254bab4f0165c1", "level": "error", "message": {"text": "GHSA-537c-gmf6-5ccf: cryptography 46.0.5 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "328475ef111db984", "scanner": "scanner-primary", "fingerprint": "71254bab4f0165c1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-537c-gmf6-5ccf"]}}, {"ruleId": "scanner-38f3d788f84ad7a5", "level": "warning", "message": {"text": "CVE-2026-39892: cryptography 46.0.5 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "f97d2dada6970f0b", "scanner": "scanner-primary", "fingerprint": "38f3d788f84ad7a5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39892"]}}, {"ruleId": "scanner-688ea7ea06a63b5a", "level": "note", "message": {"text": "CVE-2026-34073: cryptography 46.0.5 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "5f0f0411399f3d4b", "scanner": "scanner-primary", "fingerprint": "688ea7ea06a63b5a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34073"]}}, {"ruleId": "scanner-f321dd7385d5bdee", "level": "error", "message": {"text": "CVE-2026-4810: google-adk 1.26.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "6b7b83a7625ac138", "scanner": "scanner-primary", "fingerprint": "f321dd7385d5bdee", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4810"]}}, {"ruleId": "scanner-4c0aa1b520ac5f65", "level": "warning", "message": {"text": "CVE-2026-45409: idna 3.11 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "97f746cbe06d4f9a", "scanner": "scanner-primary", "fingerprint": "4c0aa1b520ac5f65", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45409"]}}, {"ruleId": "scanner-c8d911b388ab2c8f", "level": "error", "message": {"text": "CVE-2026-41205: mako 1.3.10 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "641cc6d22506a82d", "scanner": "scanner-primary", "fingerprint": "c8d911b388ab2c8f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41205"]}}, {"ruleId": "scanner-3cc5ff059554142f", "level": "error", "message": {"text": "CVE-2026-44307: mako 1.3.10 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "3b81ac94e908dccc", "scanner": "scanner-primary", "fingerprint": "3cc5ff059554142f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44307"]}}, {"ruleId": "scanner-e3e11053302e5cd1", "level": "error", "message": {"text": "CVE-2026-52869: mcp 1.26.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "44e788db93e4fd34", "scanner": "scanner-primary", "fingerprint": "e3e11053302e5cd1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-52869"]}}, {"ruleId": "scanner-5b86fa422a690b0b", "level": "error", "message": {"text": "CVE-2026-52870: mcp 1.26.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "7cc2a3ae3ce40fd3", "scanner": "scanner-primary", "fingerprint": "5b86fa422a690b0b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-52870"]}}, {"ruleId": "scanner-7149da2b21257860", "level": "error", "message": {"text": "CVE-2026-59950: mcp 1.26.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "b0df2cfcee9454de", "scanner": "scanner-primary", "fingerprint": "7149da2b21257860", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59950"]}}, {"ruleId": "scanner-5ecefc57ae9cf626", "level": "error", "message": {"text": "CVE-2026-30922: pyasn1 0.6.2 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "da0ebae6ba74b1e0", "scanner": "scanner-primary", "fingerprint": "5ecefc57ae9cf626", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-30922"]}}, {"ruleId": "scanner-191addef057ac181", "level": "error", "message": {"text": "CVE-2026-59885: pyasn1 0.6.2 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "1aa7c31af17f624b", "scanner": "scanner-primary", "fingerprint": "191addef057ac181", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59885"]}}, {"ruleId": "scanner-b908577be6148f12", "level": "error", "message": {"text": "CVE-2026-59886: pyasn1 0.6.2 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "5b0ba5478c634933", "scanner": "scanner-primary", "fingerprint": "b908577be6148f12", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59886"]}}, {"ruleId": "scanner-8cda57397929680c", "level": "warning", "message": {"text": "GHSA-4xgf-cpjx-pc3j: pydantic-settings 2.13.1 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "aa5de0f9e87d8a4d", "scanner": "scanner-primary", "fingerprint": "8cda57397929680c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-4xgf-cpjx-pc3j"]}}, {"ruleId": "scanner-a3e00ecc5e9b4b5d", "level": "error", "message": {"text": "CVE-2026-32597: pyjwt 2.11.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "29eb1f973e9c7c4c", "scanner": "scanner-primary", "fingerprint": "a3e00ecc5e9b4b5d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-32597"]}}, {"ruleId": "scanner-ac1868d6eb97fffc", "level": "error", "message": {"text": "CVE-2026-48526: pyjwt 2.11.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "bfceab4aa403c2c3", "scanner": "scanner-primary", "fingerprint": "ac1868d6eb97fffc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48526"]}}, {"ruleId": "scanner-39e1f46ae7c8d96a", "level": "warning", "message": {"text": "CVE-2026-48522: pyjwt 2.11.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "4de133c3dc0592d4", "scanner": "scanner-primary", "fingerprint": "39e1f46ae7c8d96a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48522"]}}, {"ruleId": "scanner-581bfb436edf9657", "level": "warning", "message": {"text": "CVE-2026-48523: pyjwt 2.11.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "904842b09f4ac80c", "scanner": "scanner-primary", "fingerprint": "581bfb436edf9657", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48523"]}}, {"ruleId": "scanner-01579caf25951d94", "level": "warning", "message": {"text": "CVE-2026-48525: pyjwt 2.11.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "53c72a81ebc26d3a", "scanner": "scanner-primary", "fingerprint": "01579caf25951d94", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48525"]}}, {"ruleId": "scanner-ed29724b4ca6f40c", "level": "note", "message": {"text": "CVE-2026-48524: pyjwt 2.11.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "44c019a514116abb", "scanner": "scanner-primary", "fingerprint": "ed29724b4ca6f40c", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48524"]}}, {"ruleId": "scanner-50b5a0c50a4c4ac0", "level": "error", "message": {"text": "CVE-2026-27459: pyopenssl 25.3.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "31716e4ae923c085", "scanner": "scanner-primary", "fingerprint": "50b5a0c50a4c4ac0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27459"]}}, {"ruleId": "scanner-29ae7ea06dc4e1d3", "level": "note", "message": {"text": "CVE-2026-27448: pyopenssl 25.3.0 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "716783e348c5fd3a", "scanner": "scanner-primary", "fingerprint": "29ae7ea06dc4e1d3", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27448"]}}, {"ruleId": "scanner-eb75742e82e43f15", "level": "error", "message": {"text": "CVE-2026-42561: python-multipart 0.0.22 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "ee46e33303953ff2", "scanner": "scanner-primary", "fingerprint": "eb75742e82e43f15", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42561"]}}, {"ruleId": "scanner-95b52dc839cb081b", "level": "error", "message": {"text": "CVE-2026-53539: python-multipart 0.0.22 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "912678aff6b830a0", "scanner": "scanner-primary", "fingerprint": "95b52dc839cb081b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53539"]}}, {"ruleId": "scanner-c4b71473cd8d0218", "level": "warning", "message": {"text": "CVE-2026-40347: python-multipart 0.0.22 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "909406af40e02009", "scanner": "scanner-primary", "fingerprint": "c4b71473cd8d0218", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40347"]}}, {"ruleId": "scanner-050c28636ca13807", "level": "note", "message": {"text": "CVE-2026-53537: python-multipart 0.0.22 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "1d95bba361beba1b", "scanner": "scanner-primary", "fingerprint": "050c28636ca13807", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53537"]}}, {"ruleId": "scanner-d1957ee7066c4377", "level": "note", "message": {"text": "CVE-2026-53538: python-multipart 0.0.22 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "af12d0eaa3ff70cd", "scanner": "scanner-primary", "fingerprint": "d1957ee7066c4377", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53538"]}}, {"ruleId": "scanner-f2e23bdcf513e9fa", "level": "note", "message": {"text": "CVE-2026-53540: python-multipart 0.0.22 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "da1ea8d1269bb1e3", "scanner": "scanner-primary", "fingerprint": "f2e23bdcf513e9fa", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53540"]}}, {"ruleId": "scanner-c3333920eeff3ae8", "level": "warning", "message": {"text": "CVE-2026-25645: requests 2.32.5 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "9f7c3a6ebb696abe", "scanner": "scanner-primary", "fingerprint": "c3333920eeff3ae8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25645"]}}, {"ruleId": "scanner-d2c53a9f29442fb4", "level": "error", "message": {"text": "CVE-2026-48818: starlette 0.52.1 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "b73aafbb2a018201", "scanner": "scanner-primary", "fingerprint": "d2c53a9f29442fb4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48818"]}}, {"ruleId": "scanner-d42c60b1b9b0fb4f", "level": "error", "message": {"text": "CVE-2026-54283: starlette 0.52.1 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "80ac541ccca7ddb7", "scanner": "scanner-primary", "fingerprint": "d42c60b1b9b0fb4f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54283"]}}, {"ruleId": "scanner-2a4328f08d420670", "level": "warning", "message": {"text": "CVE-2026-48710: starlette 0.52.1 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "f884b466b37d0815", "scanner": "scanner-primary", "fingerprint": "2a4328f08d420670", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48710"]}}, {"ruleId": "scanner-8bb7a580295c15a9", "level": "warning", "message": {"text": "CVE-2026-48817: starlette 0.52.1 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "fb6401f4fa1da0ea", "scanner": "scanner-primary", "fingerprint": "8bb7a580295c15a9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48817"]}}, {"ruleId": "scanner-f746d08463abe509", "level": "note", "message": {"text": "CVE-2026-54282: starlette 0.52.1 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "168dbc99eff77a33", "scanner": "scanner-primary", "fingerprint": "f746d08463abe509", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54282"]}}, {"ruleId": "scanner-a52dac1c27c03863", "level": "error", "message": {"text": "CVE-2026-44431: urllib3 2.6.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "ffe8769e9a96bcbf", "scanner": "scanner-primary", "fingerprint": "a52dac1c27c03863", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44431"]}}, {"ruleId": "scanner-ce0f6135696cb41a", "level": "error", "message": {"text": "CVE-2026-44432: urllib3 2.6.3 \u2014 generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "properties": {"repobilityId": "3bac265e175a7448", "scanner": "scanner-primary", "fingerprint": "ce0f6135696cb41a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44432"]}}, {"ruleId": "scanner-9ceb1a889a7aee5d", "level": "note", "message": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.23 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "23b7e169555deb60", "scanner": "scanner-primary", "fingerprint": "9ceb1a889a7aee5d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8769"]}}, {"ruleId": "scanner-2034fdeab49de2a5", "level": "warning", "message": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.14 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "1bc34899c0ce4a34", "scanner": "scanner-primary", "fingerprint": "2034fdeab49de2a5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-frvp-7c67-39w9"]}}, {"ruleId": "scanner-98b9a7753d37eebf", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 1.20.4 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "a78a65ad92622f3b", "scanner": "scanner-primary", "fingerprint": "98b9a7753d37eebf", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-1ba0e4c0a4c40f98", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "a78a65ad92622f3b", "scanner": "scanner-primary", "fingerprint": "1ba0e4c0a4c40f98", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-e3afe13db581902c", "level": "warning", "message": {"text": "CVE-2026-49458: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "ebcee1e5e7a1168c", "scanner": "scanner-primary", "fingerprint": "e3afe13db581902c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49458"]}}, {"ruleId": "scanner-e3903fd46c82430a", "level": "warning", "message": {"text": "CVE-2026-49459: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "693502d371c321f2", "scanner": "scanner-primary", "fingerprint": "e3903fd46c82430a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49459"]}}, {"ruleId": "scanner-cee95b06006c6b0b", "level": "warning", "message": {"text": "CVE-2026-49978: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "e70d41c8217b22ce", "scanner": "scanner-primary", "fingerprint": "cee95b06006c6b0b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49978"]}}, {"ruleId": "scanner-68ae8541ddab24ad", "level": "warning", "message": {"text": "GHSA-76mc-f452-cxcm: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "d9df5e3a51128839", "scanner": "scanner-primary", "fingerprint": "68ae8541ddab24ad", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-76mc-f452-cxcm"]}}, {"ruleId": "scanner-cb00491cb6423447", "level": "warning", "message": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "8cf305eb4e8ffa07", "scanner": "scanner-primary", "fingerprint": "cb00491cb6423447", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cmwh-pvxp-8882"]}}, {"ruleId": "scanner-ef44d9d2bb9c45de", "level": "note", "message": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "934d9e8b3427d5e5", "scanner": "scanner-primary", "fingerprint": "ef44d9d2bb9c45de", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-c2j3-45gr-mqc4"]}}, {"ruleId": "scanner-bb419ba562d55659", "level": "note", "message": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "47d14e3012bf3b55", "scanner": "scanner-primary", "fingerprint": "bb419ba562d55659", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-gvmj-g25r-r7wr"]}}, {"ruleId": "scanner-f3e80c87133493be", "level": "note", "message": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "f49ffa1a6c6df779", "scanner": "scanner-primary", "fingerprint": "f3e80c87133493be", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-vxr8-fq34-vvx9"]}}, {"ruleId": "scanner-d958878f35cec63a", "level": "note", "message": {"text": "GHSA-x4vx-rjvf-j5p4: dompurify 3.4.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "775d3db8d69bc07f", "scanner": "scanner-primary", "fingerprint": "d958878f35cec63a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-x4vx-rjvf-j5p4"]}}, {"ruleId": "scanner-1640ebac96888741", "level": "error", "message": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "09ab3bd993952e81", "scanner": "scanner-primary", "fingerprint": "1640ebac96888741", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13676"]}}, {"ruleId": "scanner-84659a08492ea51c", "level": "error", "message": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "46ced793c0c41e33", "scanner": "scanner-primary", "fingerprint": "84659a08492ea51c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-16221"]}}, {"ruleId": "scanner-9a64bec523f5a5cc", "level": "error", "message": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "7fccfb826ce6ce88", "scanner": "scanner-primary", "fingerprint": "9a64bec523f5a5cc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6321"]}}, {"ruleId": "scanner-b8c9b3b3d88ceecb", "level": "error", "message": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "feb13f15ec570f1c", "scanner": "scanner-primary", "fingerprint": "b8c9b3b3d88ceecb", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6322"]}}, {"ruleId": "scanner-ff2d0668f040fc89", "level": "error", "message": {"text": "CVE-2026-54290: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "d5c3bc23d5edb08f", "scanner": "scanner-primary", "fingerprint": "ff2d0668f040fc89", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54290"]}}, {"ruleId": "scanner-014f7155fa09511c", "level": "warning", "message": {"text": "CVE-2026-44455: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "6862a645c73508b4", "scanner": "scanner-primary", "fingerprint": "014f7155fa09511c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44455"]}}, {"ruleId": "scanner-d3811ba66a7224d4", "level": "warning", "message": {"text": "CVE-2026-44456: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "e94fd0e3627c6258", "scanner": "scanner-primary", "fingerprint": "d3811ba66a7224d4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44456"]}}, {"ruleId": "scanner-961b514163af9cc8", "level": "warning", "message": {"text": "CVE-2026-44457: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "72f0a4a849631636", "scanner": "scanner-primary", "fingerprint": "961b514163af9cc8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44457"]}}, {"ruleId": "scanner-f08124d733ccc2dc", "level": "warning", "message": {"text": "CVE-2026-44458: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "6b21285684f65ab9", "scanner": "scanner-primary", "fingerprint": "f08124d733ccc2dc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44458"]}}, {"ruleId": "scanner-7f34323f4f697eb3", "level": "warning", "message": {"text": "CVE-2026-47673: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "c31019e238851e15", "scanner": "scanner-primary", "fingerprint": "7f34323f4f697eb3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47673"]}}, {"ruleId": "scanner-461c4c2ac3ade471", "level": "warning", "message": {"text": "CVE-2026-47674: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "6eb4ee9a3ffa844e", "scanner": "scanner-primary", "fingerprint": "461c4c2ac3ade471", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47674"]}}, {"ruleId": "scanner-5ac2560617d0289c", "level": "warning", "message": {"text": "CVE-2026-47675: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "b444f0c0a7a47540", "scanner": "scanner-primary", "fingerprint": "5ac2560617d0289c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47675"]}}, {"ruleId": "scanner-4279f8d130e7b263", "level": "warning", "message": {"text": "CVE-2026-47676: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "bc790ea9a1df92f5", "scanner": "scanner-primary", "fingerprint": "4279f8d130e7b263", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47676"]}}, {"ruleId": "scanner-913fb208e20dcf48", "level": "warning", "message": {"text": "CVE-2026-54286: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "ab94996aa785fb5a", "scanner": "scanner-primary", "fingerprint": "913fb208e20dcf48", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54286"]}}, {"ruleId": "scanner-2cc0e1f5b08b9fe1", "level": "warning", "message": {"text": "CVE-2026-54287: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "6f250c78d095b198", "scanner": "scanner-primary", "fingerprint": "2cc0e1f5b08b9fe1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54287"]}}, {"ruleId": "scanner-827fb8d4ffd4bc55", "level": "warning", "message": {"text": "CVE-2026-54288: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "685b1756a0506d68", "scanner": "scanner-primary", "fingerprint": "827fb8d4ffd4bc55", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54288"]}}, {"ruleId": "scanner-bb1f23c66f5a0955", "level": "warning", "message": {"text": "CVE-2026-54289: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "32b29bee8931ca6e", "scanner": "scanner-primary", "fingerprint": "bb1f23c66f5a0955", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54289"]}}, {"ruleId": "scanner-a00f456a8a21bd00", "level": "warning", "message": {"text": "CVE-2026-59895: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "562f8c220d21e721", "scanner": "scanner-primary", "fingerprint": "a00f456a8a21bd00", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59895"]}}, {"ruleId": "scanner-2671460d16907554", "level": "warning", "message": {"text": "CVE-2026-59896: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "fe42be7e6859bcf5", "scanner": "scanner-primary", "fingerprint": "2671460d16907554", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59896"]}}, {"ruleId": "scanner-250d26bf6bcca5de", "level": "warning", "message": {"text": "CVE-2026-59897: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "a0e9d2e81f8c1d13", "scanner": "scanner-primary", "fingerprint": "250d26bf6bcca5de", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59897"]}}, {"ruleId": "scanner-3e05adb62e2541d1", "level": "note", "message": {"text": "CVE-2026-44459: hono 4.12.15 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "06626f88a2dc7b44", "scanner": "scanner-primary", "fingerprint": "3e05adb62e2541d1", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44459"]}}, {"ruleId": "scanner-1951324b06e8b398", "level": "warning", "message": {"text": "CVE-2026-42338: ip-address 10.1.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "53d1ad4ffac1f3ed", "scanner": "scanner-primary", "fingerprint": "1951324b06e8b398", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42338"]}}, {"ruleId": "scanner-aeffec36fa8778fd", "level": "error", "message": {"text": "CVE-2026-45134: langsmith 0.5.25 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "58888fe669e0cd71", "scanner": "scanner-primary", "fingerprint": "aeffec36fa8778fd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45134"]}}, {"ruleId": "scanner-9e8229c2083c89f8", "level": "warning", "message": {"text": "CVE-2026-41148: mermaid 11.14.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "7b510ee38865ff29", "scanner": "scanner-primary", "fingerprint": "9e8229c2083c89f8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41148"]}}, {"ruleId": "scanner-ac14fb6e780d639b", "level": "warning", "message": {"text": "CVE-2026-41149: mermaid 11.14.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "a3d06e0a5ceab8c6", "scanner": "scanner-primary", "fingerprint": "ac14fb6e780d639b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41149"]}}, {"ruleId": "scanner-2dae155444cc52e9", "level": "warning", "message": {"text": "CVE-2026-41150: mermaid 11.14.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "c0c788cae530f536", "scanner": "scanner-primary", "fingerprint": "2dae155444cc52e9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41150"]}}, {"ruleId": "scanner-32d9a7e9d2a1a0ea", "level": "warning", "message": {"text": "CVE-2026-41159: mermaid 11.14.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "fdaab40edcb67af8", "scanner": "scanner-primary", "fingerprint": "32d9a7e9d2a1a0ea", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41159"]}}, {"ruleId": "scanner-003f4239fdf88f3a", "level": "error", "message": {"text": "CVE-2026-44573: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "4f10fdb277e068c7", "scanner": "scanner-primary", "fingerprint": "003f4239fdf88f3a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44573"]}}, {"ruleId": "scanner-ae4891b41312c3b0", "level": "error", "message": {"text": "CVE-2026-44574: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "c7c8c00ecd63b8dd", "scanner": "scanner-primary", "fingerprint": "ae4891b41312c3b0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44574"]}}, {"ruleId": "scanner-d050fac239020078", "level": "error", "message": {"text": "CVE-2026-44575: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "98ca433729ba0f1f", "scanner": "scanner-primary", "fingerprint": "d050fac239020078", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44575"]}}, {"ruleId": "scanner-c2df79a9e636ca9b", "level": "error", "message": {"text": "CVE-2026-44578: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "fbb9fd26bcd89f38", "scanner": "scanner-primary", "fingerprint": "c2df79a9e636ca9b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44578"]}}, {"ruleId": "scanner-6248daf72b9d0e52", "level": "error", "message": {"text": "CVE-2026-44579: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "399551dad381264f", "scanner": "scanner-primary", "fingerprint": "6248daf72b9d0e52", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44579"]}}, {"ruleId": "scanner-701b5b14ebe31d3f", "level": "error", "message": {"text": "CVE-2026-45109: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "af60628a1e4bee5b", "scanner": "scanner-primary", "fingerprint": "701b5b14ebe31d3f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45109"]}}, {"ruleId": "scanner-d7eb7dd002e60e49", "level": "error", "message": {"text": "CVE-2026-64641: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "af14799a8a343d5e", "scanner": "scanner-primary", "fingerprint": "d7eb7dd002e60e49", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64641"]}}, {"ruleId": "scanner-2581afa48c4e4491", "level": "error", "message": {"text": "CVE-2026-64642: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "2594ac2b7e8e78e1", "scanner": "scanner-primary", "fingerprint": "2581afa48c4e4491", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64642"]}}, {"ruleId": "scanner-88f5df084a036f0c", "level": "error", "message": {"text": "CVE-2026-64645: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "4a53d9459023187d", "scanner": "scanner-primary", "fingerprint": "88f5df084a036f0c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64645"]}}, {"ruleId": "scanner-9ed650eb9c2e99bd", "level": "error", "message": {"text": "CVE-2026-64649: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "af07d2d2745cb15d", "scanner": "scanner-primary", "fingerprint": "9ed650eb9c2e99bd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64649"]}}, {"ruleId": "scanner-3b5ea31cc0821a05", "level": "error", "message": {"text": "GHSA-8h8q-6873-q5fj: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "53562c335ae0c60b", "scanner": "scanner-primary", "fingerprint": "3b5ea31cc0821a05", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-8h8q-6873-q5fj"]}}, {"ruleId": "scanner-15041d8034ad7545", "level": "error", "message": {"text": "GHSA-h25m-26qc-wcjf: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "95d6ee721f426c74", "scanner": "scanner-primary", "fingerprint": "15041d8034ad7545", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-h25m-26qc-wcjf"]}}, {"ruleId": "scanner-56ae987fed3e992a", "level": "error", "message": {"text": "GHSA-q4gf-8mx6-v5v3: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "7ce2db49df8e1c0c", "scanner": "scanner-primary", "fingerprint": "56ae987fed3e992a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-q4gf-8mx6-v5v3"]}}, {"ruleId": "scanner-4c20be9ba942ae50", "level": "warning", "message": {"text": "CVE-2025-59471: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "c83925ec37583102", "scanner": "scanner-primary", "fingerprint": "4c20be9ba942ae50", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-59471"]}}, {"ruleId": "scanner-1688914e8f79cf93", "level": "warning", "message": {"text": "CVE-2025-59472: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "1f581bfedd6f894e", "scanner": "scanner-primary", "fingerprint": "1688914e8f79cf93", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-59472"]}}, {"ruleId": "scanner-dc2303e8797c40d5", "level": "warning", "message": {"text": "CVE-2026-27978: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "beddebd4fdb500ff", "scanner": "scanner-primary", "fingerprint": "dc2303e8797c40d5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27978"]}}, {"ruleId": "scanner-95d0ea88d45ddf26", "level": "warning", "message": {"text": "CVE-2026-27979: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "e5b1054db48d5141", "scanner": "scanner-primary", "fingerprint": "95d0ea88d45ddf26", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27979"]}}, {"ruleId": "scanner-bce5b9ddef87e8a6", "level": "warning", "message": {"text": "CVE-2026-27980: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "ac101be81617640f", "scanner": "scanner-primary", "fingerprint": "bce5b9ddef87e8a6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27980"]}}, {"ruleId": "scanner-7bcbd29607e37893", "level": "warning", "message": {"text": "CVE-2026-29057: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "52e0b07866aeb6a5", "scanner": "scanner-primary", "fingerprint": "7bcbd29607e37893", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29057"]}}, {"ruleId": "scanner-28efc85238389836", "level": "warning", "message": {"text": "CVE-2026-44576: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "9833613fc9ab67bf", "scanner": "scanner-primary", "fingerprint": "28efc85238389836", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44576"]}}, {"ruleId": "scanner-c408a2fc5bcfea00", "level": "warning", "message": {"text": "CVE-2026-44577: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "548d07b8639542e2", "scanner": "scanner-primary", "fingerprint": "c408a2fc5bcfea00", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44577"]}}, {"ruleId": "scanner-37d78b5b7901a9be", "level": "warning", "message": {"text": "CVE-2026-44580: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "31be7fcbfba322c2", "scanner": "scanner-primary", "fingerprint": "37d78b5b7901a9be", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44580"]}}, {"ruleId": "scanner-bd4c241258782f49", "level": "warning", "message": {"text": "CVE-2026-44581: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "5ff4e5c47e119144", "scanner": "scanner-primary", "fingerprint": "bd4c241258782f49", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44581"]}}, {"ruleId": "scanner-3344eb18acd02488", "level": "warning", "message": {"text": "CVE-2026-64643: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "740a1f8eb232edb7", "scanner": "scanner-primary", "fingerprint": "3344eb18acd02488", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64643"]}}, {"ruleId": "scanner-73d7bc237c97635f", "level": "warning", "message": {"text": "CVE-2026-64644: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "e67035fd1ab722ef", "scanner": "scanner-primary", "fingerprint": "73d7bc237c97635f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64644"]}}, {"ruleId": "scanner-19ad8290ee9fa2e9", "level": "warning", "message": {"text": "CVE-2026-64646: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "9d3e539a3302bf18", "scanner": "scanner-primary", "fingerprint": "19ad8290ee9fa2e9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64646"]}}, {"ruleId": "scanner-01b64404c49b0e02", "level": "warning", "message": {"text": "CVE-2026-64647: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "142bf0f1f4d87c52", "scanner": "scanner-primary", "fingerprint": "01b64404c49b0e02", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64647"]}}, {"ruleId": "scanner-7c963f5e5d9abfb4", "level": "warning", "message": {"text": "CVE-2026-64648: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "bded3740780e3f2d", "scanner": "scanner-primary", "fingerprint": "7c963f5e5d9abfb4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64648"]}}, {"ruleId": "scanner-356c4fd35fc77d23", "level": "note", "message": {"text": "CVE-2026-27977: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "27abe852ea080699", "scanner": "scanner-primary", "fingerprint": "356c4fd35fc77d23", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27977"]}}, {"ruleId": "scanner-319719615df1944c", "level": "note", "message": {"text": "CVE-2026-44572: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "f44b1bc9018f98e8", "scanner": "scanner-primary", "fingerprint": "319719615df1944c", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44572"]}}, {"ruleId": "scanner-d71fc9d8bde3199d", "level": "note", "message": {"text": "CVE-2026-44582: next 16.1.1 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "7420c67c35095382", "scanner": "scanner-primary", "fingerprint": "d71fc9d8bde3199d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44582"]}}, {"ruleId": "scanner-eda3b07955dd098b", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "a6af72be3ade19af", "scanner": "scanner-primary", "fingerprint": "eda3b07955dd098b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-b7d8afed0482b4f2", "level": "warning", "message": {"text": "CVE-2024-53382: prismjs 1.27.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "8cc83bf767037926", "scanner": "scanner-primary", "fingerprint": "b7d8afed0482b4f2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-53382"]}}, {"ruleId": "scanner-cf8ea94e32587cd6", "level": "warning", "message": {"text": "CVE-2026-8723: qs 6.14.2 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "4ce67ef72f499573", "scanner": "scanner-primary", "fingerprint": "cf8ea94e32587cd6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8723"]}}, {"ruleId": "scanner-7ac71c3dbb5d915f", "level": "error", "message": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "b311ceed7740d107", "scanner": "scanner-primary", "fingerprint": "7ac71c3dbb5d915f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f88m-g3jw-g9cj"]}}, {"ruleId": "scanner-a28047ca3be9a5c3", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 10.0.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "be494a21e8da063a", "scanner": "scanner-primary", "fingerprint": "a28047ca3be9a5c3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-419cbbf214eb69af", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "be494a21e8da063a", "scanner": "scanner-primary", "fingerprint": "419cbbf214eb69af", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-436066a6315d64f1", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 13.0.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "be494a21e8da063a", "scanner": "scanner-primary", "fingerprint": "436066a6315d64f1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-b1e068c6fe591eb5", "level": "error", "message": {"text": "CVE-2026-48779: ws 8.20.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "f6cba5cc7bca5b9d", "scanner": "scanner-primary", "fingerprint": "b1e068c6fe591eb5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48779"]}}, {"ruleId": "scanner-8f11b15288db8850", "level": "warning", "message": {"text": "CVE-2026-45736: ws 8.20.0 \u2014 generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "properties": {"repobilityId": "385cc66f0ab501f5", "scanner": "scanner-primary", "fingerprint": "8f11b15288db8850", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45736"]}}, {"ruleId": "scanner-e740376317b7677c", "level": "note", "message": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 2.2.8 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "90e0bedbe597526e", "scanner": "scanner-primary", "fingerprint": "e740376317b7677c", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8769"]}}, {"ruleId": "scanner-4779db578cbc8851", "level": "note", "message": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.22 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "90e0bedbe597526e", "scanner": "scanner-primary", "fingerprint": "4779db578cbc8851", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8769"]}}, {"ruleId": "scanner-165b809d490257c4", "level": "warning", "message": {"text": "CVE-2026-39406: @hono/node-server 1.19.12 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "eae57a490519507e", "scanner": "scanner-primary", "fingerprint": "165b809d490257c4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39406"]}}, {"ruleId": "scanner-4282bcd1f6487e80", "level": "warning", "message": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.12 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "17b6f5de5cc87a89", "scanner": "scanner-primary", "fingerprint": "4282bcd1f6487e80", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-frvp-7c67-39w9"]}}, {"ruleId": "scanner-29c7df28751c5304", "level": "warning", "message": {"text": "CVE-2026-54285: @opentelemetry/core 2.2.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "439911726acb2fb9", "scanner": "scanner-primary", "fingerprint": "29c7df28751c5304", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54285"]}}, {"ruleId": "scanner-746c95293a54c3d6", "level": "warning", "message": {"text": "CVE-2026-54285: @opentelemetry/core 2.6.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "439911726acb2fb9", "scanner": "scanner-primary", "fingerprint": "746c95293a54c3d6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54285"]}}, {"ruleId": "scanner-9e36bcb26e6c2a93", "level": "warning", "message": {"text": "CVE-2026-44288: @protobufjs/utf8 1.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "f44ae6ab1eb2a090", "scanner": "scanner-primary", "fingerprint": "9e36bcb26e6c2a93", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44288"]}}, {"ruleId": "scanner-37f116b89eebcca7", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 1.20.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "2ec0a13cce1d9716", "scanner": "scanner-primary", "fingerprint": "37f116b89eebcca7", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-f9bf6b5a86b77e62", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "2ec0a13cce1d9716", "scanner": "scanner-primary", "fingerprint": "f9bf6b5a86b77e62", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-9cb5f4c20004df35", "level": "error", "message": {"text": "CVE-2026-13149: brace-expansion 5.0.5 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "b04e165a7b92a3df", "scanner": "scanner-primary", "fingerprint": "9cb5f4c20004df35", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13149"]}}, {"ruleId": "scanner-b8ea256807ca7e28", "level": "warning", "message": {"text": "CVE-2026-45149: brace-expansion 5.0.5 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "94d7275182596710", "scanner": "scanner-primary", "fingerprint": "b8ea256807ca7e28", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45149"]}}, {"ruleId": "scanner-b9c3e2fd46b03c46", "level": "warning", "message": {"text": "CVE-2026-41238: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "8da47fe22786e95c", "scanner": "scanner-primary", "fingerprint": "b9c3e2fd46b03c46", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41238"]}}, {"ruleId": "scanner-c9f195da9eb845a4", "level": "warning", "message": {"text": "CVE-2026-41239: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "a0df7eecce07caa7", "scanner": "scanner-primary", "fingerprint": "c9f195da9eb845a4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41239"]}}, {"ruleId": "scanner-e34fa2d41c9872de", "level": "warning", "message": {"text": "CVE-2026-41240: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "4351fa98e67e5cf5", "scanner": "scanner-primary", "fingerprint": "e34fa2d41c9872de", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41240"]}}, {"ruleId": "scanner-b4ea8d621c636357", "level": "warning", "message": {"text": "CVE-2026-49458: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "d30a9ac0f72e46d6", "scanner": "scanner-primary", "fingerprint": "b4ea8d621c636357", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49458"]}}, {"ruleId": "scanner-49a81e5ac3b913c9", "level": "warning", "message": {"text": "CVE-2026-49459: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "c4ff4a399408dd6f", "scanner": "scanner-primary", "fingerprint": "49a81e5ac3b913c9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49459"]}}, {"ruleId": "scanner-ece7bb79ccac969c", "level": "warning", "message": {"text": "CVE-2026-49978: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "6d6691a645b20e2f", "scanner": "scanner-primary", "fingerprint": "ece7bb79ccac969c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49978"]}}, {"ruleId": "scanner-b361b86e839e1aa3", "level": "warning", "message": {"text": "GHSA-39q2-94rc-95cp: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "b4b9767fac62ed09", "scanner": "scanner-primary", "fingerprint": "b361b86e839e1aa3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-39q2-94rc-95cp"]}}, {"ruleId": "scanner-2564d77525aefeea", "level": "warning", "message": {"text": "GHSA-76mc-f452-cxcm: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "afb9842f852c09af", "scanner": "scanner-primary", "fingerprint": "2564d77525aefeea", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-76mc-f452-cxcm"]}}, {"ruleId": "scanner-29fba25a03d2c12b", "level": "warning", "message": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "7acae107346184d4", "scanner": "scanner-primary", "fingerprint": "29fba25a03d2c12b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cmwh-pvxp-8882"]}}, {"ruleId": "scanner-ab35c956a2b1c12f", "level": "note", "message": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "e130274364436993", "scanner": "scanner-primary", "fingerprint": "ab35c956a2b1c12f", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-c2j3-45gr-mqc4"]}}, {"ruleId": "scanner-86ee908deba78d3e", "level": "note", "message": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "cc88343fc8a98260", "scanner": "scanner-primary", "fingerprint": "86ee908deba78d3e", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-gvmj-g25r-r7wr"]}}, {"ruleId": "scanner-24e85ae7b0e5ad8b", "level": "note", "message": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "b068194ac9f9c81d", "scanner": "scanner-primary", "fingerprint": "24e85ae7b0e5ad8b", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-vxr8-fq34-vvx9"]}}, {"ruleId": "scanner-e8898a0dfa2bba6f", "level": "note", "message": {"text": "GHSA-x4vx-rjvf-j5p4: dompurify 3.3.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "06abf594a95559ce", "scanner": "scanner-primary", "fingerprint": "e8898a0dfa2bba6f", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-x4vx-rjvf-j5p4"]}}, {"ruleId": "scanner-d8d99547efd8f37d", "level": "note", "message": {"text": "GHSA-g7r4-m6w7-qqqr: esbuild 0.27.5 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "339f81cf642f3b37", "scanner": "scanner-primary", "fingerprint": "d8d99547efd8f37d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-g7r4-m6w7-qqqr"]}}, {"ruleId": "scanner-be9deb89e4605da6", "level": "error", "message": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "bb54978a6d90699d", "scanner": "scanner-primary", "fingerprint": "be9deb89e4605da6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13676"]}}, {"ruleId": "scanner-40445d8139c47348", "level": "error", "message": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "1fa58fc1dab3f2fd", "scanner": "scanner-primary", "fingerprint": "40445d8139c47348", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-16221"]}}, {"ruleId": "scanner-db0571e3db52f310", "level": "error", "message": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "020e8c1029e3df36", "scanner": "scanner-primary", "fingerprint": "db0571e3db52f310", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6321"]}}, {"ruleId": "scanner-93cf54db1d01bd9f", "level": "error", "message": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "3b05760a35c3a0b2", "scanner": "scanner-primary", "fingerprint": "93cf54db1d01bd9f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6322"]}}, {"ruleId": "scanner-c066bf2c45b1c9fd", "level": "error", "message": {"text": "CVE-2026-12143: form-data 4.0.5 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "1ec2122c204f35d3", "scanner": "scanner-primary", "fingerprint": "c066bf2c45b1c9fd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12143"]}}, {"ruleId": "scanner-260c7563bccdf897", "level": "error", "message": {"text": "CVE-2026-54290: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "9730f8019a6ca5fe", "scanner": "scanner-primary", "fingerprint": "260c7563bccdf897", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54290"]}}, {"ruleId": "scanner-7f6e18e11c43737e", "level": "warning", "message": {"text": "CVE-2026-39407: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "f65d1b2367948e91", "scanner": "scanner-primary", "fingerprint": "7f6e18e11c43737e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39407"]}}, {"ruleId": "scanner-d11076d2d263cb3e", "level": "warning", "message": {"text": "CVE-2026-39408: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "5d4e960b38933376", "scanner": "scanner-primary", "fingerprint": "d11076d2d263cb3e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39408"]}}, {"ruleId": "scanner-d0a91d8127cd45bb", "level": "warning", "message": {"text": "CVE-2026-39409: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "2fa143d1e9acdaec", "scanner": "scanner-primary", "fingerprint": "d0a91d8127cd45bb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39409"]}}, {"ruleId": "scanner-8b91ac1042cef62f", "level": "warning", "message": {"text": "CVE-2026-39410: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "b24ebc745cae930e", "scanner": "scanner-primary", "fingerprint": "8b91ac1042cef62f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39410"]}}, {"ruleId": "scanner-3839496490d17cc8", "level": "warning", "message": {"text": "CVE-2026-44455: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "d884b85a1daa7886", "scanner": "scanner-primary", "fingerprint": "3839496490d17cc8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44455"]}}, {"ruleId": "scanner-35bd0ca22a9e704c", "level": "warning", "message": {"text": "CVE-2026-44456: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "48915fc39b83341b", "scanner": "scanner-primary", "fingerprint": "35bd0ca22a9e704c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44456"]}}, {"ruleId": "scanner-e574752fda402774", "level": "warning", "message": {"text": "CVE-2026-44457: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "b7ca9ecaad9861de", "scanner": "scanner-primary", "fingerprint": "e574752fda402774", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44457"]}}, {"ruleId": "scanner-41a04ca764f69756", "level": "warning", "message": {"text": "CVE-2026-44458: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "106f2f7cd4eac663", "scanner": "scanner-primary", "fingerprint": "41a04ca764f69756", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44458"]}}, {"ruleId": "scanner-45aa1e13ad161248", "level": "warning", "message": {"text": "CVE-2026-47673: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "32ed6d40e8a22587", "scanner": "scanner-primary", "fingerprint": "45aa1e13ad161248", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47673"]}}, {"ruleId": "scanner-2de6385625ef116c", "level": "warning", "message": {"text": "CVE-2026-47674: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "c40c90e73b1c6a02", "scanner": "scanner-primary", "fingerprint": "2de6385625ef116c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47674"]}}, {"ruleId": "scanner-db37e7e151b30490", "level": "warning", "message": {"text": "CVE-2026-47675: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "ae1013c190fc3745", "scanner": "scanner-primary", "fingerprint": "db37e7e151b30490", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47675"]}}, {"ruleId": "scanner-80aac3b7ef660f7d", "level": "warning", "message": {"text": "CVE-2026-47676: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "ad9115760027fbfb", "scanner": "scanner-primary", "fingerprint": "80aac3b7ef660f7d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47676"]}}, {"ruleId": "scanner-4b19225b7c481f5c", "level": "warning", "message": {"text": "CVE-2026-54286: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "b8c909ab3e15de84", "scanner": "scanner-primary", "fingerprint": "4b19225b7c481f5c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54286"]}}, {"ruleId": "scanner-14c0e3765e0610b1", "level": "warning", "message": {"text": "CVE-2026-54287: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "449e58b78798073f", "scanner": "scanner-primary", "fingerprint": "14c0e3765e0610b1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54287"]}}, {"ruleId": "scanner-922db8ff46ed53f4", "level": "warning", "message": {"text": "CVE-2026-54288: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "acb6f1012a019c58", "scanner": "scanner-primary", "fingerprint": "922db8ff46ed53f4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54288"]}}, {"ruleId": "scanner-b88cb966fd3b6c3c", "level": "warning", "message": {"text": "CVE-2026-54289: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "7a3e27354d550523", "scanner": "scanner-primary", "fingerprint": "b88cb966fd3b6c3c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54289"]}}, {"ruleId": "scanner-58d187d68030830c", "level": "warning", "message": {"text": "CVE-2026-56761: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "f9c5168bb662adfa", "scanner": "scanner-primary", "fingerprint": "58d187d68030830c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-56761"]}}, {"ruleId": "scanner-fa5567229be0c1ba", "level": "warning", "message": {"text": "CVE-2026-59895: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "0ecb15038a36fc39", "scanner": "scanner-primary", "fingerprint": "fa5567229be0c1ba", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59895"]}}, {"ruleId": "scanner-95429fc107c0f8c9", "level": "warning", "message": {"text": "CVE-2026-59896: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "b59aefbbc3a493e9", "scanner": "scanner-primary", "fingerprint": "95429fc107c0f8c9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59896"]}}, {"ruleId": "scanner-253ff8f6c8e71e63", "level": "warning", "message": {"text": "CVE-2026-59897: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "4891b5454653aaed", "scanner": "scanner-primary", "fingerprint": "253ff8f6c8e71e63", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59897"]}}, {"ruleId": "scanner-cea84fab78aaa0f6", "level": "warning", "message": {"text": "GHSA-26pp-8wgv-hjvm: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "af14bf9ec3765ba9", "scanner": "scanner-primary", "fingerprint": "cea84fab78aaa0f6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-26pp-8wgv-hjvm"]}}, {"ruleId": "scanner-9d413679b10876f9", "level": "note", "message": {"text": "CVE-2026-44459: hono 4.12.10 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "381e8ce85a9f5e99", "scanner": "scanner-primary", "fingerprint": "9d413679b10876f9", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44459"]}}, {"ruleId": "scanner-c5a3456e11ecbf55", "level": "warning", "message": {"text": "CVE-2026-42338: ip-address 10.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "b0c5f6be3441b876", "scanner": "scanner-primary", "fingerprint": "c5a3456e11ecbf55", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42338"]}}, {"ruleId": "scanner-71d5ae1338762ea0", "level": "error", "message": {"text": "CVE-2026-59869: js-yaml 3.14.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "7f423600817297f8", "scanner": "scanner-primary", "fingerprint": "71d5ae1338762ea0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59869"]}}, {"ruleId": "scanner-bd0c00dd8d244051", "level": "warning", "message": {"text": "CVE-2026-53550: js-yaml 3.14.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "f95640fd718d5bb3", "scanner": "scanner-primary", "fingerprint": "bd0c00dd8d244051", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53550"]}}, {"ruleId": "scanner-1a2d50b9e026e90d", "level": "error", "message": {"text": "CVE-2026-59869: js-yaml 4.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "7f423600817297f8", "scanner": "scanner-primary", "fingerprint": "1a2d50b9e026e90d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59869"]}}, {"ruleId": "scanner-de0ee7e12c7ce037", "level": "warning", "message": {"text": "CVE-2026-53550: js-yaml 4.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "f95640fd718d5bb3", "scanner": "scanner-primary", "fingerprint": "de0ee7e12c7ce037", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53550"]}}, {"ruleId": "scanner-2e6957225ac9d682", "level": "error", "message": {"text": "CVE-2026-45134: langsmith 0.3.87 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "6d09a058918a69b5", "scanner": "scanner-primary", "fingerprint": "2e6957225ac9d682", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45134"]}}, {"ruleId": "scanner-d151a813e5dca388", "level": "warning", "message": {"text": "CVE-2026-25528: langsmith 0.3.87 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "e13438bce585aa4f", "scanner": "scanner-primary", "fingerprint": "d151a813e5dca388", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25528"]}}, {"ruleId": "scanner-7d9005d2bbbff8fb", "level": "warning", "message": {"text": "CVE-2026-40190: langsmith 0.3.87 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "afbafc1e87f8529c", "scanner": "scanner-primary", "fingerprint": "7d9005d2bbbff8fb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40190"]}}, {"ruleId": "scanner-3e36a629f6b85e21", "level": "warning", "message": {"text": "CVE-2026-41182: langsmith 0.3.87 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "77181420e4bb89de", "scanner": "scanner-primary", "fingerprint": "3e36a629f6b85e21", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41182"]}}, {"ruleId": "scanner-e034d1ec33de71cf", "level": "error", "message": {"text": "CVE-2026-45134: langsmith 0.5.16 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "6d09a058918a69b5", "scanner": "scanner-primary", "fingerprint": "e034d1ec33de71cf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45134"]}}, {"ruleId": "scanner-7a6acbdf2653b7ce", "level": "warning", "message": {"text": "CVE-2026-40190: langsmith 0.5.16 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "afbafc1e87f8529c", "scanner": "scanner-primary", "fingerprint": "7a6acbdf2653b7ce", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40190"]}}, {"ruleId": "scanner-4eed585e2b7fb808", "level": "warning", "message": {"text": "CVE-2026-41182: langsmith 0.5.16 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "77181420e4bb89de", "scanner": "scanner-primary", "fingerprint": "4eed585e2b7fb808", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41182"]}}, {"ruleId": "scanner-3b2af901bd388b18", "level": "error", "message": {"text": "CVE-2026-48801: linkify-it 5.0.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "a7cdeaf71b0a40b2", "scanner": "scanner-primary", "fingerprint": "3b2af901bd388b18", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48801"]}}, {"ruleId": "scanner-eadf681250669e67", "level": "error", "message": {"text": "CVE-2026-59887: linkify-it 5.0.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "a3f6386db9533430", "scanner": "scanner-primary", "fingerprint": "eadf681250669e67", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59887"]}}, {"ruleId": "scanner-b13c87f5369ef792", "level": "error", "message": {"text": "CVE-2026-4800: lodash 4.17.21 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "8cdfdc01675836d9", "scanner": "scanner-primary", "fingerprint": "b13c87f5369ef792", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-7e616d77a8446b57", "level": "warning", "message": {"text": "CVE-2025-13465: lodash 4.17.21 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "e539e337dcea4993", "scanner": "scanner-primary", "fingerprint": "7e616d77a8446b57", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-13465"]}}, {"ruleId": "scanner-d566ab4f53a5bbef", "level": "warning", "message": {"text": "CVE-2026-2950: lodash 4.17.21 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "0727bca446f1b683", "scanner": "scanner-primary", "fingerprint": "d566ab4f53a5bbef", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-409e0cc56707168e", "level": "error", "message": {"text": "CVE-2026-4800: lodash-es 4.17.23 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "d20c1567c0fb6d29", "scanner": "scanner-primary", "fingerprint": "409e0cc56707168e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-03710688818e18cf", "level": "warning", "message": {"text": "CVE-2026-2950: lodash-es 4.17.23 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "1b6a357ec0473158", "scanner": "scanner-primary", "fingerprint": "03710688818e18cf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-28de748363c9dec3", "level": "warning", "message": {"text": "CVE-2026-48988: markdown-it 14.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "3511462cc28cdb8e", "scanner": "scanner-primary", "fingerprint": "28de748363c9dec3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48988"]}}, {"ruleId": "scanner-2dd7982841ebdc54", "level": "warning", "message": {"text": "CVE-2026-41148: mermaid 11.14.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "cea11a02f8abc563", "scanner": "scanner-primary", "fingerprint": "2dd7982841ebdc54", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41148"]}}, {"ruleId": "scanner-66f8c9ed1f03530a", "level": "warning", "message": {"text": "CVE-2026-41149: mermaid 11.14.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "1f11c591b123c21d", "scanner": "scanner-primary", "fingerprint": "66f8c9ed1f03530a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41149"]}}, {"ruleId": "scanner-474ccc0bb6f6c545", "level": "warning", "message": {"text": "CVE-2026-41150: mermaid 11.14.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "65f0dc22d0e39c93", "scanner": "scanner-primary", "fingerprint": "474ccc0bb6f6c545", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41150"]}}, {"ruleId": "scanner-27bee6b6abfc6e0e", "level": "warning", "message": {"text": "CVE-2026-41159: mermaid 11.14.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "987a0923ee53ab47", "scanner": "scanner-primary", "fingerprint": "27bee6b6abfc6e0e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41159"]}}, {"ruleId": "scanner-97626e505a1b3c07", "level": "error", "message": {"text": "CVE-2026-44573: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "7b7647b50b380430", "scanner": "scanner-primary", "fingerprint": "97626e505a1b3c07", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44573"]}}, {"ruleId": "scanner-a0d14c027f2fa43b", "level": "error", "message": {"text": "CVE-2026-44574: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "2c55cb57a8cccfec", "scanner": "scanner-primary", "fingerprint": "a0d14c027f2fa43b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44574"]}}, {"ruleId": "scanner-ec0fc622339496d6", "level": "error", "message": {"text": "CVE-2026-44575: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "953ab127a4c61339", "scanner": "scanner-primary", "fingerprint": "ec0fc622339496d6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44575"]}}, {"ruleId": "scanner-a57e9f8f4cc01f45", "level": "error", "message": {"text": "CVE-2026-44578: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "10c7634ee501c558", "scanner": "scanner-primary", "fingerprint": "a57e9f8f4cc01f45", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44578"]}}, {"ruleId": "scanner-5e5cf5b1f564fc7e", "level": "error", "message": {"text": "CVE-2026-44579: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "cdcf91bc3db30d6a", "scanner": "scanner-primary", "fingerprint": "5e5cf5b1f564fc7e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44579"]}}, {"ruleId": "scanner-b786ed9cb9a4a312", "level": "error", "message": {"text": "CVE-2026-45109: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "e50d7d650e84e7e8", "scanner": "scanner-primary", "fingerprint": "b786ed9cb9a4a312", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45109"]}}, {"ruleId": "scanner-5451b7692d10069b", "level": "error", "message": {"text": "CVE-2026-64641: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "4b075a0c2f78c763", "scanner": "scanner-primary", "fingerprint": "5451b7692d10069b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64641"]}}, {"ruleId": "scanner-791e2caf22771e93", "level": "error", "message": {"text": "CVE-2026-64642: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "e7c4ef6339741e48", "scanner": "scanner-primary", "fingerprint": "791e2caf22771e93", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64642"]}}, {"ruleId": "scanner-e24093207db87bf9", "level": "error", "message": {"text": "CVE-2026-64645: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "8fa97e81d0dd73a9", "scanner": "scanner-primary", "fingerprint": "e24093207db87bf9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64645"]}}, {"ruleId": "scanner-d25c68e839f18a1e", "level": "error", "message": {"text": "CVE-2026-64649: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "dcae2f0083310b6f", "scanner": "scanner-primary", "fingerprint": "d25c68e839f18a1e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64649"]}}, {"ruleId": "scanner-785029bd5422fdc7", "level": "error", "message": {"text": "GHSA-8h8q-6873-q5fj: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "30b65e5134401642", "scanner": "scanner-primary", "fingerprint": "785029bd5422fdc7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-8h8q-6873-q5fj"]}}, {"ruleId": "scanner-23bcfe2069663b0a", "level": "error", "message": {"text": "GHSA-h25m-26qc-wcjf: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "2a15a3a5334c61fe", "scanner": "scanner-primary", "fingerprint": "23bcfe2069663b0a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-h25m-26qc-wcjf"]}}, {"ruleId": "scanner-9fc8c7703b37ab21", "level": "error", "message": {"text": "GHSA-q4gf-8mx6-v5v3: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "550d2ec19d481922", "scanner": "scanner-primary", "fingerprint": "9fc8c7703b37ab21", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-q4gf-8mx6-v5v3"]}}, {"ruleId": "scanner-df3c05752c379e10", "level": "warning", "message": {"text": "CVE-2025-59471: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "a0b5cdde6a209490", "scanner": "scanner-primary", "fingerprint": "df3c05752c379e10", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-59471"]}}, {"ruleId": "scanner-98b3e50526fe9b06", "level": "warning", "message": {"text": "CVE-2025-59472: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "fd362a3fb3bb7bcf", "scanner": "scanner-primary", "fingerprint": "98b3e50526fe9b06", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-59472"]}}, {"ruleId": "scanner-89b3f0c25d7ced7a", "level": "warning", "message": {"text": "CVE-2026-27978: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "504c88b5b719b52f", "scanner": "scanner-primary", "fingerprint": "89b3f0c25d7ced7a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27978"]}}, {"ruleId": "scanner-7ed994e8975a7ef3", "level": "warning", "message": {"text": "CVE-2026-27979: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "a072e07aff00d10a", "scanner": "scanner-primary", "fingerprint": "7ed994e8975a7ef3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27979"]}}, {"ruleId": "scanner-ce01f56283ddb4e9", "level": "warning", "message": {"text": "CVE-2026-27980: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "ba2092f5b437a10b", "scanner": "scanner-primary", "fingerprint": "ce01f56283ddb4e9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27980"]}}, {"ruleId": "scanner-b0db9091546811bd", "level": "warning", "message": {"text": "CVE-2026-29057: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "03f72bfdec99b8a2", "scanner": "scanner-primary", "fingerprint": "b0db9091546811bd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29057"]}}, {"ruleId": "scanner-715a4140f9e3c685", "level": "warning", "message": {"text": "CVE-2026-44576: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "cdbcd628556e4a9b", "scanner": "scanner-primary", "fingerprint": "715a4140f9e3c685", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44576"]}}, {"ruleId": "scanner-d46d7c1e01ea9fdf", "level": "warning", "message": {"text": "CVE-2026-44577: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "65d264d39d377b02", "scanner": "scanner-primary", "fingerprint": "d46d7c1e01ea9fdf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44577"]}}, {"ruleId": "scanner-aaa97a670870a27b", "level": "warning", "message": {"text": "CVE-2026-44580: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "960f31a986dfd492", "scanner": "scanner-primary", "fingerprint": "aaa97a670870a27b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44580"]}}, {"ruleId": "scanner-5792d6f035023c92", "level": "warning", "message": {"text": "CVE-2026-44581: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "8c1630ee86714038", "scanner": "scanner-primary", "fingerprint": "5792d6f035023c92", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44581"]}}, {"ruleId": "scanner-894ddc0e35cdee60", "level": "warning", "message": {"text": "CVE-2026-64643: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "5363234d4ae31324", "scanner": "scanner-primary", "fingerprint": "894ddc0e35cdee60", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64643"]}}, {"ruleId": "scanner-c1689fb7065a38d1", "level": "warning", "message": {"text": "CVE-2026-64644: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "bcb198309cfa1a6b", "scanner": "scanner-primary", "fingerprint": "c1689fb7065a38d1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64644"]}}, {"ruleId": "scanner-70a313ad8a8884ef", "level": "warning", "message": {"text": "CVE-2026-64646: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "a954be02dc622ff3", "scanner": "scanner-primary", "fingerprint": "70a313ad8a8884ef", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64646"]}}, {"ruleId": "scanner-c2cec4d317eed887", "level": "warning", "message": {"text": "CVE-2026-64647: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "be490ea929e17e40", "scanner": "scanner-primary", "fingerprint": "c2cec4d317eed887", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64647"]}}, {"ruleId": "scanner-28b4dba1a648bae9", "level": "warning", "message": {"text": "CVE-2026-64648: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "526ee26988c5e1cf", "scanner": "scanner-primary", "fingerprint": "28b4dba1a648bae9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64648"]}}, {"ruleId": "scanner-bff05d415cc2b43e", "level": "note", "message": {"text": "CVE-2026-27977: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "dd169aaa7b4f8db0", "scanner": "scanner-primary", "fingerprint": "bff05d415cc2b43e", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27977"]}}, {"ruleId": "scanner-ba3fc24f68369dd1", "level": "note", "message": {"text": "CVE-2026-44572: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "19f3bddf91fa9871", "scanner": "scanner-primary", "fingerprint": "ba3fc24f68369dd1", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44572"]}}, {"ruleId": "scanner-a982509542acabd4", "level": "note", "message": {"text": "CVE-2026-44582: next 16.1.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "c8787d26ddf164e4", "scanner": "scanner-primary", "fingerprint": "a982509542acabd4", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44582"]}}, {"ruleId": "scanner-69b3d74bfb9d489c", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "88e58f03b3d9b55c", "scanner": "scanner-primary", "fingerprint": "69b3d74bfb9d489c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-88ea987e3f005eaf", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.5.8 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "88e58f03b3d9b55c", "scanner": "scanner-primary", "fingerprint": "88ea987e3f005eaf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-0765674e0f501112", "level": "warning", "message": {"text": "CVE-2024-53382: prismjs 1.27.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "5d6c58d73669e458", "scanner": "scanner-primary", "fingerprint": "0765674e0f501112", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-53382"]}}, {"ruleId": "scanner-efb5a0bcf62857e9", "level": "error", "message": {"text": "CVE-2026-41242: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "978468876c54ed48", "scanner": "scanner-primary", "fingerprint": "efb5a0bcf62857e9", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41242"]}}, {"ruleId": "scanner-8c4126834d7c4a5e", "level": "error", "message": {"text": "CVE-2026-44289: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "91a24e85bb3e5f41", "scanner": "scanner-primary", "fingerprint": "8c4126834d7c4a5e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44289"]}}, {"ruleId": "scanner-d4c7e614dd81731d", "level": "error", "message": {"text": "CVE-2026-44290: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "cda378eb681d6562", "scanner": "scanner-primary", "fingerprint": "d4c7e614dd81731d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44290"]}}, {"ruleId": "scanner-d7842a22007aab80", "level": "error", "message": {"text": "CVE-2026-44291: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "9071dbd7d174c572", "scanner": "scanner-primary", "fingerprint": "d7842a22007aab80", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44291"]}}, {"ruleId": "scanner-be649db53c281eef", "level": "error", "message": {"text": "CVE-2026-44293: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "357e70fb99b59f25", "scanner": "scanner-primary", "fingerprint": "be649db53c281eef", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44293"]}}, {"ruleId": "scanner-49a285db6d989e5d", "level": "error", "message": {"text": "CVE-2026-48712: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "a426503481801c98", "scanner": "scanner-primary", "fingerprint": "49a285db6d989e5d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48712"]}}, {"ruleId": "scanner-d6f5848a58efeb0b", "level": "warning", "message": {"text": "CVE-2026-44288: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "8400dde1c67655b5", "scanner": "scanner-primary", "fingerprint": "d6f5848a58efeb0b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44288"]}}, {"ruleId": "scanner-39695d4bb8601afd", "level": "warning", "message": {"text": "CVE-2026-44292: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "29181f6371314265", "scanner": "scanner-primary", "fingerprint": "39695d4bb8601afd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44292"]}}, {"ruleId": "scanner-e1676a6d9cb65d50", "level": "warning", "message": {"text": "CVE-2026-44294: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "a8e3793ca37d559a", "scanner": "scanner-primary", "fingerprint": "e1676a6d9cb65d50", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44294"]}}, {"ruleId": "scanner-75c09b8ae933ee31", "level": "warning", "message": {"text": "CVE-2026-45740: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "10dca259f82308c3", "scanner": "scanner-primary", "fingerprint": "75c09b8ae933ee31", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45740"]}}, {"ruleId": "scanner-4cfbfd9aaf43a366", "level": "warning", "message": {"text": "CVE-2026-54269: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "461ec3323d9efe53", "scanner": "scanner-primary", "fingerprint": "4cfbfd9aaf43a366", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54269"]}}, {"ruleId": "scanner-c7358c1b78485bba", "level": "warning", "message": {"text": "CVE-2026-59877: protobufjs 7.5.4 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "5531b80404a10077", "scanner": "scanner-primary", "fingerprint": "c7358c1b78485bba", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59877"]}}, {"ruleId": "scanner-67f565b3a6348a2f", "level": "warning", "message": {"text": "CVE-2026-8723: qs 6.14.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "67a36934bc0fa980", "scanner": "scanner-primary", "fingerprint": "67f565b3a6348a2f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8723"]}}, {"ruleId": "scanner-b76c482485c8be13", "level": "warning", "message": {"text": "CVE-2026-8723: qs 6.15.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "67a36934bc0fa980", "scanner": "scanner-primary", "fingerprint": "b76c482485c8be13", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8723"]}}, {"ruleId": "scanner-421ac77a0b4a2ec5", "level": "error", "message": {"text": "CVE-2026-34077: react-router 7.13.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "b8437b6729e13512", "scanner": "scanner-primary", "fingerprint": "421ac77a0b4a2ec5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34077"]}}, {"ruleId": "scanner-eb4efd0c3213999b", "level": "error", "message": {"text": "CVE-2026-42211: react-router 7.13.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "ffd8255a2c49b6ca", "scanner": "scanner-primary", "fingerprint": "eb4efd0c3213999b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42211"]}}, {"ruleId": "scanner-30f86e1408bbce91", "level": "error", "message": {"text": "CVE-2026-42342: react-router 7.13.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "0fc892a8bf912a91", "scanner": "scanner-primary", "fingerprint": "30f86e1408bbce91", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42342"]}}, {"ruleId": "scanner-3275dd453d5a2971", "level": "warning", "message": {"text": "CVE-2026-40181: react-router 7.13.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "95332f876768c528", "scanner": "scanner-primary", "fingerprint": "3275dd453d5a2971", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40181"]}}, {"ruleId": "scanner-65fd9d03b7e8d358", "level": "note", "message": {"text": "CVE-2026-53663: react-router 7.13.2 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "5f85977c762dbfb3", "scanner": "scanner-primary", "fingerprint": "65fd9d03b7e8d358", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53663"]}}, {"ruleId": "scanner-46346e448c6c11ad", "level": "error", "message": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "3c8d20bf2c5cc86e", "scanner": "scanner-primary", "fingerprint": "46346e448c6c11ad", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f88m-g3jw-g9cj"]}}, {"ruleId": "scanner-6a28b0b8e8517a9c", "level": "error", "message": {"text": "CVE-2026-59873: tar 7.5.13 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "8a25f9f8bb724fc8", "scanner": "scanner-primary", "fingerprint": "6a28b0b8e8517a9c", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59873"]}}, {"ruleId": "scanner-90af57803c1be2e6", "level": "error", "message": {"text": "CVE-2026-59874: tar 7.5.13 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "7eee718e3b9e544f", "scanner": "scanner-primary", "fingerprint": "90af57803c1be2e6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59874"]}}, {"ruleId": "scanner-b967a82df4bcb772", "level": "warning", "message": {"text": "CVE-2026-53655: tar 7.5.13 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "70af9b6041ae3212", "scanner": "scanner-primary", "fingerprint": "b967a82df4bcb772", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53655"]}}, {"ruleId": "scanner-5ffbc7b09ed6cb96", "level": "warning", "message": {"text": "CVE-2026-59871: tar 7.5.13 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "d85f447aa66c77a7", "scanner": "scanner-primary", "fingerprint": "5ffbc7b09ed6cb96", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59871"]}}, {"ruleId": "scanner-ae4cfd95051a88ae", "level": "warning", "message": {"text": "CVE-2026-59875: tar 7.5.13 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "c95af337d332e473", "scanner": "scanner-primary", "fingerprint": "ae4cfd95051a88ae", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59875"]}}, {"ruleId": "scanner-17e382f7b42f9d94", "level": "warning", "message": {"text": "CVE-2026-12644: ts-deepmerge 7.0.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "87066253bb1403b0", "scanner": "scanner-primary", "fingerprint": "17e382f7b42f9d94", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12644"]}}, {"ruleId": "scanner-8fc0874561a7da84", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 10.0.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "7849a73a81ef4132", "scanner": "scanner-primary", "fingerprint": "8fc0874561a7da84", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-e5eca0332f773fdb", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "7849a73a81ef4132", "scanner": "scanner-primary", "fingerprint": "e5eca0332f773fdb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-c575cf5f7fc3fa4f", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 13.0.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "7849a73a81ef4132", "scanner": "scanner-primary", "fingerprint": "c575cf5f7fc3fa4f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-66869d2a79a0974c", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "7849a73a81ef4132", "scanner": "scanner-primary", "fingerprint": "66869d2a79a0974c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-517dc4aba531e62f", "level": "error", "message": {"text": "CVE-2026-39363: vite 7.3.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "3f7a425f5f7eca11", "scanner": "scanner-primary", "fingerprint": "517dc4aba531e62f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39363"]}}, {"ruleId": "scanner-e251cae305e13fd2", "level": "error", "message": {"text": "CVE-2026-39364: vite 7.3.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "57d6d5050c765edc", "scanner": "scanner-primary", "fingerprint": "e251cae305e13fd2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39364"]}}, {"ruleId": "scanner-c887b75d574aa151", "level": "error", "message": {"text": "CVE-2026-53571: vite 7.3.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "de9c7af5367ebe2a", "scanner": "scanner-primary", "fingerprint": "c887b75d574aa151", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53571"]}}, {"ruleId": "scanner-fb17f77ccf054c3a", "level": "warning", "message": {"text": "CVE-2026-39365: vite 7.3.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "b2a4d5a8d85d0be5", "scanner": "scanner-primary", "fingerprint": "fb17f77ccf054c3a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39365"]}}, {"ruleId": "scanner-4344b4fdc4e95b26", "level": "warning", "message": {"text": "CVE-2026-53632: vite 7.3.1 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "59fbf9632b0b8596", "scanner": "scanner-primary", "fingerprint": "4344b4fdc4e95b26", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53632"]}}, {"ruleId": "scanner-28771a6dc29e3619", "level": "error", "message": {"text": "CVE-2026-39363: vite 8.0.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "3f7a425f5f7eca11", "scanner": "scanner-primary", "fingerprint": "28771a6dc29e3619", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39363"]}}, {"ruleId": "scanner-0bc597416bdeb338", "level": "error", "message": {"text": "CVE-2026-39364: vite 8.0.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "57d6d5050c765edc", "scanner": "scanner-primary", "fingerprint": "0bc597416bdeb338", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39364"]}}, {"ruleId": "scanner-53f622b1f95222f6", "level": "error", "message": {"text": "CVE-2026-53571: vite 8.0.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "de9c7af5367ebe2a", "scanner": "scanner-primary", "fingerprint": "53f622b1f95222f6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53571"]}}, {"ruleId": "scanner-5ac2d058f346ff1e", "level": "warning", "message": {"text": "CVE-2026-39365: vite 8.0.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "b2a4d5a8d85d0be5", "scanner": "scanner-primary", "fingerprint": "5ac2d058f346ff1e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39365"]}}, {"ruleId": "scanner-e453a02452b1ebac", "level": "warning", "message": {"text": "CVE-2026-53632: vite 8.0.3 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "59fbf9632b0b8596", "scanner": "scanner-primary", "fingerprint": "e453a02452b1ebac", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53632"]}}, {"ruleId": "scanner-628a8a0e2e77150f", "level": "error", "message": {"text": "CVE-2026-48779: ws 8.20.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "3e61487036a32d50", "scanner": "scanner-primary", "fingerprint": "628a8a0e2e77150f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48779"]}}, {"ruleId": "scanner-6d035f4255d07a3c", "level": "warning", "message": {"text": "CVE-2026-45736: ws 8.20.0 \u2014 generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "properties": {"repobilityId": "a41b0d268fe6949d", "scanner": "scanner-primary", "fingerprint": "6d035f4255d07a3c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45736"]}}, {"ruleId": "scanner-d5fd01ba6d4dab28", "level": "warning", "message": {"text": "CVE-2026-45409: idna 3.11 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "e808166cedc5c36c", "scanner": "scanner-primary", "fingerprint": "d5fd01ba6d4dab28", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45409"]}}, {"ruleId": "scanner-3c620c9b8b653482", "level": "warning", "message": {"text": "CVE-2026-55443: langchain 1.2.0 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "f8e203f2970f22c5", "scanner": "scanner-primary", "fingerprint": "3c620c9b8b653482", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55443"]}}, {"ruleId": "scanner-b43a520329315d09", "level": "error", "message": {"text": "CVE-2026-34070: langchain-core 1.2.16 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "1fba27d06e2771be", "scanner": "scanner-primary", "fingerprint": "b43a520329315d09", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34070"]}}, {"ruleId": "scanner-8fe834f814bad093", "level": "error", "message": {"text": "CVE-2026-44843: langchain-core 1.2.16 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "53ee59d8d6b1b4fb", "scanner": "scanner-primary", "fingerprint": "8fe834f814bad093", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44843"]}}, {"ruleId": "scanner-bf9cf71c80181c87", "level": "warning", "message": {"text": "CVE-2026-40087: langchain-core 1.2.16 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "09f752623bd78dc8", "scanner": "scanner-primary", "fingerprint": "bf9cf71c80181c87", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40087"]}}, {"ruleId": "scanner-848cca510f37d60e", "level": "note", "message": {"text": "CVE-2026-41488: langchain-openai 1.1.9 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "12d455e61c722c7e", "scanner": "scanner-primary", "fingerprint": "848cca510f37d60e", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41488"]}}, {"ruleId": "scanner-5efb7dd8275cff1e", "level": "warning", "message": {"text": "CVE-2026-28277: langgraph 1.0.7 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "9cd120cd55b28487", "scanner": "scanner-primary", "fingerprint": "5efb7dd8275cff1e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28277"]}}, {"ruleId": "scanner-b104dd588c5a47f7", "level": "warning", "message": {"text": "CVE-2026-27794: langgraph-checkpoint 3.0.1 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "4785de268f9ae936", "scanner": "scanner-primary", "fingerprint": "b104dd588c5a47f7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27794"]}}, {"ruleId": "scanner-739253171751eb47", "level": "warning", "message": {"text": "CVE-2026-48775: langgraph-checkpoint 3.0.1 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "98c773d51b121080", "scanner": "scanner-primary", "fingerprint": "739253171751eb47", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48775"]}}, {"ruleId": "scanner-c070c288aa5a9226", "level": "warning", "message": {"text": "CVE-2026-48776: langgraph-sdk 0.3.9 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "b97e356d9622ae4b", "scanner": "scanner-primary", "fingerprint": "c070c288aa5a9226", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48776"]}}, {"ruleId": "scanner-35707d83d62572c4", "level": "error", "message": {"text": "CVE-2026-45134: langsmith 0.6.6 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "ef47dd38da4962c7", "scanner": "scanner-primary", "fingerprint": "35707d83d62572c4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45134"]}}, {"ruleId": "scanner-964eb03f56802418", "level": "error", "message": {"text": "GHSA-f4xh-w4cj-qxq8: langsmith 0.6.6 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "7d463fa5906d25be", "scanner": "scanner-primary", "fingerprint": "964eb03f56802418", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f4xh-w4cj-qxq8"]}}, {"ruleId": "scanner-f7543ad5de1e740c", "level": "warning", "message": {"text": "CVE-2026-41182: langsmith 0.6.6 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "b823cd8bc9e07c87", "scanner": "scanner-primary", "fingerprint": "f7543ad5de1e740c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41182"]}}, {"ruleId": "scanner-d1fd62523402be34", "level": "error", "message": {"text": "CVE-2025-67221: orjson 3.11.5 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "719cd5ea48082454", "scanner": "scanner-primary", "fingerprint": "d1fd62523402be34", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-67221"]}}, {"ruleId": "scanner-92074ac3e8ca54b0", "level": "warning", "message": {"text": "CVE-2026-28684: python-dotenv 1.2.1 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "f7282d5150868675", "scanner": "scanner-primary", "fingerprint": "92074ac3e8ca54b0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28684"]}}, {"ruleId": "scanner-df75b91b7cfbc021", "level": "warning", "message": {"text": "CVE-2026-25645: requests 2.32.5 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "1ee5b0d0041dd6b3", "scanner": "scanner-primary", "fingerprint": "df75b91b7cfbc021", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25645"]}}, {"ruleId": "scanner-86e790278cbbcccd", "level": "error", "message": {"text": "CVE-2025-62727: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "31339c491b91cc30", "scanner": "scanner-primary", "fingerprint": "86e790278cbbcccd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-62727"]}}, {"ruleId": "scanner-279aa150f7e92795", "level": "error", "message": {"text": "CVE-2026-48818: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "d9e06b8ff722c30f", "scanner": "scanner-primary", "fingerprint": "279aa150f7e92795", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48818"]}}, {"ruleId": "scanner-afd74256d3e78799", "level": "error", "message": {"text": "CVE-2026-54283: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "c708a111537c88eb", "scanner": "scanner-primary", "fingerprint": "afd74256d3e78799", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54283"]}}, {"ruleId": "scanner-9f764996dbf098e3", "level": "warning", "message": {"text": "CVE-2025-54121: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "326aa8ccb5830dc0", "scanner": "scanner-primary", "fingerprint": "9f764996dbf098e3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-54121"]}}, {"ruleId": "scanner-c6bfd47f89f06db6", "level": "warning", "message": {"text": "CVE-2026-48710: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "3cbb06d8e4a8b7d5", "scanner": "scanner-primary", "fingerprint": "c6bfd47f89f06db6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48710"]}}, {"ruleId": "scanner-ce958434e86ef24c", "level": "warning", "message": {"text": "CVE-2026-48817: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "c14feb674475003b", "scanner": "scanner-primary", "fingerprint": "ce958434e86ef24c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48817"]}}, {"ruleId": "scanner-76697b4837768cdd", "level": "note", "message": {"text": "CVE-2026-54282: starlette 0.46.2 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "f9db28fedd90640c", "scanner": "scanner-primary", "fingerprint": "76697b4837768cdd", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54282"]}}, {"ruleId": "scanner-a08fa486784a6adf", "level": "error", "message": {"text": "CVE-2026-44431: urllib3 2.6.3 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "dfbee4f061e69d6a", "scanner": "scanner-primary", "fingerprint": "a08fa486784a6adf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44431"]}}, {"ruleId": "scanner-23f04ee111f10e6d", "level": "error", "message": {"text": "CVE-2026-44432: urllib3 2.6.3 \u2014 generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "properties": {"repobilityId": "7e7fc422e41a079e", "scanner": "scanner-primary", "fingerprint": "23f04ee111f10e6d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44432"]}}, {"ruleId": "scanner-c12cd2dbfaf4bd12", "level": "error", "message": {"text": "GHSA-537c-gmf6-5ccf: cryptography 46.0.7 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "2e622dbb38d153e8", "scanner": "scanner-primary", "fingerprint": "c12cd2dbfaf4bd12", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-537c-gmf6-5ccf"]}}, {"ruleId": "scanner-2a754f4757f2a1ea", "level": "warning", "message": {"text": "CVE-2026-45409: idna 3.11 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "7a89654332f03d1a", "scanner": "scanner-primary", "fingerprint": "2a754f4757f2a1ea", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45409"]}}, {"ruleId": "scanner-e7bb311ad65559cd", "level": "warning", "message": {"text": "CVE-2026-55443: langchain 1.2.15 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "bb062503f3770030", "scanner": "scanner-primary", "fingerprint": "e7bb311ad65559cd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55443"]}}, {"ruleId": "scanner-dc4df28ad44638c1", "level": "warning", "message": {"text": "CVE-2026-55443: langchain-anthropic 1.4.0 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "4d26528af338f45e", "scanner": "scanner-primary", "fingerprint": "dc4df28ad44638c1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55443"]}}, {"ruleId": "scanner-7f11b3c268e35697", "level": "error", "message": {"text": "CVE-2026-44843: langchain-core 1.2.29 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "746e1aac463a3c9a", "scanner": "scanner-primary", "fingerprint": "7f11b3c268e35697", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44843"]}}, {"ruleId": "scanner-02bf108b1abb68a9", "level": "note", "message": {"text": "CVE-2026-41488: langchain-openai 1.1.9 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "e3032ab272d72ee4", "scanner": "scanner-primary", "fingerprint": "02bf108b1abb68a9", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41488"]}}, {"ruleId": "scanner-af75016864d1dfcf", "level": "warning", "message": {"text": "CVE-2026-48775: langgraph-checkpoint 4.0.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "8076a13f447661bd", "scanner": "scanner-primary", "fingerprint": "af75016864d1dfcf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48775"]}}, {"ruleId": "scanner-7c7c86bfd1679e45", "level": "warning", "message": {"text": "CVE-2026-48776: langgraph-sdk 0.3.13 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "2758580b51dbf83f", "scanner": "scanner-primary", "fingerprint": "7c7c86bfd1679e45", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48776"]}}, {"ruleId": "scanner-2937a496b8882054", "level": "error", "message": {"text": "CVE-2026-45134: langsmith 0.7.31 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "9a1f1974ec992045", "scanner": "scanner-primary", "fingerprint": "2937a496b8882054", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45134"]}}, {"ruleId": "scanner-ac81c2a6e4d0136c", "level": "error", "message": {"text": "GHSA-f4xh-w4cj-qxq8: langsmith 0.7.31 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "19f29923b828a1d2", "scanner": "scanner-primary", "fingerprint": "ac81c2a6e4d0136c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f4xh-w4cj-qxq8"]}}, {"ruleId": "scanner-7cc9dda9d8566fc2", "level": "warning", "message": {"text": "CVE-2026-3219: pip 26.0.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "2742c6705b6e6cd8", "scanner": "scanner-primary", "fingerprint": "7cc9dda9d8566fc2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-3219"]}}, {"ruleId": "scanner-3390af1d58f99c86", "level": "warning", "message": {"text": "CVE-2026-6357: pip 26.0.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "d9f5c4ff8f0fb290", "scanner": "scanner-primary", "fingerprint": "3390af1d58f99c86", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6357"]}}, {"ruleId": "scanner-942c55b0b87db8e9", "level": "warning", "message": {"text": "CVE-2026-8643: pip 26.0.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "a2909ad6cb3ae70d", "scanner": "scanner-primary", "fingerprint": "942c55b0b87db8e9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8643"]}}, {"ruleId": "scanner-754185f6fbdd39ce", "level": "error", "message": {"text": "CVE-2026-48526: pyjwt 2.12.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "66bdd4d36098a4da", "scanner": "scanner-primary", "fingerprint": "754185f6fbdd39ce", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48526"]}}, {"ruleId": "scanner-2b815afe51ae2f30", "level": "warning", "message": {"text": "CVE-2026-48522: pyjwt 2.12.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "64af94164c4b740c", "scanner": "scanner-primary", "fingerprint": "2b815afe51ae2f30", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48522"]}}, {"ruleId": "scanner-4ee91ae7cfec29f9", "level": "warning", "message": {"text": "CVE-2026-48523: pyjwt 2.12.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "807709e9c29c3c16", "scanner": "scanner-primary", "fingerprint": "4ee91ae7cfec29f9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48523"]}}, {"ruleId": "scanner-8eb841638dfa8679", "level": "warning", "message": {"text": "CVE-2026-48525: pyjwt 2.12.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "e12a3e0b4a3197a0", "scanner": "scanner-primary", "fingerprint": "8eb841638dfa8679", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48525"]}}, {"ruleId": "scanner-b10e65267635823e", "level": "note", "message": {"text": "CVE-2026-48524: pyjwt 2.12.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "f1e55cc0d365b88a", "scanner": "scanner-primary", "fingerprint": "b10e65267635823e", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48524"]}}, {"ruleId": "scanner-9e0cad3311afaa32", "level": "warning", "message": {"text": "CVE-2026-59890: setuptools 82.0.1 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "63fe0a05f697f73a", "scanner": "scanner-primary", "fingerprint": "9e0cad3311afaa32", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59890"]}}, {"ruleId": "scanner-52ad2c819a1cf4fe", "level": "error", "message": {"text": "CVE-2026-48818: starlette 1.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "560df9267fefee81", "scanner": "scanner-primary", "fingerprint": "52ad2c819a1cf4fe", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48818"]}}, {"ruleId": "scanner-81bd8dba781f9278", "level": "error", "message": {"text": "CVE-2026-54283: starlette 1.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "e55f6f3be119db25", "scanner": "scanner-primary", "fingerprint": "81bd8dba781f9278", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54283"]}}, {"ruleId": "scanner-39dbc0da9ecbfcdd", "level": "warning", "message": {"text": "CVE-2026-48710: starlette 1.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "f613f3222598be46", "scanner": "scanner-primary", "fingerprint": "39dbc0da9ecbfcdd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48710"]}}, {"ruleId": "scanner-1b2035737e08539e", "level": "warning", "message": {"text": "CVE-2026-48817: starlette 1.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "b14a97db1d32eebb", "scanner": "scanner-primary", "fingerprint": "1b2035737e08539e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48817"]}}, {"ruleId": "scanner-afa2383b5649d776", "level": "note", "message": {"text": "CVE-2026-54282: starlette 1.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "55d8c0d456c333da", "scanner": "scanner-primary", "fingerprint": "afa2383b5649d776", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54282"]}}, {"ruleId": "scanner-223021c7a3771297", "level": "error", "message": {"text": "CVE-2026-44431: urllib3 2.6.3 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "d5feeac00b967dd1", "scanner": "scanner-primary", "fingerprint": "223021c7a3771297", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44431"]}}, {"ruleId": "scanner-466ae3a4e5bf66e7", "level": "error", "message": {"text": "CVE-2026-44432: urllib3 2.6.3 \u2014 generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "properties": {"repobilityId": "8b5afb20b205ee62", "scanner": "scanner-primary", "fingerprint": "466ae3a4e5bf66e7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44432"]}}, {"ruleId": "scanner-11a67cd726d5d6a1", "level": "note", "message": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.23 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "d51e1c4cac39e88d", "scanner": "scanner-primary", "fingerprint": "11a67cd726d5d6a1", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8769"]}}, {"ruleId": "scanner-83e5a62b91b852b2", "level": "warning", "message": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "bf6b0b50563e2f8f", "scanner": "scanner-primary", "fingerprint": "83e5a62b91b852b2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-frvp-7c67-39w9"]}}, {"ruleId": "scanner-36b9d4f4131ac5fd", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 1.20.4 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "bf7a61c38c27dca3", "scanner": "scanner-primary", "fingerprint": "36b9d4f4131ac5fd", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-2808c3d92866e979", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "bf7a61c38c27dca3", "scanner": "scanner-primary", "fingerprint": "2808c3d92866e979", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-d97cb18437268502", "level": "warning", "message": {"text": "CVE-2026-49458: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "2e0bde564858cc91", "scanner": "scanner-primary", "fingerprint": "d97cb18437268502", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49458"]}}, {"ruleId": "scanner-34d805abfe015a76", "level": "warning", "message": {"text": "CVE-2026-49459: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "198b49565d279c4e", "scanner": "scanner-primary", "fingerprint": "34d805abfe015a76", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49459"]}}, {"ruleId": "scanner-322253a31faa4796", "level": "warning", "message": {"text": "CVE-2026-49978: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "7e37f9341b65bfce", "scanner": "scanner-primary", "fingerprint": "322253a31faa4796", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49978"]}}, {"ruleId": "scanner-0827525b06208a12", "level": "warning", "message": {"text": "GHSA-76mc-f452-cxcm: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "eafdf95f5dab9a9c", "scanner": "scanner-primary", "fingerprint": "0827525b06208a12", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-76mc-f452-cxcm"]}}, {"ruleId": "scanner-ad214f539558c3e4", "level": "warning", "message": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "0341a048a4cf3755", "scanner": "scanner-primary", "fingerprint": "ad214f539558c3e4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cmwh-pvxp-8882"]}}, {"ruleId": "scanner-18f57badd0fd4af1", "level": "note", "message": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "e0023b4b8e25692c", "scanner": "scanner-primary", "fingerprint": "18f57badd0fd4af1", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-c2j3-45gr-mqc4"]}}, {"ruleId": "scanner-6e4bdf81fc46f368", "level": "note", "message": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "47294cc47105de4b", "scanner": "scanner-primary", "fingerprint": "6e4bdf81fc46f368", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-gvmj-g25r-r7wr"]}}, {"ruleId": "scanner-6d8dbda2a4d66cd1", "level": "note", "message": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "ce05f6cbb6fc134f", "scanner": "scanner-primary", "fingerprint": "6d8dbda2a4d66cd1", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-vxr8-fq34-vvx9"]}}, {"ruleId": "scanner-7cfd38e9652fd6fe", "level": "note", "message": {"text": "GHSA-x4vx-rjvf-j5p4: dompurify 3.4.1 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "d6157f53aa7f5888", "scanner": "scanner-primary", "fingerprint": "7cfd38e9652fd6fe", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-x4vx-rjvf-j5p4"]}}, {"ruleId": "scanner-067a4e1b257f697e", "level": "error", "message": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "2a84e61ee9a33bc5", "scanner": "scanner-primary", "fingerprint": "067a4e1b257f697e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13676"]}}, {"ruleId": "scanner-8d028ff036b5844d", "level": "error", "message": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "1af046346ca79a56", "scanner": "scanner-primary", "fingerprint": "8d028ff036b5844d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-16221"]}}, {"ruleId": "scanner-be3652dd795e141b", "level": "error", "message": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "93a0b4d3acb906b7", "scanner": "scanner-primary", "fingerprint": "be3652dd795e141b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6321"]}}, {"ruleId": "scanner-af13ca299103e969", "level": "error", "message": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "22d97ebba75d2ba3", "scanner": "scanner-primary", "fingerprint": "af13ca299103e969", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6322"]}}, {"ruleId": "scanner-ed44c8464a18e17c", "level": "error", "message": {"text": "CVE-2026-54290: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "ce64f3acacc2d270", "scanner": "scanner-primary", "fingerprint": "ed44c8464a18e17c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54290"]}}, {"ruleId": "scanner-1b9424d4f7d7f032", "level": "warning", "message": {"text": "CVE-2026-44455: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "10eb74d16042d078", "scanner": "scanner-primary", "fingerprint": "1b9424d4f7d7f032", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44455"]}}, {"ruleId": "scanner-1d65a910a167425b", "level": "warning", "message": {"text": "CVE-2026-44456: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "df8abfcfabe8becd", "scanner": "scanner-primary", "fingerprint": "1d65a910a167425b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44456"]}}, {"ruleId": "scanner-c57360000792e92b", "level": "warning", "message": {"text": "CVE-2026-44457: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "feb5f1fd0c61b475", "scanner": "scanner-primary", "fingerprint": "c57360000792e92b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44457"]}}, {"ruleId": "scanner-544420910dcd13e6", "level": "warning", "message": {"text": "CVE-2026-44458: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "d97d0181245111fe", "scanner": "scanner-primary", "fingerprint": "544420910dcd13e6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44458"]}}, {"ruleId": "scanner-936b4df305d7b946", "level": "warning", "message": {"text": "CVE-2026-47673: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "21d6fd19db4f5ad2", "scanner": "scanner-primary", "fingerprint": "936b4df305d7b946", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47673"]}}, {"ruleId": "scanner-0c667af609290a6f", "level": "warning", "message": {"text": "CVE-2026-47674: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "4288a7fa38ddb619", "scanner": "scanner-primary", "fingerprint": "0c667af609290a6f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47674"]}}, {"ruleId": "scanner-9fa0e1aa87173fa6", "level": "warning", "message": {"text": "CVE-2026-47675: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "c34ececbb660167f", "scanner": "scanner-primary", "fingerprint": "9fa0e1aa87173fa6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47675"]}}, {"ruleId": "scanner-9556fb33fe5c4764", "level": "warning", "message": {"text": "CVE-2026-47676: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "52a48db82c65cc90", "scanner": "scanner-primary", "fingerprint": "9556fb33fe5c4764", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47676"]}}, {"ruleId": "scanner-e487033b7c93e6fe", "level": "warning", "message": {"text": "CVE-2026-54286: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "0767da6a979dd6f8", "scanner": "scanner-primary", "fingerprint": "e487033b7c93e6fe", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54286"]}}, {"ruleId": "scanner-3a13f2b5249d1ba6", "level": "warning", "message": {"text": "CVE-2026-54287: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "23eb4b669e6f4875", "scanner": "scanner-primary", "fingerprint": "3a13f2b5249d1ba6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54287"]}}, {"ruleId": "scanner-30e3c85062d7e093", "level": "warning", "message": {"text": "CVE-2026-54288: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "d64a1fa3364dec4a", "scanner": "scanner-primary", "fingerprint": "30e3c85062d7e093", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54288"]}}, {"ruleId": "scanner-ba4a8ad90b4c1385", "level": "warning", "message": {"text": "CVE-2026-54289: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "a1ad104eb067e21c", "scanner": "scanner-primary", "fingerprint": "ba4a8ad90b4c1385", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54289"]}}, {"ruleId": "scanner-4e61c4864c5405fd", "level": "warning", "message": {"text": "CVE-2026-59895: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "0a19a8fad98ff585", "scanner": "scanner-primary", "fingerprint": "4e61c4864c5405fd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59895"]}}, {"ruleId": "scanner-602fd1a3594be12d", "level": "warning", "message": {"text": "CVE-2026-59896: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "95a6add31ba3133b", "scanner": "scanner-primary", "fingerprint": "602fd1a3594be12d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59896"]}}, {"ruleId": "scanner-7b7b24e5bf221553", "level": "warning", "message": {"text": "CVE-2026-59897: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "ebe11a03e03fc901", "scanner": "scanner-primary", "fingerprint": "7b7b24e5bf221553", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59897"]}}, {"ruleId": "scanner-7c2d9f163b5df5ea", "level": "note", "message": {"text": "CVE-2026-44459: hono 4.12.14 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "cc5e8f2a5bcff984", "scanner": "scanner-primary", "fingerprint": "7c2d9f163b5df5ea", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44459"]}}, {"ruleId": "scanner-9454f7734bbfaf4b", "level": "warning", "message": {"text": "CVE-2026-42338: ip-address 10.1.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "1dd002a62b4190a1", "scanner": "scanner-primary", "fingerprint": "9454f7734bbfaf4b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42338"]}}, {"ruleId": "scanner-eee5b8e1ff355710", "level": "error", "message": {"text": "CVE-2026-45134: langsmith 0.5.21 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "bdf1976ab9dd9ffd", "scanner": "scanner-primary", "fingerprint": "eee5b8e1ff355710", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45134"]}}, {"ruleId": "scanner-a4aa78c4d144537f", "level": "warning", "message": {"text": "CVE-2026-41148: mermaid 11.14.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "f54d2acced85111d", "scanner": "scanner-primary", "fingerprint": "a4aa78c4d144537f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41148"]}}, {"ruleId": "scanner-8a4809f0980762bf", "level": "warning", "message": {"text": "CVE-2026-41149: mermaid 11.14.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "a0f7e08e890d37ea", "scanner": "scanner-primary", "fingerprint": "8a4809f0980762bf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41149"]}}, {"ruleId": "scanner-feaec2448f219421", "level": "warning", "message": {"text": "CVE-2026-41150: mermaid 11.14.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "611c186e066403d6", "scanner": "scanner-primary", "fingerprint": "feaec2448f219421", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41150"]}}, {"ruleId": "scanner-3a81102eca625a06", "level": "warning", "message": {"text": "CVE-2026-41159: mermaid 11.14.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "4cd663167ebd8a1e", "scanner": "scanner-primary", "fingerprint": "3a81102eca625a06", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41159"]}}, {"ruleId": "scanner-62601947e05e3ab7", "level": "error", "message": {"text": "CVE-2026-44573: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "cef7d8a2c5b7c0b6", "scanner": "scanner-primary", "fingerprint": "62601947e05e3ab7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44573"]}}, {"ruleId": "scanner-7231eb09d5d3cdbc", "level": "error", "message": {"text": "CVE-2026-44574: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "48df2f82ca7ed69d", "scanner": "scanner-primary", "fingerprint": "7231eb09d5d3cdbc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44574"]}}, {"ruleId": "scanner-0c2dc4ae9d7b853a", "level": "error", "message": {"text": "CVE-2026-44575: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "0174aba4968802dd", "scanner": "scanner-primary", "fingerprint": "0c2dc4ae9d7b853a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44575"]}}, {"ruleId": "scanner-5a195e73470d7706", "level": "error", "message": {"text": "CVE-2026-44578: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "416572705817a369", "scanner": "scanner-primary", "fingerprint": "5a195e73470d7706", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44578"]}}, {"ruleId": "scanner-cb29acaf9f949a7d", "level": "error", "message": {"text": "CVE-2026-44579: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "f179c50c9f8fa221", "scanner": "scanner-primary", "fingerprint": "cb29acaf9f949a7d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44579"]}}, {"ruleId": "scanner-06b73217ea077493", "level": "error", "message": {"text": "CVE-2026-45109: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "0ea4fd023ada74f5", "scanner": "scanner-primary", "fingerprint": "06b73217ea077493", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45109"]}}, {"ruleId": "scanner-664322f0d5f266bc", "level": "error", "message": {"text": "CVE-2026-64641: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "2b426d228cd11caf", "scanner": "scanner-primary", "fingerprint": "664322f0d5f266bc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64641"]}}, {"ruleId": "scanner-f36d63b75d044f93", "level": "error", "message": {"text": "CVE-2026-64642: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "27ea278bda5b62bd", "scanner": "scanner-primary", "fingerprint": "f36d63b75d044f93", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64642"]}}, {"ruleId": "scanner-adba62ef09835ce9", "level": "error", "message": {"text": "CVE-2026-64645: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "36927971e2235978", "scanner": "scanner-primary", "fingerprint": "adba62ef09835ce9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64645"]}}, {"ruleId": "scanner-b0c6e2a74e741c10", "level": "error", "message": {"text": "CVE-2026-64649: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "add9eb28da910d36", "scanner": "scanner-primary", "fingerprint": "b0c6e2a74e741c10", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64649"]}}, {"ruleId": "scanner-152189684a4daed2", "level": "error", "message": {"text": "GHSA-8h8q-6873-q5fj: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "5d14b229e36d4214", "scanner": "scanner-primary", "fingerprint": "152189684a4daed2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-8h8q-6873-q5fj"]}}, {"ruleId": "scanner-60a1c64aed0d5e09", "level": "error", "message": {"text": "GHSA-q4gf-8mx6-v5v3: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "c75706bb5d086483", "scanner": "scanner-primary", "fingerprint": "60a1c64aed0d5e09", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-q4gf-8mx6-v5v3"]}}, {"ruleId": "scanner-eb40897608bf69c9", "level": "warning", "message": {"text": "CVE-2026-27978: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "d055a5d2d196eb96", "scanner": "scanner-primary", "fingerprint": "eb40897608bf69c9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27978"]}}, {"ruleId": "scanner-f5ce31f22caefa19", "level": "warning", "message": {"text": "CVE-2026-27979: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "1feee2118652636f", "scanner": "scanner-primary", "fingerprint": "f5ce31f22caefa19", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27979"]}}, {"ruleId": "scanner-f154ec74d025273a", "level": "warning", "message": {"text": "CVE-2026-27980: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "e4e808089ce7e5b5", "scanner": "scanner-primary", "fingerprint": "f154ec74d025273a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27980"]}}, {"ruleId": "scanner-661cfdb1133fb3aa", "level": "warning", "message": {"text": "CVE-2026-29057: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "1b9c80d472ca44cc", "scanner": "scanner-primary", "fingerprint": "661cfdb1133fb3aa", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29057"]}}, {"ruleId": "scanner-cf76c79f44bf2a04", "level": "warning", "message": {"text": "CVE-2026-44576: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "ba920c2c3bcd3dfb", "scanner": "scanner-primary", "fingerprint": "cf76c79f44bf2a04", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44576"]}}, {"ruleId": "scanner-9491b7f7fef56ebc", "level": "warning", "message": {"text": "CVE-2026-44577: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "1353c71b60567f33", "scanner": "scanner-primary", "fingerprint": "9491b7f7fef56ebc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44577"]}}, {"ruleId": "scanner-a2c025d2e3b307a9", "level": "warning", "message": {"text": "CVE-2026-44580: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "e39170f1d86663e6", "scanner": "scanner-primary", "fingerprint": "a2c025d2e3b307a9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44580"]}}, {"ruleId": "scanner-0028fd72e4b8a478", "level": "warning", "message": {"text": "CVE-2026-44581: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "340ddca889bb0e88", "scanner": "scanner-primary", "fingerprint": "0028fd72e4b8a478", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44581"]}}, {"ruleId": "scanner-c274b7f6bd5fc652", "level": "warning", "message": {"text": "CVE-2026-64643: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "b0f83633b417324a", "scanner": "scanner-primary", "fingerprint": "c274b7f6bd5fc652", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64643"]}}, {"ruleId": "scanner-26fadf6cb78b78bf", "level": "warning", "message": {"text": "CVE-2026-64644: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "56099186f8bc1dea", "scanner": "scanner-primary", "fingerprint": "26fadf6cb78b78bf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64644"]}}, {"ruleId": "scanner-966a989702fbc54a", "level": "warning", "message": {"text": "CVE-2026-64646: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "7f3df6a489228a7a", "scanner": "scanner-primary", "fingerprint": "966a989702fbc54a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64646"]}}, {"ruleId": "scanner-2667b67d8af4e20d", "level": "warning", "message": {"text": "CVE-2026-64647: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "9775bb02d7bbeafd", "scanner": "scanner-primary", "fingerprint": "2667b67d8af4e20d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64647"]}}, {"ruleId": "scanner-11f2b3e5a7869fdf", "level": "warning", "message": {"text": "CVE-2026-64648: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "85ee2696789e88fd", "scanner": "scanner-primary", "fingerprint": "11f2b3e5a7869fdf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64648"]}}, {"ruleId": "scanner-908909cb72c4e435", "level": "note", "message": {"text": "CVE-2026-27977: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "f54d6c3471619351", "scanner": "scanner-primary", "fingerprint": "908909cb72c4e435", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27977"]}}, {"ruleId": "scanner-b781bf6c7f5b108f", "level": "note", "message": {"text": "CVE-2026-44572: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "ec4ba474edc32cdc", "scanner": "scanner-primary", "fingerprint": "b781bf6c7f5b108f", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44572"]}}, {"ruleId": "scanner-9f204e29a02752e2", "level": "note", "message": {"text": "CVE-2026-44582: next 16.1.6 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "b137a6ed0c3aabfc", "scanner": "scanner-primary", "fingerprint": "9f204e29a02752e2", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44582"]}}, {"ruleId": "scanner-5461e65421bf4388", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "5057c16060d0c199", "scanner": "scanner-primary", "fingerprint": "5461e65421bf4388", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-b8483ec3c153d2c5", "level": "warning", "message": {"text": "CVE-2024-53382: prismjs 1.27.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "a74e388f82c52850", "scanner": "scanner-primary", "fingerprint": "b8483ec3c153d2c5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-53382"]}}, {"ruleId": "scanner-bca13151d4aaa654", "level": "warning", "message": {"text": "CVE-2026-8723: qs 6.14.2 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "91bd745e429fa77a", "scanner": "scanner-primary", "fingerprint": "bca13151d4aaa654", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8723"]}}, {"ruleId": "scanner-73f7aa5c2625abbb", "level": "error", "message": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "3a3906ee63f8c21b", "scanner": "scanner-primary", "fingerprint": "73f7aa5c2625abbb", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f88m-g3jw-g9cj"]}}, {"ruleId": "scanner-a7ba74f0779959f0", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 10.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "856b26d442355ab4", "scanner": "scanner-primary", "fingerprint": "a7ba74f0779959f0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-40cce4303294c04a", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "856b26d442355ab4", "scanner": "scanner-primary", "fingerprint": "40cce4303294c04a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-67babef6b644f24a", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 13.0.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "856b26d442355ab4", "scanner": "scanner-primary", "fingerprint": "67babef6b644f24a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-80bf17e95a4ebbf9", "level": "error", "message": {"text": "CVE-2026-48779: ws 8.20.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "7fc1e1d152d39018", "scanner": "scanner-primary", "fingerprint": "80bf17e95a4ebbf9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48779"]}}, {"ruleId": "scanner-fa3b848ad227bbb8", "level": "warning", "message": {"text": "CVE-2026-45736: ws 8.20.0 \u2014 generative_ui_agents/generative-ui-starter-project/package-lock.json"}, "properties": {"repobilityId": "478fdd6a28ad9b29", "scanner": "scanner-primary", "fingerprint": "fa3b848ad227bbb8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45736"]}}, {"ruleId": "scanner-51f663f681915dc0", "level": "error", "message": {"text": "CVE-2026-29087: @hono/node-server 1.19.8 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "d982ce071b46ba62", "scanner": "scanner-primary", "fingerprint": "51f663f681915dc0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29087"]}}, {"ruleId": "scanner-207bbda1e2149e2b", "level": "warning", "message": {"text": "CVE-2026-39406: @hono/node-server 1.19.8 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "c2ad8e419575e7f8", "scanner": "scanner-primary", "fingerprint": "207bbda1e2149e2b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39406"]}}, {"ruleId": "scanner-e806cd6d334e2953", "level": "warning", "message": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.8 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "ccb2d43262644ffe", "scanner": "scanner-primary", "fingerprint": "e806cd6d334e2953", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-frvp-7c67-39w9"]}}, {"ruleId": "scanner-65af261c31564624", "level": "error", "message": {"text": "CVE-2026-25536: @modelcontextprotocol/sdk 1.25.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "34393622db536b1a", "scanner": "scanner-primary", "fingerprint": "65af261c31564624", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25536"]}}, {"ruleId": "scanner-cef37e57736da3b5", "level": "warning", "message": {"text": "CVE-2025-69873: ajv 8.17.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "9e125f4933ce8eb7", "scanner": "scanner-primary", "fingerprint": "cef37e57736da3b5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69873"]}}, {"ruleId": "scanner-df9047f9cce2a5d3", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "43a8d1e7c126f0ea", "scanner": "scanner-primary", "fingerprint": "df9047f9cce2a5d3", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-5af28f8097a88083", "level": "error", "message": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "ee46cc39230dd1e0", "scanner": "scanner-primary", "fingerprint": "5af28f8097a88083", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13676"]}}, {"ruleId": "scanner-60bcf4c1ef1ab72c", "level": "error", "message": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "e2f1a28eb4603d3e", "scanner": "scanner-primary", "fingerprint": "60bcf4c1ef1ab72c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-16221"]}}, {"ruleId": "scanner-ed178292236c2003", "level": "error", "message": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "6ff09d76e486b625", "scanner": "scanner-primary", "fingerprint": "ed178292236c2003", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6321"]}}, {"ruleId": "scanner-23c05c2885391dce", "level": "error", "message": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "784c38b10fc1cedd", "scanner": "scanner-primary", "fingerprint": "23c05c2885391dce", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6322"]}}, {"ruleId": "scanner-f52b6fa470daad21", "level": "error", "message": {"text": "CVE-2026-22817: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "c5f28a7b98e1820f", "scanner": "scanner-primary", "fingerprint": "f52b6fa470daad21", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-22817"]}}, {"ruleId": "scanner-f8b4257b4ae28b34", "level": "error", "message": {"text": "CVE-2026-22818: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "04fd9dd2cbe7d30b", "scanner": "scanner-primary", "fingerprint": "f8b4257b4ae28b34", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-22818"]}}, {"ruleId": "scanner-2f09895837e89b9b", "level": "error", "message": {"text": "CVE-2026-29045: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "d0ef58532d7c9964", "scanner": "scanner-primary", "fingerprint": "2f09895837e89b9b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29045"]}}, {"ruleId": "scanner-1b423080b4e152bc", "level": "error", "message": {"text": "CVE-2026-54290: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "d7c6a0cbae782b11", "scanner": "scanner-primary", "fingerprint": "1b423080b4e152bc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54290"]}}, {"ruleId": "scanner-eecfc29420986a61", "level": "warning", "message": {"text": "CVE-2026-24398: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "e11ac84757e62a93", "scanner": "scanner-primary", "fingerprint": "eecfc29420986a61", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24398"]}}, {"ruleId": "scanner-30d7024e05ab2730", "level": "warning", "message": {"text": "CVE-2026-24472: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "1c84e753019ae3e4", "scanner": "scanner-primary", "fingerprint": "30d7024e05ab2730", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24472"]}}, {"ruleId": "scanner-2a8cfe6797ead01d", "level": "warning", "message": {"text": "CVE-2026-24473: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "28ee07157e2006fb", "scanner": "scanner-primary", "fingerprint": "2a8cfe6797ead01d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24473"]}}, {"ruleId": "scanner-64fe450cc735f44c", "level": "warning", "message": {"text": "CVE-2026-24771: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "14dfc1c4e5199e74", "scanner": "scanner-primary", "fingerprint": "64fe450cc735f44c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24771"]}}, {"ruleId": "scanner-000d05f58453734d", "level": "warning", "message": {"text": "CVE-2026-29085: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "01d262904963f593", "scanner": "scanner-primary", "fingerprint": "000d05f58453734d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29085"]}}, {"ruleId": "scanner-cf660c7300890968", "level": "warning", "message": {"text": "CVE-2026-29086: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "75db2550736cdc34", "scanner": "scanner-primary", "fingerprint": "cf660c7300890968", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29086"]}}, {"ruleId": "scanner-e2b2d283e623f81a", "level": "warning", "message": {"text": "CVE-2026-39407: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "3e1978f346b12c13", "scanner": "scanner-primary", "fingerprint": "e2b2d283e623f81a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39407"]}}, {"ruleId": "scanner-f88800658902deb3", "level": "warning", "message": {"text": "CVE-2026-39408: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "734c3690568fca90", "scanner": "scanner-primary", "fingerprint": "f88800658902deb3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39408"]}}, {"ruleId": "scanner-acaab246a9744250", "level": "warning", "message": {"text": "CVE-2026-39409: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "50970c2453144b48", "scanner": "scanner-primary", "fingerprint": "acaab246a9744250", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39409"]}}, {"ruleId": "scanner-3c7268d1d3af096f", "level": "warning", "message": {"text": "CVE-2026-39410: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "3cbabcd102d8e18f", "scanner": "scanner-primary", "fingerprint": "3c7268d1d3af096f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39410"]}}, {"ruleId": "scanner-48e6385e6594326b", "level": "warning", "message": {"text": "CVE-2026-44455: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "b61a0c032f0fcc16", "scanner": "scanner-primary", "fingerprint": "48e6385e6594326b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44455"]}}, {"ruleId": "scanner-7f58313e98fbe941", "level": "warning", "message": {"text": "CVE-2026-44456: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "c413a91fbdb1c158", "scanner": "scanner-primary", "fingerprint": "7f58313e98fbe941", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44456"]}}, {"ruleId": "scanner-03de96718127de76", "level": "warning", "message": {"text": "CVE-2026-44457: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "e69a0e2b81fc0996", "scanner": "scanner-primary", "fingerprint": "03de96718127de76", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44457"]}}, {"ruleId": "scanner-5b86333aece57367", "level": "warning", "message": {"text": "CVE-2026-44458: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "59a16bed31fddaf1", "scanner": "scanner-primary", "fingerprint": "5b86333aece57367", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44458"]}}, {"ruleId": "scanner-751de4567ca9471f", "level": "warning", "message": {"text": "CVE-2026-47673: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "7bd888c46cccfeb2", "scanner": "scanner-primary", "fingerprint": "751de4567ca9471f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47673"]}}, {"ruleId": "scanner-62a9c82cfef90538", "level": "warning", "message": {"text": "CVE-2026-47674: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "33f6d9bbe3c8bed3", "scanner": "scanner-primary", "fingerprint": "62a9c82cfef90538", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47674"]}}, {"ruleId": "scanner-fe77ecf260220a38", "level": "warning", "message": {"text": "CVE-2026-47675: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "5458f251b38f6948", "scanner": "scanner-primary", "fingerprint": "fe77ecf260220a38", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47675"]}}, {"ruleId": "scanner-2b36c3a7ea8ab725", "level": "warning", "message": {"text": "CVE-2026-47676: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "c6caadd367a5a284", "scanner": "scanner-primary", "fingerprint": "2b36c3a7ea8ab725", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47676"]}}, {"ruleId": "scanner-ec16223a7044fd1e", "level": "warning", "message": {"text": "CVE-2026-54286: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "5143952cf820cc0f", "scanner": "scanner-primary", "fingerprint": "ec16223a7044fd1e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54286"]}}, {"ruleId": "scanner-af987d68cb9147b8", "level": "warning", "message": {"text": "CVE-2026-54287: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "49eae2d373fa7b51", "scanner": "scanner-primary", "fingerprint": "af987d68cb9147b8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54287"]}}, {"ruleId": "scanner-e81538a28e90526e", "level": "warning", "message": {"text": "CVE-2026-54288: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "9ca220d4cc4c4f56", "scanner": "scanner-primary", "fingerprint": "e81538a28e90526e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54288"]}}, {"ruleId": "scanner-5c41bca572154f58", "level": "warning", "message": {"text": "CVE-2026-54289: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "c7abfc814fe0f2fc", "scanner": "scanner-primary", "fingerprint": "5c41bca572154f58", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54289"]}}, {"ruleId": "scanner-baff8c3107b61b69", "level": "warning", "message": {"text": "CVE-2026-56761: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "aab23ad2683fe56c", "scanner": "scanner-primary", "fingerprint": "baff8c3107b61b69", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-56761"]}}, {"ruleId": "scanner-3457fe547dce3733", "level": "warning", "message": {"text": "CVE-2026-59895: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "465066f8eaf7e345", "scanner": "scanner-primary", "fingerprint": "3457fe547dce3733", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59895"]}}, {"ruleId": "scanner-9870dfc02feb5fbf", "level": "warning", "message": {"text": "CVE-2026-59897: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "2adb5b59409a7078", "scanner": "scanner-primary", "fingerprint": "9870dfc02feb5fbf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59897"]}}, {"ruleId": "scanner-1474f4039d7bb323", "level": "warning", "message": {"text": "GHSA-26pp-8wgv-hjvm: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "1293b0a2e0991174", "scanner": "scanner-primary", "fingerprint": "1474f4039d7bb323", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-26pp-8wgv-hjvm"]}}, {"ruleId": "scanner-97df703fd7385306", "level": "warning", "message": {"text": "GHSA-v8w9-8mx6-g223: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "24f0159836632a94", "scanner": "scanner-primary", "fingerprint": "97df703fd7385306", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-v8w9-8mx6-g223"]}}, {"ruleId": "scanner-efaf6dcda886535f", "level": "note", "message": {"text": "CVE-2026-44459: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "6c969e1a0a7f37e6", "scanner": "scanner-primary", "fingerprint": "efaf6dcda886535f", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44459"]}}, {"ruleId": "scanner-6fa3a2eae6998a04", "level": "note", "message": {"text": "GHSA-gq3j-xvxp-8hrf: hono 4.11.3 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "cd528a2b2d2dd720", "scanner": "scanner-primary", "fingerprint": "6fa3a2eae6998a04", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-gq3j-xvxp-8hrf"]}}, {"ruleId": "scanner-32b3b281a6007f2f", "level": "error", "message": {"text": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "94d442d97a7eaa3a", "scanner": "scanner-primary", "fingerprint": "32b3b281a6007f2f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4926"]}}, {"ruleId": "scanner-c67ed73a52296347", "level": "warning", "message": {"text": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "2600fe0ea3147f6f", "scanner": "scanner-primary", "fingerprint": "c67ed73a52296347", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4923"]}}, {"ruleId": "scanner-eb33deb7fbd06155", "level": "warning", "message": {"text": "CVE-2026-8723: qs 6.14.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "14188103e2d41f0b", "scanner": "scanner-primary", "fingerprint": "eb33deb7fbd06155", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8723"]}}, {"ruleId": "scanner-fb9c8251ba37bfb7", "level": "note", "message": {"text": "CVE-2026-2391: qs 6.14.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json"}, "properties": {"repobilityId": "6e7e9c8aff7f07bd", "scanner": "scanner-primary", "fingerprint": "fb9c8251ba37bfb7", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2391"]}}, {"ruleId": "scanner-16e1745aa32dd020", "level": "note", "message": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.25 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "ca21630835a89c1c", "scanner": "scanner-primary", "fingerprint": "16e1745aa32dd020", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8769"]}}, {"ruleId": "scanner-9e022c85ec76f360", "level": "error", "message": {"text": "CVE-2026-29087: @hono/node-server 1.19.8 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "d51293daccd6804a", "scanner": "scanner-primary", "fingerprint": "9e022c85ec76f360", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29087"]}}, {"ruleId": "scanner-5f3ad48a2cfeb6d8", "level": "warning", "message": {"text": "CVE-2026-39406: @hono/node-server 1.19.8 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "f1d6d1e70739a261", "scanner": "scanner-primary", "fingerprint": "5f3ad48a2cfeb6d8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39406"]}}, {"ruleId": "scanner-1c670bc818d28838", "level": "warning", "message": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.8 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "c4c8b7382b87f350", "scanner": "scanner-primary", "fingerprint": "1c670bc818d28838", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-frvp-7c67-39w9"]}}, {"ruleId": "scanner-dd38dca968f75e6b", "level": "error", "message": {"text": "CVE-2026-25536: @modelcontextprotocol/sdk 1.25.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "e30a6c2af76447c6", "scanner": "scanner-primary", "fingerprint": "dd38dca968f75e6b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25536"]}}, {"ruleId": "scanner-a18bf677381bb8a1", "level": "warning", "message": {"text": "CVE-2025-69873: ajv 8.17.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "1f0d3a9bcddf5c80", "scanner": "scanner-primary", "fingerprint": "a18bf677381bb8a1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69873"]}}, {"ruleId": "scanner-7c76834c093875b3", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 1.20.4 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "9ea9a011a15892e1", "scanner": "scanner-primary", "fingerprint": "7c76834c093875b3", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-14322d3d495edad3", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "9ea9a011a15892e1", "scanner": "scanner-primary", "fingerprint": "14322d3d495edad3", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-7566da4be22b0841", "level": "warning", "message": {"text": "CVE-2026-0540: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "388f25928989b5af", "scanner": "scanner-primary", "fingerprint": "7566da4be22b0841", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-0540"]}}, {"ruleId": "scanner-186fe07963bca754", "level": "warning", "message": {"text": "CVE-2026-41238: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "c1dc0215072ef09e", "scanner": "scanner-primary", "fingerprint": "186fe07963bca754", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41238"]}}, {"ruleId": "scanner-38084c8ee5b29ec9", "level": "warning", "message": {"text": "CVE-2026-41239: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "08e4f5821fa1af01", "scanner": "scanner-primary", "fingerprint": "38084c8ee5b29ec9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41239"]}}, {"ruleId": "scanner-2f2529ed704fd48a", "level": "warning", "message": {"text": "CVE-2026-41240: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "070075a4711d3a83", "scanner": "scanner-primary", "fingerprint": "2f2529ed704fd48a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41240"]}}, {"ruleId": "scanner-355f4f848a053f51", "level": "warning", "message": {"text": "CVE-2026-49458: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "bf7082b81dbf113a", "scanner": "scanner-primary", "fingerprint": "355f4f848a053f51", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49458"]}}, {"ruleId": "scanner-eb567e396ede09c2", "level": "warning", "message": {"text": "CVE-2026-49459: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "c895f0405c7a20fe", "scanner": "scanner-primary", "fingerprint": "eb567e396ede09c2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49459"]}}, {"ruleId": "scanner-402b461e36bc5660", "level": "warning", "message": {"text": "CVE-2026-49978: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "b7e61756344b4ba8", "scanner": "scanner-primary", "fingerprint": "402b461e36bc5660", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49978"]}}, {"ruleId": "scanner-e27ef218d25523a7", "level": "warning", "message": {"text": "GHSA-39q2-94rc-95cp: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "0eafb7e4ca351653", "scanner": "scanner-primary", "fingerprint": "e27ef218d25523a7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-39q2-94rc-95cp"]}}, {"ruleId": "scanner-66f488559fad40d8", "level": "warning", "message": {"text": "GHSA-76mc-f452-cxcm: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "baf8c5518c768763", "scanner": "scanner-primary", "fingerprint": "66f488559fad40d8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-76mc-f452-cxcm"]}}, {"ruleId": "scanner-67990391f8833a4a", "level": "warning", "message": {"text": "GHSA-cj63-jhhr-wcxv: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "d15ddd108f9a4b80", "scanner": "scanner-primary", "fingerprint": "67990391f8833a4a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cj63-jhhr-wcxv"]}}, {"ruleId": "scanner-bb6c55bff02fb430", "level": "warning", "message": {"text": "GHSA-cjmm-f4jc-qw8r: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "3a5e5c0572fba6fa", "scanner": "scanner-primary", "fingerprint": "bb6c55bff02fb430", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cjmm-f4jc-qw8r"]}}, {"ruleId": "scanner-184e6b7cfcb638fd", "level": "warning", "message": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "d24d29b492d00822", "scanner": "scanner-primary", "fingerprint": "184e6b7cfcb638fd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cmwh-pvxp-8882"]}}, {"ruleId": "scanner-5150be295628e674", "level": "warning", "message": {"text": "GHSA-h8r8-wccr-v5f2: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "d560ad4fa367b526", "scanner": "scanner-primary", "fingerprint": "5150be295628e674", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-h8r8-wccr-v5f2"]}}, {"ruleId": "scanner-4760529717455ebf", "level": "note", "message": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "768fa3f3da755c8d", "scanner": "scanner-primary", "fingerprint": "4760529717455ebf", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-c2j3-45gr-mqc4"]}}, {"ruleId": "scanner-486b9d345bb12fe7", "level": "note", "message": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "fa22fda794bc8bc5", "scanner": "scanner-primary", "fingerprint": "486b9d345bb12fe7", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-gvmj-g25r-r7wr"]}}, {"ruleId": "scanner-1079b32ab8ce98ac", "level": "note", "message": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "9484268aaa74b5b0", "scanner": "scanner-primary", "fingerprint": "1079b32ab8ce98ac", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-vxr8-fq34-vvx9"]}}, {"ruleId": "scanner-d24eb3d228985d50", "level": "note", "message": {"text": "GHSA-x4vx-rjvf-j5p4: dompurify 3.3.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "0b48d179530b2bf4", "scanner": "scanner-primary", "fingerprint": "d24eb3d228985d50", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-x4vx-rjvf-j5p4"]}}, {"ruleId": "scanner-b6c122ddb0aebd13", "level": "error", "message": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "77c169bb121505b2", "scanner": "scanner-primary", "fingerprint": "b6c122ddb0aebd13", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13676"]}}, {"ruleId": "scanner-40636ce14373d4ca", "level": "error", "message": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "70cc65dd967d6a3f", "scanner": "scanner-primary", "fingerprint": "40636ce14373d4ca", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-16221"]}}, {"ruleId": "scanner-e3ed2e85ae19a431", "level": "error", "message": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "8746e0e3ad0943fa", "scanner": "scanner-primary", "fingerprint": "e3ed2e85ae19a431", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6321"]}}, {"ruleId": "scanner-1c628d44d9a099c7", "level": "error", "message": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "06215d87b475fb40", "scanner": "scanner-primary", "fingerprint": "1c628d44d9a099c7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6322"]}}, {"ruleId": "scanner-1c7f046caaebefbf", "level": "error", "message": {"text": "CVE-2026-54290: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "70e0940682e5509f", "scanner": "scanner-primary", "fingerprint": "1c7f046caaebefbf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54290"]}}, {"ruleId": "scanner-2efe592e8099ccd6", "level": "warning", "message": {"text": "CVE-2026-54286: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "b7db9687ebca1a76", "scanner": "scanner-primary", "fingerprint": "2efe592e8099ccd6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54286"]}}, {"ruleId": "scanner-0cdfacc305045a09", "level": "warning", "message": {"text": "CVE-2026-54287: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "292a7c883051ee72", "scanner": "scanner-primary", "fingerprint": "0cdfacc305045a09", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54287"]}}, {"ruleId": "scanner-155d59755dc87913", "level": "warning", "message": {"text": "CVE-2026-54288: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "a81c805a0ac1213e", "scanner": "scanner-primary", "fingerprint": "155d59755dc87913", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54288"]}}, {"ruleId": "scanner-dbce38cb467ce1d5", "level": "warning", "message": {"text": "CVE-2026-54289: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "237f2cbbac4d6539", "scanner": "scanner-primary", "fingerprint": "dbce38cb467ce1d5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54289"]}}, {"ruleId": "scanner-d5a8215482cb74a1", "level": "warning", "message": {"text": "CVE-2026-59895: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "1205e30ef50b77de", "scanner": "scanner-primary", "fingerprint": "d5a8215482cb74a1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59895"]}}, {"ruleId": "scanner-72f1f966410cb394", "level": "warning", "message": {"text": "CVE-2026-59896: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "4326d6df2694422e", "scanner": "scanner-primary", "fingerprint": "72f1f966410cb394", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59896"]}}, {"ruleId": "scanner-7e2ddcf268168780", "level": "warning", "message": {"text": "CVE-2026-59897: hono 4.12.23 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "553490ca935eb975", "scanner": "scanner-primary", "fingerprint": "7e2ddcf268168780", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59897"]}}, {"ruleId": "scanner-2bd8b324bf6d5f29", "level": "error", "message": {"text": "CVE-2026-4800: lodash-es 4.17.21 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "94d6f936a864aa8a", "scanner": "scanner-primary", "fingerprint": "2bd8b324bf6d5f29", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-e58b345a4e5bba48", "level": "warning", "message": {"text": "CVE-2025-13465: lodash-es 4.17.21 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "4255cf0dd304b984", "scanner": "scanner-primary", "fingerprint": "e58b345a4e5bba48", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-13465"]}}, {"ruleId": "scanner-e6f408965346503e", "level": "warning", "message": {"text": "CVE-2026-2950: lodash-es 4.17.21 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "4c99cea0b60a8a86", "scanner": "scanner-primary", "fingerprint": "e6f408965346503e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-f4cbe2a0b223d084", "level": "error", "message": {"text": "CVE-2026-4800: lodash-es 4.17.22 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "94d6f936a864aa8a", "scanner": "scanner-primary", "fingerprint": "f4cbe2a0b223d084", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-a95dd78113636459", "level": "warning", "message": {"text": "CVE-2025-13465: lodash-es 4.17.22 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "4255cf0dd304b984", "scanner": "scanner-primary", "fingerprint": "a95dd78113636459", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-13465"]}}, {"ruleId": "scanner-d9a02e4e708da652", "level": "warning", "message": {"text": "CVE-2026-2950: lodash-es 4.17.22 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "4c99cea0b60a8a86", "scanner": "scanner-primary", "fingerprint": "d9a02e4e708da652", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-5122d5417bba57fa", "level": "warning", "message": {"text": "CVE-2026-41148: mermaid 11.12.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "be8a057c878f70d7", "scanner": "scanner-primary", "fingerprint": "5122d5417bba57fa", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41148"]}}, {"ruleId": "scanner-de4dd1941398da98", "level": "warning", "message": {"text": "CVE-2026-41149: mermaid 11.12.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "7e63f960a5e6d07b", "scanner": "scanner-primary", "fingerprint": "de4dd1941398da98", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41149"]}}, {"ruleId": "scanner-1676e90c0990cb40", "level": "warning", "message": {"text": "CVE-2026-41150: mermaid 11.12.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "0ec7d02204694758", "scanner": "scanner-primary", "fingerprint": "1676e90c0990cb40", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41150"]}}, {"ruleId": "scanner-a951d250b992c88d", "level": "warning", "message": {"text": "CVE-2026-41159: mermaid 11.12.2 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "1bb2aa0d98b8795e", "scanner": "scanner-primary", "fingerprint": "a951d250b992c88d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41159"]}}, {"ruleId": "scanner-fee84d588b5ab2da", "level": "error", "message": {"text": "CVE-2026-44573: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "f1c2344d97a820c1", "scanner": "scanner-primary", "fingerprint": "fee84d588b5ab2da", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44573"]}}, {"ruleId": "scanner-c44e833c5e3ef452", "level": "error", "message": {"text": "CVE-2026-44574: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "ac21986aa72cf1e9", "scanner": "scanner-primary", "fingerprint": "c44e833c5e3ef452", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44574"]}}, {"ruleId": "scanner-daac8ac9d153600b", "level": "error", "message": {"text": "CVE-2026-44575: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "20ac9cef273975c3", "scanner": "scanner-primary", "fingerprint": "daac8ac9d153600b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44575"]}}, {"ruleId": "scanner-6a3c47c7a8409aee", "level": "error", "message": {"text": "CVE-2026-44578: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "4a8b2655b6fc299e", "scanner": "scanner-primary", "fingerprint": "6a3c47c7a8409aee", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44578"]}}, {"ruleId": "scanner-589a25f36c6e5c56", "level": "error", "message": {"text": "CVE-2026-44579: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "2381f21d1b9c0ea4", "scanner": "scanner-primary", "fingerprint": "589a25f36c6e5c56", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44579"]}}, {"ruleId": "scanner-70a6a8a118696afd", "level": "error", "message": {"text": "CVE-2026-45109: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "9c5b9b3b6967c39a", "scanner": "scanner-primary", "fingerprint": "70a6a8a118696afd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45109"]}}, {"ruleId": "scanner-68ad75ed84fee85a", "level": "error", "message": {"text": "CVE-2026-64641: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "1cf925b91d36c016", "scanner": "scanner-primary", "fingerprint": "68ad75ed84fee85a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64641"]}}, {"ruleId": "scanner-81e27f1a5537116e", "level": "error", "message": {"text": "CVE-2026-64642: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "55e235779ec24bbc", "scanner": "scanner-primary", "fingerprint": "81e27f1a5537116e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64642"]}}, {"ruleId": "scanner-61fc7382f1d60637", "level": "error", "message": {"text": "CVE-2026-64645: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "900822af76671c1e", "scanner": "scanner-primary", "fingerprint": "61fc7382f1d60637", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64645"]}}, {"ruleId": "scanner-25eb76023e69b2f7", "level": "error", "message": {"text": "CVE-2026-64649: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "bfafecd473db8947", "scanner": "scanner-primary", "fingerprint": "25eb76023e69b2f7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64649"]}}, {"ruleId": "scanner-903a35efcbd83faa", "level": "error", "message": {"text": "GHSA-8h8q-6873-q5fj: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "23ffad8f4f1832f2", "scanner": "scanner-primary", "fingerprint": "903a35efcbd83faa", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-8h8q-6873-q5fj"]}}, {"ruleId": "scanner-7cd745804d7c9f22", "level": "error", "message": {"text": "GHSA-h25m-26qc-wcjf: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "3b0778e9a9311cca", "scanner": "scanner-primary", "fingerprint": "7cd745804d7c9f22", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-h25m-26qc-wcjf"]}}, {"ruleId": "scanner-90514de3bff32b52", "level": "error", "message": {"text": "GHSA-q4gf-8mx6-v5v3: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "0b398918dc95a930", "scanner": "scanner-primary", "fingerprint": "90514de3bff32b52", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-q4gf-8mx6-v5v3"]}}, {"ruleId": "scanner-9aee0ecf4eeec9d3", "level": "warning", "message": {"text": "CVE-2025-59471: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "46dadd93e4478a41", "scanner": "scanner-primary", "fingerprint": "9aee0ecf4eeec9d3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-59471"]}}, {"ruleId": "scanner-a6b94515f07b2188", "level": "warning", "message": {"text": "CVE-2025-59472: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "882f70b346b5e0cb", "scanner": "scanner-primary", "fingerprint": "a6b94515f07b2188", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-59472"]}}, {"ruleId": "scanner-6c4085f56157ba3f", "level": "warning", "message": {"text": "CVE-2026-27978: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "8de0444f17dad361", "scanner": "scanner-primary", "fingerprint": "6c4085f56157ba3f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27978"]}}, {"ruleId": "scanner-b1bfc52c9cd13723", "level": "warning", "message": {"text": "CVE-2026-27979: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "448b46fe3a4aae16", "scanner": "scanner-primary", "fingerprint": "b1bfc52c9cd13723", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27979"]}}, {"ruleId": "scanner-ef5c25ad9b0bc001", "level": "warning", "message": {"text": "CVE-2026-27980: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "8fa4f976047cbd84", "scanner": "scanner-primary", "fingerprint": "ef5c25ad9b0bc001", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27980"]}}, {"ruleId": "scanner-2dbb8b08bd85da2a", "level": "warning", "message": {"text": "CVE-2026-29057: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "6cdd2955b89d38a7", "scanner": "scanner-primary", "fingerprint": "2dbb8b08bd85da2a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29057"]}}, {"ruleId": "scanner-92446a80d43550c7", "level": "warning", "message": {"text": "CVE-2026-44576: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "d419b8ba73a33d0f", "scanner": "scanner-primary", "fingerprint": "92446a80d43550c7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44576"]}}, {"ruleId": "scanner-193f314c5b0e1d3c", "level": "warning", "message": {"text": "CVE-2026-44577: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "e69f849097706a6b", "scanner": "scanner-primary", "fingerprint": "193f314c5b0e1d3c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44577"]}}, {"ruleId": "scanner-575032f3b662a166", "level": "warning", "message": {"text": "CVE-2026-44580: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "7340846eb916fda7", "scanner": "scanner-primary", "fingerprint": "575032f3b662a166", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44580"]}}, {"ruleId": "scanner-e40d66835ed0b001", "level": "warning", "message": {"text": "CVE-2026-44581: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "20b8f619368a427e", "scanner": "scanner-primary", "fingerprint": "e40d66835ed0b001", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44581"]}}, {"ruleId": "scanner-bc1eaa36e104e0b5", "level": "warning", "message": {"text": "CVE-2026-64643: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "07f80256e3a245a4", "scanner": "scanner-primary", "fingerprint": "bc1eaa36e104e0b5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64643"]}}, {"ruleId": "scanner-0d0f5ee3fea5d82a", "level": "warning", "message": {"text": "CVE-2026-64644: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "db5a094da13440fc", "scanner": "scanner-primary", "fingerprint": "0d0f5ee3fea5d82a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64644"]}}, {"ruleId": "scanner-3d99815d120e5720", "level": "warning", "message": {"text": "CVE-2026-64646: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "c33af75b2e50060f", "scanner": "scanner-primary", "fingerprint": "3d99815d120e5720", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64646"]}}, {"ruleId": "scanner-47f1e7ccec44b321", "level": "warning", "message": {"text": "CVE-2026-64647: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "24ca0e570ec66544", "scanner": "scanner-primary", "fingerprint": "47f1e7ccec44b321", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64647"]}}, {"ruleId": "scanner-25f9c72a027a671b", "level": "warning", "message": {"text": "CVE-2026-64648: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "0c96f7e98a5f4a31", "scanner": "scanner-primary", "fingerprint": "25f9c72a027a671b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64648"]}}, {"ruleId": "scanner-4ff678e5afacfd3b", "level": "note", "message": {"text": "CVE-2026-27977: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "d22e9b74a7396c9d", "scanner": "scanner-primary", "fingerprint": "4ff678e5afacfd3b", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27977"]}}, {"ruleId": "scanner-4a5067e99d1d2839", "level": "note", "message": {"text": "CVE-2026-44572: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "bc8cc07b32b75ba2", "scanner": "scanner-primary", "fingerprint": "4a5067e99d1d2839", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44572"]}}, {"ruleId": "scanner-8572864282e9d2cd", "level": "note", "message": {"text": "CVE-2026-44582: next 16.1.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "6a65fa9d7acfb07c", "scanner": "scanner-primary", "fingerprint": "8572864282e9d2cd", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44582"]}}, {"ruleId": "scanner-66a7181321cd4574", "level": "error", "message": {"text": "CVE-2026-4867: path-to-regexp 0.1.12 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "e2522be283d41fb0", "scanner": "scanner-primary", "fingerprint": "66a7181321cd4574", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4867"]}}, {"ruleId": "scanner-3278edd8bb36e9a3", "level": "error", "message": {"text": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "3fb374cad34aa5f1", "scanner": "scanner-primary", "fingerprint": "3278edd8bb36e9a3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4926"]}}, {"ruleId": "scanner-3e1e9f0ddfde7210", "level": "warning", "message": {"text": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "5b96891e62feef1f", "scanner": "scanner-primary", "fingerprint": "3e1e9f0ddfde7210", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4923"]}}, {"ruleId": "scanner-69dae9ce198962e4", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "ea11aa9b083c1ecb", "scanner": "scanner-primary", "fingerprint": "69dae9ce198962e4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-72c20d0d98cfe94d", "level": "warning", "message": {"text": "CVE-2026-8723: qs 6.14.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "5a33a5febb34a133", "scanner": "scanner-primary", "fingerprint": "72c20d0d98cfe94d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8723"]}}, {"ruleId": "scanner-37160a2bb9cd508a", "level": "note", "message": {"text": "CVE-2026-2391: qs 6.14.1 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "0c5f1883a263d45c", "scanner": "scanner-primary", "fingerprint": "37160a2bb9cd508a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2391"]}}, {"ruleId": "scanner-6cf6b4b26d8f68b5", "level": "error", "message": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "07531b293085e3ab", "scanner": "scanner-primary", "fingerprint": "6cf6b4b26d8f68b5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f88m-g3jw-g9cj"]}}, {"ruleId": "scanner-28a33e70e381c6cd", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 10.0.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "45026ebb73c88b15", "scanner": "scanner-primary", "fingerprint": "28a33e70e381c6cd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-a91f6f94f1957178", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml"}, "properties": {"repobilityId": "45026ebb73c88b15", "scanner": "scanner-primary", "fingerprint": "a91f6f94f1957178", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-b6d266a673b5606c", "level": "warning", "message": {"text": "CVE-2025-12695: dspy 2.6.18 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt"}, "properties": {"repobilityId": "e66711d74b7096df", "scanner": "scanner-primary", "fingerprint": "b6d266a673b5606c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-12695"]}}, {"ruleId": "scanner-f3a2831de2156e54", "level": "error", "message": {"text": "CVE-2025-7707: llama-index 0.12.33 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt"}, "properties": {"repobilityId": "bc619ae17404aca9", "scanner": "scanner-primary", "fingerprint": "f3a2831de2156e54", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-7707"]}}, {"ruleId": "scanner-031abdba9947ef90", "level": "warning", "message": {"text": "CVE-2025-6211: llama-index 0.12.33 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt"}, "properties": {"repobilityId": "bb5177c367e9d3ee", "scanner": "scanner-primary", "fingerprint": "031abdba9947ef90", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6211"]}}, {"ruleId": "scanner-0daf8de7326d41ae", "level": "warning", "message": {"text": "CVE-2026-28684: python-dotenv 1.1.0 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt"}, "properties": {"repobilityId": "d86869f99e606842", "scanner": "scanner-primary", "fingerprint": "0daf8de7326d41ae", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28684"]}}, {"ruleId": "scanner-baee8b37dd27fd46", "level": "warning", "message": {"text": "CVE-2024-47081: requests 2.32.3 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt"}, "properties": {"repobilityId": "0fedc237614101b4", "scanner": "scanner-primary", "fingerprint": "baee8b37dd27fd46", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-47081"]}}, {"ruleId": "scanner-2f4848150f72695b", "level": "warning", "message": {"text": "CVE-2026-25645: requests 2.32.3 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt"}, "properties": {"repobilityId": "ce1ed6afc2a2447c", "scanner": "scanner-primary", "fingerprint": "2f4848150f72695b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25645"]}}, {"ruleId": "scanner-3cbe65dabb02179c", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.44.1 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt"}, "properties": {"repobilityId": "b17caa4bfef88e10", "scanner": "scanner-primary", "fingerprint": "3cbe65dabb02179c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-c4b2b1cb8c672815", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.44.1 \u2014 rag_tutorials/agentic_rag_math_agent/requirements.txt"}, "properties": {"repobilityId": "41ef42657555daf5", "scanner": "scanner-primary", "fingerprint": "c4b2b1cb8c672815", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-028a713c1e3b2c6c", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.40.2 \u2014 rag_tutorials/contextualai_rag_agent/requirements.txt"}, "properties": {"repobilityId": "79a1901b3cd826a8", "scanner": "scanner-primary", "fingerprint": "028a713c1e3b2c6c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-d19bd25122751719", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.40.2 \u2014 rag_tutorials/contextualai_rag_agent/requirements.txt"}, "properties": {"repobilityId": "39c3f0241f0e0d03", "scanner": "scanner-primary", "fingerprint": "d19bd25122751719", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-0a85762140d8c4bd", "level": "error", "message": {"text": "CVE-2026-45134: langchain 0.3.12 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "properties": {"repobilityId": "1a84cd0aa05659b0", "scanner": "scanner-primary", "fingerprint": "0a85762140d8c4bd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45134"]}}, {"ruleId": "scanner-2abf42730d67fe75", "level": "warning", "message": {"text": "CVE-2026-55443: langchain 0.3.12 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "properties": {"repobilityId": "9a71ca465ee266a5", "scanner": "scanner-primary", "fingerprint": "2abf42730d67fe75", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55443"]}}, {"ruleId": "scanner-a06608ca1836a0c6", "level": "warning", "message": {"text": "CVE-2026-55443: langchain-anthropic 0.3.0 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "properties": {"repobilityId": "a44dfcd5086fefda", "scanner": "scanner-primary", "fingerprint": "a06608ca1836a0c6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55443"]}}, {"ruleId": "scanner-4841fb5b69798c8c", "level": "error", "message": {"text": "CVE-2025-6984: langchain-community 0.3.12 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "properties": {"repobilityId": "cbeb5aa0aee063a6", "scanner": "scanner-primary", "fingerprint": "4841fb5b69798c8c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6984"]}}, {"ruleId": "scanner-ecb0ea337cb6d656", "level": "error", "message": {"text": "CVE-2025-68664: langchain-core 0.3.28 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "properties": {"repobilityId": "1f0e7fdc75bc831c", "scanner": "scanner-primary", "fingerprint": "ecb0ea337cb6d656", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-68664"]}}, {"ruleId": "scanner-5c829f7948e1a160", "level": "error", "message": {"text": "CVE-2025-65106: langchain-core 0.3.28 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "properties": {"repobilityId": "7496b39e5ed2b198", "scanner": "scanner-primary", "fingerprint": "5c829f7948e1a160", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-65106"]}}, {"ruleId": "scanner-23e58946dd98817c", "level": "error", "message": {"text": "CVE-2026-34070: langchain-core 0.3.28 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "properties": {"repobilityId": "ead0988bfff84d0a", "scanner": "scanner-primary", "fingerprint": "23e58946dd98817c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34070"]}}, {"ruleId": "scanner-a187341b67b1e9ae", "level": "error", "message": {"text": "CVE-2026-44843: langchain-core 0.3.28 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "properties": {"repobilityId": "9426b436ec6c2917", "scanner": "scanner-primary", "fingerprint": "a187341b67b1e9ae", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44843"]}}, {"ruleId": "scanner-8cbf0bfbb205a452", "level": "warning", "message": {"text": "CVE-2026-40087: langchain-core 0.3.28 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "properties": {"repobilityId": "8f92575b8feb9d3c", "scanner": "scanner-primary", "fingerprint": "8cbf0bfbb205a452", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40087"]}}, {"ruleId": "scanner-eb03055588e02d5c", "level": "note", "message": {"text": "CVE-2026-26013: langchain-core 0.3.28 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "properties": {"repobilityId": "242c2f969e2e95e6", "scanner": "scanner-primary", "fingerprint": "eb03055588e02d5c", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26013"]}}, {"ruleId": "scanner-92383730c079c89d", "level": "note", "message": {"text": "CVE-2026-41488: langchain-openai 0.2.14 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "properties": {"repobilityId": "8b55670b1d14ccbb", "scanner": "scanner-primary", "fingerprint": "92383730c079c89d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41488"]}}, {"ruleId": "scanner-90d56bafffb98c2c", "level": "warning", "message": {"text": "CVE-2026-28277: langgraph 0.2.53 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "properties": {"repobilityId": "25acf84bf3c82253", "scanner": "scanner-primary", "fingerprint": "90d56bafffb98c2c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28277"]}}, {"ruleId": "scanner-73d2f93a146b7041", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.41.1 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "properties": {"repobilityId": "d0521148ed7a65ff", "scanner": "scanner-primary", "fingerprint": "73d2f93a146b7041", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-556fc9207b6f7353", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.41.1 \u2014 rag_tutorials/corrective_rag/requirements.txt"}, "properties": {"repobilityId": "c765f6ebfea34322", "scanner": "scanner-primary", "fingerprint": "556fc9207b6f7353", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-ad70eb282b028267", "level": "error", "message": {"text": "CVE-2025-6984: langchain-community 0.3.13 \u2014 rag_tutorials/deepseek_local_rag_agent/requirements.txt"}, "properties": {"repobilityId": "c256af8c7c3f02f7", "scanner": "scanner-primary", "fingerprint": "ad70eb282b028267", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6984"]}}, {"ruleId": "scanner-55dc2961bad3ea2a", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.41.1 \u2014 rag_tutorials/deepseek_local_rag_agent/requirements.txt"}, "properties": {"repobilityId": "c3449b88cf7c8c8a", "scanner": "scanner-primary", "fingerprint": "55dc2961bad3ea2a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-1f9582fbb6c71345", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.41.1 \u2014 rag_tutorials/deepseek_local_rag_agent/requirements.txt"}, "properties": {"repobilityId": "4a70d076cdf8c9a8", "scanner": "scanner-primary", "fingerprint": "1f9582fbb6c71345", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-f9fa1d0d8c36bb2e", "level": "error", "message": {"text": "CVE-2025-6984: langchain-community 0.3.13 \u2014 rag_tutorials/gemini_agentic_rag/requirements.txt"}, "properties": {"repobilityId": "d41c999499780d7c", "scanner": "scanner-primary", "fingerprint": "f9fa1d0d8c36bb2e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6984"]}}, {"ruleId": "scanner-76684795b6d49ddf", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.41.1 \u2014 rag_tutorials/gemini_agentic_rag/requirements.txt"}, "properties": {"repobilityId": "c7ef6cb6120b0059", "scanner": "scanner-primary", "fingerprint": "76684795b6d49ddf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-20bb93f1f7d80f1e", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.41.1 \u2014 rag_tutorials/gemini_agentic_rag/requirements.txt"}, "properties": {"repobilityId": "dac8d0c230b72e42", "scanner": "scanner-primary", "fingerprint": "20bb93f1f7d80f1e", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-73248433c69e1c19", "level": "note", "message": {"text": "CVE-2026-49356: @babel/core 7.29.0 \u2014 rag_tutorials/multimodal_agentic_rag/frontend/package-lock.json"}, "properties": {"repobilityId": "00be3d9ca13fac33", "scanner": "scanner-primary", "fingerprint": "73248433c69e1c19", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49356"]}}, {"ruleId": "scanner-be0bd023b5f7bbcd", "level": "note", "message": {"text": "GHSA-g7r4-m6w7-qqqr: esbuild 0.27.7 \u2014 rag_tutorials/multimodal_agentic_rag/frontend/package-lock.json"}, "properties": {"repobilityId": "e67b35e2f40a4803", "scanner": "scanner-primary", "fingerprint": "be0bd023b5f7bbcd", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-g7r4-m6w7-qqqr"]}}, {"ruleId": "scanner-e5763f1e06e84d2f", "level": "error", "message": {"text": "CVE-2026-53571: vite 7.3.2 \u2014 rag_tutorials/multimodal_agentic_rag/frontend/package-lock.json"}, "properties": {"repobilityId": "cd6c92fe4bf94d54", "scanner": "scanner-primary", "fingerprint": "e5763f1e06e84d2f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53571"]}}, {"ruleId": "scanner-7e8de1f0a3dc4fb5", "level": "warning", "message": {"text": "CVE-2026-53632: vite 7.3.2 \u2014 rag_tutorials/multimodal_agentic_rag/frontend/package-lock.json"}, "properties": {"repobilityId": "239d49a0f188996a", "scanner": "scanner-primary", "fingerprint": "7e8de1f0a3dc4fb5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53632"]}}, {"ruleId": "scanner-c80187d503672659", "level": "error", "message": {"text": "CVE-2026-45134: langchain 0.3.12 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "properties": {"repobilityId": "fbc6c082e406d402", "scanner": "scanner-primary", "fingerprint": "c80187d503672659", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45134"]}}, {"ruleId": "scanner-d3e1c44e1c96cd5a", "level": "warning", "message": {"text": "CVE-2026-55443: langchain 0.3.12 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "properties": {"repobilityId": "e6326aa40b898084", "scanner": "scanner-primary", "fingerprint": "d3e1c44e1c96cd5a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55443"]}}, {"ruleId": "scanner-c7d585f501f0d6d7", "level": "error", "message": {"text": "CVE-2025-6984: langchain-community 0.3.12 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "properties": {"repobilityId": "376667ec2206ce45", "scanner": "scanner-primary", "fingerprint": "c7d585f501f0d6d7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6984"]}}, {"ruleId": "scanner-71bd658d01e091bc", "level": "error", "message": {"text": "CVE-2025-68664: langchain-core 0.3.25 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "properties": {"repobilityId": "ff93866028a68f06", "scanner": "scanner-primary", "fingerprint": "71bd658d01e091bc", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-68664"]}}, {"ruleId": "scanner-044c4cbca4db85f3", "level": "error", "message": {"text": "CVE-2025-65106: langchain-core 0.3.25 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "properties": {"repobilityId": "78986e4310083455", "scanner": "scanner-primary", "fingerprint": "044c4cbca4db85f3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-65106"]}}, {"ruleId": "scanner-e77897ff5c53b223", "level": "error", "message": {"text": "CVE-2026-34070: langchain-core 0.3.25 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "properties": {"repobilityId": "6c2838fb5356c4e6", "scanner": "scanner-primary", "fingerprint": "e77897ff5c53b223", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34070"]}}, {"ruleId": "scanner-a0b495d2d74f9086", "level": "error", "message": {"text": "CVE-2026-44843: langchain-core 0.3.25 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "properties": {"repobilityId": "e8b3bf9482100405", "scanner": "scanner-primary", "fingerprint": "a0b495d2d74f9086", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44843"]}}, {"ruleId": "scanner-54688a30e3eed570", "level": "warning", "message": {"text": "CVE-2026-40087: langchain-core 0.3.25 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "properties": {"repobilityId": "914ec98570d6c725", "scanner": "scanner-primary", "fingerprint": "54688a30e3eed570", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40087"]}}, {"ruleId": "scanner-dc62b242bbeabc38", "level": "note", "message": {"text": "CVE-2026-26013: langchain-core 0.3.25 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "properties": {"repobilityId": "f81dd86cffffd0ec", "scanner": "scanner-primary", "fingerprint": "dc62b242bbeabc38", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26013"]}}, {"ruleId": "scanner-1dee694b79363a57", "level": "warning", "message": {"text": "CVE-2026-28277: langgraph 0.2.53 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "properties": {"repobilityId": "a9ce9591d550a29d", "scanner": "scanner-primary", "fingerprint": "1dee694b79363a57", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28277"]}}, {"ruleId": "scanner-044fa0ada09ca62a", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.40.2 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "properties": {"repobilityId": "e8e460285b217bdf", "scanner": "scanner-primary", "fingerprint": "044fa0ada09ca62a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-6ce328fcd4edd599", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.40.2 \u2014 rag_tutorials/rag_agent_cohere/requirements.txt"}, "properties": {"repobilityId": "f6a85488a8a0c92b", "scanner": "scanner-primary", "fingerprint": "6ce328fcd4edd599", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-dd3258de198264df", "level": "error", "message": {"text": "CVE-2026-45134: langchain 0.3.12 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "properties": {"repobilityId": "0752336ebaa86857", "scanner": "scanner-primary", "fingerprint": "dd3258de198264df", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45134"]}}, {"ruleId": "scanner-41028822093a78ec", "level": "warning", "message": {"text": "CVE-2026-55443: langchain 0.3.12 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "properties": {"repobilityId": "1f0017f5ddacaf8e", "scanner": "scanner-primary", "fingerprint": "41028822093a78ec", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55443"]}}, {"ruleId": "scanner-a106ef367caaa98a", "level": "error", "message": {"text": "CVE-2025-6984: langchain-community 0.3.12 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "properties": {"repobilityId": "1c046717127adea3", "scanner": "scanner-primary", "fingerprint": "a106ef367caaa98a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6984"]}}, {"ruleId": "scanner-e009a0109531c29c", "level": "error", "message": {"text": "CVE-2025-68664: langchain-core 0.3.28 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "properties": {"repobilityId": "5c6611efdc37669c", "scanner": "scanner-primary", "fingerprint": "e009a0109531c29c", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-68664"]}}, {"ruleId": "scanner-5f4a3369e55beaa3", "level": "error", "message": {"text": "CVE-2025-65106: langchain-core 0.3.28 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "properties": {"repobilityId": "09e2730724cf70a8", "scanner": "scanner-primary", "fingerprint": "5f4a3369e55beaa3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-65106"]}}, {"ruleId": "scanner-128154cb6c002e60", "level": "error", "message": {"text": "CVE-2026-34070: langchain-core 0.3.28 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "properties": {"repobilityId": "1913727da9a58ca6", "scanner": "scanner-primary", "fingerprint": "128154cb6c002e60", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34070"]}}, {"ruleId": "scanner-d8a8f9d61b6fd1c8", "level": "error", "message": {"text": "CVE-2026-44843: langchain-core 0.3.28 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "properties": {"repobilityId": "b3d98b7bfe521c3b", "scanner": "scanner-primary", "fingerprint": "d8a8f9d61b6fd1c8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44843"]}}, {"ruleId": "scanner-728f207e52b5ecdb", "level": "warning", "message": {"text": "CVE-2026-40087: langchain-core 0.3.28 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "properties": {"repobilityId": "8c83cf829ca8ce78", "scanner": "scanner-primary", "fingerprint": "728f207e52b5ecdb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40087"]}}, {"ruleId": "scanner-41237beb7fafa1ea", "level": "note", "message": {"text": "CVE-2026-26013: langchain-core 0.3.28 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "properties": {"repobilityId": "8caf0e2a2eeab04c", "scanner": "scanner-primary", "fingerprint": "41237beb7fafa1ea", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26013"]}}, {"ruleId": "scanner-b00a7c58db8f3d87", "level": "note", "message": {"text": "CVE-2026-41488: langchain-openai 0.2.14 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "properties": {"repobilityId": "a1ca290c21b110a6", "scanner": "scanner-primary", "fingerprint": "b00a7c58db8f3d87", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41488"]}}, {"ruleId": "scanner-ade24ce6477e7a42", "level": "warning", "message": {"text": "CVE-2026-28277: langgraph 0.2.53 \u2014 rag_tutorials/rag_database_routing/requirements.txt"}, "properties": {"repobilityId": "00692d168ad0b229", "scanner": "scanner-primary", "fingerprint": "ade24ce6477e7a42", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28277"]}}, {"ruleId": "scanner-b84fec6e04ecbd70", "level": "error", "message": {"text": "CVE-2026-25990: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "71420fee08bc3abb", "scanner": "scanner-primary", "fingerprint": "b84fec6e04ecbd70", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25990"]}}, {"ruleId": "scanner-9ccf9c4795d48007", "level": "error", "message": {"text": "CVE-2026-40192: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "1587ddcde587eb03", "scanner": "scanner-primary", "fingerprint": "9ccf9c4795d48007", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40192"]}}, {"ruleId": "scanner-566543b094f7afba", "level": "error", "message": {"text": "CVE-2026-42311: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "daba4eb841078bc3", "scanner": "scanner-primary", "fingerprint": "566543b094f7afba", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42311"]}}, {"ruleId": "scanner-b063e0a74070afc7", "level": "error", "message": {"text": "CVE-2026-54058: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "f9fa285656aeed12", "scanner": "scanner-primary", "fingerprint": "b063e0a74070afc7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54058"]}}, {"ruleId": "scanner-ee68a691fb69b747", "level": "error", "message": {"text": "CVE-2026-54059: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "e919b07bfc381550", "scanner": "scanner-primary", "fingerprint": "ee68a691fb69b747", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54059"]}}, {"ruleId": "scanner-f966c3a326f35dbd", "level": "error", "message": {"text": "CVE-2026-54060: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "cbc3f6ab64521ef6", "scanner": "scanner-primary", "fingerprint": "f966c3a326f35dbd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54060"]}}, {"ruleId": "scanner-ca976ffffa09ed88", "level": "error", "message": {"text": "CVE-2026-55379: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "f2b980c5d3f17545", "scanner": "scanner-primary", "fingerprint": "ca976ffffa09ed88", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55379"]}}, {"ruleId": "scanner-b26ddb37009f7229", "level": "error", "message": {"text": "CVE-2026-55380: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "29f49a6442df4502", "scanner": "scanner-primary", "fingerprint": "b26ddb37009f7229", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55380"]}}, {"ruleId": "scanner-c71ab73de60f94f2", "level": "error", "message": {"text": "CVE-2026-59197: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "579128c854487f02", "scanner": "scanner-primary", "fingerprint": "c71ab73de60f94f2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59197"]}}, {"ruleId": "scanner-056ff754b495f044", "level": "error", "message": {"text": "CVE-2026-59199: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "2e4fbb53f0d3e980", "scanner": "scanner-primary", "fingerprint": "056ff754b495f044", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59199"]}}, {"ruleId": "scanner-d25d42a50249f16a", "level": "error", "message": {"text": "CVE-2026-59200: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "251e9c906c02de8b", "scanner": "scanner-primary", "fingerprint": "d25d42a50249f16a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59200"]}}, {"ruleId": "scanner-0775a3d0d9ae391f", "level": "error", "message": {"text": "CVE-2026-59204: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "84d41c548c9a293a", "scanner": "scanner-primary", "fingerprint": "0775a3d0d9ae391f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59204"]}}, {"ruleId": "scanner-a89b009f459c6893", "level": "error", "message": {"text": "CVE-2026-59205: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "5c1ee16a440c7730", "scanner": "scanner-primary", "fingerprint": "a89b009f459c6893", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59205"]}}, {"ruleId": "scanner-cba3103613a8f0d0", "level": "warning", "message": {"text": "CVE-2026-42308: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "4a350252fc2051d4", "scanner": "scanner-primary", "fingerprint": "cba3103613a8f0d0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42308"]}}, {"ruleId": "scanner-b5fd46d5ec8915f5", "level": "warning", "message": {"text": "CVE-2026-42310: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "431fab4e3c69819f", "scanner": "scanner-primary", "fingerprint": "b5fd46d5ec8915f5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42310"]}}, {"ruleId": "scanner-aa6c4ed8e3ea2302", "level": "warning", "message": {"text": "CVE-2026-55798: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "120a8405d009bd6e", "scanner": "scanner-primary", "fingerprint": "aa6c4ed8e3ea2302", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55798"]}}, {"ruleId": "scanner-cc3f0f04aaafed5a", "level": "warning", "message": {"text": "CVE-2026-59198: pillow 11.1.0 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "caa9b41b61e577c0", "scanner": "scanner-primary", "fingerprint": "cc3f0f04aaafed5a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59198"]}}, {"ruleId": "scanner-f27554fc1ed50399", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.44.1 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "1f57061345f02fd1", "scanner": "scanner-primary", "fingerprint": "f27554fc1ed50399", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-f184a96da9b8a0a2", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.44.1 \u2014 starter_ai_agents/ai_breakup_recovery_agent/requirements.txt"}, "properties": {"repobilityId": "309953e6243455a5", "scanner": "scanner-primary", "fingerprint": "f184a96da9b8a0a2", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-a315cc20f6b90517", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.41.1 \u2014 starter_ai_agents/ai_data_analysis_agent/requirements.txt"}, "properties": {"repobilityId": "8b332398b3b2d6ee", "scanner": "scanner-primary", "fingerprint": "a315cc20f6b90517", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-4b7be45732420fdf", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.41.1 \u2014 starter_ai_agents/ai_data_analysis_agent/requirements.txt"}, "properties": {"repobilityId": "0c454f1999c6e039", "scanner": "scanner-primary", "fingerprint": "4b7be45732420fdf", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-be64002deca969c0", "level": "error", "message": {"text": "CVE-2026-25990: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "properties": {"repobilityId": "57b2321675af8c43", "scanner": "scanner-primary", "fingerprint": "be64002deca969c0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25990"]}}, {"ruleId": "scanner-4a7ffe9e14e8f6ce", "level": "error", "message": {"text": "CVE-2026-40192: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "properties": {"repobilityId": "17f4a4ee7586e9f5", "scanner": "scanner-primary", "fingerprint": "4a7ffe9e14e8f6ce", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40192"]}}, {"ruleId": "scanner-eb376a1bd95bc207", "level": "error", "message": {"text": "CVE-2026-42311: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "properties": {"repobilityId": "3e02c0935937fe03", "scanner": "scanner-primary", "fingerprint": "eb376a1bd95bc207", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42311"]}}, {"ruleId": "scanner-e20cd4880e31a6ad", "level": "error", "message": {"text": "CVE-2026-54058: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "properties": {"repobilityId": "86a81214454323b0", "scanner": "scanner-primary", "fingerprint": "e20cd4880e31a6ad", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54058"]}}, {"ruleId": "scanner-87cbb2446bb5cf68", "level": "error", "message": {"text": "CVE-2026-54059: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "properties": {"repobilityId": "b7ed4f4e1344b695", "scanner": "scanner-primary", "fingerprint": "87cbb2446bb5cf68", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54059"]}}, {"ruleId": "scanner-cdf72b4cb8dfa33b", "level": "error", "message": {"text": "CVE-2026-54060: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "properties": {"repobilityId": "492fed6de842696f", "scanner": "scanner-primary", "fingerprint": "cdf72b4cb8dfa33b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54060"]}}, {"ruleId": "scanner-42d91a848a8007c9", "level": "error", "message": {"text": "CVE-2026-55379: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "properties": {"repobilityId": "bd091c9fe3486288", "scanner": "scanner-primary", "fingerprint": "42d91a848a8007c9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55379"]}}, {"ruleId": "scanner-0f6f8754368ca5bb", "level": "error", "message": {"text": "CVE-2026-55380: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "properties": {"repobilityId": "6cbcaabffaffd09e", "scanner": "scanner-primary", "fingerprint": "0f6f8754368ca5bb", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55380"]}}, {"ruleId": "scanner-95c45aa6ec6a4c0a", "level": "error", "message": {"text": "CVE-2026-59197: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "properties": {"repobilityId": "1be51746e3455abe", "scanner": "scanner-primary", "fingerprint": "95c45aa6ec6a4c0a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59197"]}}, {"ruleId": "scanner-6fb524501403d8a0", "level": "error", "message": {"text": "CVE-2026-59199: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "properties": {"repobilityId": "07cd400b8cd71164", "scanner": "scanner-primary", "fingerprint": "6fb524501403d8a0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59199"]}}, {"ruleId": "scanner-50ddbe77500ea919", "level": "error", "message": {"text": "CVE-2026-59200: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "properties": {"repobilityId": "96bba002ca836065", "scanner": "scanner-primary", "fingerprint": "50ddbe77500ea919", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59200"]}}, {"ruleId": "scanner-263f336633c6bc4b", "level": "error", "message": {"text": "CVE-2026-59204: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "properties": {"repobilityId": "a63fa16db3f467eb", "scanner": "scanner-primary", "fingerprint": "263f336633c6bc4b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59204"]}}, {"ruleId": "scanner-1a7a62cf2aba602c", "level": "error", "message": {"text": "CVE-2026-59205: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "properties": {"repobilityId": "2d6cae7bdb1e4e0c", "scanner": "scanner-primary", "fingerprint": "1a7a62cf2aba602c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59205"]}}, {"ruleId": "scanner-6c3b2915f7bb2e3f", "level": "warning", "message": {"text": "CVE-2026-42308: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "properties": {"repobilityId": "5c02602bd3b3b33e", "scanner": "scanner-primary", "fingerprint": "6c3b2915f7bb2e3f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42308"]}}, {"ruleId": "scanner-697bd035e7c634e2", "level": "warning", "message": {"text": "CVE-2026-42310: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "properties": {"repobilityId": "fe9d313d67b6a021", "scanner": "scanner-primary", "fingerprint": "697bd035e7c634e2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42310"]}}, {"ruleId": "scanner-9e0799d41925203c", "level": "warning", "message": {"text": "CVE-2026-55798: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "properties": {"repobilityId": "6e01c987cb5e3328", "scanner": "scanner-primary", "fingerprint": "9e0799d41925203c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55798"]}}, {"ruleId": "scanner-3e9ebd415b1ee270", "level": "warning", "message": {"text": "CVE-2026-59198: Pillow 10.4.0 \u2014 starter_ai_agents/ai_data_visualisation_agent/requirements.txt"}, "properties": {"repobilityId": "1f2f8a1cf0f2744f", "scanner": "scanner-primary", "fingerprint": "3e9ebd415b1ee270", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59198"]}}, {"ruleId": "scanner-9a46ed01e516b553", "level": "error", "message": {"text": "CVE-2023-50447: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "262483e982548fbb", "scanner": "scanner-primary", "fingerprint": "9a46ed01e516b553", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-50447"]}}, {"ruleId": "scanner-ecb128c487b08ce8", "level": "error", "message": {"text": "CVE-2023-4863: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "5cffc9dfe44d6595", "scanner": "scanner-primary", "fingerprint": "ecb128c487b08ce8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2023-4863"]}}, {"ruleId": "scanner-bcda5eee34d17507", "level": "error", "message": {"text": "CVE-2024-28219: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "5bb97f4446fb6649", "scanner": "scanner-primary", "fingerprint": "bcda5eee34d17507", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-28219"]}}, {"ruleId": "scanner-69c345f05864dac2", "level": "error", "message": {"text": "CVE-2026-54058: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "283787b4bc86e67b", "scanner": "scanner-primary", "fingerprint": "69c345f05864dac2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54058"]}}, {"ruleId": "scanner-75ef2cec54078611", "level": "error", "message": {"text": "CVE-2026-54059: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "1b25f552fa237d29", "scanner": "scanner-primary", "fingerprint": "75ef2cec54078611", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54059"]}}, {"ruleId": "scanner-daf9c301aa069472", "level": "error", "message": {"text": "CVE-2026-54060: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "2faab8b84054d52b", "scanner": "scanner-primary", "fingerprint": "daf9c301aa069472", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54060"]}}, {"ruleId": "scanner-17cf5a5cbcc29410", "level": "error", "message": {"text": "CVE-2026-55379: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "5823e0005691d75a", "scanner": "scanner-primary", "fingerprint": "17cf5a5cbcc29410", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55379"]}}, {"ruleId": "scanner-37dc457dbfce119e", "level": "error", "message": {"text": "CVE-2026-55380: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "f9c343f707f09693", "scanner": "scanner-primary", "fingerprint": "37dc457dbfce119e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55380"]}}, {"ruleId": "scanner-35eb9d21246003bc", "level": "error", "message": {"text": "CVE-2026-59197: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "099c660e46851753", "scanner": "scanner-primary", "fingerprint": "35eb9d21246003bc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59197"]}}, {"ruleId": "scanner-7cec6be97549d94d", "level": "error", "message": {"text": "CVE-2026-59199: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "005b4e65a87d5d90", "scanner": "scanner-primary", "fingerprint": "7cec6be97549d94d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59199"]}}, {"ruleId": "scanner-1d5603a2f3f9459a", "level": "error", "message": {"text": "CVE-2026-59200: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "8fdf5a0f918b6b17", "scanner": "scanner-primary", "fingerprint": "1d5603a2f3f9459a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59200"]}}, {"ruleId": "scanner-3618bc13a322a601", "level": "error", "message": {"text": "CVE-2026-59204: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "d72b26ebca1915aa", "scanner": "scanner-primary", "fingerprint": "3618bc13a322a601", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59204"]}}, {"ruleId": "scanner-7be48508a1b3254b", "level": "error", "message": {"text": "CVE-2026-59205: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "9868f6ba85461323", "scanner": "scanner-primary", "fingerprint": "7be48508a1b3254b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59205"]}}, {"ruleId": "scanner-177c5ca8fa4e240a", "level": "warning", "message": {"text": "CVE-2026-42308: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "74bbbeb67f1b06b1", "scanner": "scanner-primary", "fingerprint": "177c5ca8fa4e240a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42308"]}}, {"ruleId": "scanner-7a0f2e5a6e45c946", "level": "warning", "message": {"text": "CVE-2026-42310: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "ff8b8b89202606df", "scanner": "scanner-primary", "fingerprint": "7a0f2e5a6e45c946", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42310"]}}, {"ruleId": "scanner-8c038172829226bd", "level": "warning", "message": {"text": "CVE-2026-55798: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "fa4348184ef7465e", "scanner": "scanner-primary", "fingerprint": "8c038172829226bd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55798"]}}, {"ruleId": "scanner-2801d34288aa337d", "level": "warning", "message": {"text": "CVE-2026-59198: Pillow 10.0.0 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "f798c1de3a918d5d", "scanner": "scanner-primary", "fingerprint": "2801d34288aa337d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59198"]}}, {"ruleId": "scanner-fa6415a2f9898168", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.40.2 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "5c31648890521134", "scanner": "scanner-primary", "fingerprint": "fa6415a2f9898168", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-086c3cbbf7180871", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.40.2 \u2014 starter_ai_agents/ai_medical_imaging_agent/requirements.txt"}, "properties": {"repobilityId": "bf339d04423328e0", "scanner": "scanner-primary", "fingerprint": "086c3cbbf7180871", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-50ffa3ccc5778840", "level": "error", "message": {"text": "CVE-2025-47241: browser-use 0.1.26 \u2014 starter_ai_agents/ai_meme_generator_agent_browseruse/requirements.txt"}, "properties": {"repobilityId": "e788c8623a8f6002", "scanner": "scanner-primary", "fingerprint": "50ffa3ccc5778840", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-47241"]}}, {"ruleId": "scanner-f9514c12492c75b2", "level": "warning", "message": {"text": "CVE-2024-47081: Requests 2.32.3 \u2014 starter_ai_agents/ai_music_generator_agent/requirements.txt"}, "properties": {"repobilityId": "0b727e068cc69a01", "scanner": "scanner-primary", "fingerprint": "f9514c12492c75b2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-47081"]}}, {"ruleId": "scanner-26d86af34b4291bf", "level": "warning", "message": {"text": "CVE-2026-25645: Requests 2.32.3 \u2014 starter_ai_agents/ai_music_generator_agent/requirements.txt"}, "properties": {"repobilityId": "d3283fd7fe31ada4", "scanner": "scanner-primary", "fingerprint": "26d86af34b4291bf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25645"]}}, {"ruleId": "scanner-bec541e27cf2c78c", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.44.1 \u2014 starter_ai_agents/ai_music_generator_agent/requirements.txt"}, "properties": {"repobilityId": "b069979305ec0f15", "scanner": "scanner-primary", "fingerprint": "bec541e27cf2c78c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-cfc0037fe907b69c", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.44.1 \u2014 starter_ai_agents/ai_music_generator_agent/requirements.txt"}, "properties": {"repobilityId": "d77034edd1ae0882", "scanner": "scanner-primary", "fingerprint": "cfc0037fe907b69c", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-3e4be090e8dc43fd", "level": "error", "message": {"text": "CVE-2026-49825: lxml_html_clean 0.4.1 \u2014 starter_ai_agents/ai_startup_trend_analysis_agent/requirements.txt"}, "properties": {"repobilityId": "7cc758091f97f2e9", "scanner": "scanner-primary", "fingerprint": "3e4be090e8dc43fd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49825"]}}, {"ruleId": "scanner-4d17463603288f86", "level": "warning", "message": {"text": "CVE-2026-28348: lxml_html_clean 0.4.1 \u2014 starter_ai_agents/ai_startup_trend_analysis_agent/requirements.txt"}, "properties": {"repobilityId": "2b7d1abe4a78a8c6", "scanner": "scanner-primary", "fingerprint": "4d17463603288f86", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28348"]}}, {"ruleId": "scanner-0eace0482081f955", "level": "warning", "message": {"text": "CVE-2026-28350: lxml_html_clean 0.4.1 \u2014 starter_ai_agents/ai_startup_trend_analysis_agent/requirements.txt"}, "properties": {"repobilityId": "7f4564a64d25dd49", "scanner": "scanner-primary", "fingerprint": "0eace0482081f955", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28350"]}}, {"ruleId": "scanner-94671a265290be2c", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.40.2 \u2014 starter_ai_agents/ai_startup_trend_analysis_agent/requirements.txt"}, "properties": {"repobilityId": "008ceb9144e1f4f4", "scanner": "scanner-primary", "fingerprint": "94671a265290be2c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-31786e3ca25810a0", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.40.2 \u2014 starter_ai_agents/ai_startup_trend_analysis_agent/requirements.txt"}, "properties": {"repobilityId": "1dbff28154551185", "scanner": "scanner-primary", "fingerprint": "31786e3ca25810a0", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-00b68e0977411b0a", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.40.2 \u2014 starter_ai_agents/multimodal_ai_agent/requirements.txt"}, "properties": {"repobilityId": "96eb9edc677b8d3a", "scanner": "scanner-primary", "fingerprint": "00b68e0977411b0a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-8bec9abb4ff675ea", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.40.2 \u2014 starter_ai_agents/multimodal_ai_agent/requirements.txt"}, "properties": {"repobilityId": "7af72bcc65a9fc14", "scanner": "scanner-primary", "fingerprint": "8bec9abb4ff675ea", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-24e50370336732b7", "level": "warning", "message": {"text": "CVE-2026-28684: python-dotenv 1.0.1 \u2014 voice_ai_agents/ai_audio_tour_agent/requirements.txt"}, "properties": {"repobilityId": "672c88cac744d36f", "scanner": "scanner-primary", "fingerprint": "24e50370336732b7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28684"]}}, {"ruleId": "scanner-0ca870d181070bd1", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.43.2 \u2014 voice_ai_agents/ai_audio_tour_agent/requirements.txt"}, "properties": {"repobilityId": "5cfc82e4c1f8a1ea", "scanner": "scanner-primary", "fingerprint": "0ca870d181070bd1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-9fa8c450417ce0a8", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.43.2 \u2014 voice_ai_agents/ai_audio_tour_agent/requirements.txt"}, "properties": {"repobilityId": "fcfadedf0a60bc3f", "scanner": "scanner-primary", "fingerprint": "9fa8c450417ce0a8", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-73be0e5ba6f6a888", "level": "warning", "message": {"text": "CVE-2026-55443: langchain 1.0.3 \u2014 voice_ai_agents/voice_rag_openaisdk/requirements.txt"}, "properties": {"repobilityId": "b0eb55719532f319", "scanner": "scanner-primary", "fingerprint": "73be0e5ba6f6a888", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55443"]}}, {"ruleId": "scanner-9aebeeac2dd6a742", "level": "note", "message": {"text": "CVE-2026-41488: langchain-openai 1.0.2 \u2014 voice_ai_agents/voice_rag_openaisdk/requirements.txt"}, "properties": {"repobilityId": "aff7ca269d18fca9", "scanner": "scanner-primary", "fingerprint": "9aebeeac2dd6a742", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41488"]}}, {"ruleId": "scanner-a554fac8520e9d28", "level": "warning", "message": {"text": "CVE-2026-41481: langchain-text-splitters 1.0.0 \u2014 voice_ai_agents/voice_rag_openaisdk/requirements.txt"}, "properties": {"repobilityId": "cb8847b484144cd0", "scanner": "scanner-primary", "fingerprint": "a554fac8520e9d28", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41481"]}}, {"ruleId": "scanner-f0e87a3bb4d98a32", "level": "warning", "message": {"text": "CVE-2026-33682: streamlit 1.51.0 \u2014 voice_ai_agents/voice_rag_openaisdk/requirements.txt"}, "properties": {"repobilityId": "161a47e48f3899a6", "scanner": "scanner-primary", "fingerprint": "f0e87a3bb4d98a32", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33682"]}}, {"ruleId": "scanner-2305c18156848004", "level": "note", "message": {"text": "CVE-2026-10804: streamlit 1.51.0 \u2014 voice_ai_agents/voice_rag_openaisdk/requirements.txt"}, "properties": {"repobilityId": "3c4279e417887a04", "scanner": "scanner-primary", "fingerprint": "2305c18156848004", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-10804"]}}, {"ruleId": "scanner-8938d771197d84ac", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/Dockerfile"}, "properties": {"repobilityId": "5ff6fca735b74e8f", "scanner": "scanner-primary", "fingerprint": "8938d771197d84ac", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-839e962f2f1ffccc", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/Dockerfile"}, "properties": {"repobilityId": "ce812f5e1d187660", "scanner": "scanner-primary", "fingerprint": "839e962f2f1ffccc", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-b21aca1308f11221", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/ai-deep-research-agent/Dockerfile"}, "properties": {"repobilityId": "db041f549bcbddb7", "scanner": "scanner-primary", "fingerprint": "b21aca1308f11221", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-081a48a6697b6153", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/ai-deep-research-agent/Dockerfile"}, "properties": {"repobilityId": "efcb44eda462bd57", "scanner": "scanner-primary", "fingerprint": "081a48a6697b6153", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-5bf9d24cc015f39e", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/ai-financial-coach-agent/Dockerfile"}, "properties": {"repobilityId": "2bf993fce9e6504e", "scanner": "scanner-primary", "fingerprint": "5bf9d24cc015f39e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-31f7c4a60d8e456d", "level": "warning", "message": {"text": "DS-0013: 'RUN cd ...' to change directory \u2014 generative_ui_agents/ai-financial-coach-agent/Dockerfile"}, "properties": {"repobilityId": "38e199c6b649a399", "scanner": "scanner-primary", "fingerprint": "31f7c4a60d8e456d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-91906d0e116a5960", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/ai-financial-coach-agent/Dockerfile"}, "properties": {"repobilityId": "93123a9555239b8a", "scanner": "scanner-primary", "fingerprint": "91906d0e116a5960", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-ac9f1191b5ce66ac", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/ai-financial-coach-agent/docker/Dockerfile.agent"}, "properties": {"repobilityId": "ae5a90bc4c96014d", "scanner": "scanner-primary", "fingerprint": "ac9f1191b5ce66ac", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-26be52808012d0c5", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/ai-financial-coach-agent/docker/Dockerfile.agent"}, "properties": {"repobilityId": "6548167792c465e8", "scanner": "scanner-primary", "fingerprint": "26be52808012d0c5", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-fa0975fc495021a4", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/ai-financial-coach-agent/docker/Dockerfile.app"}, "properties": {"repobilityId": "8d6129e13031db3e", "scanner": "scanner-primary", "fingerprint": "fa0975fc495021a4", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-507e4e17ddb45104", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/ai-mcp-app-builder/Dockerfile"}, "properties": {"repobilityId": "302f4187d6afa78d", "scanner": "scanner-primary", "fingerprint": "507e4e17ddb45104", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-b6d057d4af9502ec", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/generative-ui-starter-project/Dockerfile"}, "properties": {"repobilityId": "ddb1009443d75daf", "scanner": "scanner-primary", "fingerprint": "b6d057d4af9502ec", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-c48646794ac03091", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/generative-ui-starter-project/Dockerfile"}, "properties": {"repobilityId": "135db742850b7fb2", "scanner": "scanner-primary", "fingerprint": "c48646794ac03091", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-ea7fc5d12b158d6d", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/generative-ui-starter-project/docker/Dockerfile.agent"}, "properties": {"repobilityId": "8ef2389582f84902", "scanner": "scanner-primary", "fingerprint": "ea7fc5d12b158d6d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-1cf4323a20789861", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/generative-ui-starter-project/docker/Dockerfile.agent"}, "properties": {"repobilityId": "167893b35c65f564", "scanner": "scanner-primary", "fingerprint": "1cf4323a20789861", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-198bc87686f1287c", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/generative-ui-starter-project/docker/Dockerfile.app"}, "properties": {"repobilityId": "f52a71bc399495e5", "scanner": "scanner-primary", "fingerprint": "198bc87686f1287c", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-093c0107b9bab304", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/Dockerfile"}, "properties": {"repobilityId": "18490f286c107742", "scanner": "scanner-primary", "fingerprint": "093c0107b9bab304", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-aff8f1d6b1d8da6b", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/Dockerfile"}, "properties": {"repobilityId": "e4f1697a7baa1a3b", "scanner": "scanner-primary", "fingerprint": "aff8f1d6b1d8da6b", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-c5880ea9dadba81f", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/Dockerfile"}, "properties": {"repobilityId": "8b45706e4b3a5f23", "scanner": "scanner-primary", "fingerprint": "c5880ea9dadba81f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-a2eca1a6cdf16a2e", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/Dockerfile"}, "properties": {"repobilityId": "2cb5870bde790559", "scanner": "scanner-primary", "fingerprint": "a2eca1a6cdf16a2e", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-f3eb66f7f6cc9a54", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 rag_tutorials/knowledge_graph_rag_citations/Dockerfile"}, "properties": {"repobilityId": "6d77f1dc8982120a", "scanner": "scanner-primary", "fingerprint": "f3eb66f7f6cc9a54", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-ba1a339a3725a627", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 rag_tutorials/knowledge_graph_rag_citations/Dockerfile"}, "properties": {"repobilityId": "73423e94df7ac070", "scanner": "scanner-primary", "fingerprint": "ba1a339a3725a627", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-30f81ea77323cb9a", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: agent_skills/commit-archaeologist/SKILL.md"}, "properties": {"repobilityId": "6f0b6fc2288f0476", "scanner": "scanner-primary", "fingerprint": "30f81ea77323cb9a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/commit-archaeologist/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-acd837563f524652", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: agent_skills/project-graveyard/SKILL.md"}, "properties": {"repobilityId": "abc90e0c51f75be3", "scanner": "scanner-primary", "fingerprint": "acd837563f524652", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/project-graveyard/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8b57d2c201369bdd", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: generative_ui_agents/ai-shadcn-component-generator/.mcp.json"}, "properties": {"repobilityId": "ae9bdcd40be0cf67", "scanner": "scanner-primary", "fingerprint": "8b57d2c201369bdd", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "mcp_config"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/.mcp.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-45e53fb3ee663120", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: generative_ui_agents/ai-dashboard-canvas-agent/AGENTS.md"}, "properties": {"repobilityId": "cc282c8daaf0df14", "scanner": "scanner-primary", "fingerprint": "45e53fb3ee663120", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "agents_md"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/AGENTS.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-54b357e483905b5f", "level": "warning", "message": {"text": "SkillSpector E1 (data-exfil) in agent_skills/advisor-orchestrator-worker/references/fallbacks.md"}, "properties": {"repobilityId": "7d4387460be4c99d", "scanner": "scanner-primary", "fingerprint": "54b357e483905b5f", "layer": "security", "severity": "medium", "confidence": 0.6, "tags": ["skillspector", "mcp-skill", "data-exfil", "E1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/advisor-orchestrator-worker/references/fallbacks.md"}, "region": {"startLine": 20}}}]}, {"ruleId": "scanner-8c1d1336667d25e7", "level": "note", "message": {"text": "SkillSpector EA3 (excessive-agency) in agent_skills/advisor-orchestrator-worker/README.md"}, "properties": {"repobilityId": "b8c840d861960a61", "scanner": "scanner-primary", "fingerprint": "8c1d1336667d25e7", "layer": "security", "severity": "low", "confidence": 0.75, "tags": ["skillspector", "mcp-skill", "excessive-agency", "EA3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/advisor-orchestrator-worker/README.md"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-1dc3805cb32d42d5", "level": "error", "message": {"text": "SkillSpector TM2 (tool-misuse) in agent_skills/advisor-orchestrator-worker/SKILL.md"}, "properties": {"repobilityId": "264a1f7984ba6eb9", "scanner": "scanner-primary", "fingerprint": "1dc3805cb32d42d5", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["skillspector", "mcp-skill", "tool-misuse", "TM2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/advisor-orchestrator-worker/SKILL.md"}, "region": {"startLine": 50}}}]}, {"ruleId": "scanner-d5fad7a53d87de8c", "level": "warning", "message": {"text": "SkillSpector AST4 (behavioral-ast) in agent_skills/commit-archaeologist/scripts/archaeologist.py"}, "properties": {"repobilityId": "66592dece9b0021f", "scanner": "scanner-primary", "fingerprint": "d5fad7a53d87de8c", "layer": "security", "severity": "medium", "confidence": 0.6, "tags": ["skillspector", "mcp-skill", "behavioral-ast", "AST4", "code-exec"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/commit-archaeologist/scripts/archaeologist.py"}, "region": {"startLine": 36}}}]}, {"ruleId": "scanner-09bc9d14b99cab54", "level": "warning", "message": {"text": "SkillSpector LP3 (mcp-least-priv) in agent_skills/commit-archaeologist/SKILL.md"}, "properties": {"repobilityId": "9eeab93cf1328334", "scanner": "scanner-primary", "fingerprint": "09bc9d14b99cab54", "layer": "security", "severity": "medium", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "mcp-least-priv", "LP3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/commit-archaeologist/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ccccec0ff2b15dfa", "level": "error", "message": {"text": "SkillSpector OH1 (output-handling) in agent_skills/commit-archaeologist/scripts/archaeologist.py"}, "properties": {"repobilityId": "9032377a8ad0d1fc", "scanner": "scanner-primary", "fingerprint": "ccccec0ff2b15dfa", "layer": "security", "severity": "high", "confidence": 0.95, "tags": ["skillspector", "mcp-skill", "output-handling", "OH1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/commit-archaeologist/scripts/archaeologist.py"}, "region": {"startLine": 36}}}]}, {"ruleId": "scanner-569a37efd41eeb09", "level": "warning", "message": {"text": "SkillSpector AST4 (behavioral-ast) in agent_skills/project-graveyard/scripts/graveyard.py"}, "properties": {"repobilityId": "d08386255d4e368f", "scanner": "scanner-primary", "fingerprint": "569a37efd41eeb09", "layer": "security", "severity": "medium", "confidence": 0.6, "tags": ["skillspector", "mcp-skill", "behavioral-ast", "AST4", "code-exec"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/project-graveyard/scripts/graveyard.py"}, "region": {"startLine": 57}}}]}, {"ruleId": "scanner-87a345ddad05493c", "level": "warning", "message": {"text": "SkillSpector LP3 (mcp-least-priv) in agent_skills/project-graveyard/SKILL.md"}, "properties": {"repobilityId": "82c522315dcdfe97", "scanner": "scanner-primary", "fingerprint": "87a345ddad05493c", "layer": "security", "severity": "medium", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "mcp-least-priv", "LP3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/project-graveyard/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c43f4e4ae5eeb967", "level": "error", "message": {"text": "SkillSpector OH1 (output-handling) in agent_skills/project-graveyard/scripts/graveyard.py"}, "properties": {"repobilityId": "9e63c647b21b7583", "scanner": "scanner-primary", "fingerprint": "c43f4e4ae5eeb967", "layer": "security", "severity": "high", "confidence": 0.95, "tags": ["skillspector", "mcp-skill", "output-handling", "OH1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/project-graveyard/scripts/graveyard.py"}, "region": {"startLine": 57}}}]}, {"ruleId": "scanner-7ac10d9fa1ef5161", "level": "warning", "message": {"text": "SkillSpector RA2 (rogue-agent) in agent_skills/project-graveyard/SKILL.md"}, "properties": {"repobilityId": "d435a4b470c380f0", "scanner": "scanner-primary", "fingerprint": "7ac10d9fa1ef5161", "layer": "security", "severity": "medium", "confidence": 0.6, "tags": ["skillspector", "mcp-skill", "rogue-agent", "RA2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/project-graveyard/SKILL.md"}, "region": {"startLine": 157}}}]}, {"ruleId": "scanner-7e7d84e51266fcd6", "level": "warning", "message": {"text": "SkillSpector AST4 (behavioral-ast) in agent_skills/scope-creep-detector/scripts/scope_creep.py"}, "properties": {"repobilityId": "884a65cb9a10d35b", "scanner": "scanner-primary", "fingerprint": "7e7d84e51266fcd6", "layer": "security", "severity": "medium", "confidence": 0.6, "tags": ["skillspector", "mcp-skill", "behavioral-ast", "AST4", "code-exec"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/scope-creep-detector/scripts/scope_creep.py"}, "region": {"startLine": 427}}}]}, {"ruleId": "scanner-fd9cde77f014e8c9", "level": "warning", "message": {"text": "SkillSpector LP3 (mcp-least-priv) in agent_skills/scope-creep-detector/SKILL.md"}, "properties": {"repobilityId": "1460b705b886ab40", "scanner": "scanner-primary", "fingerprint": "fd9cde77f014e8c9", "layer": "security", "severity": "medium", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "mcp-least-priv", "LP3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/scope-creep-detector/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ce9adb40c7043c45", "level": "error", "message": {"text": "SkillSpector OH1 (output-handling) in agent_skills/scope-creep-detector/scripts/scope_creep.py"}, "properties": {"repobilityId": "cbe60489517be605", "scanner": "scanner-primary", "fingerprint": "ce9adb40c7043c45", "layer": "security", "severity": "high", "confidence": 0.95, "tags": ["skillspector", "mcp-skill", "output-handling", "OH1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/scope-creep-detector/scripts/scope_creep.py"}, "region": {"startLine": 427}}}]}, {"ruleId": "scanner-79cbe26707ef2b73", "level": "warning", "message": {"text": "SkillSpector EA2 (excessive-agency) in agent_skills/thinking-out-loud/README.md"}, "properties": {"repobilityId": "f0020b4cae2ada78", "scanner": "scanner-primary", "fingerprint": "79cbe26707ef2b73", "layer": "security", "severity": "medium", "confidence": 0.75, "tags": ["skillspector", "mcp-skill", "excessive-agency", "EA2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/thinking-out-loud/README.md"}, "region": {"startLine": 55}}}]}, {"ruleId": "scanner-e637c415447867e4", "level": "none", "message": {"text": "Run SkillSpector's LLM-backed analysis in your own pipeline"}, "properties": {"repobilityId": "1936f198ff5212bf", "scanner": "scanner-primary", "fingerprint": "e637c415447867e4", "layer": "security", "severity": "info", "confidence": 1.0, "tags": ["skillspector", "mcp-skill", "llm-advisory", "ai-coder"]}}, {"ruleId": "scanner-0996d21f4d7057fe", "level": "warning", "message": {"text": "Dockerfile runs as root: rag_tutorials/knowledge_graph_rag_citations/Dockerfile"}, "properties": {"repobilityId": "eabedc3c51cfb2cb", "scanner": "scanner-primary", "fingerprint": "0996d21f4d7057fe", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-124e8b75ae537f2d", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim"}, "properties": {"repobilityId": "473c8096f65a50ac", "scanner": "scanner-primary", "fingerprint": "124e8b75ae537f2d", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/knowledge_graph_rag_citations/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d81e2fbc3ea73b52", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine"}, "properties": {"repobilityId": "790496f738f52e7b", "scanner": "scanner-primary", "fingerprint": "d81e2fbc3ea73b52", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/Dockerfile"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-bf5ee7e9e953b467", "level": "warning", "message": {"text": "Dockerfile runs as root: generative_ui_agents/mcp-apps-generative-ui-showcase/Dockerfile"}, "properties": {"repobilityId": "21755b869b57717d", "scanner": "scanner-primary", "fingerprint": "bf5ee7e9e953b467", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-0a92dc478fc49a78", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-slim"}, "properties": {"repobilityId": "6fd37ae7a1c0c16c", "scanner": "scanner-primary", "fingerprint": "0a92dc478fc49a78", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/mcp-apps-generative-ui-showcase/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-30f23287d71c59b5", "level": "warning", "message": {"text": "Dockerfile runs as root: generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/Dockerfile"}, "properties": {"repobilityId": "63a12522257a9bec", "scanner": "scanner-primary", "fingerprint": "30f23287d71c59b5", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-59733e35f10f58df", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-slim"}, "properties": {"repobilityId": "ac51d3b78ca516ab", "scanner": "scanner-primary", "fingerprint": "59733e35f10f58df", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7c203178a6c043d3", "level": "warning", "message": {"text": "Dockerfile runs as root: generative_ui_agents/generative-ui-starter-project/Dockerfile"}, "properties": {"repobilityId": "7bd7f6e9d8e0eff3", "scanner": "scanner-primary", "fingerprint": "7c203178a6c043d3", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-c333e416b5eb87a3", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-slim"}, "properties": {"repobilityId": "01a113564dc0dc6f", "scanner": "scanner-primary", "fingerprint": "c333e416b5eb87a3", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/Dockerfile"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-deb95921985c0eba", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12.10-slim"}, "properties": {"repobilityId": "6e63293f6ddf2658", "scanner": "scanner-primary", "fingerprint": "deb95921985c0eba", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/Dockerfile"}, "region": {"startLine": 26}}}]}, {"ruleId": "scanner-908ced333e1756aa", "level": "warning", "message": {"text": "Dockerfile runs as root: generative_ui_agents/ai-financial-coach-agent/Dockerfile"}, "properties": {"repobilityId": "720638c3ebc83550", "scanner": "scanner-primary", "fingerprint": "908ced333e1756aa", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-137b47b1586706ea", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-slim"}, "properties": {"repobilityId": "17ec57211061e28f", "scanner": "scanner-primary", "fingerprint": "137b47b1586706ea", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/Dockerfile"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-7cf87170c056b4ce", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "properties": {"repobilityId": "ec1b224d87b92c30", "scanner": "scanner-primary", "fingerprint": "7cf87170c056b4ce", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/Dockerfile"}, "region": {"startLine": 16}}}]}, {"ruleId": "scanner-2587dffec04f204d", "level": "warning", "message": {"text": "Dockerfile runs as root: generative_ui_agents/ai-deep-research-agent/Dockerfile"}, "properties": {"repobilityId": "e055b8ce1b5263f7", "scanner": "scanner-primary", "fingerprint": "2587dffec04f204d", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-b7c8b2c0e3faccc1", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-slim"}, "properties": {"repobilityId": "19786e7f73d47f05", "scanner": "scanner-primary", "fingerprint": "b7c8b2c0e3faccc1", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5c2bdbe291c36263", "level": "warning", "message": {"text": "Dockerfile runs as root: advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/Dockerfile"}, "properties": {"repobilityId": "8c9e16b5a6408b9b", "scanner": "scanner-primary", "fingerprint": "5c2bdbe291c36263", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-fcaaee4a9a3b1419", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim-bookworm"}, "properties": {"repobilityId": "e7f37ef60e4d632f", "scanner": "scanner-primary", "fingerprint": "fcaaee4a9a3b1419", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-6084631fc9d83f2e", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in agent_skills/self-improving-agent-skills/frontend/src/app/layout.tsx:21"}, "properties": {"repobilityId": "bd2604e083c397bd", "scanner": "scanner-primary", "fingerprint": "6084631fc9d83f2e", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/src/app/layout.tsx"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-d58bb89ade03cfdf", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in agent_skills/self-improving-agent-skills/backend/app.py:36"}, "properties": {"repobilityId": "6641badc6f460667", "scanner": "scanner-primary", "fingerprint": "d58bb89ade03cfdf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/backend/app.py"}, "region": {"startLine": 36}}}]}, {"ruleId": "scanner-6a9d1b01da28042f", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in generative_ui_agents/ai-mcp-app-builder/apps/threejs-server/server-utils.ts:29"}, "properties": {"repobilityId": "e5e1888296d29bc0", "scanner": "scanner-primary", "fingerprint": "6a9d1b01da28042f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/threejs-server/server-utils.ts"}, "region": {"startLine": 29}}}]}, {"ruleId": "scanner-811f4c0054412f39", "level": "error", "message": {"text": "Insecure pattern 'new_function_used' in generative_ui_agents/ai-mcp-app-builder/apps/threejs-server/src/threejs-app.tsx:152"}, "properties": {"repobilityId": "8240fed5a9fbad9d", "scanner": "scanner-primary", "fingerprint": "811f4c0054412f39", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "new_function_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/threejs-server/src/threejs-app.tsx"}, "region": {"startLine": 152}}}]}, {"ruleId": "scanner-be05b94be89f8482", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in generative_ui_agents/ai-mcp-app-builder/apps/web/app/api/copilotkit/route.ts:224"}, "properties": {"repobilityId": "74c3c89ff266aa5c", "scanner": "scanner-primary", "fingerprint": "be05b94be89f8482", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/app/api/copilotkit/route.ts"}, "region": {"startLine": 224}}}]}, {"ruleId": "scanner-338b6d95f886c01c", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in generative_ui_agents/ai-mcp-app-builder/apps/web/lib/workspace/types.ts:35"}, "properties": {"repobilityId": "656ad649eaece484", "scanner": "scanner-primary", "fingerprint": "338b6d95f886c01c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/lib/workspace/types.ts"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-72d1bfd86c18bddd", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in generative_ui_agents/ai-mcp-app-builder/apps/web/lib/workspace/e2b.ts:121"}, "properties": {"repobilityId": "e837d2a1095e6e23", "scanner": "scanner-primary", "fingerprint": "72d1bfd86c18bddd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/lib/workspace/e2b.ts"}, "region": {"startLine": 121}}}]}, {"ruleId": "scanner-5b447def713a97aa", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/server.ts:1011"}, "properties": {"repobilityId": "be967f360c593f0c", "scanner": "scanner-primary", "fingerprint": "5b447def713a97aa", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/server.ts"}, "region": {"startLine": 1011}}}]}, {"ruleId": "scanner-7debbe8750a4dc50", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/apps/trading-app.html:1251"}, "properties": {"repobilityId": "cd3d27ed6ddddf4f", "scanner": "scanner-primary", "fingerprint": "7debbe8750a4dc50", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/apps/trading-app.html"}, "region": {"startLine": 1251}}}]}, {"ruleId": "scanner-45c29b0ae527233a", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/apps/kanban-app.html:1255"}, "properties": {"repobilityId": "a016341f047db687", "scanner": "scanner-primary", "fingerprint": "45c29b0ae527233a", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/apps/kanban-app.html"}, "region": {"startLine": 1255}}}]}, {"ruleId": "scanner-5a6a73adb0304304", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in generative_ui_agents/generative-ui-starter-project/serve.py:35"}, "properties": {"repobilityId": "af35c5629f90a118", "scanner": "scanner-primary", "fingerprint": "5a6a73adb0304304", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/serve.py"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-4566df7e467de5ab", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in generative_ui_agents/ai-shadcn-component-generator/apps/ui/src/components/ui/chart.tsx:75"}, "properties": {"repobilityId": "0f3b835333287c73", "scanner": "scanner-primary", "fingerprint": "4566df7e467de5ab", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/ui/src/components/ui/chart.tsx"}, "region": {"startLine": 75}}}]}, {"ruleId": "scanner-ea4a8a80849d9085", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in generative_ui_agents/ai-shadcn-component-generator/apps/runtime/server.ts:25"}, "properties": {"repobilityId": "edff447a9a9637a8", "scanner": "scanner-primary", "fingerprint": "ea4a8a80849d9085", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/runtime/server.ts"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-df43e23c70c7c0ac", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in generative_ui_agents/ai-dashboard-canvas-agent/src/components/ui/chart.tsx:83"}, "properties": {"repobilityId": "a1938cdf1c58ee60", "scanner": "scanner-primary", "fingerprint": "df43e23c70c7c0ac", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/src/components/ui/chart.tsx"}, "region": {"startLine": 83}}}]}, {"ruleId": "scanner-8452a3b1942852d9", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in generative_ui_agents/ai-deep-research-agent/agent/main.py:30"}, "properties": {"repobilityId": "8c981fb2c0712f1d", "scanner": "scanner-primary", "fingerprint": "8452a3b1942852d9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/main.py"}, "region": {"startLine": 30}}}]}, {"ruleId": "scanner-8d6e1a2745160507", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in advanced_llm_apps/multimodal_video_moment_finder/backend/server.py:25"}, "properties": {"repobilityId": "9ec4a1334e982e19", "scanner": "scanner-primary", "fingerprint": "8d6e1a2745160507", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/backend/server.py"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-ff6f9d00edcd112c", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent/live_demo/app.js:234"}, "properties": {"repobilityId": "b65f018c94dfc50e", "scanner": "scanner-primary", "fingerprint": "ff6f9d00edcd112c", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent/live_demo/app.js"}, "region": {"startLine": 234}}}]}, {"ruleId": "scanner-4f4fb7777a289e32", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/api/app.py:47"}, "properties": {"repobilityId": "c2487d5eab31e359", "scanner": "scanner-primary", "fingerprint": "4f4fb7777a289e32", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/api/app.py"}, "region": {"startLine": 47}}}]}, {"ruleId": "scanner-11e607b5080657ef", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in advanced_ai_agents/multi_agent_apps/ai_speech_trainer_agent/backend/main.py:19"}, "properties": {"repobilityId": "4d95bfc927cd23a5", "scanner": "scanner-primary", "fingerprint": "11e607b5080657ef", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_speech_trainer_agent/backend/main.py"}, "region": {"startLine": 19}}}]}, {"ruleId": "scanner-aee83c85e2149402", "level": "error", "message": {"text": "Insecure pattern 'subprocess_shell_true' in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/scheduler.py:97"}, "properties": {"repobilityId": "353c0118f8dbc34a", "scanner": "scanner-primary", "fingerprint": "aee83c85e2149402", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "subprocess_shell_true"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/scheduler.py"}, "region": {"startLine": 97}}}]}, {"ruleId": "scanner-7e952106ac751d6c", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/main.py:43"}, "properties": {"repobilityId": "887f8af71955e882", "scanner": "scanner-primary", "fingerprint": "7e952106ac751d6c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/main.py"}, "region": {"startLine": 43}}}]}, {"ruleId": "scanner-c84de2baf86a7c9a", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ScriptConfirmation.js:116"}, "properties": {"repobilityId": "dd9d1a84e6e4e47c", "scanner": "scanner-primary", "fingerprint": "c84de2baf86a7c9a", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ScriptConfirmation.js"}, "region": {"startLine": 116}}}]}, {"ruleId": "scanner-46157b1f2a30f4d9", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ChatMessage.js:320"}, "properties": {"repobilityId": "9920dc9b6f929009", "scanner": "scanner-primary", "fingerprint": "46157b1f2a30f4d9", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/components/ChatMessage.js"}, "region": {"startLine": 320}}}]}, {"ruleId": "scanner-2a7a31d542a1ad59", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/ArticleDetail.js:217"}, "properties": {"repobilityId": "f823e60adca6e699", "scanner": "scanner-primary", "fingerprint": "2a7a31d542a1ad59", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/ArticleDetail.js"}, "region": {"startLine": 217}}}]}, {"ruleId": "scanner-7c814311053a5c62", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/ArticleDetail.js:37"}, "properties": {"repobilityId": "486cc77885bf492d", "scanner": "scanner-primary", "fingerprint": "7c814311053a5c62", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/ArticleDetail.js"}, "region": {"startLine": 37}}}]}, {"ruleId": "scanner-10db8d5934adbdd5", "level": "warning", "message": {"text": "Possible secret in ai_agent_framework_crash_course/google_adk_crash_course/4_tool_using_agent/4_2_function_tools/utility_agent/agent.py"}, "properties": {"repobilityId": "d2b8efc6b7761da9", "scanner": "scanner-primary", "fingerprint": "10db8d5934adbdd5", "layer": "security", "severity": "medium", "confidence": 0.58, "tags": ["secrets", "password_literal"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "ai_agent_framework_crash_course/google_adk_crash_course/4_tool_using_agent/4_2_function_tools/utility_agent/agent.py"}, "region": {"startLine": 67}}}]}, {"ruleId": "scanner-ebad02ab93d6ca4d", "level": "warning", "message": {"text": "Insecure pattern 'weak_hash' in ai_agent_framework_crash_course/google_adk_crash_course/4_tool_using_agent/4_2_function_tools/utility_agent/agent.py:39"}, "properties": {"repobilityId": "880931b3c46cae75", "scanner": "scanner-primary", "fingerprint": "ebad02ab93d6ca4d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "weak_hash"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "ai_agent_framework_crash_course/google_adk_crash_course/4_tool_using_agent/4_2_function_tools/utility_agent/agent.py"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-0df1d3afe4852060", "level": "error", "message": {"text": "Insecure pattern 'eval_used' in ai_agent_framework_crash_course/google_adk_crash_course/4_tool_using_agent/4_2_function_tools/calculator_agent/tools.py:30"}, "properties": {"repobilityId": "095ff6bb51c5a086", "scanner": "scanner-primary", "fingerprint": "0df1d3afe4852060", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "eval_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "ai_agent_framework_crash_course/google_adk_crash_course/4_tool_using_agent/4_2_function_tools/calculator_agent/tools.py"}, "region": {"startLine": 30}}}]}, {"ruleId": "scanner-79d4ad6330dc2aba", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in voice_ai_agents/insurance_claim_live_agent_team/live_demo/app.js:88"}, "properties": {"repobilityId": "c015c343a5a6863f", "scanner": "scanner-primary", "fingerprint": "79d4ad6330dc2aba", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "voice_ai_agents/insurance_claim_live_agent_team/live_demo/app.js"}, "region": {"startLine": 88}}}]}, {"ruleId": "scanner-de53ac274e5b4ecf", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "02600186fc092bd4", "scanner": "scanner-primary", "fingerprint": "de53ac274e5b4ecf", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/claude.yml"}, "region": {"startLine": 28}}}]}, {"ruleId": "scanner-37716d9c0a33ad5c", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "abfb5752158cf655", "scanner": "scanner-primary", "fingerprint": "37716d9c0a33ad5c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/claude.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5b2949ca1261d964", "level": "warning", "message": {"text": "Install-time lifecycle script performs network/shell-sensitive actions"}, "properties": {"repobilityId": "64b5068abc67f86a", "scanner": "scanner-primary", "fingerprint": "5b2949ca1261d964", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "npm", "install-scripts"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/mcp-use-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a705dfe1f502cc21", "level": "note", "message": {"text": "package.json defines install-time lifecycle scripts"}, "properties": {"repobilityId": "40ccbbb548af09a2", "scanner": "scanner-primary", "fingerprint": "a705dfe1f502cc21", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "npm", "install-scripts"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-823c96aab48f155e", "level": "note", "message": {"text": "package.json defines install-time lifecycle scripts"}, "properties": {"repobilityId": "6c5898603c99fdb2", "scanner": "scanner-primary", "fingerprint": "823c96aab48f155e", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "npm", "install-scripts"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9eed015d6887d44c", "level": "note", "message": {"text": "package.json defines install-time lifecycle scripts"}, "properties": {"repobilityId": "379e914882d9f780", "scanner": "scanner-primary", "fingerprint": "9eed015d6887d44c", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "npm", "install-scripts"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-caab76011a0db20c", "level": "note", "message": {"text": "Very large file: advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/app/plan/page.tsx (1570 lines)"}, "properties": {"repobilityId": "ba650af3c46e8c50", "scanner": "scanner-primary", "fingerprint": "caab76011a0db20c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-635f69733dae0e7a", "level": "note", "message": {"text": "Very large file: advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/app/plan/[id]/page.tsx (1408 lines)"}, "properties": {"repobilityId": "2de441a84dcf29c1", "scanner": "scanner-primary", "fingerprint": "635f69733dae0e7a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-0be509d7d6947cf4", "level": "note", "message": {"text": "Very large file: advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/StudioChat.js (1117 lines)"}, "properties": {"repobilityId": "fcec04c48389b4f9", "scanner": "scanner-primary", "fingerprint": "0be509d7d6947cf4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-48bb1e4ea95373c5", "level": "note", "message": {"text": "Very large file: advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/pages/Voyager.js (1149 lines)"}, "properties": {"repobilityId": "e1f96b74554ac9b9", "scanner": "scanner-primary", "fingerprint": "48bb1e4ea95373c5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-f8adda22c6c7cf34", "level": "note", "message": {"text": "Very large file: advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/icons/Spoot.js (1606 lines)"}, "properties": {"repobilityId": "6ec530eb444424f0", "scanner": "scanner-primary", "fingerprint": "f8adda22c6c7cf34", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-cc50b20e62a007b0", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: generative_ui_agents/ai-mcp-app-builder/apps/mcp-use-server/package.json"}, "properties": {"repobilityId": "7d8acf799b655d87", "scanner": "scanner-primary", "fingerprint": "cc50b20e62a007b0", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/mcp-use-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-872999b329355dc0", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: generative_ui_agents/ai-mcp-app-builder/apps/threejs-server/package.json"}, "properties": {"repobilityId": "631d1624d376a202", "scanner": "scanner-primary", "fingerprint": "872999b329355dc0", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/threejs-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7841b0cd403d4440", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: generative_ui_agents/ai-mcp-app-builder/apps/web/package.json"}, "properties": {"repobilityId": "08bc90495cabd27f", "scanner": "scanner-primary", "fingerprint": "7841b0cd403d4440", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e4b50c035209810b", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: generative_ui_agents/ai-shadcn-component-generator/package.json"}, "properties": {"repobilityId": "adbc60a719a29eda", "scanner": "scanner-primary", "fingerprint": "e4b50c035209810b", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-39738f8ef6ff0eed", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: generative_ui_agents/ai-shadcn-component-generator/apps/ui/package.json"}, "properties": {"repobilityId": "78b089642575a57a", "scanner": "scanner-primary", "fingerprint": "39738f8ef6ff0eed", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/ui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-43d15c3aa1283e4e", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: generative_ui_agents/ai-shadcn-component-generator/apps/runtime/package.json"}, "properties": {"repobilityId": "8c9c1c4434b3ef4c", "scanner": "scanner-primary", "fingerprint": "43d15c3aa1283e4e", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/runtime/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e47f1e9c51c8bd25", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: advanced_llm_apps/chat_with_X_tutorials/streaming_ai_chatbot/package.json"}, "properties": {"repobilityId": "481d53dab2eed7c5", "scanner": "scanner-primary", "fingerprint": "e47f1e9c51c8bd25", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/chat_with_X_tutorials/streaming_ai_chatbot/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b1479f7ec75d9ba8", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/package.json"}, "properties": {"repobilityId": "fbff437ddab3ca93", "scanner": "scanner-primary", "fingerprint": "b1479f7ec75d9ba8", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "ca6adbb924c6280c", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "1e9e26a232f1b020", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "7c263af1dab3107c", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "710c7be0d8ec9158", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-a49eac436c6b66f7", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 starter_ai_agents/ai_music_generator_agent/music_generator_agent.py:56"}, "properties": {"repobilityId": "da458db46f02959a", "scanner": "scanner-primary", "fingerprint": "a49eac436c6b66f7", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "starter_ai_agents/ai_music_generator_agent/music_generator_agent.py"}, "region": {"startLine": 56}}}]}, {"ruleId": "scanner-2c748e4c47855574", "level": "note", "message": {"text": "Legacy-named symbol `eleven_multilingual_v2` in starter_ai_agents/ai_blog_to_podcast_agent/blog_to_podcast_agent.py:57"}, "properties": {"repobilityId": "7364855d6c808eee", "scanner": "scanner-primary", "fingerprint": "2c748e4c47855574", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-a3c153f48164339c", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 agent_skills/scope-creep-detector/scripts/scope_creep.py:427"}, "properties": {"repobilityId": "ec79b6e66837178c", "scanner": "scanner-primary", "fingerprint": "a3c153f48164339c", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/scope-creep-detector/scripts/scope_creep.py"}, "region": {"startLine": 427}}}]}, {"ruleId": "scanner-96705cdbd4436716", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 rag_tutorials/rag-as-a-service/rag_app.py:40"}, "properties": {"repobilityId": "fdea1f110c4ee960", "scanner": "scanner-primary", "fingerprint": "96705cdbd4436716", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/rag-as-a-service/rag_app.py"}, "region": {"startLine": 40}}}]}, {"ruleId": "scanner-1852c16d70f02b90", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in rag_tutorials/agentic_typed_rag_pydanticai/agent.py:217"}, "properties": {"repobilityId": "7a15da9dfc63b13a", "scanner": "scanner-primary", "fingerprint": "1852c16d70f02b90", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-81b04e2bb62c8118", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 rag_tutorials/agentic_rag_math_agent/rag/query_router.py:61"}, "properties": {"repobilityId": "e43faac85d0eb94c", "scanner": "scanner-primary", "fingerprint": "81b04e2bb62c8118", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/agentic_rag_math_agent/rag/query_router.py"}, "region": {"startLine": 61}}}]}, {"ruleId": "scanner-8f1b3d32e2605136", "level": "warning", "message": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 generative_ui_agents/ai-mcp-app-builder/apps/web/app/page.tsx:226"}, "properties": {"repobilityId": "5d782bcc7129bace", "scanner": "scanner-primary", "fingerprint": "8f1b3d32e2605136", "layer": "quality", "severity": "medium", "confidence": 0.9, "tags": ["integrity", "fragile-runtime", "robustness", "unhandled-promise"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/app/page.tsx"}, "region": {"startLine": 226}}}]}, {"ruleId": "scanner-e3cc5b8a888d4a2f", "level": "none", "message": {"text": "Commented-code block (6 lines) in generative_ui_agents/ai-dashboard-canvas-agent/agent/state.py:5"}, "properties": {"repobilityId": "60d66319a1dda559", "scanner": "scanner-primary", "fingerprint": "e3cc5b8a888d4a2f", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/agent/state.py"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-7d0d0669f49a41f9", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 advanced_llm_apps/multimodal_video_moment_finder/backend/video_store.py:89"}, "properties": {"repobilityId": "dd12461d40ba7f9a", "scanner": "scanner-primary", "fingerprint": "7d0d0669f49a41f9", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/backend/video_store.py"}, "region": {"startLine": 89}}}]}, {"ruleId": "scanner-d728da5a2e75f623", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent/youtube_ingest.py:332"}, "properties": {"repobilityId": "46d46cb8599136c4", "scanner": "scanner-primary", "fingerprint": "d728da5a2e75f623", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent/youtube_ingest.py"}, "region": {"startLine": 332}}}]}, {"ruleId": "scanner-5ae8d134083a71e4", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent/agent.py:235"}, "properties": {"repobilityId": "48cc257981b3026c", "scanner": "scanner-primary", "fingerprint": "5ae8d134083a71e4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-b6b2aa877ba27ad2", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 advanced_ai_agents/single_agent_apps/ai_fraud_investigation_agent/fraud_investigation_agent.py:634"}, "properties": {"repobilityId": "578f85abdb842072", "scanner": "scanner-primary", "fingerprint": "b6b2aa877ba27ad2", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/ai_fraud_investigation_agent/fraud_investigation_agent.py"}, "region": {"startLine": 634}}}]}, {"ruleId": "scanner-71d7cc7a73b2fe1e", "level": "note", "message": {"text": "Legacy-named symbol `kitchen_modern_renovation_v1` in advanced_ai_agents/multi_agent_apps/ai_home_renovation_agent/agent.py:151"}, "properties": {"repobilityId": "95526f2c886249d0", "scanner": "scanner-primary", "fingerprint": "71d7cc7a73b2fe1e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-7950fd1d9182434a", "level": "note", "message": {"text": "Legacy-named symbol `landing_page_v1` in advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_uiux_feedback_agent_team/agent.py:64"}, "properties": {"repobilityId": "5595fce3dd1afabf", "scanner": "scanner-primary", "fingerprint": "7950fd1d9182434a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-468b5acbb598a972", "level": "none", "message": {"text": "Commented-code block (6 lines) in advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/broswer.py:37"}, "properties": {"repobilityId": "91e6385a38f7e474", "scanner": "scanner-primary", "fingerprint": "468b5acbb598a972", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/broswer.py"}, "region": {"startLine": 37}}}]}, {"ruleId": "scanner-be783e8c72fcdf64", "level": "none", "message": {"text": "Commented-code block (5 lines) in advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/config/logger.py:40"}, "properties": {"repobilityId": "decddc62b3f29391", "scanner": "scanner-primary", "fingerprint": "be783e8c72fcdf64", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/config/logger.py"}, "region": {"startLine": 40}}}]}, {"ruleId": "scanner-a55eff85d3e0f5f7", "level": "none", "message": {"text": "Commented-code block (7 lines) in advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/agents/team.py:13"}, "properties": {"repobilityId": "1c09113a058ba754", "scanner": "scanner-primary", "fingerprint": "a55eff85d3e0f5f7", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/agents/team.py"}, "region": {"startLine": 13}}}]}, {"ruleId": "scanner-31f40a004d49d5c3", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 advanced_ai_agents/multi_agent_apps/ai_speech_trainer_agent/frontend/Home.py:106"}, "properties": {"repobilityId": "01e23ad1d2b9df92", "scanner": "scanner-primary", "fingerprint": "31f40a004d49d5c3", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_speech_trainer_agent/frontend/Home.py"}, "region": {"startLine": 106}}}]}, {"ruleId": "scanner-c1f7398cf92ed3b8", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/bootstrap_demo.py:26"}, "properties": {"repobilityId": "1963cd624d4c7963", "scanner": "scanner-primary", "fingerprint": "c1f7398cf92ed3b8", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/bootstrap_demo.py"}, "region": {"startLine": 26}}}]}, {"ruleId": "scanner-09fb576b3e715218", "level": "note", "message": {"text": "Legacy-named symbol `eleven_multilingual_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/utils/tts_engine_selector.py:7"}, "properties": {"repobilityId": "82a135d772c30e6f", "scanner": "scanner-primary", "fingerprint": "09fb576b3e715218", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-8ed3aa9d0eb9c153", "level": "note", "message": {"text": "Legacy-named symbol `eleven_multilingual_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/utils/text_to_audio_elevenslab.py:8"}, "properties": {"repobilityId": "6a14231604c7cb85", "scanner": "scanner-primary", "fingerprint": "8ed3aa9d0eb9c153", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-eb0ec874aaf31986", "level": "note", "message": {"text": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/processors/podcast_generator_processor.py:11"}, "properties": {"repobilityId": "3a781971ecce0500", "scanner": "scanner-primary", "fingerprint": "eb0ec874aaf31986", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-3ebfe452bbcefede", "level": "note", "message": {"text": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/agents/image_generate_agent.py:8"}, "properties": {"repobilityId": "67f2d07b0ceb5d0d", "scanner": "scanner-primary", "fingerprint": "3ebfe452bbcefede", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-404af33d6e730e42", "level": "note", "message": {"text": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/services/celery_tasks.py:8"}, "properties": {"repobilityId": "58bcc2839a930e16", "scanner": "scanner-primary", "fingerprint": "404af33d6e730e42", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-5e62817dec9afdfd", "level": "note", "message": {"text": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/services/internal_session_service.py:6"}, "properties": {"repobilityId": "97e538ee9a6c0a27", "scanner": "scanner-primary", "fingerprint": "5e62817dec9afdfd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-a21fac9cb1b0dbb5", "level": "note", "message": {"text": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/services/async_podcast_agent_service.py:10"}, "properties": {"repobilityId": "b915f2e17f19bcff", "scanner": "scanner-primary", "fingerprint": "a21fac9cb1b0dbb5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-9c5c35d717897304", "level": "note", "message": {"text": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/tools/ui_manager.py:3"}, "properties": {"repobilityId": "4fe7fa046b549ab2", "scanner": "scanner-primary", "fingerprint": "9c5c35d717897304", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-4235c803d9fb73d8", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/tools/wikipedia_search.py:32"}, "properties": {"repobilityId": "c8b9b40ac55138f0", "scanner": "scanner-primary", "fingerprint": "4235c803d9fb73d8", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/tools/wikipedia_search.py"}, "region": {"startLine": 32}}}]}, {"ruleId": "scanner-6ea3cc34c2d9c136", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/tools/jikan_search.py:53"}, "properties": {"repobilityId": "874ef3339a0394d2", "scanner": "scanner-primary", "fingerprint": "6ea3cc34c2d9c136", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/tools/jikan_search.py"}, "region": {"startLine": 53}}}]}, {"ruleId": "scanner-fd3f23453e3191e7", "level": "note", "message": {"text": "Legacy-named symbol `agent_config_v2` in advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/tools/pipeline/image_generate_agent.py:8"}, "properties": {"repobilityId": "f6d1063db0bb81ee", "scanner": "scanner-primary", "fingerprint": "fd3f23453e3191e7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-5423af470f883720", "level": "note", "message": {"text": "Legacy-named symbol `board_copy` in advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/utils.py:185"}, "properties": {"repobilityId": "48feb93193440e43", "scanner": "scanner-primary", "fingerprint": "5423af470f883720", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-9a4850d5fbbc29bd", "level": "note", "message": {"text": "59 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "e3d3d9745573e944", "scanner": "scanner-primary", "fingerprint": "9a4850d5fbbc29bd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "d0095379ed6369c2", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "08805a6bfd6657ff", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-91d2d7fd41747bf9", "level": "warning", "message": {"text": "Frontend route `/studio/chat/:sessionId` has no Link/navigate to it \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/App.js"}, "properties": {"repobilityId": "27796dab1bbfcbb3", "scanner": "scanner-primary", "fingerprint": "91d2d7fd41747bf9", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-51072af88bcd328f", "level": "warning", "message": {"text": "Frontend route `/articles/:articleId` has no Link/navigate to it \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/App.js"}, "properties": {"repobilityId": "4f261fb0c87ce16a", "scanner": "scanner-primary", "fingerprint": "51072af88bcd328f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-6d34df607b93ea5d", "level": "warning", "message": {"text": "Frontend route `/podcasts/:identifier` has no Link/navigate to it \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/App.js"}, "properties": {"repobilityId": "d35495b0307fff2e", "scanner": "scanner-primary", "fingerprint": "6d34df607b93ea5d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-1f969b91b1f4ca8f", "level": "warning", "message": {"text": "Frontend route `/sources/:sourceId/edit` has no Link/navigate to it \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/App.js"}, "properties": {"repobilityId": "d38803381698d8f0", "scanner": "scanner-primary", "fingerprint": "1f969b91b1f4ca8f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-10fa0dcd7990bf47", "level": "warning", "message": {"text": "Frontend route `/sources/:sourceId` has no Link/navigate to it \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/App.js"}, "properties": {"repobilityId": "297621b4699f0295", "scanner": "scanner-primary", "fingerprint": "10fa0dcd7990bf47", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-84ed6fc3e78a60cc", "level": "warning", "message": {"text": "Frontend route `/social-media/:postId` has no Link/navigate to it \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/web/src/App.js"}, "properties": {"repobilityId": "66493a0eab4ba452", "scanner": "scanner-primary", "fingerprint": "84ed6fc3e78a60cc", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-61caf05e28b3d9fd", "level": "error", "message": {"text": "FastAPI POST `scheduler_trigger` without auth dependency \u2014 always_on_agents/release_radar_agent/scheduler_api.py:100"}, "properties": {"repobilityId": "6e8364cc129868f2", "scanner": "scanner-primary", "fingerprint": "61caf05e28b3d9fd", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "always_on_agents/release_radar_agent/scheduler_api.py"}, "region": {"startLine": 100}}}]}, {"ruleId": "scanner-c509fb643aec15ce", "level": "error", "message": {"text": "FastAPI POST `pubsub_trigger` without auth dependency \u2014 always_on_agents/release_radar_agent/scheduler_api.py:109"}, "properties": {"repobilityId": "51f0c7e0fc23ba26", "scanner": "scanner-primary", "fingerprint": "c509fb643aec15ce", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "always_on_agents/release_radar_agent/scheduler_api.py"}, "region": {"startLine": 109}}}]}, {"ruleId": "scanner-81cd83813a501cae", "level": "error", "message": {"text": "FastAPI POST `scheduler_trigger` without auth dependency \u2014 always_on_agents/always_on_hn_briefing_agent/scheduler_api.py:93"}, "properties": {"repobilityId": "2f2d96c5fcac3d1b", "scanner": "scanner-primary", "fingerprint": "81cd83813a501cae", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "always_on_agents/always_on_hn_briefing_agent/scheduler_api.py"}, "region": {"startLine": 93}}}]}, {"ruleId": "scanner-ea1bbfeb180b97da", "level": "error", "message": {"text": "FastAPI POST `pubsub_trigger` without auth dependency \u2014 always_on_agents/always_on_hn_briefing_agent/scheduler_api.py:102"}, "properties": {"repobilityId": "574c642b226dc256", "scanner": "scanner-primary", "fingerprint": "ea1bbfeb180b97da", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "always_on_agents/always_on_hn_briefing_agent/scheduler_api.py"}, "region": {"startLine": 102}}}]}, {"ruleId": "scanner-87b2632a52be4e97", "level": "error", "message": {"text": "FastAPI POST `upload_skill` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:124"}, "properties": {"repobilityId": "4681fdcecf7deacf", "scanner": "scanner-primary", "fingerprint": "87b2632a52be4e97", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/backend/app.py"}, "region": {"startLine": 124}}}]}, {"ruleId": "scanner-5e0110760c7dce55", "level": "error", "message": {"text": "FastAPI POST `upload_files` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:173"}, "properties": {"repobilityId": "bdc4ec55dd1c0384", "scanner": "scanner-primary", "fingerprint": "5e0110760c7dce55", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/backend/app.py"}, "region": {"startLine": 173}}}]}, {"ruleId": "scanner-b32d4adc174d0535", "level": "error", "message": {"text": "FastAPI POST `analyze_skill` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:211"}, "properties": {"repobilityId": "58bca8fd07b635f6", "scanner": "scanner-primary", "fingerprint": "b32d4adc174d0535", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/backend/app.py"}, "region": {"startLine": 211}}}]}, {"ruleId": "scanner-5093b88dfaf70d52", "level": "error", "message": {"text": "FastAPI POST `regenerate_config` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:229"}, "properties": {"repobilityId": "45a1fe16f98c35ca", "scanner": "scanner-primary", "fingerprint": "5093b88dfaf70d52", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/backend/app.py"}, "region": {"startLine": 229}}}]}, {"ruleId": "scanner-5f80a1e4e0153d5e", "level": "error", "message": {"text": "FastAPI POST `update_config` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:236"}, "properties": {"repobilityId": "d763b35beced7b58", "scanner": "scanner-primary", "fingerprint": "5f80a1e4e0153d5e", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/backend/app.py"}, "region": {"startLine": 236}}}]}, {"ruleId": "scanner-00a0741302ff40cc", "level": "error", "message": {"text": "FastAPI POST `start_optimization` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:278"}, "properties": {"repobilityId": "2e6aa66c85afad9f", "scanner": "scanner-primary", "fingerprint": "00a0741302ff40cc", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/backend/app.py"}, "region": {"startLine": 278}}}]}, {"ruleId": "scanner-08647908d15abb93", "level": "error", "message": {"text": "FastAPI POST `stop_optimization` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:399"}, "properties": {"repobilityId": "a78271c71dafd483", "scanner": "scanner-primary", "fingerprint": "08647908d15abb93", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/backend/app.py"}, "region": {"startLine": 399}}}]}, {"ruleId": "scanner-047fcf3bd9e686c2", "level": "error", "message": {"text": "FastAPI POST `load_example` without auth dependency \u2014 agent_skills/self-improving-agent-skills/backend/app.py:464"}, "properties": {"repobilityId": "8a5158f18608f45c", "scanner": "scanner-primary", "fingerprint": "047fcf3bd9e686c2", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/backend/app.py"}, "region": {"startLine": 464}}}]}, {"ruleId": "scanner-5a03991fcd5710b3", "level": "error", "message": {"text": "FastAPI POST `add_text_source` without auth dependency \u2014 rag_tutorials/multimodal_agentic_rag/backend/server.py:154"}, "properties": {"repobilityId": "fa829268b3f27486", "scanner": "scanner-primary", "fingerprint": "5a03991fcd5710b3", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/multimodal_agentic_rag/backend/server.py"}, "region": {"startLine": 154}}}]}, {"ruleId": "scanner-fe59c76b3fb256c2", "level": "error", "message": {"text": "FastAPI POST `add_url_source` without auth dependency \u2014 rag_tutorials/multimodal_agentic_rag/backend/server.py:164"}, "properties": {"repobilityId": "b5a031c1f000caa5", "scanner": "scanner-primary", "fingerprint": "fe59c76b3fb256c2", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/multimodal_agentic_rag/backend/server.py"}, "region": {"startLine": 164}}}]}, {"ruleId": "scanner-b32c5ba50f1a2f17", "level": "error", "message": {"text": "FastAPI POST `add_file_source` without auth dependency \u2014 rag_tutorials/multimodal_agentic_rag/backend/server.py:181"}, "properties": {"repobilityId": "400237b8e5af6680", "scanner": "scanner-primary", "fingerprint": "b32c5ba50f1a2f17", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/multimodal_agentic_rag/backend/server.py"}, "region": {"startLine": 181}}}]}, {"ruleId": "scanner-ba5c8e076ce6bfa8", "level": "error", "message": {"text": "FastAPI DELETE `delete_source` without auth dependency \u2014 rag_tutorials/multimodal_agentic_rag/backend/server.py:204"}, "properties": {"repobilityId": "dcf3b56deff837b3", "scanner": "scanner-primary", "fingerprint": "ba5c8e076ce6bfa8", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/multimodal_agentic_rag/backend/server.py"}, "region": {"startLine": 204}}}]}, {"ruleId": "scanner-dbcd74a51ecb43e0", "level": "error", "message": {"text": "FastAPI POST `ask` without auth dependency \u2014 rag_tutorials/multimodal_agentic_rag/backend/server.py:212"}, "properties": {"repobilityId": "5a34f385b02f52b5", "scanner": "scanner-primary", "fingerprint": "dbcd74a51ecb43e0", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "rag_tutorials/multimodal_agentic_rag/backend/server.py"}, "region": {"startLine": 212}}}]}, {"ruleId": "scanner-3fa4242568f45ee3", "level": "error", "message": {"text": "FastAPI POST `upload_video` without auth dependency \u2014 advanced_llm_apps/multimodal_video_moment_finder/backend/server.py:52"}, "properties": {"repobilityId": "0b697e20d561fc16", "scanner": "scanner-primary", "fingerprint": "3fa4242568f45ee3", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/backend/server.py"}, "region": {"startLine": 52}}}]}, {"ruleId": "scanner-ae641ccb8a8dd186", "level": "error", "message": {"text": "FastAPI POST `find_moment` without auth dependency \u2014 advanced_llm_apps/multimodal_video_moment_finder/backend/server.py:76"}, "properties": {"repobilityId": "dff8eb44f3a6fa56", "scanner": "scanner-primary", "fingerprint": "ae641ccb8a8dd186", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/backend/server.py"}, "region": {"startLine": 76}}}]}, {"ruleId": "scanner-dd64f451e1fa270b", "level": "error", "message": {"text": "FastAPI POST `find_moment_text` without auth dependency \u2014 advanced_llm_apps/multimodal_video_moment_finder/backend/server.py:107"}, "properties": {"repobilityId": "6e20c6a126df27a1", "scanner": "scanner-primary", "fingerprint": "dd64f451e1fa270b", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/backend/server.py"}, "region": {"startLine": 107}}}]}, {"ruleId": "scanner-c99983543a29b0ff", "level": "error", "message": {"text": "FastAPI DELETE `delete_video` without auth dependency \u2014 advanced_llm_apps/multimodal_video_moment_finder/backend/server.py:138"}, "properties": {"repobilityId": "f7b7047dec6c0e68", "scanner": "scanner-primary", "fingerprint": "c99983543a29b0ff", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/backend/server.py"}, "region": {"startLine": 138}}}]}, {"ruleId": "scanner-43a18f40e146e507", "level": "error", "message": {"text": "FastAPI POST `create_session` without auth dependency \u2014 advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent/live_demo/server.py:102"}, "properties": {"repobilityId": "2faeffa3fc9239fa", "scanner": "scanner-primary", "fingerprint": "43a18f40e146e507", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/earnings_call_analyst_agent/live_demo/server.py"}, "region": {"startLine": 102}}}]}, {"ruleId": "scanner-27c6cf93ba572773", "level": "error", "message": {"text": "FastAPI POST `trigger_trip_craft_agent` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/router/plan.py:13"}, "properties": {"repobilityId": "7d7fea17eff0bc85", "scanner": "scanner-primary", "fingerprint": "27c6cf93ba572773", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/router/plan.py"}, "region": {"startLine": 13}}}]}, {"ruleId": "scanner-569b8691fbd9862c", "level": "error", "message": {"text": "FastAPI POST `analyze` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_speech_trainer_agent/backend/main.py:35"}, "properties": {"repobilityId": "1aa8d3340162590c", "scanner": "scanner-primary", "fingerprint": "569b8691fbd9862c", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_speech_trainer_agent/backend/main.py"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-f42399ea65be7d44", "level": "error", "message": {"text": "FastAPI POST `create_task` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/task_router.py:73"}, "properties": {"repobilityId": "6e25979d87b7b9b6", "scanner": "scanner-primary", "fingerprint": "f42399ea65be7d44", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/task_router.py"}, "region": {"startLine": 73}}}]}, {"ruleId": "scanner-e73d311332e0a93f", "level": "error", "message": {"text": "FastAPI PUT `update_task` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/task_router.py:90"}, "properties": {"repobilityId": "e45ee74b1118dafe", "scanner": "scanner-primary", "fingerprint": "e73d311332e0a93f", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/task_router.py"}, "region": {"startLine": 90}}}]}, {"ruleId": "scanner-d0a5609d2b32c99a", "level": "error", "message": {"text": "FastAPI DELETE `delete_task` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/task_router.py:105"}, "properties": {"repobilityId": "55b983154b942e4e", "scanner": "scanner-primary", "fingerprint": "d0a5609d2b32c99a", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/task_router.py"}, "region": {"startLine": 105}}}]}, {"ruleId": "scanner-b7ef3afc7a42e602", "level": "error", "message": {"text": "FastAPI POST `enable_task` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/task_router.py:117"}, "properties": {"repobilityId": "39ed610f3eeea00b", "scanner": "scanner-primary", "fingerprint": "b7ef3afc7a42e602", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/task_router.py"}, "region": {"startLine": 117}}}]}, {"ruleId": "scanner-c917a6628bbbd738", "level": "error", "message": {"text": "FastAPI POST `disable_task` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/task_router.py:129"}, "properties": {"repobilityId": "db81c5b02d7b9363", "scanner": "scanner-primary", "fingerprint": "c917a6628bbbd738", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/task_router.py"}, "region": {"startLine": 129}}}]}, {"ruleId": "scanner-ef7a4ae5dd07f76f", "level": "error", "message": {"text": "FastAPI POST `create_podcast_config` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_config_router.py:34"}, "properties": {"repobilityId": "171678f6aad73231", "scanner": "scanner-primary", "fingerprint": "ef7a4ae5dd07f76f", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_config_router.py"}, "region": {"startLine": 34}}}]}, {"ruleId": "scanner-4c60e3fc8acdd932", "level": "error", "message": {"text": "FastAPI PUT `update_podcast_config` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_config_router.py:55"}, "properties": {"repobilityId": "2b3267d1558103ac", "scanner": "scanner-primary", "fingerprint": "4c60e3fc8acdd932", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_config_router.py"}, "region": {"startLine": 55}}}]}, {"ruleId": "scanner-4b354f58200264e5", "level": "error", "message": {"text": "FastAPI DELETE `delete_podcast_config` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_config_router.py:70"}, "properties": {"repobilityId": "3b30683abbde4987", "scanner": "scanner-primary", "fingerprint": "4b354f58200264e5", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_config_router.py"}, "region": {"startLine": 70}}}]}, {"ruleId": "scanner-2525800ab6320c12", "level": "error", "message": {"text": "FastAPI POST `enable_podcast_config` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_config_router.py:82"}, "properties": {"repobilityId": "4f682d36e9f3cc82", "scanner": "scanner-primary", "fingerprint": "2525800ab6320c12", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_config_router.py"}, "region": {"startLine": 82}}}]}, {"ruleId": "scanner-d4c1f6f2dc85a9bc", "level": "error", "message": {"text": "FastAPI POST `disable_podcast_config` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_config_router.py:94"}, "properties": {"repobilityId": "2e8e33362cb0e23e", "scanner": "scanner-primary", "fingerprint": "d4c1f6f2dc85a9bc", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_config_router.py"}, "region": {"startLine": 94}}}]}, {"ruleId": "scanner-bb6012543cd29c46", "level": "error", "message": {"text": "FastAPI POST `create_session` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/async_podcast_agent_router.py:34"}, "properties": {"repobilityId": "c57c2e55a961ea93", "scanner": "scanner-primary", "fingerprint": "bb6012543cd29c46", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/async_podcast_agent_router.py"}, "region": {"startLine": 34}}}]}, {"ruleId": "scanner-86ab646e542fea06", "level": "error", "message": {"text": "FastAPI POST `chat` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/async_podcast_agent_router.py:40"}, "properties": {"repobilityId": "b3ece7c89d329ec6", "scanner": "scanner-primary", "fingerprint": "86ab646e542fea06", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/async_podcast_agent_router.py"}, "region": {"startLine": 40}}}]}, {"ruleId": "scanner-6e1dc6e164731c14", "level": "error", "message": {"text": "FastAPI POST `check_status` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/async_podcast_agent_router.py:46"}, "properties": {"repobilityId": "ebff4e2da9163aae", "scanner": "scanner-primary", "fingerprint": "6e1dc6e164731c14", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/async_podcast_agent_router.py"}, "region": {"startLine": 46}}}]}, {"ruleId": "scanner-8d83bda11b8791aa", "level": "error", "message": {"text": "FastAPI DELETE `delete_session` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/async_podcast_agent_router.py:64"}, "properties": {"repobilityId": "5a49114e4fac0149", "scanner": "scanner-primary", "fingerprint": "8d83bda11b8791aa", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/async_podcast_agent_router.py"}, "region": {"startLine": 64}}}]}, {"ruleId": "scanner-31212311ba87b129", "level": "error", "message": {"text": "FastAPI POST `create_source` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/source_router.py:67"}, "properties": {"repobilityId": "c1e2d96a14facf78", "scanner": "scanner-primary", "fingerprint": "31212311ba87b129", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/source_router.py"}, "region": {"startLine": 67}}}]}, {"ruleId": "scanner-c4ce1d65568530f9", "level": "error", "message": {"text": "FastAPI PUT `update_source` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/source_router.py:80"}, "properties": {"repobilityId": "1e91af3c42dd0fe9", "scanner": "scanner-primary", "fingerprint": "c4ce1d65568530f9", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/source_router.py"}, "region": {"startLine": 80}}}]}, {"ruleId": "scanner-6be21128aefead6d", "level": "error", "message": {"text": "FastAPI DELETE `delete_source` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/source_router.py:94"}, "properties": {"repobilityId": "42892c4713c48a14", "scanner": "scanner-primary", "fingerprint": "6be21128aefead6d", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/source_router.py"}, "region": {"startLine": 94}}}]}, {"ruleId": "scanner-57c34e9e9294e318", "level": "error", "message": {"text": "FastAPI POST `add_feed` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/source_router.py:107"}, "properties": {"repobilityId": "c2210e96cfcab537", "scanner": "scanner-primary", "fingerprint": "57c34e9e9294e318", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/source_router.py"}, "region": {"startLine": 107}}}]}, {"ruleId": "scanner-b421669e475d0fd6", "level": "error", "message": {"text": "FastAPI PUT `update_feed` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/source_router.py:118"}, "properties": {"repobilityId": "db3796f383a1ccf7", "scanner": "scanner-primary", "fingerprint": "b421669e475d0fd6", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/source_router.py"}, "region": {"startLine": 118}}}]}, {"ruleId": "scanner-17cd587c9182a973", "level": "error", "message": {"text": "FastAPI DELETE `delete_feed` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/source_router.py:129"}, "properties": {"repobilityId": "ad35c80120bae0ec", "scanner": "scanner-primary", "fingerprint": "17cd587c9182a973", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/source_router.py"}, "region": {"startLine": 129}}}]}, {"ruleId": "scanner-7dbce697e68b80f6", "level": "error", "message": {"text": "FastAPI POST `setup_browser_session` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/social_media_router.py:156"}, "properties": {"repobilityId": "48a231b81d8a5f66", "scanner": "scanner-primary", "fingerprint": "7dbce697e68b80f6", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/social_media_router.py"}, "region": {"startLine": 156}}}]}, {"ruleId": "scanner-275b4ae145b2e292", "level": "error", "message": {"text": "FastAPI POST `create_podcast` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_router.py:107"}, "properties": {"repobilityId": "b63c0f4652a43b9e", "scanner": "scanner-primary", "fingerprint": "275b4ae145b2e292", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_router.py"}, "region": {"startLine": 107}}}]}, {"ruleId": "scanner-3dd53eb22c0a65c7", "level": "error", "message": {"text": "FastAPI PUT `update_podcast` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_router.py:128"}, "properties": {"repobilityId": "3fe433eb84f7f074", "scanner": "scanner-primary", "fingerprint": "3dd53eb22c0a65c7", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_router.py"}, "region": {"startLine": 128}}}]}, {"ruleId": "scanner-f91cac77c75e470c", "level": "error", "message": {"text": "FastAPI DELETE `delete_podcast` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_router.py:143"}, "properties": {"repobilityId": "d6ce5b339bb8223d", "scanner": "scanner-primary", "fingerprint": "f91cac77c75e470c", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_router.py"}, "region": {"startLine": 143}}}]}, {"ruleId": "scanner-ec3a38afb35d1c42", "level": "error", "message": {"text": "FastAPI POST `upload_audio` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_router.py:159"}, "properties": {"repobilityId": "f1d46ab52d19f4e4", "scanner": "scanner-primary", "fingerprint": "ec3a38afb35d1c42", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_router.py"}, "region": {"startLine": 159}}}]}, {"ruleId": "scanner-a1c9702a99dfcc18", "level": "error", "message": {"text": "FastAPI POST `upload_banner` without auth dependency \u2014 advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_router.py:173"}, "properties": {"repobilityId": "64e8bfd3ab533c60", "scanner": "scanner-primary", "fingerprint": "a1c9702a99dfcc18", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/routers/podcast_router.py"}, "region": {"startLine": 173}}}]}, {"ruleId": "scanner-c3117bfd7b32518e", "level": "error", "message": {"text": "FastAPI POST `create_session` without auth dependency \u2014 voice_ai_agents/insurance_claim_live_agent_team/live_demo/server.py:410"}, "properties": {"repobilityId": "9392a9540d66a814", "scanner": "scanner-primary", "fingerprint": "c3117bfd7b32518e", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "voice_ai_agents/insurance_claim_live_agent_team/live_demo/server.py"}, "region": {"startLine": 410}}}]}, {"ruleId": "scanner-c794a6f8bced630c", "level": "error", "message": {"text": "FastAPI POST `message` without auth dependency \u2014 voice_ai_agents/insurance_claim_live_agent_team/live_demo/server.py:448"}, "properties": {"repobilityId": "abb28d29dd2c757b", "scanner": "scanner-primary", "fingerprint": "c794a6f8bced630c", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "voice_ai_agents/insurance_claim_live_agent_team/live_demo/server.py"}, "region": {"startLine": 448}}}]}, {"ruleId": "scanner-83d34cdc40ed7c37", "level": "warning", "message": {"text": "Vulnerable dependency agno 1.5.6: GHSA-77rh-m34w-rv36"}, "properties": {"repobilityId": "dac5bb0a794003c4", "scanner": "scanner-primary", "fingerprint": "83d34cdc40ed7c37", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-77rh-m34w-rv36"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-feea9b10efeda72c", "level": "warning", "message": {"text": "Vulnerable dependency agno 1.5.6: GHSA-82m5-3pcp-hccq"}, "properties": {"repobilityId": "e5bee5d5ce60922a", "scanner": "scanner-primary", "fingerprint": "feea9b10efeda72c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-82m5-3pcp-hccq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-285d17e14917f08c", "level": "warning", "message": {"text": "Vulnerable dependency agno 1.5.6: PYSEC-2026-2333"}, "properties": {"repobilityId": "06297170958aa270", "scanner": "scanner-primary", "fingerprint": "285d17e14917f08c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2333"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-840593fff2e1deab", "level": "warning", "message": {"text": "Vulnerable dependency agno 1.5.6: PYSEC-2026-256"}, "properties": {"repobilityId": "7646cd7ce06e3268", "scanner": "scanner-primary", "fingerprint": "840593fff2e1deab", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-256"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-287cfd8bf7019f0e", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-2fqr-mr3j-6wp8"}, "properties": {"repobilityId": "0736584da3a867e0", "scanner": "scanner-primary", "fingerprint": "287cfd8bf7019f0e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2fqr-mr3j-6wp8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cf7edc8d7e4b6a60", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-2vrm-gr82-f7m5"}, "properties": {"repobilityId": "8d3313eef656d79a", "scanner": "scanner-primary", "fingerprint": "cf7edc8d7e4b6a60", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2vrm-gr82-f7m5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ecf0f6efce210b05", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-3wq7-rqq7-wx6j"}, "properties": {"repobilityId": "9b1be22338c20cf4", "scanner": "scanner-primary", "fingerprint": "ecf0f6efce210b05", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3wq7-rqq7-wx6j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4551092bc2772a78", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-4fvr-rgm6-gqmc"}, "properties": {"repobilityId": "de05afb07d7aee5e", "scanner": "scanner-primary", "fingerprint": "4551092bc2772a78", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4fvr-rgm6-gqmc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d7101223db67bd98", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-4m7w-qmgq-4wj5"}, "properties": {"repobilityId": "77f44d541cf17bdc", "scanner": "scanner-primary", "fingerprint": "d7101223db67bd98", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4m7w-qmgq-4wj5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c2d361bcf90cfd4d", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-54jq-c3m8-4m76"}, "properties": {"repobilityId": "e3c034953525aa41", "scanner": "scanner-primary", "fingerprint": "c2d361bcf90cfd4d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-54jq-c3m8-4m76"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-02fa2a68ca55dedc", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-63hf-3vf5-4wqf"}, "properties": {"repobilityId": "91dd3bbb22c9d4a3", "scanner": "scanner-primary", "fingerprint": "02fa2a68ca55dedc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-63hf-3vf5-4wqf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8f4d15d0633c14f2", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-63hw-fmq6-xxg2"}, "properties": {"repobilityId": "7b31234a1fc67b6b", "scanner": "scanner-primary", "fingerprint": "8f4d15d0633c14f2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-63hw-fmq6-xxg2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fb4968ce3299963a", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-69f9-5gxw-wvc2"}, "properties": {"repobilityId": "d2f979cc8461828a", "scanner": "scanner-primary", "fingerprint": "fb4968ce3299963a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-69f9-5gxw-wvc2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e7d05aa3c0d405ee", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-6jhg-hg63-jvvf"}, "properties": {"repobilityId": "869200d5ae1feabb", "scanner": "scanner-primary", "fingerprint": "e7d05aa3c0d405ee", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6jhg-hg63-jvvf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-397fd315b3f1d627", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-6mq8-rvhq-8wgg"}, "properties": {"repobilityId": "9df60f452e142775", "scanner": "scanner-primary", "fingerprint": "397fd315b3f1d627", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6mq8-rvhq-8wgg"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bb2c31abce229abc", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-9548-qrrj-x5pj"}, "properties": {"repobilityId": "69832f08e17cdf56", "scanner": "scanner-primary", "fingerprint": "bb2c31abce229abc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9548-qrrj-x5pj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1ff12d5fec3a5a8c", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-966j-vmvw-g2g9"}, "properties": {"repobilityId": "0333f7006847ef42", "scanner": "scanner-primary", "fingerprint": "1ff12d5fec3a5a8c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-966j-vmvw-g2g9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-68248764f61388b5", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-9x8q-7h8h-wcw9"}, "properties": {"repobilityId": "941519d99faf2dd3", "scanner": "scanner-primary", "fingerprint": "68248764f61388b5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9x8q-7h8h-wcw9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c0ff523e8aaff503", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-c427-h43c-vf67"}, "properties": {"repobilityId": "299e2524de80fb2c", "scanner": "scanner-primary", "fingerprint": "c0ff523e8aaff503", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-c427-h43c-vf67"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b00e7f44ab64883e", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-fh55-r93g-j68g"}, "properties": {"repobilityId": "471e1323a4f755d8", "scanner": "scanner-primary", "fingerprint": "b00e7f44ab64883e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-fh55-r93g-j68g"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-02c7f4709cc11079", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-g3cq-j2xw-wf74"}, "properties": {"repobilityId": "a74c23fbc99a6614", "scanner": "scanner-primary", "fingerprint": "02c7f4709cc11079", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-g3cq-j2xw-wf74"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-15c7922dbcec6551", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-g84x-mcqj-x9qq"}, "properties": {"repobilityId": "4f3116c24638cee8", "scanner": "scanner-primary", "fingerprint": "15c7922dbcec6551", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-g84x-mcqj-x9qq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fabcbdeb1d94c683", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-hcc4-c3v8-rx92"}, "properties": {"repobilityId": "061515243e7f093e", "scanner": "scanner-primary", "fingerprint": "fabcbdeb1d94c683", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hcc4-c3v8-rx92"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-34ddd8e905c3eccd", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-hg6j-4rv6-33pg"}, "properties": {"repobilityId": "4843b7acdb196111", "scanner": "scanner-primary", "fingerprint": "34ddd8e905c3eccd", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hg6j-4rv6-33pg"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-be08d8aae712a66e", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-hpj7-wq8m-9hgp"}, "properties": {"repobilityId": "5cf505e2009249ab", "scanner": "scanner-primary", "fingerprint": "be08d8aae712a66e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hpj7-wq8m-9hgp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6f30c1afe3e7a592", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-jg22-mg44-37j8"}, "properties": {"repobilityId": "b8bbddc2a23210c6", "scanner": "scanner-primary", "fingerprint": "6f30c1afe3e7a592", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jg22-mg44-37j8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f1c3425615956a24", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-jj3x-wxrx-4x23"}, "properties": {"repobilityId": "87d278a8e49dc65c", "scanner": "scanner-primary", "fingerprint": "f1c3425615956a24", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jj3x-wxrx-4x23"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0b3170f2b2f878c1", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-m5qp-6w8w-w647"}, "properties": {"repobilityId": "258779eabf452bfc", "scanner": "scanner-primary", "fingerprint": "0b3170f2b2f878c1", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m5qp-6w8w-w647"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-16dfe03ea34e1957", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-m6qw-4cw2-hm4m"}, "properties": {"repobilityId": "0d2a3ab6bb95167f", "scanner": "scanner-primary", "fingerprint": "16dfe03ea34e1957", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m6qw-4cw2-hm4m"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7b282df70afd8044", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-mqqc-3gqh-h2x8"}, "properties": {"repobilityId": "adb29108daa660db", "scanner": "scanner-primary", "fingerprint": "7b282df70afd8044", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mqqc-3gqh-h2x8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7e9d68b44010f187", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-mwh4-6h8g-pg8w"}, "properties": {"repobilityId": "015547750c7cb249", "scanner": "scanner-primary", "fingerprint": "7e9d68b44010f187", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mwh4-6h8g-pg8w"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ef8fdbfb37390ec4", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-p998-jp59-783m"}, "properties": {"repobilityId": "a6b552cdb8d11b07", "scanner": "scanner-primary", "fingerprint": "ef8fdbfb37390ec4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p998-jp59-783m"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e0288627e2f42897", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-w2fm-2cpv-w7v5"}, "properties": {"repobilityId": "ddb6d43c9d470531", "scanner": "scanner-primary", "fingerprint": "e0288627e2f42897", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w2fm-2cpv-w7v5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dfea9a62dec577dc", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: GHSA-xcgm-r5h9-7989"}, "properties": {"repobilityId": "c34d9f893914fdf7", "scanner": "scanner-primary", "fingerprint": "dfea9a62dec577dc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xcgm-r5h9-7989"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c7e3597f5e874cb9", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1097"}, "properties": {"repobilityId": "5f6a08dbc5794161", "scanner": "scanner-primary", "fingerprint": "c7e3597f5e874cb9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1097"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d3102c3cd05489c3", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1099"}, "properties": {"repobilityId": "97643d81b8b87e1c", "scanner": "scanner-primary", "fingerprint": "d3102c3cd05489c3", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1099"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d7a5d2727942a419", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1100"}, "properties": {"repobilityId": "c88510951f77e150", "scanner": "scanner-primary", "fingerprint": "d7a5d2727942a419", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1100"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-399a4b53ffccf1da", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1101"}, "properties": {"repobilityId": "0187f4ef8a9fd6f5", "scanner": "scanner-primary", "fingerprint": "399a4b53ffccf1da", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1101"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa7126575e0859b4", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1104"}, "properties": {"repobilityId": "6ce2c643612590d4", "scanner": "scanner-primary", "fingerprint": "aa7126575e0859b4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1104"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9c728ae8d18008b3", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1105"}, "properties": {"repobilityId": "1224419129ffd9de", "scanner": "scanner-primary", "fingerprint": "9c728ae8d18008b3", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1105"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9b97ae6c28f10726", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1106"}, "properties": {"repobilityId": "8bc0b7383fa2882a", "scanner": "scanner-primary", "fingerprint": "9b97ae6c28f10726", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1106"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2533a7495f6be6a5", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1107"}, "properties": {"repobilityId": "9139436f67863dae", "scanner": "scanner-primary", "fingerprint": "2533a7495f6be6a5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1107"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-df14aa7a1179b1f9", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-1109"}, "properties": {"repobilityId": "a7d5c784cb565aed", "scanner": "scanner-primary", "fingerprint": "df14aa7a1179b1f9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1109"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-df375ca47e347310", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2094"}, "properties": {"repobilityId": "490ff53a72ad44e0", "scanner": "scanner-primary", "fingerprint": "df375ca47e347310", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2094"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-eaa372b610040fcc", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2095"}, "properties": {"repobilityId": "74ef1c923baf300a", "scanner": "scanner-primary", "fingerprint": "eaa372b610040fcc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2095"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-50739925cbc8e39f", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2097"}, "properties": {"repobilityId": "8318e48bcf90fa1c", "scanner": "scanner-primary", "fingerprint": "50739925cbc8e39f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2097"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ef6c2ae9b2f86e49", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2098"}, "properties": {"repobilityId": "8ad53b2a350cefca", "scanner": "scanner-primary", "fingerprint": "ef6c2ae9b2f86e49", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2098"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-11fd49cd2312eb74", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2100"}, "properties": {"repobilityId": "713c06d8006e66c2", "scanner": "scanner-primary", "fingerprint": "11fd49cd2312eb74", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2100"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f7c2d12502193be4", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2101"}, "properties": {"repobilityId": "0876c976fab4feaa", "scanner": "scanner-primary", "fingerprint": "f7c2d12502193be4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2101"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-24ad4c7f5fdb8128", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2102"}, "properties": {"repobilityId": "a751b165c58e888e", "scanner": "scanner-primary", "fingerprint": "24ad4c7f5fdb8128", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2102"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e5d81b2f6e4e3541", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2103"}, "properties": {"repobilityId": "a914e5ffd90658c5", "scanner": "scanner-primary", "fingerprint": "e5d81b2f6e4e3541", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2103"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c91a537c5ca59f60", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2104"}, "properties": {"repobilityId": "ad3696e585f4fb21", "scanner": "scanner-primary", "fingerprint": "c91a537c5ca59f60", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2104"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-501988317a274659", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2105"}, "properties": {"repobilityId": "05cfbde9a771a10b", "scanner": "scanner-primary", "fingerprint": "501988317a274659", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2105"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-96007ce9d8897f16", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2106"}, "properties": {"repobilityId": "5eb35e13a004893f", "scanner": "scanner-primary", "fingerprint": "96007ce9d8897f16", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2106"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7cb4f44f56f33088", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2108"}, "properties": {"repobilityId": "5cb46a7a093ce3b1", "scanner": "scanner-primary", "fingerprint": "7cb4f44f56f33088", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2108"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7aaddd600d288926", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2109"}, "properties": {"repobilityId": "5d2cc5cd492bb9b1", "scanner": "scanner-primary", "fingerprint": "7aaddd600d288926", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2109"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9b9f32d26884b623", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2110"}, "properties": {"repobilityId": "ce27ee43654cd6f3", "scanner": "scanner-primary", "fingerprint": "9b9f32d26884b623", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2110"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2372db1554f82fc0", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2111"}, "properties": {"repobilityId": "65c598c424780446", "scanner": "scanner-primary", "fingerprint": "2372db1554f82fc0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2111"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bdcb74fa87cc876e", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.6: PYSEC-2026-2113"}, "properties": {"repobilityId": "df513f8716a9b2ee", "scanner": "scanner-primary", "fingerprint": "bdcb74fa87cc876e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2113"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f6ee4907d59a4e0f", "level": "warning", "message": {"text": "Vulnerable dependency click 8.2.1: PYSEC-2026-2132"}, "properties": {"repobilityId": "0c2a5874a5d89276", "scanner": "scanner-primary", "fingerprint": "f6ee4907d59a4e0f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2132"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-56346a9e7ea90bbc", "level": "warning", "message": {"text": "Vulnerable dependency gitpython 3.1.44: GHSA-2f96-g7mh-g2hx"}, "properties": {"repobilityId": "0886542a45cca1ca", "scanner": "scanner-primary", "fingerprint": "56346a9e7ea90bbc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2f96-g7mh-g2hx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fbdec05475a3fa9a", "level": "warning", "message": {"text": "Vulnerable dependency gitpython 3.1.44: GHSA-7545-fcxq-7j24"}, "properties": {"repobilityId": "6d91c3a4abc7ff38", "scanner": "scanner-primary", "fingerprint": "fbdec05475a3fa9a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-7545-fcxq-7j24"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-23df121e023af519", "level": "warning", "message": {"text": "Vulnerable dependency gitpython 3.1.44: GHSA-956x-8gvw-wg5v"}, "properties": {"repobilityId": "2e166a5c81015e7f", "scanner": "scanner-primary", "fingerprint": "23df121e023af519", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-956x-8gvw-wg5v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d06118c4c1dd4228", "level": "warning", "message": {"text": "Vulnerable dependency gitpython 3.1.44: GHSA-mv93-w799-cj2w"}, "properties": {"repobilityId": "93b3308d6c48c072", "scanner": "scanner-primary", "fingerprint": "d06118c4c1dd4228", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mv93-w799-cj2w"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dfd77c6ec01f5a08", "level": "warning", "message": {"text": "Vulnerable dependency gitpython 3.1.44: GHSA-rpm5-65cw-6hj4"}, "properties": {"repobilityId": "4752e9fe6c856bb0", "scanner": "scanner-primary", "fingerprint": "dfd77c6ec01f5a08", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-rpm5-65cw-6hj4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2ce08b845b170e46", "level": "warning", "message": {"text": "Vulnerable dependency gitpython 3.1.44: GHSA-rwj8-pgh3-r573"}, "properties": {"repobilityId": "d3d674e9112aae8e", "scanner": "scanner-primary", "fingerprint": "2ce08b845b170e46", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-rwj8-pgh3-r573"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dccadf61db2cd2bb", "level": "warning", "message": {"text": "Vulnerable dependency gitpython 3.1.44: GHSA-v87r-6q3f-2j67"}, "properties": {"repobilityId": "a6c61ef595513477", "scanner": "scanner-primary", "fingerprint": "dccadf61db2cd2bb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-v87r-6q3f-2j67"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-51f142bd8e15a20e", "level": "warning", "message": {"text": "Vulnerable dependency gitpython 3.1.44: GHSA-x2qx-6953-8485"}, "properties": {"repobilityId": "18b9191e45d53674", "scanner": "scanner-primary", "fingerprint": "51f142bd8e15a20e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-x2qx-6953-8485"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-88a30670956769c2", "level": "warning", "message": {"text": "Vulnerable dependency gitpython 3.1.44: PYSEC-2026-2160"}, "properties": {"repobilityId": "17e218b2aa93e92b", "scanner": "scanner-primary", "fingerprint": "88a30670956769c2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2160"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0703d01599e1b3e6", "level": "warning", "message": {"text": "Vulnerable dependency gitpython 3.1.44: PYSEC-2026-2161"}, "properties": {"repobilityId": "addd1e07cf078f59", "scanner": "scanner-primary", "fingerprint": "0703d01599e1b3e6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2161"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-13d61b7424fc860c", "level": "warning", "message": {"text": "Vulnerable dependency gitpython 3.1.44: PYSEC-2026-2162"}, "properties": {"repobilityId": "5bcd82f25be4d031", "scanner": "scanner-primary", "fingerprint": "13d61b7424fc860c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2162"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2eb88effe9bb9e73", "level": "warning", "message": {"text": "Vulnerable dependency gitpython 3.1.44: PYSEC-2026-2163"}, "properties": {"repobilityId": "d3a8e0bcf28c15dd", "scanner": "scanner-primary", "fingerprint": "2eb88effe9bb9e73", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2163"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3dba88bf6c9678c9", "level": "warning", "message": {"text": "Vulnerable dependency h2 4.2.0: GHSA-847f-9342-265h"}, "properties": {"repobilityId": "a21a2832ccb45d87", "scanner": "scanner-primary", "fingerprint": "3dba88bf6c9678c9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-847f-9342-265h"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-599e0119804a5427", "level": "warning", "message": {"text": "Vulnerable dependency h2 4.2.0: PYSEC-2026-1435"}, "properties": {"repobilityId": "397f676fc377440b", "scanner": "scanner-primary", "fingerprint": "599e0119804a5427", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1435"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-81ba7c156ede9306", "level": "warning", "message": {"text": "Vulnerable dependency idna 3.10: GHSA-65pc-fj4g-8rjx"}, "properties": {"repobilityId": "1a5051d57b921bd6", "scanner": "scanner-primary", "fingerprint": "81ba7c156ede9306", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-65pc-fj4g-8rjx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fe83bd5958898558", "level": "warning", "message": {"text": "Vulnerable dependency idna 3.10: PYSEC-2026-215"}, "properties": {"repobilityId": "a7c331713183d94b", "scanner": "scanner-primary", "fingerprint": "fe83bd5958898558", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-215"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fb9ef090a27dccdd", "level": "warning", "message": {"text": "Vulnerable dependency mem0ai 0.1.102: GHSA-cgx8-qgvr-f7vf"}, "properties": {"repobilityId": "88ace57549725988", "scanner": "scanner-primary", "fingerprint": "fb9ef090a27dccdd", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-cgx8-qgvr-f7vf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5f50c0c9f906b360", "level": "warning", "message": {"text": "Vulnerable dependency mem0ai 0.1.102: GHSA-gq6f-qwv9-rf4j"}, "properties": {"repobilityId": "e507080183aa3966", "scanner": "scanner-primary", "fingerprint": "5f50c0c9f906b360", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gq6f-qwv9-rf4j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f071f9c0bd81cebc", "level": "warning", "message": {"text": "Vulnerable dependency mem0ai 0.1.102: GHSA-jfv9-68m5-gjjr"}, "properties": {"repobilityId": "01045f8f4f0cc96b", "scanner": "scanner-primary", "fingerprint": "f071f9c0bd81cebc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jfv9-68m5-gjjr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-07bf0f76bd23d38a", "level": "warning", "message": {"text": "Vulnerable dependency mem0ai 0.1.102: GHSA-xqxw-r767-67m7"}, "properties": {"repobilityId": "ab1f576fe855ab47", "scanner": "scanner-primary", "fingerprint": "07bf0f76bd23d38a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xqxw-r767-67m7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0922b48893e45be1", "level": "warning", "message": {"text": "Vulnerable dependency mem0ai 0.1.102: PYSEC-2026-2633"}, "properties": {"repobilityId": "73d91534bc1d8848", "scanner": "scanner-primary", "fingerprint": "0922b48893e45be1", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2633"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cfe2837b2d9ec571", "level": "warning", "message": {"text": "Vulnerable dependency mem0ai 0.1.102: PYSEC-2026-2634"}, "properties": {"repobilityId": "7955f84f437a0b51", "scanner": "scanner-primary", "fingerprint": "cfe2837b2d9ec571", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2634"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c734b48858cc7f44", "level": "warning", "message": {"text": "Vulnerable dependency mem0ai 0.1.102: PYSEC-2026-2635"}, "properties": {"repobilityId": "13bbca2ac4e920c4", "scanner": "scanner-primary", "fingerprint": "c734b48858cc7f44", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2635"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-261329f4f16f17fe", "level": "warning", "message": {"text": "Vulnerable dependency mem0ai 0.1.102: PYSEC-2026-2636"}, "properties": {"repobilityId": "01a8f39a420bfe59", "scanner": "scanner-primary", "fingerprint": "261329f4f16f17fe", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2636"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5027315bcb24ff20", "level": "warning", "message": {"text": "Vulnerable dependency protobuf 6.31.1: GHSA-7gcm-g887-7qv7"}, "properties": {"repobilityId": "b312580e4524a98d", "scanner": "scanner-primary", "fingerprint": "5027315bcb24ff20", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-7gcm-g887-7qv7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-15f89a3ba893666e", "level": "warning", "message": {"text": "Vulnerable dependency protobuf 6.31.1: PYSEC-2026-1805"}, "properties": {"repobilityId": "d628dd427481a0ed", "scanner": "scanner-primary", "fingerprint": "15f89a3ba893666e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1805"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7fbf26228463805b", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.1: GHSA-63vm-454h-vhhq"}, "properties": {"repobilityId": "9911703c1f6f9206", "scanner": "scanner-primary", "fingerprint": "7fbf26228463805b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-63vm-454h-vhhq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-470d6112a4d90d65", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.1: GHSA-8ppf-4f7h-5ppj"}, "properties": {"repobilityId": "873a8ac7359bf771", "scanner": "scanner-primary", "fingerprint": "470d6112a4d90d65", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8ppf-4f7h-5ppj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1a9e1ece58347580", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.1: GHSA-hm4w-wwcw-mr6r"}, "properties": {"repobilityId": "6f8dc18ac8a6262e", "scanner": "scanner-primary", "fingerprint": "1a9e1ece58347580", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hm4w-wwcw-mr6r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5a071fa1c5ca1b33", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.1: GHSA-jr27-m4p2-rc6r"}, "properties": {"repobilityId": "0af88eff8d72ff3b", "scanner": "scanner-primary", "fingerprint": "5a071fa1c5ca1b33", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jr27-m4p2-rc6r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-782f39797ff0711f", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-1810"}, "properties": {"repobilityId": "a6f92f2047ca4b05", "scanner": "scanner-primary", "fingerprint": "782f39797ff0711f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1810"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-11200cdd7bfea923", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-2263"}, "properties": {"repobilityId": "3e295e87c8f50918", "scanner": "scanner-primary", "fingerprint": "11200cdd7bfea923", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2263"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-df3981f12693b1bd", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3455"}, "properties": {"repobilityId": "9ae4837eca152517", "scanner": "scanner-primary", "fingerprint": "df3981f12693b1bd", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3455"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f008a1d5687f4a65", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3456"}, "properties": {"repobilityId": "fc68b67ad6f707ca", "scanner": "scanner-primary", "fingerprint": "f008a1d5687f4a65", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3456"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f20b3f488a5e53d6", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3457"}, "properties": {"repobilityId": "a7e24f54feb6f519", "scanner": "scanner-primary", "fingerprint": "f20b3f488a5e53d6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3457"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-650d99b27fbbe9db", "level": "warning", "message": {"text": "Vulnerable dependency pygments 2.19.1: GHSA-5239-wwwm-4pmq"}, "properties": {"repobilityId": "fe8a95d5f7a7720f", "scanner": "scanner-primary", "fingerprint": "650d99b27fbbe9db", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-5239-wwwm-4pmq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-186ea5b4d906f6c4", "level": "warning", "message": {"text": "Vulnerable dependency pygments 2.19.1: PYSEC-2026-2987"}, "properties": {"repobilityId": "0dcc32684b8c69fa", "scanner": "scanner-primary", "fingerprint": "186ea5b4d906f6c4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2987"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4f42112bc2e80a54", "level": "warning", "message": {"text": "Vulnerable dependency pytest 8.3.5: GHSA-6w46-j5rx-g56g"}, "properties": {"repobilityId": "a6b92ed982ebc93c", "scanner": "scanner-primary", "fingerprint": "4f42112bc2e80a54", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6w46-j5rx-g56g"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9f399a73d9f84ebf", "level": "warning", "message": {"text": "Vulnerable dependency pytest 8.3.5: PYSEC-2026-1845"}, "properties": {"repobilityId": "1a8a199bafc71f4c", "scanner": "scanner-primary", "fingerprint": "9f399a73d9f84ebf", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1845"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f9a44dcfab63eba7", "level": "warning", "message": {"text": "Vulnerable dependency python-dotenv 1.1.0: GHSA-mf9w-mj56-hr94"}, "properties": {"repobilityId": "3e03b643522545a5", "scanner": "scanner-primary", "fingerprint": "f9a44dcfab63eba7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mf9w-mj56-hr94"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dd3ef06c2eec2234", "level": "warning", "message": {"text": "Vulnerable dependency python-dotenv 1.1.0: PYSEC-2026-2270"}, "properties": {"repobilityId": "0cdc16801a64514b", "scanner": "scanner-primary", "fingerprint": "dd3ef06c2eec2234", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2270"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-49686e89d9b8742a", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.20: GHSA-5rvq-cxj2-64vf"}, "properties": {"repobilityId": "4cfe05f96ba224ee", "scanner": "scanner-primary", "fingerprint": "49686e89d9b8742a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-5rvq-cxj2-64vf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-06649765a144f32c", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.20: GHSA-6jv3-5f52-599m"}, "properties": {"repobilityId": "079067cd48403c10", "scanner": "scanner-primary", "fingerprint": "06649765a144f32c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6jv3-5f52-599m"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e3f56f829239e231", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.20: GHSA-mj87-hwqh-73pj"}, "properties": {"repobilityId": "19b8d00eb6ecce32", "scanner": "scanner-primary", "fingerprint": "e3f56f829239e231", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mj87-hwqh-73pj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4b80a4994a090c6a", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.20: GHSA-pp6c-gr5w-3c5g"}, "properties": {"repobilityId": "1b3b056f6c9692e5", "scanner": "scanner-primary", "fingerprint": "4b80a4994a090c6a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pp6c-gr5w-3c5g"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d300907710daee1f", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.20: GHSA-v9pg-7xvm-68hf"}, "properties": {"repobilityId": "89a90e5211533db0", "scanner": "scanner-primary", "fingerprint": "d300907710daee1f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-v9pg-7xvm-68hf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bc259b4c527b353a", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.20: GHSA-vffw-93wf-4j4q"}, "properties": {"repobilityId": "a680b45cdc8b2830", "scanner": "scanner-primary", "fingerprint": "bc259b4c527b353a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vffw-93wf-4j4q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-afc563be12710e46", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.20: GHSA-wp53-j4wj-2cfg"}, "properties": {"repobilityId": "768b787b8b6b4499", "scanner": "scanner-primary", "fingerprint": "afc563be12710e46", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wp53-j4wj-2cfg"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-96455aad9cbe5dba", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-1852"}, "properties": {"repobilityId": "28de226d83f85ff7", "scanner": "scanner-primary", "fingerprint": "96455aad9cbe5dba", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1852"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-46c008b7cdc3c743", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-3036"}, "properties": {"repobilityId": "bb497bc01775fc6c", "scanner": "scanner-primary", "fingerprint": "46c008b7cdc3c743", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3036"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0dc9da349d54f592", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-3037"}, "properties": {"repobilityId": "7351c5d3c4adca0a", "scanner": "scanner-primary", "fingerprint": "0dc9da349d54f592", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3037"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-898b2e747719b517", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-3038"}, "properties": {"repobilityId": "dd5319567f4e520e", "scanner": "scanner-primary", "fingerprint": "898b2e747719b517", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3038"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-de9d09c97366e3fc", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-3039"}, "properties": {"repobilityId": "14d68246136c894c", "scanner": "scanner-primary", "fingerprint": "de9d09c97366e3fc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3039"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bee0e69c84d7132c", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-3040"}, "properties": {"repobilityId": "626c9e9858f7d80e", "scanner": "scanner-primary", "fingerprint": "bee0e69c84d7132c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3040"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0aec62f3aa56be46", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.20: PYSEC-2026-3041"}, "properties": {"repobilityId": "aa1048d489c9f9bb", "scanner": "scanner-primary", "fingerprint": "0aec62f3aa56be46", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3041"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-74843c1929b64b79", "level": "warning", "message": {"text": "Vulnerable dependency requests 2.32.3: GHSA-9hjg-9r4m-mvj7"}, "properties": {"repobilityId": "cb76020e142ccf21", "scanner": "scanner-primary", "fingerprint": "74843c1929b64b79", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9hjg-9r4m-mvj7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7a33c32467acd12b", "level": "warning", "message": {"text": "Vulnerable dependency requests 2.32.3: GHSA-gc5v-m9x4-r6x2"}, "properties": {"repobilityId": "9c9c86dfba4d2bc9", "scanner": "scanner-primary", "fingerprint": "7a33c32467acd12b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gc5v-m9x4-r6x2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-748056b95c60a7e5", "level": "warning", "message": {"text": "Vulnerable dependency requests 2.32.3: PYSEC-2026-1872"}, "properties": {"repobilityId": "5078f57171c8f8cf", "scanner": "scanner-primary", "fingerprint": "748056b95c60a7e5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1872"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-128ec0dbaed4496b", "level": "warning", "message": {"text": "Vulnerable dependency requests 2.32.3: PYSEC-2026-2275"}, "properties": {"repobilityId": "a2644e4d9d33dd19", "scanner": "scanner-primary", "fingerprint": "128ec0dbaed4496b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2275"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9a123c9e344a2675", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.46.2: GHSA-2c2j-9gv5-cj73"}, "properties": {"repobilityId": "9b35d99d44044250", "scanner": "scanner-primary", "fingerprint": "9a123c9e344a2675", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2c2j-9gv5-cj73"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-30b296101ff59fbb", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.46.2: GHSA-7f5h-v6xp-fcq8"}, "properties": {"repobilityId": "052722fcd97b3b80", "scanner": "scanner-primary", "fingerprint": "30b296101ff59fbb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-7f5h-v6xp-fcq8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-179c1c219207eb2b", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.46.2: GHSA-82w8-qh3p-5jfq"}, "properties": {"repobilityId": "562e6691c7991ece", "scanner": "scanner-primary", "fingerprint": "179c1c219207eb2b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-82w8-qh3p-5jfq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-677edecf6ab66014", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.46.2: GHSA-86qp-5c8j-p5mr"}, "properties": {"repobilityId": "578764ef063ae1b0", "scanner": "scanner-primary", "fingerprint": "677edecf6ab66014", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-86qp-5c8j-p5mr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-99acd821a9de3b5c", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.46.2: GHSA-jp82-jpqv-5vv3"}, "properties": {"repobilityId": "c4bf97b009ce4d0a", "scanner": "scanner-primary", "fingerprint": "99acd821a9de3b5c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jp82-jpqv-5vv3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-170da18f7077eeab", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.46.2: GHSA-wqp7-x3pw-xc5r"}, "properties": {"repobilityId": "1994e90573350c2a", "scanner": "scanner-primary", "fingerprint": "170da18f7077eeab", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wqp7-x3pw-xc5r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-42d88c1b398c0576", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.46.2: GHSA-x746-7m8f-x49c"}, "properties": {"repobilityId": "a88cbd3ca0e586c8", "scanner": "scanner-primary", "fingerprint": "42d88c1b398c0576", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-x746-7m8f-x49c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a49b7496266d3f5c", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-161"}, "properties": {"repobilityId": "46860c1bd27ef117", "scanner": "scanner-primary", "fingerprint": "a49b7496266d3f5c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-161"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8de9337408fa0766", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-1941"}, "properties": {"repobilityId": "013638b048b787c2", "scanner": "scanner-primary", "fingerprint": "8de9337408fa0766", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1941"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-20559aa906fc1ef2", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-1942"}, "properties": {"repobilityId": "e53ad2bc6f51f4dc", "scanner": "scanner-primary", "fingerprint": "20559aa906fc1ef2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1942"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-68f3d0d1cdcbda74", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-2280"}, "properties": {"repobilityId": "c1dc11b14d359c1a", "scanner": "scanner-primary", "fingerprint": "68f3d0d1cdcbda74", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2280"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-795b90303383c9a9", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-2281"}, "properties": {"repobilityId": "22364ad04ef558d2", "scanner": "scanner-primary", "fingerprint": "795b90303383c9a9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2281"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1d7adc6af694fc2a", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-248"}, "properties": {"repobilityId": "41e3667e1a0b5b44", "scanner": "scanner-primary", "fingerprint": "1d7adc6af694fc2a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-248"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-44e6cd02b30a52b3", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.46.2: PYSEC-2026-249"}, "properties": {"repobilityId": "6c993cfb7c949f22", "scanner": "scanner-primary", "fingerprint": "44e6cd02b30a52b3", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-249"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6c22ce5017cfa400", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.4.0: GHSA-2xpw-w6gg-jr37"}, "properties": {"repobilityId": "2e852fbd90c3f490", "scanner": "scanner-primary", "fingerprint": "6c22ce5017cfa400", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2xpw-w6gg-jr37"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6eaf9142750ed99a", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.4.0: GHSA-38jv-5279-wg99"}, "properties": {"repobilityId": "24be30925ed7aed9", "scanner": "scanner-primary", "fingerprint": "6eaf9142750ed99a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-38jv-5279-wg99"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-212dabf1482f8852", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.4.0: GHSA-48p4-8xcf-vxj5"}, "properties": {"repobilityId": "b26e1d876f147489", "scanner": "scanner-primary", "fingerprint": "212dabf1482f8852", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-48p4-8xcf-vxj5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4f3366091d009050", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.4.0: GHSA-gm62-xv2j-4w53"}, "properties": {"repobilityId": "5385f73b458c453a", "scanner": "scanner-primary", "fingerprint": "4f3366091d009050", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gm62-xv2j-4w53"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5d66f1fa7a3c0872", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.4.0: GHSA-pq67-6m6q-mj2v"}, "properties": {"repobilityId": "41047f2a5c723731", "scanner": "scanner-primary", "fingerprint": "5d66f1fa7a3c0872", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pq67-6m6q-mj2v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-66d913f223d3edc8", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.4.0: GHSA-qccp-gfcp-xxvc"}, "properties": {"repobilityId": "b484bf486c59bdc7", "scanner": "scanner-primary", "fingerprint": "66d913f223d3edc8", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-qccp-gfcp-xxvc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e0c716881d5fe073", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.4.0: PYSEC-2026-141"}, "properties": {"repobilityId": "b4654298dbafad86", "scanner": "scanner-primary", "fingerprint": "e0c716881d5fe073", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-141"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a22f51fc9de629f6", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.4.0: PYSEC-2026-1994"}, "properties": {"repobilityId": "c2d79dbf765e1c6c", "scanner": "scanner-primary", "fingerprint": "a22f51fc9de629f6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1994"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-38632d6285de9bcb", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.4.0: PYSEC-2026-1996"}, "properties": {"repobilityId": "b479bcf768a02283", "scanner": "scanner-primary", "fingerprint": "38632d6285de9bcb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1996"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fb6c5d3a218172d1", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.4.0: PYSEC-2026-1997"}, "properties": {"repobilityId": "674f9fc89b06d3ad", "scanner": "scanner-primary", "fingerprint": "fb6c5d3a218172d1", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1997"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-90450112510e1c7c", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.4.0: PYSEC-2026-1998"}, "properties": {"repobilityId": "c2fe8060cd4bdb88", "scanner": "scanner-primary", "fingerprint": "90450112510e1c7c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1998"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-28096e034d4da2d9", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.4.0: PYSEC-2026-1999"}, "properties": {"repobilityId": "75ee287cd89a442e", "scanner": "scanner-primary", "fingerprint": "28096e034d4da2d9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1999"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7b609220a3384bcb", "level": "warning", "message": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-2vg6-77g8-24mp"}, "properties": {"repobilityId": "25f05967f74f9b68", "scanner": "scanner-primary", "fingerprint": "7b609220a3384bcb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2vg6-77g8-24mp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9e807eaa175b7dba", "level": "warning", "message": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-36rg-gfq2-3h56"}, "properties": {"repobilityId": "62d4e685478d0263", "scanner": "scanner-primary", "fingerprint": "9e807eaa175b7dba", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-36rg-gfq2-3h56"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0cf9d5cebbba24df", "level": "warning", "message": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-569q-mpph-wgww"}, "properties": {"repobilityId": "42304d0dd0883db8", "scanner": "scanner-primary", "fingerprint": "0cf9d5cebbba24df", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-569q-mpph-wgww"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3a45d5e8fee0413c", "level": "warning", "message": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-7w99-5wm4-3g79"}, "properties": {"repobilityId": "53484b67bd44fff8", "scanner": "scanner-primary", "fingerprint": "3a45d5e8fee0413c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-7w99-5wm4-3g79"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3fa68a03d953891f", "level": "warning", "message": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-86j7-9j95-vpqj"}, "properties": {"repobilityId": "43d2c811fc0b606d", "scanner": "scanner-primary", "fingerprint": "3fa68a03d953891f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-86j7-9j95-vpqj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-257a4df60d2073e3", "level": "warning", "message": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-99h5-pjcv-gr6v"}, "properties": {"repobilityId": "bae401f16127cfed", "scanner": "scanner-primary", "fingerprint": "257a4df60d2073e3", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-99h5-pjcv-gr6v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-efed22d8b242c21f", "level": "warning", "message": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-9h47-pqcx-hjr4"}, "properties": {"repobilityId": "007e31b73fc8f029", "scanner": "scanner-primary", "fingerprint": "efed22d8b242c21f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9h47-pqcx-hjr4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-38e32962c3439ba7", "level": "warning", "message": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-fmh4-wcc4-5jm3"}, "properties": {"repobilityId": "fb46d1e55cdd3c46", "scanner": "scanner-primary", "fingerprint": "38e32962c3439ba7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-fmh4-wcc4-5jm3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-edfcd7ad190df690", "level": "warning", "message": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-g38m-r43w-p2q7"}, "properties": {"repobilityId": "33e3122cd82f3903", "scanner": "scanner-primary", "fingerprint": "edfcd7ad190df690", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-g38m-r43w-p2q7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7974783fa5f2312d", "level": "warning", "message": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-p6v2-xcpg-h6xw"}, "properties": {"repobilityId": "6466fb34332a199e", "scanner": "scanner-primary", "fingerprint": "7974783fa5f2312d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p6v2-xcpg-h6xw"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9e418b75b567f9e3", "level": "warning", "message": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-pw9m-5jxm-xr6h"}, "properties": {"repobilityId": "dff489c6878a16f7", "scanner": "scanner-primary", "fingerprint": "9e418b75b567f9e3", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pw9m-5jxm-xr6h"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-69909e6552e8998c", "level": "warning", "message": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-wxw3-q3m9-c3jr"}, "properties": {"repobilityId": "1f195890086f2e5d", "scanner": "scanner-primary", "fingerprint": "69909e6552e8998c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wxw3-q3m9-c3jr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2b5343a0c2da46c6", "level": "warning", "message": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-x732-6j76-qmhm"}, "properties": {"repobilityId": "e0ccddaa589bcb04", "scanner": "scanner-primary", "fingerprint": "2b5343a0c2da46c6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-x732-6j76-qmhm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-777bb3e971b0912b", "level": "warning", "message": {"text": "Vulnerable dependency better-auth 1.2.8: GHSA-xg6x-h9c9-2m83"}, "properties": {"repobilityId": "24c0c7d097d11def", "scanner": "scanner-primary", "fingerprint": "777bb3e971b0912b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xg6x-h9c9-2m83"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5da10e8c8e832db7", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-267c-6grr-h53f"}, "properties": {"repobilityId": "5e7de4cfbd2abba1", "scanner": "scanner-primary", "fingerprint": "5da10e8c8e832db7", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-267c-6grr-h53f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c662c4f78e841fd6", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-26hh-7cqf-hhc6"}, "properties": {"repobilityId": "3364d8ee503ead41", "scanner": "scanner-primary", "fingerprint": "c662c4f78e841fd6", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-26hh-7cqf-hhc6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-20c59a52543d948c", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-36qx-fr4f-26g5"}, "properties": {"repobilityId": "53977f914822d2c4", "scanner": "scanner-primary", "fingerprint": "20c59a52543d948c", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-36qx-fr4f-26g5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dcaf034db29b0769", "level": "note", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-3g8h-86w9-wvmq"}, "properties": {"repobilityId": "abe4888cd4674548", "scanner": "scanner-primary", "fingerprint": "dcaf034db29b0769", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3g8h-86w9-wvmq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b36f4917ac1bf954", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-3x4c-7xq6-9pq8"}, "properties": {"repobilityId": "d466c31731245523", "scanner": "scanner-primary", "fingerprint": "b36f4917ac1bf954", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3x4c-7xq6-9pq8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9f18b2ae3ebe4935", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-4342-x723-ch2f"}, "properties": {"repobilityId": "ee165eda8ed2e807", "scanner": "scanner-primary", "fingerprint": "9f18b2ae3ebe4935", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4342-x723-ch2f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6e9864fca1357703", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-4633-3j49-mh5q"}, "properties": {"repobilityId": "7cdaaa7c4ef3781d", "scanner": "scanner-primary", "fingerprint": "6e9864fca1357703", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4633-3j49-mh5q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-91d5f6593346a691", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-4c39-4ccg-62r3"}, "properties": {"repobilityId": "999705866c24bc35", "scanner": "scanner-primary", "fingerprint": "91d5f6593346a691", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4c39-4ccg-62r3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1ce5be35c3336360", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-68g3-v927-f742"}, "properties": {"repobilityId": "ab0cd5434d685925", "scanner": "scanner-primary", "fingerprint": "1ce5be35c3336360", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-68g3-v927-f742"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9026c23407580f4f", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-89xv-2m56-2m9x"}, "properties": {"repobilityId": "caebb152de9b5074", "scanner": "scanner-primary", "fingerprint": "9026c23407580f4f", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-89xv-2m56-2m9x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-25babb73c6b5e08f", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-8h8q-6873-q5fj"}, "properties": {"repobilityId": "d1e09dd947dfbf18", "scanner": "scanner-primary", "fingerprint": "25babb73c6b5e08f", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8h8q-6873-q5fj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e4952da4c5ddb0af", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-955p-x3mx-jcvp"}, "properties": {"repobilityId": "6350455afd1f410e", "scanner": "scanner-primary", "fingerprint": "e4952da4c5ddb0af", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-955p-x3mx-jcvp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ced1ec76b2dd9305", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-9g9p-9gw9-jx7f"}, "properties": {"repobilityId": "943a6d42815e6be4", "scanner": "scanner-primary", "fingerprint": "ced1ec76b2dd9305", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9g9p-9gw9-jx7f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d0f5da35f882dc34", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-9qr9-h5gf-34mp"}, "properties": {"repobilityId": "5bd18e9ec938658d", "scanner": "scanner-primary", "fingerprint": "d0f5da35f882dc34", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9qr9-h5gf-34mp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-709b71355fe6f634", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-c4j6-fc7j-m34r"}, "properties": {"repobilityId": "ca54b7492c594fce", "scanner": "scanner-primary", "fingerprint": "709b71355fe6f634", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-c4j6-fc7j-m34r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6807b1cf47e05d30", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-ffhc-5mcf-pf4q"}, "properties": {"repobilityId": "a34e0029deda11ce", "scanner": "scanner-primary", "fingerprint": "6807b1cf47e05d30", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ffhc-5mcf-pf4q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a2886d884e567448", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-g5qg-72qw-gw5v"}, "properties": {"repobilityId": "7884fb7f8b1ca1c5", "scanner": "scanner-primary", "fingerprint": "a2886d884e567448", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-g5qg-72qw-gw5v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-49bea8a3cbf28055", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-ggv3-7p47-pfv8"}, "properties": {"repobilityId": "ec752c40476d2d99", "scanner": "scanner-primary", "fingerprint": "49bea8a3cbf28055", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ggv3-7p47-pfv8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-85b4c5189cc53309", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-gx5p-jg67-6x7h"}, "properties": {"repobilityId": "5b8bed22a57fc4da", "scanner": "scanner-primary", "fingerprint": "85b4c5189cc53309", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gx5p-jg67-6x7h"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1c6cb64e82353ee4", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-h25m-26qc-wcjf"}, "properties": {"repobilityId": "061c2aea0a53ecff", "scanner": "scanner-primary", "fingerprint": "1c6cb64e82353ee4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h25m-26qc-wcjf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-abd9e2dd2baca3a3", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-h64f-5h5j-jqjh"}, "properties": {"repobilityId": "66311bc76796e405", "scanner": "scanner-primary", "fingerprint": "abd9e2dd2baca3a3", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h64f-5h5j-jqjh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b80a5d1ae604bb16", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-m99w-x7hq-7vfj"}, "properties": {"repobilityId": "f8aa74a31a22e607", "scanner": "scanner-primary", "fingerprint": "b80a5d1ae604bb16", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m99w-x7hq-7vfj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7224a862c3eeb23a", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-mg66-mrh9-m8jx"}, "properties": {"repobilityId": "da1d599fc3157452", "scanner": "scanner-primary", "fingerprint": "7224a862c3eeb23a", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mg66-mrh9-m8jx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3cad4943eaa4f9d6", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-mwv6-3258-q52c"}, "properties": {"repobilityId": "4e73388050db2ce2", "scanner": "scanner-primary", "fingerprint": "3cad4943eaa4f9d6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mwv6-3258-q52c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cb45d5b7663a38fe", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-p9j2-gv94-2wf4"}, "properties": {"repobilityId": "8c28b4f357b6b328", "scanner": "scanner-primary", "fingerprint": "cb45d5b7663a38fe", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p9j2-gv94-2wf4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-98096085a2c4306a", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-q4gf-8mx6-v5v3"}, "properties": {"repobilityId": "512448985803e85b", "scanner": "scanner-primary", "fingerprint": "98096085a2c4306a", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q4gf-8mx6-v5v3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ae1145fe6d646e0f", "level": "note", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-vfv6-92ff-j949"}, "properties": {"repobilityId": "fccde40bddda250d", "scanner": "scanner-primary", "fingerprint": "ae1145fe6d646e0f", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vfv6-92ff-j949"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ac1fa2c170311189", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-w37m-7fhw-fmv9"}, "properties": {"repobilityId": "5cb5f3a7ce495b44", "scanner": "scanner-primary", "fingerprint": "ac1fa2c170311189", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w37m-7fhw-fmv9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-97f8cee7297a1bbc", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-wfc6-r584-vfw7"}, "properties": {"repobilityId": "21d7235b7bec714e", "scanner": "scanner-primary", "fingerprint": "97f8cee7297a1bbc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wfc6-r584-vfw7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2b9aec619e0c3a43", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.3: GHSA-xv57-4mr9-wg8v"}, "properties": {"repobilityId": "d993180e44c4e908", "scanner": "scanner-primary", "fingerprint": "2b9aec619e0c3a43", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xv57-4mr9-wg8v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4e19ec5a29905d86", "level": "error", "message": {"text": "Vulnerable dependency postcss 8.4.31: GHSA-6g55-p6wh-862q"}, "properties": {"repobilityId": "86c312e6e8a1e925", "scanner": "scanner-primary", "fingerprint": "4e19ec5a29905d86", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6g55-p6wh-862q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ac1de0e7a590a6db", "level": "warning", "message": {"text": "Vulnerable dependency postcss 8.4.31: GHSA-qx2v-qp2m-jg93"}, "properties": {"repobilityId": "00a7666aebb4f6a3", "scanner": "scanner-primary", "fingerprint": "ac1de0e7a590a6db", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-qx2v-qp2m-jg93"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a64e0d4d479f868a", "level": "error", "message": {"text": "Vulnerable dependency postcss 8.5.4: GHSA-6g55-p6wh-862q"}, "properties": {"repobilityId": "7c7eda42ec58bb63", "scanner": "scanner-primary", "fingerprint": "a64e0d4d479f868a", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6g55-p6wh-862q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6ed4051c0564006b", "level": "warning", "message": {"text": "Vulnerable dependency postcss 8.5.4: GHSA-qx2v-qp2m-jg93"}, "properties": {"repobilityId": "bf7ac018dc8625cd", "scanner": "scanner-primary", "fingerprint": "6ed4051c0564006b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-qx2v-qp2m-jg93"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-11cd97ebbbf20189", "level": "warning", "message": {"text": "Vulnerable dependency tar 7.4.3: GHSA-23hp-3jrh-7fpw"}, "properties": {"repobilityId": "1b56de1f63a1d94b", "scanner": "scanner-primary", "fingerprint": "11cd97ebbbf20189", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-23hp-3jrh-7fpw"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f150a2229ae61a26", "level": "warning", "message": {"text": "Vulnerable dependency tar 7.4.3: GHSA-34x7-hfp2-rc4v"}, "properties": {"repobilityId": "4b0393c92afe2641", "scanner": "scanner-primary", "fingerprint": "f150a2229ae61a26", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-34x7-hfp2-rc4v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0323477449708360", "level": "warning", "message": {"text": "Vulnerable dependency tar 7.4.3: GHSA-83g3-92jg-28cx"}, "properties": {"repobilityId": "1981c7e849125af7", "scanner": "scanner-primary", "fingerprint": "0323477449708360", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-83g3-92jg-28cx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fff91d36e8073c77", "level": "warning", "message": {"text": "Vulnerable dependency tar 7.4.3: GHSA-8qq5-rm4j-mr97"}, "properties": {"repobilityId": "298856e07bb1ce67", "scanner": "scanner-primary", "fingerprint": "fff91d36e8073c77", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8qq5-rm4j-mr97"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-64873ca0df37026c", "level": "warning", "message": {"text": "Vulnerable dependency tar 7.4.3: GHSA-8x88-c5mf-7j5w"}, "properties": {"repobilityId": "c071d184a5deefa9", "scanner": "scanner-primary", "fingerprint": "64873ca0df37026c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8x88-c5mf-7j5w"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6bd4be222882688c", "level": "warning", "message": {"text": "Vulnerable dependency tar 7.4.3: GHSA-9ppj-qmqm-q256"}, "properties": {"repobilityId": "52cc83f07799af10", "scanner": "scanner-primary", "fingerprint": "6bd4be222882688c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9ppj-qmqm-q256"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d6f822e32a674755", "level": "warning", "message": {"text": "Vulnerable dependency tar 7.4.3: GHSA-gvwx-54wh-qm9j"}, "properties": {"repobilityId": "ab1e8b9e8d58b02a", "scanner": "scanner-primary", "fingerprint": "d6f822e32a674755", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gvwx-54wh-qm9j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bdd46a2a0fecbb63", "level": "warning", "message": {"text": "Vulnerable dependency tar 7.4.3: GHSA-qffp-2rhf-9h96"}, "properties": {"repobilityId": "89517037461e9191", "scanner": "scanner-primary", "fingerprint": "bdd46a2a0fecbb63", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-qffp-2rhf-9h96"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5ab42ba718bb54ad", "level": "warning", "message": {"text": "Vulnerable dependency tar 7.4.3: GHSA-r6q2-hw4h-h46w"}, "properties": {"repobilityId": "099591009ae12b0a", "scanner": "scanner-primary", "fingerprint": "5ab42ba718bb54ad", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-r6q2-hw4h-h46w"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b048abe6812739ea", "level": "warning", "message": {"text": "Vulnerable dependency tar 7.4.3: GHSA-vmf3-w455-68vh"}, "properties": {"repobilityId": "0cc5cb1b89b1095b", "scanner": "scanner-primary", "fingerprint": "b048abe6812739ea", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vmf3-w455-68vh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-82997768a250bec7", "level": "warning", "message": {"text": "Vulnerable dependency tar 7.4.3: GHSA-w8wr-v893-vjvp"}, "properties": {"repobilityId": "7ddd420d6115e66b", "scanner": "scanner-primary", "fingerprint": "82997768a250bec7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w8wr-v893-vjvp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c2eb24934dedabce", "level": "warning", "message": {"text": "Vulnerable dependency @hono/node-server 1.19.9: GHSA-92pp-h63x-v22m"}, "properties": {"repobilityId": "7ceab5ad6b1bbfd8", "scanner": "scanner-primary", "fingerprint": "c2eb24934dedabce", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-92pp-h63x-v22m"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e7c7d90aa359f40e", "level": "warning", "message": {"text": "Vulnerable dependency @hono/node-server 1.19.9: GHSA-frvp-7c67-39w9"}, "properties": {"repobilityId": "e2b61b4fef8c165d", "scanner": "scanner-primary", "fingerprint": "e7c7d90aa359f40e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-frvp-7c67-39w9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ffc3fc5852012edd", "level": "warning", "message": {"text": "Vulnerable dependency @hono/node-server 1.19.9: GHSA-wc8c-qw6v-h7f6"}, "properties": {"repobilityId": "a3b4ce8e59f3787c", "scanner": "scanner-primary", "fingerprint": "ffc3fc5852012edd", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wc8c-qw6v-h7f6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9ca71e2dd617063a", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-26pp-8wgv-hjvm"}, "properties": {"repobilityId": "b09c3d6bced4cf29", "scanner": "scanner-primary", "fingerprint": "9ca71e2dd617063a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-26pp-8wgv-hjvm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aac04a277f139b46", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-2gcr-mfcq-wcc3"}, "properties": {"repobilityId": "ee278f19ac25fa8a", "scanner": "scanner-primary", "fingerprint": "aac04a277f139b46", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2gcr-mfcq-wcc3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-48b4b407e033c993", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-3hrh-pfw6-9m5x"}, "properties": {"repobilityId": "1538fe8ecb2d657c", "scanner": "scanner-primary", "fingerprint": "48b4b407e033c993", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3hrh-pfw6-9m5x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6540c8ab0bf3a69a", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-458j-xx4x-4375"}, "properties": {"repobilityId": "04df17d1dafd2e11", "scanner": "scanner-primary", "fingerprint": "6540c8ab0bf3a69a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-458j-xx4x-4375"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a64877f56d386ca4", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-5pq2-9x2x-5p6w"}, "properties": {"repobilityId": "07d2e824d3b5ad19", "scanner": "scanner-primary", "fingerprint": "a64877f56d386ca4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-5pq2-9x2x-5p6w"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9e5858355d36ee9b", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-69xw-7hcm-h432"}, "properties": {"repobilityId": "e1816d55a9497422", "scanner": "scanner-primary", "fingerprint": "9e5858355d36ee9b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-69xw-7hcm-h432"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5cc34e760aeca336", "level": "error", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-88fw-hqm2-52qc"}, "properties": {"repobilityId": "4bcacc292168aa88", "scanner": "scanner-primary", "fingerprint": "5cc34e760aeca336", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-88fw-hqm2-52qc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0b5bb81bf4d13459", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-9vqf-7f2p-gf9v"}, "properties": {"repobilityId": "3ff7c1a7791a79cd", "scanner": "scanner-primary", "fingerprint": "0b5bb81bf4d13459", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9vqf-7f2p-gf9v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a5b633ce2b7e8102", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-f577-qrjj-4474"}, "properties": {"repobilityId": "700b5fddf9c70991", "scanner": "scanner-primary", "fingerprint": "a5b633ce2b7e8102", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-f577-qrjj-4474"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-34c20cb3c07404a2", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-gq3j-xvxp-8hrf"}, "properties": {"repobilityId": "7ccd09ab751c1a82", "scanner": "scanner-primary", "fingerprint": "34c20cb3c07404a2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gq3j-xvxp-8hrf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-82530e94cdc05637", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-hm8q-7f3q-5f36"}, "properties": {"repobilityId": "11fcb126465a579f", "scanner": "scanner-primary", "fingerprint": "82530e94cdc05637", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hm8q-7f3q-5f36"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d3f08a51b730fc68", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-j6c9-x7qj-28xf"}, "properties": {"repobilityId": "d586873b55577574", "scanner": "scanner-primary", "fingerprint": "d3f08a51b730fc68", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-j6c9-x7qj-28xf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c8b0c8d4a914c29e", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-p6xx-57qc-3wxr"}, "properties": {"repobilityId": "91b9dfe6fdd5524b", "scanner": "scanner-primary", "fingerprint": "c8b0c8d4a914c29e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p6xx-57qc-3wxr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c679e4824777ab75", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-p77w-8qqv-26rm"}, "properties": {"repobilityId": "060b4b562de013c3", "scanner": "scanner-primary", "fingerprint": "c679e4824777ab75", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p77w-8qqv-26rm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d5569135a9ae3249", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-q5qw-h33p-qvwr"}, "properties": {"repobilityId": "dc615943e5eccc8a", "scanner": "scanner-primary", "fingerprint": "d5569135a9ae3249", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q5qw-h33p-qvwr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dcdcde43d9000b52", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-qp7p-654g-cw7p"}, "properties": {"repobilityId": "993300233aaa3ab1", "scanner": "scanner-primary", "fingerprint": "dcdcde43d9000b52", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-qp7p-654g-cw7p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a31b05c818db37d2", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-r5rp-j6wh-rvv4"}, "properties": {"repobilityId": "b01fe6da38e821f7", "scanner": "scanner-primary", "fingerprint": "a31b05c818db37d2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-r5rp-j6wh-rvv4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8d8946a3471f476c", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-rv63-4mwf-qqc2"}, "properties": {"repobilityId": "305f1a17280de27e", "scanner": "scanner-primary", "fingerprint": "8d8946a3471f476c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-rv63-4mwf-qqc2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-713787bb34064797", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-v8w9-8mx6-g223"}, "properties": {"repobilityId": "7733f3c12d4cb7e1", "scanner": "scanner-primary", "fingerprint": "713787bb34064797", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-v8w9-8mx6-g223"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-380a4be0b5b49d13", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-w62v-xxxg-mg59"}, "properties": {"repobilityId": "4ae2d225cc6a1fea", "scanner": "scanner-primary", "fingerprint": "380a4be0b5b49d13", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w62v-xxxg-mg59"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8efed76c3471ca5e", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-wgpf-jwqj-8h8p"}, "properties": {"repobilityId": "52ef5fe2af81aa14", "scanner": "scanner-primary", "fingerprint": "8efed76c3471ca5e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wgpf-jwqj-8h8p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c8f355cf3dcdf5f5", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-wmmm-f939-6g9c"}, "properties": {"repobilityId": "17a0468c9778e3f7", "scanner": "scanner-primary", "fingerprint": "c8f355cf3dcdf5f5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wmmm-f939-6g9c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1d7a03ed5d250718", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-wwfh-h76j-fc44"}, "properties": {"repobilityId": "3e056aa7f0f6489c", "scanner": "scanner-primary", "fingerprint": "1d7a03ed5d250718", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wwfh-h76j-fc44"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b0ee02c8ab1fa57b", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-xf4j-xp2r-rqqx"}, "properties": {"repobilityId": "bb374c3006bca8c5", "scanner": "scanner-primary", "fingerprint": "b0ee02c8ab1fa57b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xf4j-xp2r-rqqx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-53bfb8b30e3a82f5", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-xgm2-5f3f-mvvc"}, "properties": {"repobilityId": "a1c486b84e75bcd9", "scanner": "scanner-primary", "fingerprint": "53bfb8b30e3a82f5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xgm2-5f3f-mvvc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-44ec0d81833cc010", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-xpcf-pg52-r92g"}, "properties": {"repobilityId": "3cb6ec0f4b7c944c", "scanner": "scanner-primary", "fingerprint": "44ec0d81833cc010", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xpcf-pg52-r92g"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bd06d5c0254a2fab", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.7: GHSA-xrhx-7g5j-rcj5"}, "properties": {"repobilityId": "d2b827213c6953aa", "scanner": "scanner-primary", "fingerprint": "bd06d5c0254a2fab", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xrhx-7g5j-rcj5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ec65e0136f55e6fe", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-267c-6grr-h53f"}, "properties": {"repobilityId": "d3eeb9e81fdb3a8d", "scanner": "scanner-primary", "fingerprint": "ec65e0136f55e6fe", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-267c-6grr-h53f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a4549c4241c29a4b", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-26hh-7cqf-hhc6"}, "properties": {"repobilityId": "6fe14a39ffc56c66", "scanner": "scanner-primary", "fingerprint": "a4549c4241c29a4b", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-26hh-7cqf-hhc6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7e8ace79fbd65aa9", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-36qx-fr4f-26g5"}, "properties": {"repobilityId": "148e2452f6e700ed", "scanner": "scanner-primary", "fingerprint": "7e8ace79fbd65aa9", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-36qx-fr4f-26g5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-14db7748fd13ec0c", "level": "note", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-3g8h-86w9-wvmq"}, "properties": {"repobilityId": "5e6092816b09c174", "scanner": "scanner-primary", "fingerprint": "14db7748fd13ec0c", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3g8h-86w9-wvmq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a1d0ffcf32d6fe28", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-3x4c-7xq6-9pq8"}, "properties": {"repobilityId": "fbe3b1916285f487", "scanner": "scanner-primary", "fingerprint": "a1d0ffcf32d6fe28", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3x4c-7xq6-9pq8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b1e83e463a74d76f", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-4633-3j49-mh5q"}, "properties": {"repobilityId": "4a3aa4814d1a655d", "scanner": "scanner-primary", "fingerprint": "b1e83e463a74d76f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4633-3j49-mh5q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c5c5bdf10f1f011d", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-492v-c6pp-mqqv"}, "properties": {"repobilityId": "ea4a768c0ca07906", "scanner": "scanner-primary", "fingerprint": "c5c5bdf10f1f011d", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-492v-c6pp-mqqv"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bdccac0189d86cad", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-4c39-4ccg-62r3"}, "properties": {"repobilityId": "09dd4167a2e7fbf5", "scanner": "scanner-primary", "fingerprint": "bdccac0189d86cad", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4c39-4ccg-62r3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8fd06ae5d4dc1e38", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-68g3-v927-f742"}, "properties": {"repobilityId": "ec67cd0d3d47c260", "scanner": "scanner-primary", "fingerprint": "8fd06ae5d4dc1e38", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-68g3-v927-f742"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-210ac085b29c04f3", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-89xv-2m56-2m9x"}, "properties": {"repobilityId": "e6cbe3ced4a0c81c", "scanner": "scanner-primary", "fingerprint": "210ac085b29c04f3", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-89xv-2m56-2m9x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dfa758b109d2fdd5", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-8h8q-6873-q5fj"}, "properties": {"repobilityId": "aca4f00e23b65ff0", "scanner": "scanner-primary", "fingerprint": "dfa758b109d2fdd5", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8h8q-6873-q5fj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-322ec4b5fe1872ef", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-955p-x3mx-jcvp"}, "properties": {"repobilityId": "e44fa5d1a588bc95", "scanner": "scanner-primary", "fingerprint": "322ec4b5fe1872ef", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-955p-x3mx-jcvp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-300721534e7a06f4", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-c4j6-fc7j-m34r"}, "properties": {"repobilityId": "04bf02edbf3d193d", "scanner": "scanner-primary", "fingerprint": "300721534e7a06f4", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-c4j6-fc7j-m34r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8eac48cd33d1821b", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-ffhc-5mcf-pf4q"}, "properties": {"repobilityId": "2e0e12b68d16e70b", "scanner": "scanner-primary", "fingerprint": "8eac48cd33d1821b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ffhc-5mcf-pf4q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e3c02f790fc692db", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-ggv3-7p47-pfv8"}, "properties": {"repobilityId": "5e8dd599e75a5384", "scanner": "scanner-primary", "fingerprint": "e3c02f790fc692db", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ggv3-7p47-pfv8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4170b81b2197ba71", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-gx5p-jg67-6x7h"}, "properties": {"repobilityId": "41f66f7789dd1c19", "scanner": "scanner-primary", "fingerprint": "4170b81b2197ba71", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gx5p-jg67-6x7h"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ff28515acbdfdc9a", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-h64f-5h5j-jqjh"}, "properties": {"repobilityId": "225c91881d6f70cf", "scanner": "scanner-primary", "fingerprint": "ff28515acbdfdc9a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h64f-5h5j-jqjh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-567ad37756ffc375", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-m99w-x7hq-7vfj"}, "properties": {"repobilityId": "84adabc3139914ab", "scanner": "scanner-primary", "fingerprint": "567ad37756ffc375", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m99w-x7hq-7vfj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bfc1e35b68029dd4", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-mg66-mrh9-m8jx"}, "properties": {"repobilityId": "0c20fd080e5fc97a", "scanner": "scanner-primary", "fingerprint": "bfc1e35b68029dd4", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mg66-mrh9-m8jx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b758ad5b471ac69a", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-p9j2-gv94-2wf4"}, "properties": {"repobilityId": "8946e1236ecbf992", "scanner": "scanner-primary", "fingerprint": "b758ad5b471ac69a", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p9j2-gv94-2wf4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1c58fb5f5d2afde9", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-q4gf-8mx6-v5v3"}, "properties": {"repobilityId": "cb9f1fc342fb5caa", "scanner": "scanner-primary", "fingerprint": "1c58fb5f5d2afde9", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q4gf-8mx6-v5v3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2b64effc8f493ea6", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-q8wf-6r8g-63ch"}, "properties": {"repobilityId": "168da00f23158c99", "scanner": "scanner-primary", "fingerprint": "2b64effc8f493ea6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q8wf-6r8g-63ch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-af5210b5beecc1a9", "level": "note", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-vfv6-92ff-j949"}, "properties": {"repobilityId": "e2bdf8dcf32f78e1", "scanner": "scanner-primary", "fingerprint": "af5210b5beecc1a9", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vfv6-92ff-j949"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-544354ab8799549a", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.12: GHSA-wfc6-r584-vfw7"}, "properties": {"repobilityId": "066aeac1126967ce", "scanner": "scanner-primary", "fingerprint": "544354ab8799549a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wfc6-r584-vfw7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-492f6212c8b6d40c", "level": "error", "message": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-6g55-p6wh-862q"}, "properties": {"repobilityId": "b8944461c8644339", "scanner": "scanner-primary", "fingerprint": "492f6212c8b6d40c", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-6g55-p6wh-862q", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c67336a6ee573687", "level": "warning", "message": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-qx2v-qp2m-jg93"}, "properties": {"repobilityId": "6c83605d3aa8fcef", "scanner": "scanner-primary", "fingerprint": "c67336a6ee573687", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-qx2v-qp2m-jg93", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4bcd1705a2f9e0f8", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-2fqr-mr3j-6wp8"}, "properties": {"repobilityId": "3bc184c6650e7d22", "scanner": "scanner-primary", "fingerprint": "4bcd1705a2f9e0f8", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2fqr-mr3j-6wp8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9121d174f2eeab15", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-2vrm-gr82-f7m5"}, "properties": {"repobilityId": "66b31f6a120394de", "scanner": "scanner-primary", "fingerprint": "9121d174f2eeab15", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2vrm-gr82-f7m5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b6c31bb511d3ccb6", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-3wq7-rqq7-wx6j"}, "properties": {"repobilityId": "9c548834c5b797b9", "scanner": "scanner-primary", "fingerprint": "b6c31bb511d3ccb6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3wq7-rqq7-wx6j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2193308d66e00036", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-4fvr-rgm6-gqmc"}, "properties": {"repobilityId": "640a43f4a0fa388b", "scanner": "scanner-primary", "fingerprint": "2193308d66e00036", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4fvr-rgm6-gqmc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-05abe65493869090", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-4m7w-qmgq-4wj5"}, "properties": {"repobilityId": "bf79be131731d2d3", "scanner": "scanner-primary", "fingerprint": "05abe65493869090", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4m7w-qmgq-4wj5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-689a21a85fcdbea5", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-54jq-c3m8-4m76"}, "properties": {"repobilityId": "ab503bf066689f32", "scanner": "scanner-primary", "fingerprint": "689a21a85fcdbea5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-54jq-c3m8-4m76"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f4349fe1a9a65278", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-63hf-3vf5-4wqf"}, "properties": {"repobilityId": "aefe8cc510527fd5", "scanner": "scanner-primary", "fingerprint": "f4349fe1a9a65278", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-63hf-3vf5-4wqf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6bb3dbc13ad5c0d1", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-63hw-fmq6-xxg2"}, "properties": {"repobilityId": "e243fb0d30fe2dcc", "scanner": "scanner-primary", "fingerprint": "6bb3dbc13ad5c0d1", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-63hw-fmq6-xxg2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7897b187d4427a60", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-69f9-5gxw-wvc2"}, "properties": {"repobilityId": "bb94f4baa7808d25", "scanner": "scanner-primary", "fingerprint": "7897b187d4427a60", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-69f9-5gxw-wvc2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-97a10e35839a3020", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-6jhg-hg63-jvvf"}, "properties": {"repobilityId": "80104dfb31fd6369", "scanner": "scanner-primary", "fingerprint": "97a10e35839a3020", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6jhg-hg63-jvvf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-07ad91d50549f684", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-6mq8-rvhq-8wgg"}, "properties": {"repobilityId": "8b05805fdfec0657", "scanner": "scanner-primary", "fingerprint": "07ad91d50549f684", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6mq8-rvhq-8wgg"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-89f0cdf705372708", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-9548-qrrj-x5pj"}, "properties": {"repobilityId": "274797c1d8e1787a", "scanner": "scanner-primary", "fingerprint": "89f0cdf705372708", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9548-qrrj-x5pj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-795a2409109a9f57", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-966j-vmvw-g2g9"}, "properties": {"repobilityId": "5dbb13ac1f587697", "scanner": "scanner-primary", "fingerprint": "795a2409109a9f57", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-966j-vmvw-g2g9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-681f13588d797e04", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-9x8q-7h8h-wcw9"}, "properties": {"repobilityId": "5eb0b1d9ebeac0da", "scanner": "scanner-primary", "fingerprint": "681f13588d797e04", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9x8q-7h8h-wcw9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e5f2e6d75ac86d30", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-c427-h43c-vf67"}, "properties": {"repobilityId": "0312f60f0f806691", "scanner": "scanner-primary", "fingerprint": "e5f2e6d75ac86d30", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-c427-h43c-vf67"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-031c59487bdcfa4b", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-fh55-r93g-j68g"}, "properties": {"repobilityId": "a456407c6ec96ba6", "scanner": "scanner-primary", "fingerprint": "031c59487bdcfa4b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-fh55-r93g-j68g"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-50a9d3f78b2b0792", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-g3cq-j2xw-wf74"}, "properties": {"repobilityId": "65e9090d3f56babd", "scanner": "scanner-primary", "fingerprint": "50a9d3f78b2b0792", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-g3cq-j2xw-wf74"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-49a1930ea07673be", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-g84x-mcqj-x9qq"}, "properties": {"repobilityId": "cacc54b2c25140ef", "scanner": "scanner-primary", "fingerprint": "49a1930ea07673be", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-g84x-mcqj-x9qq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3939752ceeb3892f", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-hcc4-c3v8-rx92"}, "properties": {"repobilityId": "e16b1947d85adf9f", "scanner": "scanner-primary", "fingerprint": "3939752ceeb3892f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hcc4-c3v8-rx92"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-57fb787d196a4e61", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-hg6j-4rv6-33pg"}, "properties": {"repobilityId": "1233bb2732addd2d", "scanner": "scanner-primary", "fingerprint": "57fb787d196a4e61", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hg6j-4rv6-33pg"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-da725a7180e726ec", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-hpj7-wq8m-9hgp"}, "properties": {"repobilityId": "52589d109aea3d1f", "scanner": "scanner-primary", "fingerprint": "da725a7180e726ec", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hpj7-wq8m-9hgp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3e7374c79b08594a", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-jg22-mg44-37j8"}, "properties": {"repobilityId": "ad51e509732b3696", "scanner": "scanner-primary", "fingerprint": "3e7374c79b08594a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jg22-mg44-37j8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e62e1b5161f77239", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-jj3x-wxrx-4x23"}, "properties": {"repobilityId": "dd985bacc6b7b50e", "scanner": "scanner-primary", "fingerprint": "e62e1b5161f77239", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jj3x-wxrx-4x23"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7a4adeb85ed9fbe3", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-m5qp-6w8w-w647"}, "properties": {"repobilityId": "3123c4b3293fb1db", "scanner": "scanner-primary", "fingerprint": "7a4adeb85ed9fbe3", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m5qp-6w8w-w647"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-594b024049d50710", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-m6qw-4cw2-hm4m"}, "properties": {"repobilityId": "2c282952ed17a7af", "scanner": "scanner-primary", "fingerprint": "594b024049d50710", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m6qw-4cw2-hm4m"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-868546cee51a8e37", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-mqqc-3gqh-h2x8"}, "properties": {"repobilityId": "248116132c876007", "scanner": "scanner-primary", "fingerprint": "868546cee51a8e37", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mqqc-3gqh-h2x8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e863e24cae2aff4f", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-mwh4-6h8g-pg8w"}, "properties": {"repobilityId": "c6f1fba28f91ea54", "scanner": "scanner-primary", "fingerprint": "e863e24cae2aff4f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mwh4-6h8g-pg8w"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2e3ea13c1d401696", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-p998-jp59-783m"}, "properties": {"repobilityId": "6ac4fb2097bbb861", "scanner": "scanner-primary", "fingerprint": "2e3ea13c1d401696", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p998-jp59-783m"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e9d08674d44d1c32", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-w2fm-2cpv-w7v5"}, "properties": {"repobilityId": "d6c051ae986a7538", "scanner": "scanner-primary", "fingerprint": "e9d08674d44d1c32", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w2fm-2cpv-w7v5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-077b3c41d988230d", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: GHSA-xcgm-r5h9-7989"}, "properties": {"repobilityId": "168986436112e23b", "scanner": "scanner-primary", "fingerprint": "077b3c41d988230d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xcgm-r5h9-7989"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-102488ed35835f87", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1097"}, "properties": {"repobilityId": "006d07e61540a99b", "scanner": "scanner-primary", "fingerprint": "102488ed35835f87", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1097"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f1bcd00db0df4bb3", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1099"}, "properties": {"repobilityId": "8ddad5d1cc1a9c9f", "scanner": "scanner-primary", "fingerprint": "f1bcd00db0df4bb3", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1099"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-464a897268a65de4", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1100"}, "properties": {"repobilityId": "0c1ae562cc9468b9", "scanner": "scanner-primary", "fingerprint": "464a897268a65de4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1100"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bc0b4304667c3a2d", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1101"}, "properties": {"repobilityId": "1b0dd489df8aa417", "scanner": "scanner-primary", "fingerprint": "bc0b4304667c3a2d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1101"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-71a67320ce60edd0", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1104"}, "properties": {"repobilityId": "60d75891b9645c5a", "scanner": "scanner-primary", "fingerprint": "71a67320ce60edd0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1104"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e0ee500012acea27", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1105"}, "properties": {"repobilityId": "b37921bb227e50aa", "scanner": "scanner-primary", "fingerprint": "e0ee500012acea27", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1105"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-97ff2ef574696398", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1106"}, "properties": {"repobilityId": "c3592b6464597b79", "scanner": "scanner-primary", "fingerprint": "97ff2ef574696398", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1106"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e285327e620d3a3e", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1107"}, "properties": {"repobilityId": "4ac00802fe7b8ef4", "scanner": "scanner-primary", "fingerprint": "e285327e620d3a3e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1107"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a6c95e751a676054", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-1109"}, "properties": {"repobilityId": "32656f59bfc5cc7b", "scanner": "scanner-primary", "fingerprint": "a6c95e751a676054", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1109"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8fa137bf6d43da61", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2094"}, "properties": {"repobilityId": "3a52019877dfe1f0", "scanner": "scanner-primary", "fingerprint": "8fa137bf6d43da61", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2094"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7949f5fdbebbd17c", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2095"}, "properties": {"repobilityId": "78e102da1eb577e2", "scanner": "scanner-primary", "fingerprint": "7949f5fdbebbd17c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2095"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-24b3dcd87c71b423", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2097"}, "properties": {"repobilityId": "4b31b8300784a5e5", "scanner": "scanner-primary", "fingerprint": "24b3dcd87c71b423", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2097"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3fae733c4f38bc71", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2098"}, "properties": {"repobilityId": "be95b19fc90163de", "scanner": "scanner-primary", "fingerprint": "3fae733c4f38bc71", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2098"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1af58bbaaf1f7d55", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2100"}, "properties": {"repobilityId": "c29c09f88ad6b6b9", "scanner": "scanner-primary", "fingerprint": "1af58bbaaf1f7d55", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2100"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b7e1f46ecdb21ac8", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2101"}, "properties": {"repobilityId": "c308de5e1d1b8c8e", "scanner": "scanner-primary", "fingerprint": "b7e1f46ecdb21ac8", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2101"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f6d7c2f2e6c6d8fd", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2102"}, "properties": {"repobilityId": "6ea374d2ea5a2637", "scanner": "scanner-primary", "fingerprint": "f6d7c2f2e6c6d8fd", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2102"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5a979d4a0615c818", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2103"}, "properties": {"repobilityId": "86381cbf8330ea6b", "scanner": "scanner-primary", "fingerprint": "5a979d4a0615c818", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2103"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0506d69e23a8ec73", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2104"}, "properties": {"repobilityId": "9c1c642d30cdb36e", "scanner": "scanner-primary", "fingerprint": "0506d69e23a8ec73", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2104"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ba270c40360697ce", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2105"}, "properties": {"repobilityId": "725a1a054198ed2a", "scanner": "scanner-primary", "fingerprint": "ba270c40360697ce", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2105"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0e30944679632a5f", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2106"}, "properties": {"repobilityId": "f3677cb7400f438a", "scanner": "scanner-primary", "fingerprint": "0e30944679632a5f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2106"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2153e9edbaf12e2d", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2108"}, "properties": {"repobilityId": "b6e4c1dd78daecbc", "scanner": "scanner-primary", "fingerprint": "2153e9edbaf12e2d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2108"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cca9bdb5512fbb46", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2109"}, "properties": {"repobilityId": "c6ce85b1374c5a97", "scanner": "scanner-primary", "fingerprint": "cca9bdb5512fbb46", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2109"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2da3665b43197bcd", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2110"}, "properties": {"repobilityId": "58a0782e8644f2cf", "scanner": "scanner-primary", "fingerprint": "2da3665b43197bcd", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2110"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1444597e19b16b35", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2111"}, "properties": {"repobilityId": "f3343af1fc4afc46", "scanner": "scanner-primary", "fingerprint": "1444597e19b16b35", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2111"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bb1630d6588aefc4", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.12.12: PYSEC-2026-2113"}, "properties": {"repobilityId": "32118e7a964399c8", "scanner": "scanner-primary", "fingerprint": "bb1630d6588aefc4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2113"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8411b87bc5e6120c", "level": "error", "message": {"text": "Vulnerable dependency langchain 0.3.25: GHSA-3644-q5cj-c5c7"}, "properties": {"repobilityId": "78a7d88f547a5297", "scanner": "scanner-primary", "fingerprint": "8411b87bc5e6120c", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3644-q5cj-c5c7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cbba48a036cfbdbf", "level": "warning", "message": {"text": "Vulnerable dependency langchain 0.3.25: GHSA-gr75-jv2w-4656"}, "properties": {"repobilityId": "ce05ea69290173f7", "scanner": "scanner-primary", "fingerprint": "cbba48a036cfbdbf", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gr75-jv2w-4656"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-20f952129a3537e7", "level": "warning", "message": {"text": "Vulnerable dependency langchain-community 0.3.25: GHSA-pc6w-59fv-rh23"}, "properties": {"repobilityId": "c2cd037844201074", "scanner": "scanner-primary", "fingerprint": "20f952129a3537e7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pc6w-59fv-rh23"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-10b93e917252bd7f", "level": "warning", "message": {"text": "Vulnerable dependency langchain-community 0.3.25: PYSEC-2026-1515"}, "properties": {"repobilityId": "e449e7633c4abf5e", "scanner": "scanner-primary", "fingerprint": "10b93e917252bd7f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1515"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a113e7b71a5a8b52", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 0.3.65: GHSA-2g6r-c272-w58r"}, "properties": {"repobilityId": "32765a3f665815b5", "scanner": "scanner-primary", "fingerprint": "a113e7b71a5a8b52", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2g6r-c272-w58r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e0a656dd3a00eb86", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 0.3.65: GHSA-6qv9-48xg-fc7f"}, "properties": {"repobilityId": "64ba45cb2c37849a", "scanner": "scanner-primary", "fingerprint": "e0a656dd3a00eb86", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6qv9-48xg-fc7f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-740046de036f13be", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 0.3.65: GHSA-926x-3r5x-gfhw"}, "properties": {"repobilityId": "ba866337d9171a97", "scanner": "scanner-primary", "fingerprint": "740046de036f13be", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-926x-3r5x-gfhw"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3bb40c87bccffe52", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 0.3.65: GHSA-c67j-w6g6-q2cm"}, "properties": {"repobilityId": "ca0206560e14193a", "scanner": "scanner-primary", "fingerprint": "3bb40c87bccffe52", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-c67j-w6g6-q2cm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-92d89e3ae5aa0de5", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 0.3.65: GHSA-pjwx-r37v-7724"}, "properties": {"repobilityId": "18d843f33ee13338", "scanner": "scanner-primary", "fingerprint": "92d89e3ae5aa0de5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pjwx-r37v-7724"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-17e7c6ad4e4e9226", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 0.3.65: GHSA-qh6h-p6c9-ff54"}, "properties": {"repobilityId": "986ac20def392e57", "scanner": "scanner-primary", "fingerprint": "17e7c6ad4e4e9226", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-qh6h-p6c9-ff54"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-16f09d51f5005c95", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 0.3.65: PYSEC-2026-1518"}, "properties": {"repobilityId": "b3c0df109a9ea02e", "scanner": "scanner-primary", "fingerprint": "16f09d51f5005c95", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1518"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-22aac77ba9b23c20", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 0.3.65: PYSEC-2026-2193"}, "properties": {"repobilityId": "e0c39906e8117dbe", "scanner": "scanner-primary", "fingerprint": "22aac77ba9b23c20", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2193"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-32dc632836381b61", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 0.3.65: PYSEC-2026-2562"}, "properties": {"repobilityId": "9c61fee6a83c13a4", "scanner": "scanner-primary", "fingerprint": "32dc632836381b61", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2562"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5e70520ee7e595fb", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 0.3.65: PYSEC-2026-2563"}, "properties": {"repobilityId": "d82f412ba9303e66", "scanner": "scanner-primary", "fingerprint": "5e70520ee7e595fb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2563"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-19fe4c6ce92ed3b5", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 0.3.65: PYSEC-2026-2564"}, "properties": {"repobilityId": "b3413032d37a4b9c", "scanner": "scanner-primary", "fingerprint": "19fe4c6ce92ed3b5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2564"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0bf04c30d2b85274", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 0.3.65: PYSEC-2026-373"}, "properties": {"repobilityId": "aa664739a8ddf36f", "scanner": "scanner-primary", "fingerprint": "0bf04c30d2b85274", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-373"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6501e27b43cd4211", "level": "warning", "message": {"text": "Vulnerable dependency langchain-text-splitters 0.3.8: GHSA-fv5p-p927-qmxr"}, "properties": {"repobilityId": "eb70670f38d5ec24", "scanner": "scanner-primary", "fingerprint": "6501e27b43cd4211", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-fv5p-p927-qmxr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0be400af9052214f", "level": "warning", "message": {"text": "Vulnerable dependency langchain-text-splitters 0.3.8: GHSA-m42m-m8cr-8m58"}, "properties": {"repobilityId": "28dbaee83274ad74", "scanner": "scanner-primary", "fingerprint": "0be400af9052214f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m42m-m8cr-8m58"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6d580682113384c5", "level": "warning", "message": {"text": "Vulnerable dependency langchain-text-splitters 0.3.8: PYSEC-2026-1520"}, "properties": {"repobilityId": "9833be23f85d0590", "scanner": "scanner-primary", "fingerprint": "6d580682113384c5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1520"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5ce1c3787d1cb608", "level": "warning", "message": {"text": "Vulnerable dependency langchain-text-splitters 0.3.8: PYSEC-2026-77"}, "properties": {"repobilityId": "45dd214c62213c5c", "scanner": "scanner-primary", "fingerprint": "5ce1c3787d1cb608", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-77"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-10b03c5b9cdb769b", "level": "error", "message": {"text": "Vulnerable dependency langsmith 0.3.45: GHSA-3644-q5cj-c5c7"}, "properties": {"repobilityId": "4bb4e447bb54975b", "scanner": "scanner-primary", "fingerprint": "10b03c5b9cdb769b", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3644-q5cj-c5c7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ca79a62e0e914ee0", "level": "warning", "message": {"text": "Vulnerable dependency langsmith 0.3.45: GHSA-f4xh-w4cj-qxq8"}, "properties": {"repobilityId": "0847dbb5ebd8177b", "scanner": "scanner-primary", "fingerprint": "ca79a62e0e914ee0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-f4xh-w4cj-qxq8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3cc9f966e34be408", "level": "warning", "message": {"text": "Vulnerable dependency langsmith 0.3.45: GHSA-rr7j-v2q5-chgv"}, "properties": {"repobilityId": "645b2dbe582344ab", "scanner": "scanner-primary", "fingerprint": "3cc9f966e34be408", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-rr7j-v2q5-chgv"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0216ae4f0f605ec9", "level": "warning", "message": {"text": "Vulnerable dependency langsmith 0.3.45: PYSEC-2026-2583"}, "properties": {"repobilityId": "008656a0ec71cdcd", "scanner": "scanner-primary", "fingerprint": "0216ae4f0f605ec9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2583"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-70ea3038bd1c4646", "level": "warning", "message": {"text": "Vulnerable dependency orjson 3.10.18: GHSA-hx9q-6w63-j58v"}, "properties": {"repobilityId": "29e8f2908bc87f1f", "scanner": "scanner-primary", "fingerprint": "70ea3038bd1c4646", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hx9q-6w63-j58v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cdbccd33e54c30db", "level": "warning", "message": {"text": "Vulnerable dependency orjson 3.10.18: PYSEC-2026-107"}, "properties": {"repobilityId": "d7fed2ad2be3b8d7", "scanner": "scanner-primary", "fingerprint": "cdbccd33e54c30db", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-107"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f9aadf6242994d35", "level": "error", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-45hq-cxwh-f6vc"}, "properties": {"repobilityId": "15023e2a40082bcd", "scanner": "scanner-primary", "fingerprint": "f9aadf6242994d35", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-45hq-cxwh-f6vc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0bfefeae95f962cb", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-4x4j-2g7c-83w6"}, "properties": {"repobilityId": "f61abc1664b5fcd2", "scanner": "scanner-primary", "fingerprint": "0bfefeae95f962cb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4x4j-2g7c-83w6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8d153e704171e85e", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-5x94-69rx-g8h2"}, "properties": {"repobilityId": "2ca7581efda56014", "scanner": "scanner-primary", "fingerprint": "8d153e704171e85e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-5x94-69rx-g8h2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fca132e2f3a30a63", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-5xmw-vc9v-4wf2"}, "properties": {"repobilityId": "23b150cba67dbbc0", "scanner": "scanner-primary", "fingerprint": "fca132e2f3a30a63", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-5xmw-vc9v-4wf2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b80ab3ad93d0ccd0", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-62p4-gmf7-7g93"}, "properties": {"repobilityId": "488105085dd85604", "scanner": "scanner-primary", "fingerprint": "b80ab3ad93d0ccd0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-62p4-gmf7-7g93"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-25df7cc436c11952", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-6r8x-57c9-28j4"}, "properties": {"repobilityId": "4d6eaae3926d426f", "scanner": "scanner-primary", "fingerprint": "25df7cc436c11952", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6r8x-57c9-28j4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e8536c8346be7e55", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-8v84-f9pq-wr9x"}, "properties": {"repobilityId": "e2f4ac78397f9bd9", "scanner": "scanner-primary", "fingerprint": "e8536c8346be7e55", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8v84-f9pq-wr9x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-addd35e9d34d29e8", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-9hw9-ch79-4vh6"}, "properties": {"repobilityId": "286b3caf3388b3b8", "scanner": "scanner-primary", "fingerprint": "addd35e9d34d29e8", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9hw9-ch79-4vh6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c920a2a31e9d4c60", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-cfh3-3jmp-rvhc"}, "properties": {"repobilityId": "4f8378eb0c461db1", "scanner": "scanner-primary", "fingerprint": "c920a2a31e9d4c60", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-cfh3-3jmp-rvhc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-29f16fe6e38e84e1", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-fj7v-r99m-22gq"}, "properties": {"repobilityId": "4612f0084948050d", "scanner": "scanner-primary", "fingerprint": "29f16fe6e38e84e1", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-fj7v-r99m-22gq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a5ceac7a9d00be03", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-jjj6-mw9f-p565"}, "properties": {"repobilityId": "6b328c3e1edf628e", "scanner": "scanner-primary", "fingerprint": "a5ceac7a9d00be03", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jjj6-mw9f-p565"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f2d74f05310123c0", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-phj9-mv4w-65pm"}, "properties": {"repobilityId": "aca74d838d76abab", "scanner": "scanner-primary", "fingerprint": "f2d74f05310123c0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-phj9-mv4w-65pm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-00aaa31e082a9795", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-pwv6-vv43-88gr"}, "properties": {"repobilityId": "7d7e8dd4886404fd", "scanner": "scanner-primary", "fingerprint": "00aaa31e082a9795", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pwv6-vv43-88gr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9de962c68203b514", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-r73j-pqj5-w3x7"}, "properties": {"repobilityId": "2003b88e607ff325", "scanner": "scanner-primary", "fingerprint": "9de962c68203b514", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-r73j-pqj5-w3x7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e596db9c199c4f9b", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-vjc4-5qp5-m44j"}, "properties": {"repobilityId": "7a689c6d74f046d0", "scanner": "scanner-primary", "fingerprint": "e596db9c199c4f9b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vjc4-5qp5-m44j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a7cdeccf46d45d16", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-whj4-6x5x-4v2j"}, "properties": {"repobilityId": "a31833b4c2ed8bb7", "scanner": "scanner-primary", "fingerprint": "a7cdeccf46d45d16", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-whj4-6x5x-4v2j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b28c8653bc04cb81", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-wjx4-4jcj-g98j"}, "properties": {"repobilityId": "4f8598bf0bcad14f", "scanner": "scanner-primary", "fingerprint": "b28c8653bc04cb81", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wjx4-4jcj-g98j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-01d12da8456ae28a", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-xg8h-j46f-w952"}, "properties": {"repobilityId": "de2bc0447b236ce9", "scanner": "scanner-primary", "fingerprint": "01d12da8456ae28a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xg8h-j46f-w952"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-be25fb62f0112c5e", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: GHSA-xj96-63gp-2gmr"}, "properties": {"repobilityId": "6edcfd5ea3c07ec7", "scanner": "scanner-primary", "fingerprint": "be25fb62f0112c5e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xj96-63gp-2gmr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b0b1d0f52e15be7d", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2025-61"}, "properties": {"repobilityId": "b2c5be792b02a974", "scanner": "scanner-primary", "fingerprint": "b0b1d0f52e15be7d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2025-61"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-16760e4c66e40292", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-165"}, "properties": {"repobilityId": "b64c55d03c3ba0ce", "scanner": "scanner-primary", "fingerprint": "16760e4c66e40292", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-165"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8e73b43b75c29597", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2249"}, "properties": {"repobilityId": "af5a12d91eedfb16", "scanner": "scanner-primary", "fingerprint": "8e73b43b75c29597", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2249"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-91a93e5a23ea08cc", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2250"}, "properties": {"repobilityId": "be2416ea1dd81bdc", "scanner": "scanner-primary", "fingerprint": "91a93e5a23ea08cc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2250"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c1ecf5f517461864", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2251"}, "properties": {"repobilityId": "ce1d5485e8f39d80", "scanner": "scanner-primary", "fingerprint": "c1ecf5f517461864", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2251"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4bd6ba707ac37bdf", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2252"}, "properties": {"repobilityId": "c6734b56686bbb37", "scanner": "scanner-primary", "fingerprint": "4bd6ba707ac37bdf", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2252"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f1351b1199df497a", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2253"}, "properties": {"repobilityId": "db6caf300d11972c", "scanner": "scanner-primary", "fingerprint": "f1351b1199df497a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2253"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ead160560383bfdf", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2254"}, "properties": {"repobilityId": "585547a7009e7c84", "scanner": "scanner-primary", "fingerprint": "ead160560383bfdf", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2254"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c7849566ca5a8a9e", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2256"}, "properties": {"repobilityId": "f9ae5363f8cb60bf", "scanner": "scanner-primary", "fingerprint": "c7849566ca5a8a9e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2256"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-57bfb857705a69d8", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-2874"}, "properties": {"repobilityId": "3a901502a8adb2db", "scanner": "scanner-primary", "fingerprint": "57bfb857705a69d8", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2874"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d920c3e11f2bdd6e", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3451"}, "properties": {"repobilityId": "72bc850ed603654a", "scanner": "scanner-primary", "fingerprint": "d920c3e11f2bdd6e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3451"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d3d766fe6e93a4f5", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3453"}, "properties": {"repobilityId": "ecab11f9e20a5695", "scanner": "scanner-primary", "fingerprint": "d3d766fe6e93a4f5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3453"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5ff0e56be1f88c20", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3454"}, "properties": {"repobilityId": "dee462005fb8fa46", "scanner": "scanner-primary", "fingerprint": "5ff0e56be1f88c20", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3454"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-682a95eb0d8f6b38", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3493"}, "properties": {"repobilityId": "687f042dfb397ab7", "scanner": "scanner-primary", "fingerprint": "682a95eb0d8f6b38", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3493"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6a86eed20037af58", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3494"}, "properties": {"repobilityId": "8beeb6256a1bef59", "scanner": "scanner-primary", "fingerprint": "6a86eed20037af58", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3494"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-59769f6ba6a2c0d7", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3495"}, "properties": {"repobilityId": "ed4b39d6f4e8a40f", "scanner": "scanner-primary", "fingerprint": "59769f6ba6a2c0d7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3495"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d3d17d25ca78f555", "level": "warning", "message": {"text": "Vulnerable dependency pillow 11.2.1: PYSEC-2026-3496"}, "properties": {"repobilityId": "4ab05c0c73a5f39e", "scanner": "scanner-primary", "fingerprint": "d3d17d25ca78f555", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3496"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3af9e92b16066e21", "level": "warning", "message": {"text": "Vulnerable dependency requests 2.32.4: GHSA-gc5v-m9x4-r6x2"}, "properties": {"repobilityId": "ab2c29034019e1a6", "scanner": "scanner-primary", "fingerprint": "3af9e92b16066e21", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gc5v-m9x4-r6x2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c88ead0f3169aa49", "level": "warning", "message": {"text": "Vulnerable dependency requests 2.32.4: PYSEC-2026-2275"}, "properties": {"repobilityId": "c96dd9b9c139aaf0", "scanner": "scanner-primary", "fingerprint": "c88ead0f3169aa49", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2275"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9a65bf71395b1a8f", "level": "warning", "message": {"text": "Vulnerable dependency setuptools 80.9.0: GHSA-h35f-9h28-mq5c"}, "properties": {"repobilityId": "14f64c68863e4b70", "scanner": "scanner-primary", "fingerprint": "9a65bf71395b1a8f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h35f-9h28-mq5c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f7ce7d7a5fe8eddf", "level": "warning", "message": {"text": "Vulnerable dependency setuptools 80.9.0: PYSEC-2026-3447"}, "properties": {"repobilityId": "71c9d8c0d47dedd0", "scanner": "scanner-primary", "fingerprint": "f7ce7d7a5fe8eddf", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3447"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0929ca37e9f00f4c", "level": "warning", "message": {"text": "Vulnerable dependency soupsieve 2.7: GHSA-2wc2-fm75-p42x"}, "properties": {"repobilityId": "5d58f8cc4a6a5513", "scanner": "scanner-primary", "fingerprint": "0929ca37e9f00f4c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2wc2-fm75-p42x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f81e453504c55172", "level": "warning", "message": {"text": "Vulnerable dependency soupsieve 2.7: GHSA-836r-79rf-4m37"}, "properties": {"repobilityId": "db516a3b8760cfd2", "scanner": "scanner-primary", "fingerprint": "f81e453504c55172", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-836r-79rf-4m37"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-169d8af1521568f9", "level": "warning", "message": {"text": "Vulnerable dependency soupsieve 2.7: PYSEC-2026-3071"}, "properties": {"repobilityId": "21bdb057ef7ba921", "scanner": "scanner-primary", "fingerprint": "169d8af1521568f9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3071"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7f27d27bfda0d727", "level": "warning", "message": {"text": "Vulnerable dependency soupsieve 2.7: PYSEC-2026-3072"}, "properties": {"repobilityId": "baf25bce6d464bfc", "scanner": "scanner-primary", "fingerprint": "7f27d27bfda0d727", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3072"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6d41d19b5d84477a", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-267c-6grr-h53f"}, "properties": {"repobilityId": "3708940b2ab3dc6b", "scanner": "scanner-primary", "fingerprint": "6d41d19b5d84477a", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-267c-6grr-h53f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-228dd5f4bf333b1b", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-26hh-7cqf-hhc6"}, "properties": {"repobilityId": "a53da63fa7d784b7", "scanner": "scanner-primary", "fingerprint": "228dd5f4bf333b1b", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-26hh-7cqf-hhc6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fb47c794fababcf8", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-36qx-fr4f-26g5"}, "properties": {"repobilityId": "fc7744c20ea98806", "scanner": "scanner-primary", "fingerprint": "fb47c794fababcf8", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-36qx-fr4f-26g5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-db84db354100f56e", "level": "note", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-3g8h-86w9-wvmq"}, "properties": {"repobilityId": "900b57d9c1f7e194", "scanner": "scanner-primary", "fingerprint": "db84db354100f56e", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3g8h-86w9-wvmq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6a8dbe98018cafcb", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-3x4c-7xq6-9pq8"}, "properties": {"repobilityId": "51628ef0b365e46b", "scanner": "scanner-primary", "fingerprint": "6a8dbe98018cafcb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3x4c-7xq6-9pq8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b12b9ec92f643a6f", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-4633-3j49-mh5q"}, "properties": {"repobilityId": "2d649e5e57ff6cb6", "scanner": "scanner-primary", "fingerprint": "b12b9ec92f643a6f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4633-3j49-mh5q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa7763ceec966d7a", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-492v-c6pp-mqqv"}, "properties": {"repobilityId": "d24a0fa912d1e04a", "scanner": "scanner-primary", "fingerprint": "aa7763ceec966d7a", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-492v-c6pp-mqqv"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bddc434f7015e935", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-4c39-4ccg-62r3"}, "properties": {"repobilityId": "662a81a94e3a7ebc", "scanner": "scanner-primary", "fingerprint": "bddc434f7015e935", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4c39-4ccg-62r3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2e70c96eac0d8d70", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-68g3-v927-f742"}, "properties": {"repobilityId": "b5e7b2382a50577a", "scanner": "scanner-primary", "fingerprint": "2e70c96eac0d8d70", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-68g3-v927-f742"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-36b1c43e99b7367b", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-6gpp-xcg3-4w24"}, "properties": {"repobilityId": "d15316045a9b03b6", "scanner": "scanner-primary", "fingerprint": "36b1c43e99b7367b", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6gpp-xcg3-4w24"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e27ef00f1ca3aee6", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-89xv-2m56-2m9x"}, "properties": {"repobilityId": "8cbacec70b7c7195", "scanner": "scanner-primary", "fingerprint": "e27ef00f1ca3aee6", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-89xv-2m56-2m9x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6acfbfe7dcc12698", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-8h8q-6873-q5fj"}, "properties": {"repobilityId": "c61a0c071ac39d53", "scanner": "scanner-primary", "fingerprint": "6acfbfe7dcc12698", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8h8q-6873-q5fj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5fb0f0f841969b5b", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-955p-x3mx-jcvp"}, "properties": {"repobilityId": "fb8419cc43ac3ba6", "scanner": "scanner-primary", "fingerprint": "5fb0f0f841969b5b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-955p-x3mx-jcvp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1643400d94fdae48", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-c4j6-fc7j-m34r"}, "properties": {"repobilityId": "74cdb5616b49a582", "scanner": "scanner-primary", "fingerprint": "1643400d94fdae48", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-c4j6-fc7j-m34r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7633ef9eeb7a0c32", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-ffhc-5mcf-pf4q"}, "properties": {"repobilityId": "0b3cf6bf4e7a0b02", "scanner": "scanner-primary", "fingerprint": "7633ef9eeb7a0c32", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ffhc-5mcf-pf4q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7a0a0d196bc2644f", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-ggv3-7p47-pfv8"}, "properties": {"repobilityId": "81cbbad60d5fbd4a", "scanner": "scanner-primary", "fingerprint": "7a0a0d196bc2644f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ggv3-7p47-pfv8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5d14c80dfcde339e", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-gx5p-jg67-6x7h"}, "properties": {"repobilityId": "02432a4df744c996", "scanner": "scanner-primary", "fingerprint": "5d14c80dfcde339e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gx5p-jg67-6x7h"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ecf38c6075b76510", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-h27x-g6w4-24gq"}, "properties": {"repobilityId": "f51bacfba1218354", "scanner": "scanner-primary", "fingerprint": "ecf38c6075b76510", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h27x-g6w4-24gq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-21fc2c80639cc84e", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-h64f-5h5j-jqjh"}, "properties": {"repobilityId": "19955fe845c7cfb2", "scanner": "scanner-primary", "fingerprint": "21fc2c80639cc84e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h64f-5h5j-jqjh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-22694e26fad606a0", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-jcc7-9wpm-mj36"}, "properties": {"repobilityId": "0df15800dc50f97d", "scanner": "scanner-primary", "fingerprint": "22694e26fad606a0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jcc7-9wpm-mj36"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-12024fcd1d5adec4", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-m99w-x7hq-7vfj"}, "properties": {"repobilityId": "a3fc9a2bbb41bf1c", "scanner": "scanner-primary", "fingerprint": "12024fcd1d5adec4", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m99w-x7hq-7vfj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-212c62b5914af9eb", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-mg66-mrh9-m8jx"}, "properties": {"repobilityId": "8b4a1aafdda0467a", "scanner": "scanner-primary", "fingerprint": "212c62b5914af9eb", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mg66-mrh9-m8jx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-10ecaa4f345f6c72", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-mq59-m269-xvcx"}, "properties": {"repobilityId": "d3eccf0a013f6e9d", "scanner": "scanner-primary", "fingerprint": "10ecaa4f345f6c72", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mq59-m269-xvcx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5bd47020777fd274", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-p9j2-gv94-2wf4"}, "properties": {"repobilityId": "423677b66ed8f9f0", "scanner": "scanner-primary", "fingerprint": "5bd47020777fd274", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p9j2-gv94-2wf4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7cc488b141ba38ac", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-q4gf-8mx6-v5v3"}, "properties": {"repobilityId": "66e931275063f8bd", "scanner": "scanner-primary", "fingerprint": "7cc488b141ba38ac", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q4gf-8mx6-v5v3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6c90b619f8950a47", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-q8wf-6r8g-63ch"}, "properties": {"repobilityId": "7a28661a22c099a4", "scanner": "scanner-primary", "fingerprint": "6c90b619f8950a47", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q8wf-6r8g-63ch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a656a4f52ae8cdc2", "level": "note", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-vfv6-92ff-j949"}, "properties": {"repobilityId": "65c727db5ce72555", "scanner": "scanner-primary", "fingerprint": "a656a4f52ae8cdc2", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vfv6-92ff-j949"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b857a474fc56e115", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-wfc6-r584-vfw7"}, "properties": {"repobilityId": "edc5a9e8364ab838", "scanner": "scanner-primary", "fingerprint": "b857a474fc56e115", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wfc6-r584-vfw7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9f0ba69a8769a605", "level": "error", "message": {"text": "Vulnerable dependency postcss 8.5.8: GHSA-6g55-p6wh-862q"}, "properties": {"repobilityId": "f8e5c9580aa38973", "scanner": "scanner-primary", "fingerprint": "9f0ba69a8769a605", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-6g55-p6wh-862q", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d0332d5e3c05fd58", "level": "warning", "message": {"text": "Vulnerable dependency postcss 8.5.8: GHSA-qx2v-qp2m-jg93"}, "properties": {"repobilityId": "cd077b2d3b1cc33b", "scanner": "scanner-primary", "fingerprint": "d0332d5e3c05fd58", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-qx2v-qp2m-jg93", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-08f2e05e22ce335a", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-35jp-ww65-95wh"}, "properties": {"repobilityId": "05f2c27356b53c92", "scanner": "scanner-primary", "fingerprint": "08f2e05e22ce335a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-35jp-ww65-95wh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-814d66d9828c04e2", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-3g43-6gmg-66jw"}, "properties": {"repobilityId": "60ef9102db829667", "scanner": "scanner-primary", "fingerprint": "814d66d9828c04e2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3g43-6gmg-66jw"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-009520a68cce8704", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-3p68-rc4w-qgx5"}, "properties": {"repobilityId": "7c6bdd6bda64d373", "scanner": "scanner-primary", "fingerprint": "009520a68cce8704", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3p68-rc4w-qgx5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9c2af18b7ae2af4c", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-3w6x-2g7m-8v23"}, "properties": {"repobilityId": "4de336915660ef60", "scanner": "scanner-primary", "fingerprint": "9c2af18b7ae2af4c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3w6x-2g7m-8v23"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f7bbea57b4997075", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-42h9-826w-cgv3"}, "properties": {"repobilityId": "594f2c19a1a0758a", "scanner": "scanner-primary", "fingerprint": "f7bbea57b4997075", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-42h9-826w-cgv3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b67dd38387904a47", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-43fc-jf86-j433"}, "properties": {"repobilityId": "2127042c6af9e617", "scanner": "scanner-primary", "fingerprint": "b67dd38387904a47", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-43fc-jf86-j433"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ee8a1ff2ca8cf6fc", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-445q-vr5w-6q77"}, "properties": {"repobilityId": "1adaf4a1e4c24b29", "scanner": "scanner-primary", "fingerprint": "ee8a1ff2ca8cf6fc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-445q-vr5w-6q77"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2db2cd3055a4a2f4", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-4hjh-wcwx-xvwj"}, "properties": {"repobilityId": "791220207e0747d2", "scanner": "scanner-primary", "fingerprint": "2db2cd3055a4a2f4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4hjh-wcwx-xvwj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a039c0af076a3735", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-5c9x-8gcm-mpgx"}, "properties": {"repobilityId": "ba0cc4407c8fdad8", "scanner": "scanner-primary", "fingerprint": "a039c0af076a3735", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-5c9x-8gcm-mpgx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-727cc8c4f75187a6", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-62hf-57xw-28j9"}, "properties": {"repobilityId": "4d636f351e8e9558", "scanner": "scanner-primary", "fingerprint": "727cc8c4f75187a6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-62hf-57xw-28j9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c46b95e5477d197e", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-6chq-wfr3-2hj9"}, "properties": {"repobilityId": "ed38c4c3cfaebe6d", "scanner": "scanner-primary", "fingerprint": "c46b95e5477d197e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6chq-wfr3-2hj9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-979e3ad812a60b83", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-777c-7fjr-54vf"}, "properties": {"repobilityId": "3c3eddbb33a00747", "scanner": "scanner-primary", "fingerprint": "979e3ad812a60b83", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-777c-7fjr-54vf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1a1634914cd42338", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-7q8q-rj6j-mhjq"}, "properties": {"repobilityId": "7b3318693c04113f", "scanner": "scanner-primary", "fingerprint": "1a1634914cd42338", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-7q8q-rj6j-mhjq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-78a436ac5b83b90b", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-898c-q2cr-xwhg"}, "properties": {"repobilityId": "e8ad8afe64ec82b1", "scanner": "scanner-primary", "fingerprint": "78a436ac5b83b90b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-898c-q2cr-xwhg"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-77088e97ede35190", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-fvcv-3m26-pcqx"}, "properties": {"repobilityId": "5b066ced2a6105d4", "scanner": "scanner-primary", "fingerprint": "77088e97ede35190", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-fvcv-3m26-pcqx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3dcf07308fdb2db9", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-hfxv-24rg-xrqf"}, "properties": {"repobilityId": "c3d82b38adfd9043", "scanner": "scanner-primary", "fingerprint": "3dcf07308fdb2db9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hfxv-24rg-xrqf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0c8ff34925117e3b", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-j5f8-grm9-p9fc"}, "properties": {"repobilityId": "0e203b7f595de8ab", "scanner": "scanner-primary", "fingerprint": "0c8ff34925117e3b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-j5f8-grm9-p9fc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9316dbce0158f716", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-jqh4-m9w3-8hp9"}, "properties": {"repobilityId": "78945630b27575e7", "scanner": "scanner-primary", "fingerprint": "9316dbce0158f716", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jqh4-m9w3-8hp9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-481559b4320de4e5", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-m7pr-hjqh-92cm"}, "properties": {"repobilityId": "adf4c342277974c5", "scanner": "scanner-primary", "fingerprint": "481559b4320de4e5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m7pr-hjqh-92cm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-65bc0a2f855dd091", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-mmx7-hfxf-jppx"}, "properties": {"repobilityId": "ee6a3c132fc91ed4", "scanner": "scanner-primary", "fingerprint": "65bc0a2f855dd091", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mmx7-hfxf-jppx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-eb1106c0a41f4c26", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-p92q-9vqr-4j8v"}, "properties": {"repobilityId": "8dea82a798e20f76", "scanner": "scanner-primary", "fingerprint": "eb1106c0a41f4c26", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p92q-9vqr-4j8v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-61ee42081c14aaca", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-pf86-5x62-jrwf"}, "properties": {"repobilityId": "003097528769892c", "scanner": "scanner-primary", "fingerprint": "61ee42081c14aaca", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pf86-5x62-jrwf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-02f049c4cda80be7", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-pmv8-rq9r-6j72"}, "properties": {"repobilityId": "d910a7245be25c22", "scanner": "scanner-primary", "fingerprint": "02f049c4cda80be7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pmv8-rq9r-6j72"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e21c6a708b8f31bc", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-pmwg-cvhr-8vh7"}, "properties": {"repobilityId": "bfeb5254db199991", "scanner": "scanner-primary", "fingerprint": "e21c6a708b8f31bc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pmwg-cvhr-8vh7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-40c06b29d7b10796", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-q8qp-cvcw-x6jj"}, "properties": {"repobilityId": "ce9944b77f85c09d", "scanner": "scanner-primary", "fingerprint": "40c06b29d7b10796", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q8qp-cvcw-x6jj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-beed1dee6387c1bc", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-vf2m-468p-8v99"}, "properties": {"repobilityId": "bb0fa118bfb7ca20", "scanner": "scanner-primary", "fingerprint": "beed1dee6387c1bc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vf2m-468p-8v99"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2ba5d37e9ebb7ead", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-w9j2-pvgh-6h63"}, "properties": {"repobilityId": "7523c5fbc29fb65d", "scanner": "scanner-primary", "fingerprint": "2ba5d37e9ebb7ead", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w9j2-pvgh-6h63"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-147489be53febd4a", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-xhjh-pmcv-23jw"}, "properties": {"repobilityId": "fcb81ff2279573ce", "scanner": "scanner-primary", "fingerprint": "147489be53febd4a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xhjh-pmcv-23jw"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-10d203c8f2340363", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.11.0: GHSA-xx6v-rp6x-q39c"}, "properties": {"repobilityId": "5cd78980ffad60ca", "scanner": "scanner-primary", "fingerprint": "10d203c8f2340363", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xx6v-rp6x-q39c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cf338cf76f24b16e", "level": "warning", "message": {"text": "Vulnerable dependency electron 37.2.6: GHSA-3c8v-cfp5-9885"}, "properties": {"repobilityId": "84c5a37efd80223f", "scanner": "scanner-primary", "fingerprint": "cf338cf76f24b16e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3c8v-cfp5-9885"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7b922335d976f42d", "level": "warning", "message": {"text": "Vulnerable dependency electron 37.2.6: GHSA-4p4r-m79c-wq3v"}, "properties": {"repobilityId": "421082690c0f597c", "scanner": "scanner-primary", "fingerprint": "7b922335d976f42d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4p4r-m79c-wq3v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-05845fc98881bc91", "level": "warning", "message": {"text": "Vulnerable dependency electron 37.2.6: GHSA-532v-xpq5-8h95"}, "properties": {"repobilityId": "a3f180974f738546", "scanner": "scanner-primary", "fingerprint": "05845fc98881bc91", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-532v-xpq5-8h95"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-72d3dc0676c330f9", "level": "warning", "message": {"text": "Vulnerable dependency electron 37.2.6: GHSA-5rqw-r77c-jp79"}, "properties": {"repobilityId": "1b4a86c66d809158", "scanner": "scanner-primary", "fingerprint": "72d3dc0676c330f9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-5rqw-r77c-jp79"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ed6e709c4ef2db22", "level": "warning", "message": {"text": "Vulnerable dependency electron 37.2.6: GHSA-8337-3p73-46f4"}, "properties": {"repobilityId": "5518c84b1e4fe785", "scanner": "scanner-primary", "fingerprint": "ed6e709c4ef2db22", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8337-3p73-46f4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fcccb2bf78bb2654", "level": "warning", "message": {"text": "Vulnerable dependency electron 37.2.6: GHSA-8x5q-pvf5-64mp"}, "properties": {"repobilityId": "dee5cebe771dca21", "scanner": "scanner-primary", "fingerprint": "fcccb2bf78bb2654", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8x5q-pvf5-64mp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5dcca1137d36e6e2", "level": "warning", "message": {"text": "Vulnerable dependency electron 37.2.6: GHSA-9899-m83m-qhpj"}, "properties": {"repobilityId": "c11ec44cc6fe0f53", "scanner": "scanner-primary", "fingerprint": "5dcca1137d36e6e2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9899-m83m-qhpj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ef164b37ae427f0", "level": "warning", "message": {"text": "Vulnerable dependency electron 37.2.6: GHSA-9w97-2464-8783"}, "properties": {"repobilityId": "8fe1ae7e98cd72e0", "scanner": "scanner-primary", "fingerprint": "3ef164b37ae427f0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9w97-2464-8783"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9445fb1dda7e7af6", "level": "warning", "message": {"text": "Vulnerable dependency electron 37.2.6: GHSA-9wfr-w7mm-pc7f"}, "properties": {"repobilityId": "e39a9d3ab8531da6", "scanner": "scanner-primary", "fingerprint": "9445fb1dda7e7af6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9wfr-w7mm-pc7f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a001199030d427fb", "level": "warning", "message": {"text": "Vulnerable dependency electron 37.2.6: GHSA-f37v-82c4-4x64"}, "properties": {"repobilityId": "7a8f636a65d215f6", "scanner": "scanner-primary", "fingerprint": "a001199030d427fb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-f37v-82c4-4x64"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fbf30e166decc37a", "level": "warning", "message": {"text": "Vulnerable dependency electron 37.2.6: GHSA-f3pv-wv63-48x8"}, "properties": {"repobilityId": "aaf9b8f567b80c32", "scanner": "scanner-primary", "fingerprint": "fbf30e166decc37a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-f3pv-wv63-48x8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa6674f9c21315da", "level": "warning", "message": {"text": "Vulnerable dependency electron 37.2.6: GHSA-jfqx-fxh3-c62j"}, "properties": {"repobilityId": "9e87db2ae065fcbc", "scanner": "scanner-primary", "fingerprint": "aa6674f9c21315da", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jfqx-fxh3-c62j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6e1c503e26bf4c7d", "level": "warning", "message": {"text": "Vulnerable dependency electron 37.2.6: GHSA-jjp3-mq3x-295m"}, "properties": {"repobilityId": "53c7edcdd487093c", "scanner": "scanner-primary", "fingerprint": "6e1c503e26bf4c7d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jjp3-mq3x-295m"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9223eb674152033d", "level": "warning", "message": {"text": "Vulnerable dependency electron 37.2.6: GHSA-mwmh-mq4g-g6gr"}, "properties": {"repobilityId": "ec9d815900a6b12b", "scanner": "scanner-primary", "fingerprint": "9223eb674152033d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mwmh-mq4g-g6gr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b30c98cbe425cd39", "level": "warning", "message": {"text": "Vulnerable dependency electron 37.2.6: GHSA-r5p7-gp4j-qhrx"}, "properties": {"repobilityId": "4a02286177453c64", "scanner": "scanner-primary", "fingerprint": "b30c98cbe425cd39", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-r5p7-gp4j-qhrx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f82610ea891284b2", "level": "warning", "message": {"text": "Vulnerable dependency electron 37.2.6: GHSA-vmqv-hx8q-j7mg"}, "properties": {"repobilityId": "db6ad953a071b4b1", "scanner": "scanner-primary", "fingerprint": "f82610ea891284b2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vmqv-hx8q-j7mg"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-667d4d0061362efe", "level": "warning", "message": {"text": "Vulnerable dependency electron 37.2.6: GHSA-xj5x-m3f3-5x3h"}, "properties": {"repobilityId": "7180b79fbdb2cc01", "scanner": "scanner-primary", "fingerprint": "667d4d0061362efe", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xj5x-m3f3-5x3h"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fd8aae660189773f", "level": "warning", "message": {"text": "Vulnerable dependency electron 37.2.6: GHSA-xwr5-m59h-vwqr"}, "properties": {"repobilityId": "6c6cb66a09ef6244", "scanner": "scanner-primary", "fingerprint": "fd8aae660189773f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xwr5-m59h-vwqr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-484b4abf758a1ed3", "level": "warning", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-23hp-3jrh-7fpw"}, "properties": {"repobilityId": "2b31f5b015f63b19", "scanner": "scanner-primary", "fingerprint": "484b4abf758a1ed3", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-23hp-3jrh-7fpw", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ae463d5502621523", "level": "warning", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-34x7-hfp2-rc4v"}, "properties": {"repobilityId": "6278a266c23d1504", "scanner": "scanner-primary", "fingerprint": "ae463d5502621523", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-34x7-hfp2-rc4v", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a080bbceacea5120", "level": "warning", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-83g3-92jg-28cx"}, "properties": {"repobilityId": "de5b704a7f8378d1", "scanner": "scanner-primary", "fingerprint": "a080bbceacea5120", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-83g3-92jg-28cx", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d4b5b3167bbd41b3", "level": "warning", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-8qq5-rm4j-mr97"}, "properties": {"repobilityId": "f87ce42440b8ea48", "scanner": "scanner-primary", "fingerprint": "d4b5b3167bbd41b3", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-8qq5-rm4j-mr97", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ba49b5fdb33775e0", "level": "warning", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-8x88-c5mf-7j5w"}, "properties": {"repobilityId": "a97460913e322b17", "scanner": "scanner-primary", "fingerprint": "ba49b5fdb33775e0", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-8x88-c5mf-7j5w", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4b87004a76c96813", "level": "warning", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-9ppj-qmqm-q256"}, "properties": {"repobilityId": "ba7848efc0447c3d", "scanner": "scanner-primary", "fingerprint": "4b87004a76c96813", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-9ppj-qmqm-q256", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fa0048609ee5f671", "level": "warning", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-gvwx-54wh-qm9j"}, "properties": {"repobilityId": "af4ef3e7bc207515", "scanner": "scanner-primary", "fingerprint": "fa0048609ee5f671", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-gvwx-54wh-qm9j", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-79efca9486942718", "level": "warning", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-qffp-2rhf-9h96"}, "properties": {"repobilityId": "2cc0d011c816508c", "scanner": "scanner-primary", "fingerprint": "79efca9486942718", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-qffp-2rhf-9h96", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a87c61d1deaea113", "level": "warning", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-r6q2-hw4h-h46w"}, "properties": {"repobilityId": "9d2e042e0c9a08f0", "scanner": "scanner-primary", "fingerprint": "a87c61d1deaea113", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-r6q2-hw4h-h46w", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-205ec9c81e3c2f29", "level": "warning", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-vmf3-w455-68vh"}, "properties": {"repobilityId": "120517fd80ea2fcd", "scanner": "scanner-primary", "fingerprint": "205ec9c81e3c2f29", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-vmf3-w455-68vh", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-84c5084dfe1cc645", "level": "warning", "message": {"text": "Vulnerable dependency tar 6.2.1: GHSA-w8wr-v893-vjvp"}, "properties": {"repobilityId": "7b9b54b883d7996a", "scanner": "scanner-primary", "fingerprint": "84c5084dfe1cc645", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-w8wr-v893-vjvp", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "advanced_llm_apps/thinkpath_chatbot_app/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-259e1b236aedc2e2", "level": "warning", "message": {"text": "Vulnerable dependency diff 7.0.0: GHSA-73rr-hh4g-fpgx"}, "properties": {"repobilityId": "e3bbea3c8c4d9b9c", "scanner": "scanner-primary", "fingerprint": "259e1b236aedc2e2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-73rr-hh4g-fpgx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ec6e06b5a2bb6dca", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-267c-6grr-h53f"}, "properties": {"repobilityId": "c62d89fc55e81804", "scanner": "scanner-primary", "fingerprint": "ec6e06b5a2bb6dca", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-267c-6grr-h53f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2e37d7b45eeccb19", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-26hh-7cqf-hhc6"}, "properties": {"repobilityId": "a36fc6767e02c7e2", "scanner": "scanner-primary", "fingerprint": "2e37d7b45eeccb19", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-26hh-7cqf-hhc6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-07c2e77581cf82eb", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-36qx-fr4f-26g5"}, "properties": {"repobilityId": "e160426ce5bb58d2", "scanner": "scanner-primary", "fingerprint": "07c2e77581cf82eb", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-36qx-fr4f-26g5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dccf6217737c52d3", "level": "note", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-3g8h-86w9-wvmq"}, "properties": {"repobilityId": "364ad432b68a1549", "scanner": "scanner-primary", "fingerprint": "dccf6217737c52d3", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3g8h-86w9-wvmq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d8d9b315e2d99de8", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-4633-3j49-mh5q"}, "properties": {"repobilityId": "aa44341e01e788c9", "scanner": "scanner-primary", "fingerprint": "d8d9b315e2d99de8", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4633-3j49-mh5q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4c1fcf92142bf910", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-492v-c6pp-mqqv"}, "properties": {"repobilityId": "7486e3dedc02354b", "scanner": "scanner-primary", "fingerprint": "4c1fcf92142bf910", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-492v-c6pp-mqqv"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1fe0ff76651e32c2", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-4c39-4ccg-62r3"}, "properties": {"repobilityId": "d0c4bf38467dd080", "scanner": "scanner-primary", "fingerprint": "1fe0ff76651e32c2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4c39-4ccg-62r3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b41c312612d72b3c", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-68g3-v927-f742"}, "properties": {"repobilityId": "c967067e6e8f820e", "scanner": "scanner-primary", "fingerprint": "b41c312612d72b3c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-68g3-v927-f742"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-397895e88fab637b", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-89xv-2m56-2m9x"}, "properties": {"repobilityId": "eb0b244d64d831a1", "scanner": "scanner-primary", "fingerprint": "397895e88fab637b", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-89xv-2m56-2m9x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa4d5644b78da3f6", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-8h8q-6873-q5fj"}, "properties": {"repobilityId": "12026a7084cef59a", "scanner": "scanner-primary", "fingerprint": "aa4d5644b78da3f6", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8h8q-6873-q5fj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-45d1a5030ad52858", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-955p-x3mx-jcvp"}, "properties": {"repobilityId": "0b9f22b7120c6c49", "scanner": "scanner-primary", "fingerprint": "45d1a5030ad52858", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-955p-x3mx-jcvp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dfec36d14bdd6cf5", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-c4j6-fc7j-m34r"}, "properties": {"repobilityId": "10cdecbfe44c0747", "scanner": "scanner-primary", "fingerprint": "dfec36d14bdd6cf5", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-c4j6-fc7j-m34r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e7b3644dbac20632", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-ffhc-5mcf-pf4q"}, "properties": {"repobilityId": "4aa5e16ee8f47b75", "scanner": "scanner-primary", "fingerprint": "e7b3644dbac20632", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ffhc-5mcf-pf4q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8542f6b49da8ca39", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-gx5p-jg67-6x7h"}, "properties": {"repobilityId": "fc13f37681db476d", "scanner": "scanner-primary", "fingerprint": "8542f6b49da8ca39", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gx5p-jg67-6x7h"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c4cecc82edb7e0b7", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-h64f-5h5j-jqjh"}, "properties": {"repobilityId": "5ff307fb322ec079", "scanner": "scanner-primary", "fingerprint": "c4cecc82edb7e0b7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h64f-5h5j-jqjh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4e1f7bd2146ab61e", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-m99w-x7hq-7vfj"}, "properties": {"repobilityId": "51be6b36cf0fcd50", "scanner": "scanner-primary", "fingerprint": "4e1f7bd2146ab61e", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m99w-x7hq-7vfj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9ba598575c89d0aa", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-mg66-mrh9-m8jx"}, "properties": {"repobilityId": "1d2c603a78893960", "scanner": "scanner-primary", "fingerprint": "9ba598575c89d0aa", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mg66-mrh9-m8jx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-03de3249db0bc70e", "level": "error", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-p9j2-gv94-2wf4"}, "properties": {"repobilityId": "dfc87099954df84e", "scanner": "scanner-primary", "fingerprint": "03de3249db0bc70e", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p9j2-gv94-2wf4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-436157ebeb5eff82", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-q8wf-6r8g-63ch"}, "properties": {"repobilityId": "6698cca92f36c06a", "scanner": "scanner-primary", "fingerprint": "436157ebeb5eff82", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q8wf-6r8g-63ch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-456aeb6bc5b13608", "level": "note", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-vfv6-92ff-j949"}, "properties": {"repobilityId": "915ad4eff93cec6d", "scanner": "scanner-primary", "fingerprint": "456aeb6bc5b13608", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vfv6-92ff-j949"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f876bfd6ecd99389", "level": "warning", "message": {"text": "Vulnerable dependency next 15.5.15: GHSA-wfc6-r584-vfw7"}, "properties": {"repobilityId": "6a713b7c9a8198dd", "scanner": "scanner-primary", "fingerprint": "f876bfd6ecd99389", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wfc6-r584-vfw7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent_skills/self-improving-agent-skills/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6de55bf6b59e6511", "level": "warning", "message": {"text": "Vulnerable dependency @hono/node-server 1.19.14: GHSA-frvp-7c67-39w9"}, "properties": {"repobilityId": "e20a828d2748b708", "scanner": "scanner-primary", "fingerprint": "6de55bf6b59e6511", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-frvp-7c67-39w9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ad8cae985e6d5f59", "level": "warning", "message": {"text": "Vulnerable dependency diff 5.2.0: GHSA-73rr-hh4g-fpgx"}, "properties": {"repobilityId": "6df2fd82149f67bd", "scanner": "scanner-primary", "fingerprint": "ad8cae985e6d5f59", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-73rr-hh4g-fpgx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5abf71efbf6ffec5", "level": "error", "message": {"text": "Vulnerable dependency hono 4.12.23: GHSA-88fw-hqm2-52qc"}, "properties": {"repobilityId": "9b27f6238e0a499c", "scanner": "scanner-primary", "fingerprint": "5abf71efbf6ffec5", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-88fw-hqm2-52qc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/mcp-apps-generative-ui-showcase/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d71dade93d23d920", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.23: GHSA-hvrm-45r6-mjfj"}, "properties": {"repobilityId": "3344643289ee1878", "scanner": "scanner-primary", "fingerprint": "d71dade93d23d920", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hvrm-45r6-mjfj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/mcp-apps-generative-ui-showcase/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1484299770f3d114", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.23: GHSA-j6c9-x7qj-28xf"}, "properties": {"repobilityId": "20028bec3be440f5", "scanner": "scanner-primary", "fingerprint": "1484299770f3d114", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-j6c9-x7qj-28xf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/mcp-apps-generative-ui-showcase/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c3686711b6b8f4f1", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.23: GHSA-rv63-4mwf-qqc2"}, "properties": {"repobilityId": "87f22ec1ad31440f", "scanner": "scanner-primary", "fingerprint": "c3686711b6b8f4f1", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-rv63-4mwf-qqc2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/mcp-apps-generative-ui-showcase/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5b147445e8285cad", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.23: GHSA-w62v-xxxg-mg59"}, "properties": {"repobilityId": "f7bf490b61a49cf0", "scanner": "scanner-primary", "fingerprint": "5b147445e8285cad", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w62v-xxxg-mg59"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/mcp-apps-generative-ui-showcase/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6af05213761f2a52", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.23: GHSA-wgpf-jwqj-8h8p"}, "properties": {"repobilityId": "143895454b53f13e", "scanner": "scanner-primary", "fingerprint": "6af05213761f2a52", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wgpf-jwqj-8h8p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/mcp-apps-generative-ui-showcase/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8113b565ce825d3e", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.23: GHSA-wwfh-h76j-fc44"}, "properties": {"repobilityId": "99c2ba573be94993", "scanner": "scanner-primary", "fingerprint": "8113b565ce825d3e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wwfh-h76j-fc44"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/mcp-apps-generative-ui-showcase/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c9ef7ab0cc2d7115", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.23: GHSA-xgm2-5f3f-mvvc"}, "properties": {"repobilityId": "2bbc021370e7bf05", "scanner": "scanner-primary", "fingerprint": "c9ef7ab0cc2d7115", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xgm2-5f3f-mvvc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/mcp-apps-generative-ui-showcase/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-25983bfdb03dc630", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-267c-6grr-h53f"}, "properties": {"repobilityId": "e231873e5f141398", "scanner": "scanner-primary", "fingerprint": "25983bfdb03dc630", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-267c-6grr-h53f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4643287facd07c9a", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-26hh-7cqf-hhc6"}, "properties": {"repobilityId": "fe9903935f75c4c8", "scanner": "scanner-primary", "fingerprint": "4643287facd07c9a", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-26hh-7cqf-hhc6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-86595941c3e52307", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-36qx-fr4f-26g5"}, "properties": {"repobilityId": "5e44ddccb82c45f5", "scanner": "scanner-primary", "fingerprint": "86595941c3e52307", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-36qx-fr4f-26g5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-89c13578f103dcb3", "level": "note", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-3g8h-86w9-wvmq"}, "properties": {"repobilityId": "74e8a56508dea462", "scanner": "scanner-primary", "fingerprint": "89c13578f103dcb3", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3g8h-86w9-wvmq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ee3cff0dd5336778", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-3x4c-7xq6-9pq8"}, "properties": {"repobilityId": "0b6c923af0f01dbe", "scanner": "scanner-primary", "fingerprint": "ee3cff0dd5336778", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3x4c-7xq6-9pq8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0ad8097e4830c737", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-4342-x723-ch2f"}, "properties": {"repobilityId": "364f5d95e65a73ed", "scanner": "scanner-primary", "fingerprint": "0ad8097e4830c737", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4342-x723-ch2f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a0acf591b774bcf4", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-4633-3j49-mh5q"}, "properties": {"repobilityId": "28f62023949f9a8e", "scanner": "scanner-primary", "fingerprint": "a0acf591b774bcf4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4633-3j49-mh5q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e7ef30a54ca634be", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-4c39-4ccg-62r3"}, "properties": {"repobilityId": "d1851fcf4c4fe753", "scanner": "scanner-primary", "fingerprint": "e7ef30a54ca634be", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4c39-4ccg-62r3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-40fa9286d5bac9bb", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-68g3-v927-f742"}, "properties": {"repobilityId": "0e232b2c70266d26", "scanner": "scanner-primary", "fingerprint": "40fa9286d5bac9bb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-68g3-v927-f742"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7a793187280e314f", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-89xv-2m56-2m9x"}, "properties": {"repobilityId": "8347078bde6052d1", "scanner": "scanner-primary", "fingerprint": "7a793187280e314f", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-89xv-2m56-2m9x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2c6ceb7c946c512b", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-8h8q-6873-q5fj"}, "properties": {"repobilityId": "bdfe8bc3ca79ac0e", "scanner": "scanner-primary", "fingerprint": "2c6ceb7c946c512b", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8h8q-6873-q5fj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e369fa0a3e8694c6", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-955p-x3mx-jcvp"}, "properties": {"repobilityId": "3e3613a8bd510619", "scanner": "scanner-primary", "fingerprint": "e369fa0a3e8694c6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-955p-x3mx-jcvp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5f93c684bd08aec1", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-9g9p-9gw9-jx7f"}, "properties": {"repobilityId": "75449ee65ff2ff35", "scanner": "scanner-primary", "fingerprint": "5f93c684bd08aec1", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9g9p-9gw9-jx7f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-413499a6eae2a1cf", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-9qr9-h5gf-34mp"}, "properties": {"repobilityId": "39c339dab3f320cc", "scanner": "scanner-primary", "fingerprint": "413499a6eae2a1cf", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9qr9-h5gf-34mp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9a6cd8de9dd1ff92", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-c4j6-fc7j-m34r"}, "properties": {"repobilityId": "8de900d8dc91a1a9", "scanner": "scanner-primary", "fingerprint": "9a6cd8de9dd1ff92", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-c4j6-fc7j-m34r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-356a382fdace0846", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-ffhc-5mcf-pf4q"}, "properties": {"repobilityId": "d4620c478aee8e83", "scanner": "scanner-primary", "fingerprint": "356a382fdace0846", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ffhc-5mcf-pf4q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f5b29dabeb303a21", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-g5qg-72qw-gw5v"}, "properties": {"repobilityId": "9740740c8dd86a4f", "scanner": "scanner-primary", "fingerprint": "f5b29dabeb303a21", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-g5qg-72qw-gw5v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c925a7c6c1bb3db4", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-ggv3-7p47-pfv8"}, "properties": {"repobilityId": "a63a997071202f2d", "scanner": "scanner-primary", "fingerprint": "c925a7c6c1bb3db4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ggv3-7p47-pfv8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ce59df6e344bde19", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-gx5p-jg67-6x7h"}, "properties": {"repobilityId": "d555f0d2b31c5837", "scanner": "scanner-primary", "fingerprint": "ce59df6e344bde19", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gx5p-jg67-6x7h"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f52b3ffd4202b015", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-h25m-26qc-wcjf"}, "properties": {"repobilityId": "b7422998fc50257e", "scanner": "scanner-primary", "fingerprint": "f52b3ffd4202b015", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h25m-26qc-wcjf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-efd6e9382523c7ee", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-h64f-5h5j-jqjh"}, "properties": {"repobilityId": "dbc07b30d2af1723", "scanner": "scanner-primary", "fingerprint": "efd6e9382523c7ee", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h64f-5h5j-jqjh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d079a2ebf88c49c0", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-m99w-x7hq-7vfj"}, "properties": {"repobilityId": "0db7d00488f80299", "scanner": "scanner-primary", "fingerprint": "d079a2ebf88c49c0", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m99w-x7hq-7vfj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-915d7df90dd95828", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-mg66-mrh9-m8jx"}, "properties": {"repobilityId": "8f166a81994f0d9b", "scanner": "scanner-primary", "fingerprint": "915d7df90dd95828", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mg66-mrh9-m8jx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-55a19d3270c227a9", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-mwv6-3258-q52c"}, "properties": {"repobilityId": "7cb67afa171ab835", "scanner": "scanner-primary", "fingerprint": "55a19d3270c227a9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mwv6-3258-q52c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5d58cf137fb608fd", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-p9j2-gv94-2wf4"}, "properties": {"repobilityId": "afb3f61124f957b9", "scanner": "scanner-primary", "fingerprint": "5d58cf137fb608fd", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p9j2-gv94-2wf4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9ad402be7a7bdba1", "level": "error", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-q4gf-8mx6-v5v3"}, "properties": {"repobilityId": "6cf6532149748569", "scanner": "scanner-primary", "fingerprint": "9ad402be7a7bdba1", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q4gf-8mx6-v5v3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ac4f9b871930f97d", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-r2fc-ccr8-96c4"}, "properties": {"repobilityId": "013033e3a82fb738", "scanner": "scanner-primary", "fingerprint": "ac4f9b871930f97d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-r2fc-ccr8-96c4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-750353a4077ee998", "level": "note", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-vfv6-92ff-j949"}, "properties": {"repobilityId": "825bf1b81997fefc", "scanner": "scanner-primary", "fingerprint": "750353a4077ee998", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vfv6-92ff-j949"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b56e0397208d028b", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-w37m-7fhw-fmv9"}, "properties": {"repobilityId": "f7e271bbba36e5f4", "scanner": "scanner-primary", "fingerprint": "b56e0397208d028b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w37m-7fhw-fmv9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-12a6a41cc333fdd0", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-wfc6-r584-vfw7"}, "properties": {"repobilityId": "a18f6eb86b08a202", "scanner": "scanner-primary", "fingerprint": "12a6a41cc333fdd0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wfc6-r584-vfw7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-79e4fa34b1d2c1ab", "level": "warning", "message": {"text": "Vulnerable dependency next 15.3.2: GHSA-xv57-4mr9-wg8v"}, "properties": {"repobilityId": "9d99ace54562f607", "scanner": "scanner-primary", "fingerprint": "79e4fa34b1d2c1ab", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xv57-4mr9-wg8v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f2c05d08eb4007c6", "level": "warning", "message": {"text": "Vulnerable dependency click 8.3.1: PYSEC-2026-2132"}, "properties": {"repobilityId": "346057e715e4d8e2", "scanner": "scanner-primary", "fingerprint": "f2c05d08eb4007c6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2132"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2320582a958fc949", "level": "warning", "message": {"text": "Vulnerable dependency idna 3.11: GHSA-65pc-fj4g-8rjx"}, "properties": {"repobilityId": "fb9a242b2a48123b", "scanner": "scanner-primary", "fingerprint": "2320582a958fc949", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-65pc-fj4g-8rjx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0dbf50da30592d7e", "level": "warning", "message": {"text": "Vulnerable dependency idna 3.11: PYSEC-2026-215"}, "properties": {"repobilityId": "b8ede6cf01a2d587", "scanner": "scanner-primary", "fingerprint": "0dbf50da30592d7e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-215"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5c337cecea05467e", "level": "warning", "message": {"text": "Vulnerable dependency langchain 1.2.7: GHSA-gr75-jv2w-4656"}, "properties": {"repobilityId": "28147b6c1199f5f3", "scanner": "scanner-primary", "fingerprint": "5c337cecea05467e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gr75-jv2w-4656"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-10c5f19c31c89afc", "level": "warning", "message": {"text": "Vulnerable dependency langchain-anthropic 1.3.1: GHSA-gr75-jv2w-4656"}, "properties": {"repobilityId": "f814d0cb723f638f", "scanner": "scanner-primary", "fingerprint": "10c5f19c31c89afc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gr75-jv2w-4656"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-71cfe576975d031e", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 1.2.7: GHSA-2g6r-c272-w58r"}, "properties": {"repobilityId": "e0e2193006c3bfa1", "scanner": "scanner-primary", "fingerprint": "71cfe576975d031e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2g6r-c272-w58r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-050540da2643e9cb", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 1.2.7: GHSA-926x-3r5x-gfhw"}, "properties": {"repobilityId": "d1f046e4e468789a", "scanner": "scanner-primary", "fingerprint": "050540da2643e9cb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-926x-3r5x-gfhw"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d094f6c72f5899a7", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 1.2.7: GHSA-pjwx-r37v-7724"}, "properties": {"repobilityId": "faa23b920ffc0b05", "scanner": "scanner-primary", "fingerprint": "d094f6c72f5899a7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pjwx-r37v-7724"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-62b4c0ba4f336c45", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 1.2.7: GHSA-qh6h-p6c9-ff54"}, "properties": {"repobilityId": "f6c7b95625897fd6", "scanner": "scanner-primary", "fingerprint": "62b4c0ba4f336c45", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-qh6h-p6c9-ff54"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7a25856b17d8f18c", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 1.2.7: PYSEC-2026-2193"}, "properties": {"repobilityId": "2ca7baa32029b8ab", "scanner": "scanner-primary", "fingerprint": "7a25856b17d8f18c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2193"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-579d801a66d6c0c2", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 1.2.7: PYSEC-2026-2562"}, "properties": {"repobilityId": "aed3994f1bcf0abb", "scanner": "scanner-primary", "fingerprint": "579d801a66d6c0c2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2562"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0fe42e0906b76391", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 1.2.7: PYSEC-2026-2563"}, "properties": {"repobilityId": "e3a13ecc9df75cbd", "scanner": "scanner-primary", "fingerprint": "0fe42e0906b76391", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2563"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5737bc2d6fad5a43", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 1.2.7: PYSEC-2026-2564"}, "properties": {"repobilityId": "d5db9145dd416616", "scanner": "scanner-primary", "fingerprint": "5737bc2d6fad5a43", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2564"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c640af3794f656da", "level": "warning", "message": {"text": "Vulnerable dependency langchain-openai 1.1.7: GHSA-r7w7-9xr2-qq2r"}, "properties": {"repobilityId": "38beb2b706544f1e", "scanner": "scanner-primary", "fingerprint": "c640af3794f656da", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-r7w7-9xr2-qq2r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-55126f1d03233dc2", "level": "warning", "message": {"text": "Vulnerable dependency langchain-openai 1.1.7: PYSEC-2026-76"}, "properties": {"repobilityId": "599f8b8f5d54681b", "scanner": "scanner-primary", "fingerprint": "55126f1d03233dc2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-76"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0f48de024d48fad5", "level": "warning", "message": {"text": "Vulnerable dependency langgraph 1.0.7: GHSA-g48c-2wqr-h844"}, "properties": {"repobilityId": "a124cb7f7e9a5ad3", "scanner": "scanner-primary", "fingerprint": "0f48de024d48fad5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-g48c-2wqr-h844"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/agent/pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-781794e3869c37ce", "level": "warning", "message": {"text": "Vulnerable dependency langgraph 1.0.7: PYSEC-2026-83"}, "properties": {"repobilityId": "b52b652e3702baee", "scanner": "scanner-primary", "fingerprint": "781794e3869c37ce", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-83"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/agent/pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-54d06dcfc5fe133d", "level": "error", "message": {"text": "Vulnerable dependency langsmith 0.6.4: GHSA-3644-q5cj-c5c7"}, "properties": {"repobilityId": "43d6f435def0e386", "scanner": "scanner-primary", "fingerprint": "54d06dcfc5fe133d", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3644-q5cj-c5c7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-76f3bac0628979a8", "level": "warning", "message": {"text": "Vulnerable dependency langsmith 0.6.4: GHSA-f4xh-w4cj-qxq8"}, "properties": {"repobilityId": "b50e0b1eaf67bcdc", "scanner": "scanner-primary", "fingerprint": "76f3bac0628979a8", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-f4xh-w4cj-qxq8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aca567edde0ca147", "level": "warning", "message": {"text": "Vulnerable dependency langsmith 0.6.4: GHSA-rr7j-v2q5-chgv"}, "properties": {"repobilityId": "b099daa5059e4b7c", "scanner": "scanner-primary", "fingerprint": "aca567edde0ca147", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-rr7j-v2q5-chgv"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ea32917d705f8bf3", "level": "warning", "message": {"text": "Vulnerable dependency langsmith 0.6.4: PYSEC-2026-2583"}, "properties": {"repobilityId": "eed0190d2458ac9b", "scanner": "scanner-primary", "fingerprint": "ea32917d705f8bf3", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2583"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dfc9e364167fac5e", "level": "warning", "message": {"text": "Vulnerable dependency orjson 3.11.5: GHSA-hx9q-6w63-j58v"}, "properties": {"repobilityId": "259872a723c58df1", "scanner": "scanner-primary", "fingerprint": "dfc9e364167fac5e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hx9q-6w63-j58v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a4e664a075331610", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.2: GHSA-8ppf-4f7h-5ppj"}, "properties": {"repobilityId": "17ebc1e5a8db0c6a", "scanner": "scanner-primary", "fingerprint": "a4e664a075331610", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8ppf-4f7h-5ppj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d3f661eb004a9b93", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.2: GHSA-hm4w-wwcw-mr6r"}, "properties": {"repobilityId": "bdbf2963273d7077", "scanner": "scanner-primary", "fingerprint": "d3f661eb004a9b93", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hm4w-wwcw-mr6r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-de288bf4685518ef", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.2: GHSA-jr27-m4p2-rc6r"}, "properties": {"repobilityId": "9127b41e279073ba", "scanner": "scanner-primary", "fingerprint": "de288bf4685518ef", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jr27-m4p2-rc6r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-52e7d2602bd9b5d2", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.2: PYSEC-2026-2263"}, "properties": {"repobilityId": "7b45d967d1bc8002", "scanner": "scanner-primary", "fingerprint": "52e7d2602bd9b5d2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2263"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-86a2796b63900a1a", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.2: PYSEC-2026-3455"}, "properties": {"repobilityId": "423b2ac2b4c772c8", "scanner": "scanner-primary", "fingerprint": "86a2796b63900a1a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3455"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9c49da643885aa4e", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.2: PYSEC-2026-3456"}, "properties": {"repobilityId": "fe51b8c2901d38d0", "scanner": "scanner-primary", "fingerprint": "9c49da643885aa4e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3456"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-63a30e5b9f08e00c", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.2: PYSEC-2026-3457"}, "properties": {"repobilityId": "8e0c17f91f0477f7", "scanner": "scanner-primary", "fingerprint": "63a30e5b9f08e00c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3457"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a0f7a4c12507b244", "level": "warning", "message": {"text": "Vulnerable dependency python-dotenv 1.2.1: GHSA-mf9w-mj56-hr94"}, "properties": {"repobilityId": "c0b0f199ae9f3260", "scanner": "scanner-primary", "fingerprint": "a0f7a4c12507b244", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mf9w-mj56-hr94"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aca15b04e9a933e8", "level": "warning", "message": {"text": "Vulnerable dependency python-dotenv 1.2.1: PYSEC-2026-2270"}, "properties": {"repobilityId": "13b6671508444c05", "scanner": "scanner-primary", "fingerprint": "aca15b04e9a933e8", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2270"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-675101e200c7bceb", "level": "warning", "message": {"text": "Vulnerable dependency requests 2.32.5: GHSA-gc5v-m9x4-r6x2"}, "properties": {"repobilityId": "5a83342b2ace364f", "scanner": "scanner-primary", "fingerprint": "675101e200c7bceb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gc5v-m9x4-r6x2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-14c979f9d47ba2d0", "level": "warning", "message": {"text": "Vulnerable dependency requests 2.32.5: PYSEC-2026-2275"}, "properties": {"repobilityId": "9ca627556ae0371e", "scanner": "scanner-primary", "fingerprint": "14c979f9d47ba2d0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2275"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f4a150bfe9984abd", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.6.3: GHSA-mf9v-mfxr-j63j"}, "properties": {"repobilityId": "58bf68e0b735c3e5", "scanner": "scanner-primary", "fingerprint": "f4a150bfe9984abd", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mf9v-mfxr-j63j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ab01730b729b428d", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.6.3: GHSA-qccp-gfcp-xxvc"}, "properties": {"repobilityId": "85d3ff0504c74b92", "scanner": "scanner-primary", "fingerprint": "ab01730b729b428d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-qccp-gfcp-xxvc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-360c72c25a1bd03d", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.6.3: PYSEC-2026-141"}, "properties": {"repobilityId": "701c2015b9d154c2", "scanner": "scanner-primary", "fingerprint": "360c72c25a1bd03d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-141"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-611eb46eafe539c6", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.6.3: PYSEC-2026-142"}, "properties": {"repobilityId": "49390d2c616581f1", "scanner": "scanner-primary", "fingerprint": "611eb46eafe539c6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-142"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ba1c9689d1e4e42c", "level": "warning", "message": {"text": "Vulnerable dependency @modelcontextprotocol/sdk 1.25.3: GHSA-345p-7cg4-v4c7"}, "properties": {"repobilityId": "85b612e2c9030fc8", "scanner": "scanner-primary", "fingerprint": "ba1c9689d1e4e42c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-345p-7cg4-v4c7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5aa35d30bda80ae5", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-26pp-8wgv-hjvm"}, "properties": {"repobilityId": "c0b6bae3f10a970e", "scanner": "scanner-primary", "fingerprint": "5aa35d30bda80ae5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-26pp-8wgv-hjvm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-79d20d86634355d4", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-2gcr-mfcq-wcc3"}, "properties": {"repobilityId": "9dbcec52f76250b7", "scanner": "scanner-primary", "fingerprint": "79d20d86634355d4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2gcr-mfcq-wcc3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4928c7b6e6ec8143", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-3hrh-pfw6-9m5x"}, "properties": {"repobilityId": "8a9e4b2da78f41ff", "scanner": "scanner-primary", "fingerprint": "4928c7b6e6ec8143", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3hrh-pfw6-9m5x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0659973ada00c6d2", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-458j-xx4x-4375"}, "properties": {"repobilityId": "eaeb3a3cde38faae", "scanner": "scanner-primary", "fingerprint": "0659973ada00c6d2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-458j-xx4x-4375"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3fc4925e2f26ba5a", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-5pq2-9x2x-5p6w"}, "properties": {"repobilityId": "f652d96f8c9b2f50", "scanner": "scanner-primary", "fingerprint": "3fc4925e2f26ba5a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-5pq2-9x2x-5p6w"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fadb65be81d590d2", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-69xw-7hcm-h432"}, "properties": {"repobilityId": "ac631bc9d08fde19", "scanner": "scanner-primary", "fingerprint": "fadb65be81d590d2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-69xw-7hcm-h432"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-94561469639a0cd5", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-6wqw-2p9w-4vw4"}, "properties": {"repobilityId": "a35381b618c15af3", "scanner": "scanner-primary", "fingerprint": "94561469639a0cd5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6wqw-2p9w-4vw4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-802e7e7c4f82590d", "level": "error", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-88fw-hqm2-52qc"}, "properties": {"repobilityId": "886d9c43654b3e78", "scanner": "scanner-primary", "fingerprint": "802e7e7c4f82590d", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-88fw-hqm2-52qc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bd4f532bf6e2474a", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-9r54-q6cx-xmh5"}, "properties": {"repobilityId": "c98281b4a235d590", "scanner": "scanner-primary", "fingerprint": "bd4f532bf6e2474a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9r54-q6cx-xmh5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b682b3f7e271aafe", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-9vqf-7f2p-gf9v"}, "properties": {"repobilityId": "b182426b6cfd0780", "scanner": "scanner-primary", "fingerprint": "b682b3f7e271aafe", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9vqf-7f2p-gf9v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2bf01df89831bb75", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-f577-qrjj-4474"}, "properties": {"repobilityId": "0061915270e05006", "scanner": "scanner-primary", "fingerprint": "2bf01df89831bb75", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-f577-qrjj-4474"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c1bb9969e3d766b1", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-gq3j-xvxp-8hrf"}, "properties": {"repobilityId": "411212e280bcbceb", "scanner": "scanner-primary", "fingerprint": "c1bb9969e3d766b1", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gq3j-xvxp-8hrf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dafca213b5e14498", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-hm8q-7f3q-5f36"}, "properties": {"repobilityId": "69f938cd16ec0da1", "scanner": "scanner-primary", "fingerprint": "dafca213b5e14498", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hm8q-7f3q-5f36"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b26b185dc16cf4e0", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-j6c9-x7qj-28xf"}, "properties": {"repobilityId": "9b109c3d1195fb29", "scanner": "scanner-primary", "fingerprint": "b26b185dc16cf4e0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-j6c9-x7qj-28xf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-75d86c488bf95c88", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-p6xx-57qc-3wxr"}, "properties": {"repobilityId": "7bf5d3ed000e9513", "scanner": "scanner-primary", "fingerprint": "75d86c488bf95c88", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p6xx-57qc-3wxr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d08e2ca22d6db8ca", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-p77w-8qqv-26rm"}, "properties": {"repobilityId": "5dc69d9d9e788485", "scanner": "scanner-primary", "fingerprint": "d08e2ca22d6db8ca", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p77w-8qqv-26rm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-86206b1043dd54c6", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-q5qw-h33p-qvwr"}, "properties": {"repobilityId": "637e1c6301f21c4a", "scanner": "scanner-primary", "fingerprint": "86206b1043dd54c6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q5qw-h33p-qvwr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-576fb0a0772b27ff", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-qp7p-654g-cw7p"}, "properties": {"repobilityId": "e2ba7ae884f55cf8", "scanner": "scanner-primary", "fingerprint": "576fb0a0772b27ff", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-qp7p-654g-cw7p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d155b61a5712a670", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-r354-f388-2fhh"}, "properties": {"repobilityId": "3e277e510a546fe9", "scanner": "scanner-primary", "fingerprint": "d155b61a5712a670", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-r354-f388-2fhh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-76802254abea2242", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-r5rp-j6wh-rvv4"}, "properties": {"repobilityId": "4904164128ca8646", "scanner": "scanner-primary", "fingerprint": "76802254abea2242", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-r5rp-j6wh-rvv4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-92ab8206a2611a80", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-rv63-4mwf-qqc2"}, "properties": {"repobilityId": "32bbd4e68860d7b6", "scanner": "scanner-primary", "fingerprint": "92ab8206a2611a80", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-rv63-4mwf-qqc2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cb01d23ebaca84ff", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-v8w9-8mx6-g223"}, "properties": {"repobilityId": "55b396e350500cf7", "scanner": "scanner-primary", "fingerprint": "cb01d23ebaca84ff", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-v8w9-8mx6-g223"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cbfa6d023199ca3e", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-w332-q679-j88p"}, "properties": {"repobilityId": "85adc6d9708a5c3d", "scanner": "scanner-primary", "fingerprint": "cbfa6d023199ca3e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w332-q679-j88p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b9a6149dafd72b0c", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-w62v-xxxg-mg59"}, "properties": {"repobilityId": "90bc2c4bf1dfd5d1", "scanner": "scanner-primary", "fingerprint": "b9a6149dafd72b0c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w62v-xxxg-mg59"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-211772ba498d9dcf", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-wgpf-jwqj-8h8p"}, "properties": {"repobilityId": "88d17e5532735d9c", "scanner": "scanner-primary", "fingerprint": "211772ba498d9dcf", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wgpf-jwqj-8h8p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-88e0ec1b07e1c567", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-wmmm-f939-6g9c"}, "properties": {"repobilityId": "584dec06175dfd2b", "scanner": "scanner-primary", "fingerprint": "88e0ec1b07e1c567", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wmmm-f939-6g9c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-49b5f6e3686da5e2", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-wwfh-h76j-fc44"}, "properties": {"repobilityId": "babf4516d3a6b6a2", "scanner": "scanner-primary", "fingerprint": "49b5f6e3686da5e2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wwfh-h76j-fc44"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f1bd3adb583a75b7", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-xf4j-xp2r-rqqx"}, "properties": {"repobilityId": "d8228c491cdbb8a3", "scanner": "scanner-primary", "fingerprint": "f1bd3adb583a75b7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xf4j-xp2r-rqqx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-768d0c2530403f38", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-xgm2-5f3f-mvvc"}, "properties": {"repobilityId": "89776fec5efac058", "scanner": "scanner-primary", "fingerprint": "768d0c2530403f38", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xgm2-5f3f-mvvc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6baa4a8054e3fc55", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-xpcf-pg52-r92g"}, "properties": {"repobilityId": "a651e55660a8856b", "scanner": "scanner-primary", "fingerprint": "6baa4a8054e3fc55", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xpcf-pg52-r92g"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7131e779dd804266", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.11.5: GHSA-xrhx-7g5j-rcj5"}, "properties": {"repobilityId": "8004fc77df6596f5", "scanner": "scanner-primary", "fingerprint": "7131e779dd804266", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xrhx-7g5j-rcj5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d41bddbbb65323a7", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-267c-6grr-h53f"}, "properties": {"repobilityId": "2912ff03adc3dab3", "scanner": "scanner-primary", "fingerprint": "d41bddbbb65323a7", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-267c-6grr-h53f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-85ce1969636b9cd3", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-26hh-7cqf-hhc6"}, "properties": {"repobilityId": "270a3065db6de5ac", "scanner": "scanner-primary", "fingerprint": "85ce1969636b9cd3", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-26hh-7cqf-hhc6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8805e772e15ebd81", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-36qx-fr4f-26g5"}, "properties": {"repobilityId": "531d251d1a67fc40", "scanner": "scanner-primary", "fingerprint": "8805e772e15ebd81", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-36qx-fr4f-26g5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6f56ae3368641f58", "level": "note", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-3g8h-86w9-wvmq"}, "properties": {"repobilityId": "965c9011960c604b", "scanner": "scanner-primary", "fingerprint": "6f56ae3368641f58", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3g8h-86w9-wvmq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-532f4dd041a47c6b", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-3x4c-7xq6-9pq8"}, "properties": {"repobilityId": "dbc203e191804ec1", "scanner": "scanner-primary", "fingerprint": "532f4dd041a47c6b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3x4c-7xq6-9pq8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ce8de164097ce37c", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-4633-3j49-mh5q"}, "properties": {"repobilityId": "a332c74f2b1af3a9", "scanner": "scanner-primary", "fingerprint": "ce8de164097ce37c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4633-3j49-mh5q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1b4510cb5251a14d", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-492v-c6pp-mqqv"}, "properties": {"repobilityId": "fb6405d364b43fde", "scanner": "scanner-primary", "fingerprint": "1b4510cb5251a14d", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-492v-c6pp-mqqv"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-40a19a8a573a3309", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-4c39-4ccg-62r3"}, "properties": {"repobilityId": "32816a13c4da5f3d", "scanner": "scanner-primary", "fingerprint": "40a19a8a573a3309", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4c39-4ccg-62r3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8d23fcd1d1fa3e3a", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-5f7q-jpqc-wp7h"}, "properties": {"repobilityId": "17c370a9600326d0", "scanner": "scanner-primary", "fingerprint": "8d23fcd1d1fa3e3a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-5f7q-jpqc-wp7h"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-558e2c2d1eab809a", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-68g3-v927-f742"}, "properties": {"repobilityId": "c7cbb139da4a1c16", "scanner": "scanner-primary", "fingerprint": "558e2c2d1eab809a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-68g3-v927-f742"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-85b7b5b7bf727340", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-6gpp-xcg3-4w24"}, "properties": {"repobilityId": "c54b824d19107f0b", "scanner": "scanner-primary", "fingerprint": "85b7b5b7bf727340", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6gpp-xcg3-4w24"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-800a145a5dfd3d17", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-89xv-2m56-2m9x"}, "properties": {"repobilityId": "34d61f890183949a", "scanner": "scanner-primary", "fingerprint": "800a145a5dfd3d17", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-89xv-2m56-2m9x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-84abeb606a544a28", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-8h8q-6873-q5fj"}, "properties": {"repobilityId": "60c93aa51f690b14", "scanner": "scanner-primary", "fingerprint": "84abeb606a544a28", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8h8q-6873-q5fj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a9db58c2f17ea3bd", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-955p-x3mx-jcvp"}, "properties": {"repobilityId": "1c4c2900630d7afe", "scanner": "scanner-primary", "fingerprint": "a9db58c2f17ea3bd", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-955p-x3mx-jcvp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3e9ade4b18616679", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-9g9p-9gw9-jx7f"}, "properties": {"repobilityId": "8bfa0155901b726f", "scanner": "scanner-primary", "fingerprint": "3e9ade4b18616679", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9g9p-9gw9-jx7f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2ed41bfc316bae99", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-c4j6-fc7j-m34r"}, "properties": {"repobilityId": "712b9565e2c388c1", "scanner": "scanner-primary", "fingerprint": "2ed41bfc316bae99", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-c4j6-fc7j-m34r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-38a19468485405a7", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-ffhc-5mcf-pf4q"}, "properties": {"repobilityId": "226501199e546ecb", "scanner": "scanner-primary", "fingerprint": "38a19468485405a7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ffhc-5mcf-pf4q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a48357eea14b0e8f", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-ggv3-7p47-pfv8"}, "properties": {"repobilityId": "74f2363b1ce82780", "scanner": "scanner-primary", "fingerprint": "a48357eea14b0e8f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ggv3-7p47-pfv8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f68b684b2806438a", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-gx5p-jg67-6x7h"}, "properties": {"repobilityId": "d271b78236801af4", "scanner": "scanner-primary", "fingerprint": "f68b684b2806438a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gx5p-jg67-6x7h"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-df7ce90f795ef7da", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-h25m-26qc-wcjf"}, "properties": {"repobilityId": "2729a3f3c9a7a49c", "scanner": "scanner-primary", "fingerprint": "df7ce90f795ef7da", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h25m-26qc-wcjf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2d785890a396f91d", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-h27x-g6w4-24gq"}, "properties": {"repobilityId": "9a5505c0ee18046c", "scanner": "scanner-primary", "fingerprint": "2d785890a396f91d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h27x-g6w4-24gq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-24684883c5bd1804", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-h64f-5h5j-jqjh"}, "properties": {"repobilityId": "84f6bd98fb0ec899", "scanner": "scanner-primary", "fingerprint": "24684883c5bd1804", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h64f-5h5j-jqjh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a1b44fbf0a39da07", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-jcc7-9wpm-mj36"}, "properties": {"repobilityId": "c5047414511c81ef", "scanner": "scanner-primary", "fingerprint": "a1b44fbf0a39da07", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jcc7-9wpm-mj36"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5c258ee50a4bc414", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-m99w-x7hq-7vfj"}, "properties": {"repobilityId": "9e5ccb6700a72b15", "scanner": "scanner-primary", "fingerprint": "5c258ee50a4bc414", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m99w-x7hq-7vfj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ad1de68b26198aea", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-mg66-mrh9-m8jx"}, "properties": {"repobilityId": "694f9f8fb5869174", "scanner": "scanner-primary", "fingerprint": "ad1de68b26198aea", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mg66-mrh9-m8jx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2eae071c558ae957", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-mq59-m269-xvcx"}, "properties": {"repobilityId": "16df775117111a89", "scanner": "scanner-primary", "fingerprint": "2eae071c558ae957", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mq59-m269-xvcx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c562a52adc7f4206", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-p9j2-gv94-2wf4"}, "properties": {"repobilityId": "b77f70dbc75251f8", "scanner": "scanner-primary", "fingerprint": "c562a52adc7f4206", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p9j2-gv94-2wf4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-32e09ad3b5eea58e", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-q4gf-8mx6-v5v3"}, "properties": {"repobilityId": "2f7e725fa539d825", "scanner": "scanner-primary", "fingerprint": "32e09ad3b5eea58e", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q4gf-8mx6-v5v3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bbe11a8c9880f949", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-q8wf-6r8g-63ch"}, "properties": {"repobilityId": "3d564f6d19bf6de2", "scanner": "scanner-primary", "fingerprint": "bbe11a8c9880f949", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q8wf-6r8g-63ch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fba697ec6de59ab7", "level": "note", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-vfv6-92ff-j949"}, "properties": {"repobilityId": "6e697c5633425c8b", "scanner": "scanner-primary", "fingerprint": "fba697ec6de59ab7", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vfv6-92ff-j949"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5d8912b23b8d73e2", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.1: GHSA-wfc6-r584-vfw7"}, "properties": {"repobilityId": "a4495ab5b9d82834", "scanner": "scanner-primary", "fingerprint": "5d8912b23b8d73e2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wfc6-r584-vfw7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-deep-research-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8fd4338dbb86373e", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-2fqr-mr3j-6wp8"}, "properties": {"repobilityId": "7ef4cda3aabc8a78", "scanner": "scanner-primary", "fingerprint": "8fd4338dbb86373e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2fqr-mr3j-6wp8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-47b9faecc32b3fc9", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-2vrm-gr82-f7m5"}, "properties": {"repobilityId": "f85c0b73b2e5a699", "scanner": "scanner-primary", "fingerprint": "47b9faecc32b3fc9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2vrm-gr82-f7m5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cb9dff6b489714c9", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-3wq7-rqq7-wx6j"}, "properties": {"repobilityId": "9f3813a15fb8afb3", "scanner": "scanner-primary", "fingerprint": "cb9dff6b489714c9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3wq7-rqq7-wx6j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9815f91b0dbcef73", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-4fvr-rgm6-gqmc"}, "properties": {"repobilityId": "731e09e18014b328", "scanner": "scanner-primary", "fingerprint": "9815f91b0dbcef73", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4fvr-rgm6-gqmc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4cb7cbdf9adec549", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-4m7w-qmgq-4wj5"}, "properties": {"repobilityId": "9c6bc4a985c874aa", "scanner": "scanner-primary", "fingerprint": "4cb7cbdf9adec549", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4m7w-qmgq-4wj5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b20a1a4198f1b775", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-63hf-3vf5-4wqf"}, "properties": {"repobilityId": "0cc90cb870a1dd35", "scanner": "scanner-primary", "fingerprint": "b20a1a4198f1b775", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-63hf-3vf5-4wqf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3e26b4a17a098b70", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-63hw-fmq6-xxg2"}, "properties": {"repobilityId": "f9bc9509fc24935f", "scanner": "scanner-primary", "fingerprint": "3e26b4a17a098b70", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-63hw-fmq6-xxg2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-24452b263a79ef8d", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-966j-vmvw-g2g9"}, "properties": {"repobilityId": "11a33473ddd7cf1e", "scanner": "scanner-primary", "fingerprint": "24452b263a79ef8d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-966j-vmvw-g2g9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c9a33482a88ae1e5", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-9x8q-7h8h-wcw9"}, "properties": {"repobilityId": "f4283f27a3d602f3", "scanner": "scanner-primary", "fingerprint": "c9a33482a88ae1e5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9x8q-7h8h-wcw9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-95140ede6a0b0b7f", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-c427-h43c-vf67"}, "properties": {"repobilityId": "8462de36b474aab5", "scanner": "scanner-primary", "fingerprint": "95140ede6a0b0b7f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-c427-h43c-vf67"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fa67ffe5dac3fabf", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-g3cq-j2xw-wf74"}, "properties": {"repobilityId": "1e2a14ee29866652", "scanner": "scanner-primary", "fingerprint": "fa67ffe5dac3fabf", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-g3cq-j2xw-wf74"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-75807b2c7ee21d0d", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-hcc4-c3v8-rx92"}, "properties": {"repobilityId": "65700a967284d0be", "scanner": "scanner-primary", "fingerprint": "75807b2c7ee21d0d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hcc4-c3v8-rx92"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-88a06f9ad7120d7c", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-hg6j-4rv6-33pg"}, "properties": {"repobilityId": "25b722ac25954261", "scanner": "scanner-primary", "fingerprint": "88a06f9ad7120d7c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hg6j-4rv6-33pg"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-55026c97311e3a1c", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-hpj7-wq8m-9hgp"}, "properties": {"repobilityId": "785aa05368258fea", "scanner": "scanner-primary", "fingerprint": "55026c97311e3a1c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hpj7-wq8m-9hgp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2c71a72a4937465d", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-jg22-mg44-37j8"}, "properties": {"repobilityId": "1e8d545951768da3", "scanner": "scanner-primary", "fingerprint": "2c71a72a4937465d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jg22-mg44-37j8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a01eb9b7ba9317dd", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-m5qp-6w8w-w647"}, "properties": {"repobilityId": "5e89d6a5e54f1947", "scanner": "scanner-primary", "fingerprint": "a01eb9b7ba9317dd", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m5qp-6w8w-w647"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-441e2f24ee8460e6", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-m6qw-4cw2-hm4m"}, "properties": {"repobilityId": "c9911bc967c559ca", "scanner": "scanner-primary", "fingerprint": "441e2f24ee8460e6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m6qw-4cw2-hm4m"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-61dea895105a6b32", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-mwh4-6h8g-pg8w"}, "properties": {"repobilityId": "8a3d3232f9818b84", "scanner": "scanner-primary", "fingerprint": "61dea895105a6b32", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mwh4-6h8g-pg8w"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9e038d7476051bfb", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-p998-jp59-783m"}, "properties": {"repobilityId": "161f251789517fb3", "scanner": "scanner-primary", "fingerprint": "9e038d7476051bfb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p998-jp59-783m"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-95aff45a4b2bb736", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-w2fm-2cpv-w7v5"}, "properties": {"repobilityId": "d7d32d1b01aa0b47", "scanner": "scanner-primary", "fingerprint": "95aff45a4b2bb736", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w2fm-2cpv-w7v5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9ac4aaf1c86ec314", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-xcgm-r5h9-7989"}, "properties": {"repobilityId": "040d52aad6fb3751", "scanner": "scanner-primary", "fingerprint": "9ac4aaf1c86ec314", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xcgm-r5h9-7989"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-550178420448ef49", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2094"}, "properties": {"repobilityId": "0387c1b85d74f4ed", "scanner": "scanner-primary", "fingerprint": "550178420448ef49", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2094"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6bef4a117fc4d37c", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2095"}, "properties": {"repobilityId": "5f31e99c2c55d644", "scanner": "scanner-primary", "fingerprint": "6bef4a117fc4d37c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2095"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-16bc8d03bf7944ec", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2097"}, "properties": {"repobilityId": "8bea7c3c251f6060", "scanner": "scanner-primary", "fingerprint": "16bc8d03bf7944ec", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2097"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-63bf583ec20ebde2", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2098"}, "properties": {"repobilityId": "2ad0ecab9d274e71", "scanner": "scanner-primary", "fingerprint": "63bf583ec20ebde2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2098"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7393b06c11d5980a", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2100"}, "properties": {"repobilityId": "24c78effaa40eebf", "scanner": "scanner-primary", "fingerprint": "7393b06c11d5980a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2100"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6c42f7d4f08eb732", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2101"}, "properties": {"repobilityId": "a2ecfb4978b6e1ef", "scanner": "scanner-primary", "fingerprint": "6c42f7d4f08eb732", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2101"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-904cceab0b4fb98a", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2102"}, "properties": {"repobilityId": "1e2b4731b536ce8a", "scanner": "scanner-primary", "fingerprint": "904cceab0b4fb98a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2102"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-787adb5b9cf175d8", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2103"}, "properties": {"repobilityId": "4b55e4d387e0e786", "scanner": "scanner-primary", "fingerprint": "787adb5b9cf175d8", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2103"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9a0562075797fb8d", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2104"}, "properties": {"repobilityId": "c521ccce96eb012b", "scanner": "scanner-primary", "fingerprint": "9a0562075797fb8d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2104"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-eee16a45f74568c1", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2105"}, "properties": {"repobilityId": "fb3ead7c796bac7f", "scanner": "scanner-primary", "fingerprint": "eee16a45f74568c1", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2105"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cea4364a0252c5df", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2106"}, "properties": {"repobilityId": "4457047245c0c2cd", "scanner": "scanner-primary", "fingerprint": "cea4364a0252c5df", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2106"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-985e1c2857c0c22a", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2108"}, "properties": {"repobilityId": "cc65385679179c2e", "scanner": "scanner-primary", "fingerprint": "985e1c2857c0c22a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2108"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e41706c5f8254bf0", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2109"}, "properties": {"repobilityId": "e496766550d548d2", "scanner": "scanner-primary", "fingerprint": "e41706c5f8254bf0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2109"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-42b40d518b47d7f9", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2110"}, "properties": {"repobilityId": "4a93247cae6650d6", "scanner": "scanner-primary", "fingerprint": "42b40d518b47d7f9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2110"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7fdc6c7acd417e10", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2111"}, "properties": {"repobilityId": "d6e2cc234947d8ce", "scanner": "scanner-primary", "fingerprint": "7fdc6c7acd417e10", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2111"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a4b816fd7a92ae32", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2113"}, "properties": {"repobilityId": "567f6f5b1b73c5da", "scanner": "scanner-primary", "fingerprint": "a4b816fd7a92ae32", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2113"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b9aee01be5e569ee", "level": "warning", "message": {"text": "Vulnerable dependency google-adk 1.26.0: GHSA-rg7c-g689-fr3x"}, "properties": {"repobilityId": "165ae2414995745e", "scanner": "scanner-primary", "fingerprint": "b9aee01be5e569ee", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-rg7c-g689-fr3x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d730fb2d5f1adad9", "level": "warning", "message": {"text": "Vulnerable dependency google-adk 1.26.0: PYSEC-2026-344"}, "properties": {"repobilityId": "5f31af7431e7dc60", "scanner": "scanner-primary", "fingerprint": "d730fb2d5f1adad9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-344"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8035d1da0d628d35", "level": "warning", "message": {"text": "Vulnerable dependency mcp 1.26.0: GHSA-hvrp-rf83-w775"}, "properties": {"repobilityId": "372a3eab7c0415af", "scanner": "scanner-primary", "fingerprint": "8035d1da0d628d35", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hvrp-rf83-w775"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7b2acca52eea176f", "level": "warning", "message": {"text": "Vulnerable dependency mcp 1.26.0: GHSA-jpw9-pfvf-9f58"}, "properties": {"repobilityId": "b1057d1f32458bbd", "scanner": "scanner-primary", "fingerprint": "7b2acca52eea176f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jpw9-pfvf-9f58"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3c78c4bd934e2905", "level": "warning", "message": {"text": "Vulnerable dependency mcp 1.26.0: GHSA-vj7q-gjh5-988w"}, "properties": {"repobilityId": "131e03c60523a66a", "scanner": "scanner-primary", "fingerprint": "3c78c4bd934e2905", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vj7q-gjh5-988w"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f077f322ac920a82", "level": "warning", "message": {"text": "Vulnerable dependency mcp 1.26.0: PYSEC-2026-3481"}, "properties": {"repobilityId": "64420dfe890022e2", "scanner": "scanner-primary", "fingerprint": "f077f322ac920a82", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3481"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8729597f44c3b474", "level": "warning", "message": {"text": "Vulnerable dependency mcp 1.26.0: PYSEC-2026-3482"}, "properties": {"repobilityId": "5d0c0e703af632a8", "scanner": "scanner-primary", "fingerprint": "8729597f44c3b474", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3482"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b85ef3c7dea87afd", "level": "warning", "message": {"text": "Vulnerable dependency mcp 1.26.0: PYSEC-2026-3483"}, "properties": {"repobilityId": "7987c6d2f17744d9", "scanner": "scanner-primary", "fingerprint": "b85ef3c7dea87afd", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3483"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-745839925f4f67d5", "level": "warning", "message": {"text": "Vulnerable dependency pydantic-settings 2.13.1: GHSA-4xgf-cpjx-pc3j"}, "properties": {"repobilityId": "c06b11fbfae6fa12", "scanner": "scanner-primary", "fingerprint": "745839925f4f67d5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4xgf-cpjx-pc3j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-31f841f0bde645c1", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.11.0: GHSA-752w-5fwx-jx9f"}, "properties": {"repobilityId": "75003a36eb55fb62", "scanner": "scanner-primary", "fingerprint": "31f841f0bde645c1", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-752w-5fwx-jx9f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7972c1a4d6858565", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.11.0: GHSA-993g-76c3-p5m4"}, "properties": {"repobilityId": "3e7712f0d850fd41", "scanner": "scanner-primary", "fingerprint": "7972c1a4d6858565", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-993g-76c3-p5m4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1173313eb0ea38fc", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.11.0: GHSA-fhv5-28vv-h8m8"}, "properties": {"repobilityId": "bf2c3e073af6d274", "scanner": "scanner-primary", "fingerprint": "1173313eb0ea38fc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-fhv5-28vv-h8m8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-23a354813d55c9a6", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.11.0: GHSA-jq35-7prp-9v3f"}, "properties": {"repobilityId": "8158c5e8d4819c70", "scanner": "scanner-primary", "fingerprint": "23a354813d55c9a6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jq35-7prp-9v3f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5c4862ac5f376b27", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.11.0: GHSA-w7vc-732c-9m39"}, "properties": {"repobilityId": "2544f309e2304088", "scanner": "scanner-primary", "fingerprint": "5c4862ac5f376b27", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w7vc-732c-9m39"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-145b12fc0d4b238f", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.11.0: GHSA-xgmm-8j9v-c9wx"}, "properties": {"repobilityId": "3045f2a4cc5d55c6", "scanner": "scanner-primary", "fingerprint": "145b12fc0d4b238f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xgmm-8j9v-c9wx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7a8681fe269fdc57", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.11.0: PYSEC-2026-120"}, "properties": {"repobilityId": "8e0da721daa9a674", "scanner": "scanner-primary", "fingerprint": "7a8681fe269fdc57", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-120"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e498d38662979e8b", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.11.0: PYSEC-2026-175"}, "properties": {"repobilityId": "7f1f943c951a5c04", "scanner": "scanner-primary", "fingerprint": "e498d38662979e8b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-175"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9f3e708cf88f041a", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.11.0: PYSEC-2026-176"}, "properties": {"repobilityId": "aeaf9be7b09df90a", "scanner": "scanner-primary", "fingerprint": "9f3e708cf88f041a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-176"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3787d673ec30b79e", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.11.0: PYSEC-2026-177"}, "properties": {"repobilityId": "d02db87502f57d83", "scanner": "scanner-primary", "fingerprint": "3787d673ec30b79e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-177"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c10539dae56a1e86", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.11.0: PYSEC-2026-178"}, "properties": {"repobilityId": "c6522d7456e22718", "scanner": "scanner-primary", "fingerprint": "c10539dae56a1e86", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-178"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5ea9b247dca06b54", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.11.0: PYSEC-2026-179"}, "properties": {"repobilityId": "5cb8398e2d8fe712", "scanner": "scanner-primary", "fingerprint": "5ea9b247dca06b54", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-179"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d633118398334767", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-5rvq-cxj2-64vf"}, "properties": {"repobilityId": "4f41851ea516bb0f", "scanner": "scanner-primary", "fingerprint": "d633118398334767", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-5rvq-cxj2-64vf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b1e1bfe8ddd857d0", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-6jv3-5f52-599m"}, "properties": {"repobilityId": "66d5af8983f693af", "scanner": "scanner-primary", "fingerprint": "b1e1bfe8ddd857d0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6jv3-5f52-599m"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4521384e6357b38f", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-mj87-hwqh-73pj"}, "properties": {"repobilityId": "7bff27eec4731ee3", "scanner": "scanner-primary", "fingerprint": "4521384e6357b38f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mj87-hwqh-73pj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0d358ed7a0f4caea", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-pp6c-gr5w-3c5g"}, "properties": {"repobilityId": "014b999f1f965261", "scanner": "scanner-primary", "fingerprint": "0d358ed7a0f4caea", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pp6c-gr5w-3c5g"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1ce105834d93ecf0", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-v9pg-7xvm-68hf"}, "properties": {"repobilityId": "663738fec3cd7bf3", "scanner": "scanner-primary", "fingerprint": "1ce105834d93ecf0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-v9pg-7xvm-68hf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5471b86ca0edd516", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-vffw-93wf-4j4q"}, "properties": {"repobilityId": "6f7b3b5ac1ccc65f", "scanner": "scanner-primary", "fingerprint": "5471b86ca0edd516", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vffw-93wf-4j4q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d1a6c1fb146e5fae", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3036"}, "properties": {"repobilityId": "b714656e65c43580", "scanner": "scanner-primary", "fingerprint": "d1a6c1fb146e5fae", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3036"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a76f7ef58018cbab", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3037"}, "properties": {"repobilityId": "3397e4bdf58b4620", "scanner": "scanner-primary", "fingerprint": "a76f7ef58018cbab", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3037"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4bb95bc19c7e2c9f", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3038"}, "properties": {"repobilityId": "7f85ddb03b451085", "scanner": "scanner-primary", "fingerprint": "4bb95bc19c7e2c9f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3038"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-25f015baaa07ca74", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3039"}, "properties": {"repobilityId": "0542a2b6b9d7f33f", "scanner": "scanner-primary", "fingerprint": "25f015baaa07ca74", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3039"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-60bb6d47a0b91df7", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3040"}, "properties": {"repobilityId": "d1aad14e8e40c34a", "scanner": "scanner-primary", "fingerprint": "60bb6d47a0b91df7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3040"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bb3c0bd145de12b5", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3041"}, "properties": {"repobilityId": "e662c64103e6ef60", "scanner": "scanner-primary", "fingerprint": "bb3c0bd145de12b5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3041"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-956f9f7464d669cb", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-82w8-qh3p-5jfq"}, "properties": {"repobilityId": "b251d93440cbabf3", "scanner": "scanner-primary", "fingerprint": "956f9f7464d669cb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-82w8-qh3p-5jfq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8f275ecbd53fe568", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-86qp-5c8j-p5mr"}, "properties": {"repobilityId": "bfe8ab9063c6084a", "scanner": "scanner-primary", "fingerprint": "8f275ecbd53fe568", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-86qp-5c8j-p5mr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fd666f835a1605d1", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-jp82-jpqv-5vv3"}, "properties": {"repobilityId": "67a5509c81c86f46", "scanner": "scanner-primary", "fingerprint": "fd666f835a1605d1", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jp82-jpqv-5vv3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e85042c94c74cbc2", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-wqp7-x3pw-xc5r"}, "properties": {"repobilityId": "07cd6a5b2e071130", "scanner": "scanner-primary", "fingerprint": "e85042c94c74cbc2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wqp7-x3pw-xc5r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-89cfcbd7b744abc8", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-x746-7m8f-x49c"}, "properties": {"repobilityId": "b734eb1689015a3c", "scanner": "scanner-primary", "fingerprint": "89cfcbd7b744abc8", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-x746-7m8f-x49c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a3ea3f2ae21103ff", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-161"}, "properties": {"repobilityId": "a07c0c07cc0cf598", "scanner": "scanner-primary", "fingerprint": "a3ea3f2ae21103ff", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-161"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-62b2226a96e2a6e2", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-2280"}, "properties": {"repobilityId": "1942c6f60e92bc32", "scanner": "scanner-primary", "fingerprint": "62b2226a96e2a6e2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2280"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-13c486807da6e154", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-2281"}, "properties": {"repobilityId": "6e311b680f1aaba6", "scanner": "scanner-primary", "fingerprint": "13c486807da6e154", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2281"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2928f42662458d7b", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-248"}, "properties": {"repobilityId": "c4e67d11d07156d9", "scanner": "scanner-primary", "fingerprint": "2928f42662458d7b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-248"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bad9ff1f92bf9711", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-249"}, "properties": {"repobilityId": "a36296b0e1a0a7f9", "scanner": "scanner-primary", "fingerprint": "bad9ff1f92bf9711", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-249"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-58e034301bb6b7a2", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.15: GHSA-2gcr-mfcq-wcc3"}, "properties": {"repobilityId": "f28252c238df8cd1", "scanner": "scanner-primary", "fingerprint": "58e034301bb6b7a2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2gcr-mfcq-wcc3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-697a17e86702153a", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.15: GHSA-3hrh-pfw6-9m5x"}, "properties": {"repobilityId": "2cae5350b86ec15c", "scanner": "scanner-primary", "fingerprint": "697a17e86702153a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3hrh-pfw6-9m5x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8229a20596fddede", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.15: GHSA-69xw-7hcm-h432"}, "properties": {"repobilityId": "b7103297433368a1", "scanner": "scanner-primary", "fingerprint": "8229a20596fddede", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-69xw-7hcm-h432"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d52702fa48f98dc7", "level": "error", "message": {"text": "Vulnerable dependency hono 4.12.15: GHSA-88fw-hqm2-52qc"}, "properties": {"repobilityId": "967679ab9a1cd4cf", "scanner": "scanner-primary", "fingerprint": "d52702fa48f98dc7", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-88fw-hqm2-52qc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-db7d569aaf434a4e", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.15: GHSA-9vqf-7f2p-gf9v"}, "properties": {"repobilityId": "9e5e716eb556fc56", "scanner": "scanner-primary", "fingerprint": "db7d569aaf434a4e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9vqf-7f2p-gf9v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ba225b4f735b0a57", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.15: GHSA-f577-qrjj-4474"}, "properties": {"repobilityId": "9b34d8a976d364b5", "scanner": "scanner-primary", "fingerprint": "ba225b4f735b0a57", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-f577-qrjj-4474"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f67c1369aeec7a9d", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.15: GHSA-hm8q-7f3q-5f36"}, "properties": {"repobilityId": "caf6e20845d7df73", "scanner": "scanner-primary", "fingerprint": "f67c1369aeec7a9d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hm8q-7f3q-5f36"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-583a72baba1ddc59", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.15: GHSA-hvrm-45r6-mjfj"}, "properties": {"repobilityId": "9c25d007af888f2e", "scanner": "scanner-primary", "fingerprint": "583a72baba1ddc59", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hvrm-45r6-mjfj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-da3f313e5ac0042e", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.15: GHSA-j6c9-x7qj-28xf"}, "properties": {"repobilityId": "9153a67889b396b9", "scanner": "scanner-primary", "fingerprint": "da3f313e5ac0042e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-j6c9-x7qj-28xf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c8251f9a60cc37f9", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.15: GHSA-p77w-8qqv-26rm"}, "properties": {"repobilityId": "a7070d525bdde7aa", "scanner": "scanner-primary", "fingerprint": "c8251f9a60cc37f9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p77w-8qqv-26rm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b9cf7e7a8cae054b", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.15: GHSA-qp7p-654g-cw7p"}, "properties": {"repobilityId": "3cce1d3f1d986f8c", "scanner": "scanner-primary", "fingerprint": "b9cf7e7a8cae054b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-qp7p-654g-cw7p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bf97e3f99543ed7b", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.15: GHSA-rv63-4mwf-qqc2"}, "properties": {"repobilityId": "f37edf0b85732a72", "scanner": "scanner-primary", "fingerprint": "bf97e3f99543ed7b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-rv63-4mwf-qqc2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7c499a56010c10c7", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.15: GHSA-w62v-xxxg-mg59"}, "properties": {"repobilityId": "82e005525a9450b2", "scanner": "scanner-primary", "fingerprint": "7c499a56010c10c7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w62v-xxxg-mg59"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-717b45e6f55370c8", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.15: GHSA-wgpf-jwqj-8h8p"}, "properties": {"repobilityId": "89e2bf2de968b241", "scanner": "scanner-primary", "fingerprint": "717b45e6f55370c8", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wgpf-jwqj-8h8p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-33d3f42fd34e9a22", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.15: GHSA-wwfh-h76j-fc44"}, "properties": {"repobilityId": "18da89b912819d64", "scanner": "scanner-primary", "fingerprint": "33d3f42fd34e9a22", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wwfh-h76j-fc44"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ced3f5815208fac0", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.15: GHSA-xgm2-5f3f-mvvc"}, "properties": {"repobilityId": "7ef3bf239e3fa792", "scanner": "scanner-primary", "fingerprint": "ced3f5815208fac0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xgm2-5f3f-mvvc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9e64aae9278b014d", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.15: GHSA-xrhx-7g5j-rcj5"}, "properties": {"repobilityId": "6e6dccf4506b5cca", "scanner": "scanner-primary", "fingerprint": "9e64aae9278b014d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xrhx-7g5j-rcj5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-568ce6b423d45050", "level": "error", "message": {"text": "Vulnerable dependency postcss 8.5.10: GHSA-6g55-p6wh-862q"}, "properties": {"repobilityId": "8a94917bf6cfa1fe", "scanner": "scanner-primary", "fingerprint": "568ce6b423d45050", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-6g55-p6wh-862q", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-financial-coach-agent/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2874d809b800a08c", "level": "warning", "message": {"text": "Vulnerable dependency @hono/node-server 1.19.12: GHSA-92pp-h63x-v22m"}, "properties": {"repobilityId": "345820718d498439", "scanner": "scanner-primary", "fingerprint": "2874d809b800a08c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-92pp-h63x-v22m"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-24a923395b6fd4e4", "level": "warning", "message": {"text": "Vulnerable dependency @hono/node-server 1.19.12: GHSA-frvp-7c67-39w9"}, "properties": {"repobilityId": "8363b1510f3ea73d", "scanner": "scanner-primary", "fingerprint": "24a923395b6fd4e4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-frvp-7c67-39w9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a2a43f4761a7d43a", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-26pp-8wgv-hjvm"}, "properties": {"repobilityId": "13777521052e9b6c", "scanner": "scanner-primary", "fingerprint": "a2a43f4761a7d43a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-26pp-8wgv-hjvm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7c93c1bb4145ab84", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-2gcr-mfcq-wcc3"}, "properties": {"repobilityId": "4e20969007b73a45", "scanner": "scanner-primary", "fingerprint": "7c93c1bb4145ab84", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2gcr-mfcq-wcc3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b8243515b69714f2", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-3hrh-pfw6-9m5x"}, "properties": {"repobilityId": "a3ec07e8af424b93", "scanner": "scanner-primary", "fingerprint": "b8243515b69714f2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3hrh-pfw6-9m5x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f09bb2f1e967c866", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-458j-xx4x-4375"}, "properties": {"repobilityId": "c0e9c6224595966b", "scanner": "scanner-primary", "fingerprint": "f09bb2f1e967c866", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-458j-xx4x-4375"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b040d4c49be64bd8", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-69xw-7hcm-h432"}, "properties": {"repobilityId": "aec3781878eb2976", "scanner": "scanner-primary", "fingerprint": "b040d4c49be64bd8", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-69xw-7hcm-h432"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-73659387e6d5d876", "level": "error", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-88fw-hqm2-52qc"}, "properties": {"repobilityId": "173baa1cdc784654", "scanner": "scanner-primary", "fingerprint": "73659387e6d5d876", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-88fw-hqm2-52qc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-22bb42ab1decb8f2", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-9vqf-7f2p-gf9v"}, "properties": {"repobilityId": "1a907187f9325807", "scanner": "scanner-primary", "fingerprint": "22bb42ab1decb8f2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9vqf-7f2p-gf9v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-076ee3761af5ccf7", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-f577-qrjj-4474"}, "properties": {"repobilityId": "6269d8df0eb4ff46", "scanner": "scanner-primary", "fingerprint": "076ee3761af5ccf7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-f577-qrjj-4474"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-36225fc773f92027", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-hm8q-7f3q-5f36"}, "properties": {"repobilityId": "48e7c999d55ec393", "scanner": "scanner-primary", "fingerprint": "36225fc773f92027", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hm8q-7f3q-5f36"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-64989c2663acb2f4", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-hvrm-45r6-mjfj"}, "properties": {"repobilityId": "67ab81ff71e8ac6d", "scanner": "scanner-primary", "fingerprint": "64989c2663acb2f4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hvrm-45r6-mjfj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-95c6c63d803133b3", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-j6c9-x7qj-28xf"}, "properties": {"repobilityId": "d060d67d53d21ef2", "scanner": "scanner-primary", "fingerprint": "95c6c63d803133b3", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-j6c9-x7qj-28xf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f0270ba1a88a0044", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-p77w-8qqv-26rm"}, "properties": {"repobilityId": "734ca7b1aa3c656d", "scanner": "scanner-primary", "fingerprint": "f0270ba1a88a0044", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p77w-8qqv-26rm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-817793ddd6b7bab8", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-qp7p-654g-cw7p"}, "properties": {"repobilityId": "1a8ddfa55f73757b", "scanner": "scanner-primary", "fingerprint": "817793ddd6b7bab8", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-qp7p-654g-cw7p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-57f205be7d1af9c7", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-r5rp-j6wh-rvv4"}, "properties": {"repobilityId": "abaf677d0c910b14", "scanner": "scanner-primary", "fingerprint": "57f205be7d1af9c7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-r5rp-j6wh-rvv4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-172c646fbd10afd0", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-rv63-4mwf-qqc2"}, "properties": {"repobilityId": "f6cb65cf461bdb23", "scanner": "scanner-primary", "fingerprint": "172c646fbd10afd0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-rv63-4mwf-qqc2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a98a3064d5c0c0c0", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-w62v-xxxg-mg59"}, "properties": {"repobilityId": "60e9cb143dbe76e5", "scanner": "scanner-primary", "fingerprint": "a98a3064d5c0c0c0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w62v-xxxg-mg59"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cfd21471f070f1c7", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-wgpf-jwqj-8h8p"}, "properties": {"repobilityId": "2c1e0ae04376ffd2", "scanner": "scanner-primary", "fingerprint": "cfd21471f070f1c7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wgpf-jwqj-8h8p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a7838f3db70d31ae", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-wmmm-f939-6g9c"}, "properties": {"repobilityId": "2e26c1cd7b0ee5b5", "scanner": "scanner-primary", "fingerprint": "a7838f3db70d31ae", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wmmm-f939-6g9c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8f57ec7fe70a3d90", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-wwfh-h76j-fc44"}, "properties": {"repobilityId": "35cd547b0570611d", "scanner": "scanner-primary", "fingerprint": "8f57ec7fe70a3d90", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wwfh-h76j-fc44"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b3d16eff6f338c5d", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-xf4j-xp2r-rqqx"}, "properties": {"repobilityId": "ed4c9a946e7ac2aa", "scanner": "scanner-primary", "fingerprint": "b3d16eff6f338c5d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xf4j-xp2r-rqqx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3fb489bf61e2a18b", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-xgm2-5f3f-mvvc"}, "properties": {"repobilityId": "e9d2ef02d11a6ecb", "scanner": "scanner-primary", "fingerprint": "3fb489bf61e2a18b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xgm2-5f3f-mvvc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-24031c5fd7928f08", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-xpcf-pg52-r92g"}, "properties": {"repobilityId": "33f87737926c38f4", "scanner": "scanner-primary", "fingerprint": "24031c5fd7928f08", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xpcf-pg52-r92g"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3acf580738d9cc80", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.10: GHSA-xrhx-7g5j-rcj5"}, "properties": {"repobilityId": "fc6f7ac70e5a47ab", "scanner": "scanner-primary", "fingerprint": "3acf580738d9cc80", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xrhx-7g5j-rcj5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-89090f8f96dfc666", "level": "warning", "message": {"text": "Vulnerable dependency react-router 7.13.2: GHSA-2j2x-hqr9-3h42"}, "properties": {"repobilityId": "80eb82864d62a3dc", "scanner": "scanner-primary", "fingerprint": "89090f8f96dfc666", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2j2x-hqr9-3h42"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/mcp-use-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-067d42057ee42daf", "level": "warning", "message": {"text": "Vulnerable dependency react-router 7.13.2: GHSA-49rj-9fvp-4h2h"}, "properties": {"repobilityId": "f703375c114d3fbc", "scanner": "scanner-primary", "fingerprint": "067d42057ee42daf", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-49rj-9fvp-4h2h"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/mcp-use-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bfdba2fcd1520066", "level": "warning", "message": {"text": "Vulnerable dependency react-router 7.13.2: GHSA-84g9-w2xq-vcv6"}, "properties": {"repobilityId": "dd5459a55226ed4f", "scanner": "scanner-primary", "fingerprint": "bfdba2fcd1520066", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-84g9-w2xq-vcv6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/mcp-use-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-387d31ca3007ba59", "level": "warning", "message": {"text": "Vulnerable dependency react-router 7.13.2: GHSA-8x6r-g9mw-2r78"}, "properties": {"repobilityId": "30eb01a60d65ab6f", "scanner": "scanner-primary", "fingerprint": "387d31ca3007ba59", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8x6r-g9mw-2r78"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/mcp-use-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3f1e6d65c8420dfe", "level": "warning", "message": {"text": "Vulnerable dependency react-router 7.13.2: GHSA-rxv8-25v2-qmq8"}, "properties": {"repobilityId": "fae31d1e67d9ceae", "scanner": "scanner-primary", "fingerprint": "3f1e6d65c8420dfe", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-rxv8-25v2-qmq8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/mcp-use-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3036b17119b14f5c", "level": "warning", "message": {"text": "Vulnerable dependency tar 7.5.13: GHSA-23hp-3jrh-7fpw"}, "properties": {"repobilityId": "5c9c167ab493aa7a", "scanner": "scanner-primary", "fingerprint": "3036b17119b14f5c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-23hp-3jrh-7fpw"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-29d3a9a0d1a09910", "level": "warning", "message": {"text": "Vulnerable dependency tar 7.5.13: GHSA-8x88-c5mf-7j5w"}, "properties": {"repobilityId": "cb21b85a204d571b", "scanner": "scanner-primary", "fingerprint": "29d3a9a0d1a09910", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8x88-c5mf-7j5w"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2691a591eb730179", "level": "warning", "message": {"text": "Vulnerable dependency tar 7.5.13: GHSA-gvwx-54wh-qm9j"}, "properties": {"repobilityId": "62e99564d6cb9359", "scanner": "scanner-primary", "fingerprint": "2691a591eb730179", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gvwx-54wh-qm9j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ada0255315465195", "level": "warning", "message": {"text": "Vulnerable dependency tar 7.5.13: GHSA-vmf3-w455-68vh"}, "properties": {"repobilityId": "5113ab34429f8dc2", "scanner": "scanner-primary", "fingerprint": "ada0255315465195", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vmf3-w455-68vh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a0632063ac3c3c87", "level": "warning", "message": {"text": "Vulnerable dependency tar 7.5.13: GHSA-w8wr-v893-vjvp"}, "properties": {"repobilityId": "4debe9b4f384d56c", "scanner": "scanner-primary", "fingerprint": "a0632063ac3c3c87", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w8wr-v893-vjvp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d2d41f95c6ed075d", "level": "warning", "message": {"text": "Vulnerable dependency turbo 2.9.3: GHSA-3qcw-2rhx-2726"}, "properties": {"repobilityId": "9639dc17e0701d22", "scanner": "scanner-primary", "fingerprint": "d2d41f95c6ed075d", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3qcw-2rhx-2726", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-488eab4f4db3a2cb", "level": "warning", "message": {"text": "Vulnerable dependency turbo 2.9.3: GHSA-hcf7-66rw-9f5r"}, "properties": {"repobilityId": "543897163415455e", "scanner": "scanner-primary", "fingerprint": "488eab4f4db3a2cb", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-hcf7-66rw-9f5r", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-257f0c0e8b5306fe", "level": "warning", "message": {"text": "Vulnerable dependency vite 6.4.1: GHSA-4w7w-66w2-5vf9"}, "properties": {"repobilityId": "8f492a912139007a", "scanner": "scanner-primary", "fingerprint": "257f0c0e8b5306fe", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-4w7w-66w2-5vf9", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/threejs-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e61d6a281d32426a", "level": "error", "message": {"text": "Vulnerable dependency vite 6.4.1: GHSA-fx2h-pf6j-xcff"}, "properties": {"repobilityId": "ea2c1060b30e2ff5", "scanner": "scanner-primary", "fingerprint": "e61d6a281d32426a", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-fx2h-pf6j-xcff", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/threejs-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c352ec90ac235ffb", "level": "error", "message": {"text": "Vulnerable dependency vite 6.4.1: GHSA-p9ff-h696-f583"}, "properties": {"repobilityId": "27aa331eba031f35", "scanner": "scanner-primary", "fingerprint": "c352ec90ac235ffb", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-p9ff-h696-f583", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/threejs-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f569b2fecd6a84cd", "level": "warning", "message": {"text": "Vulnerable dependency vite 6.4.1: GHSA-v6wh-96g9-6wx3"}, "properties": {"repobilityId": "ab7386e4ced67400", "scanner": "scanner-primary", "fingerprint": "f569b2fecd6a84cd", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v6wh-96g9-6wx3", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/threejs-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ab60190dbbccf0af", "level": "warning", "message": {"text": "Vulnerable dependency vite 7.3.1: GHSA-4w7w-66w2-5vf9"}, "properties": {"repobilityId": "e918f17f602550fb", "scanner": "scanner-primary", "fingerprint": "ab60190dbbccf0af", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-4w7w-66w2-5vf9", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/mcp-use-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-eb1e41517cb3b9b7", "level": "error", "message": {"text": "Vulnerable dependency vite 7.3.1: GHSA-fx2h-pf6j-xcff"}, "properties": {"repobilityId": "0c0fb8fcfc9a2711", "scanner": "scanner-primary", "fingerprint": "eb1e41517cb3b9b7", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-fx2h-pf6j-xcff", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/mcp-use-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c658c26bcf996874", "level": "error", "message": {"text": "Vulnerable dependency vite 7.3.1: GHSA-p9ff-h696-f583"}, "properties": {"repobilityId": "bc2f4b3a640a4eef", "scanner": "scanner-primary", "fingerprint": "c658c26bcf996874", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-p9ff-h696-f583", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/mcp-use-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-75f5d8336c1c0c78", "level": "warning", "message": {"text": "Vulnerable dependency vite 7.3.1: GHSA-v2wj-q39q-566r"}, "properties": {"repobilityId": "6218f4560d531ff5", "scanner": "scanner-primary", "fingerprint": "75f5d8336c1c0c78", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v2wj-q39q-566r", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/mcp-use-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dd33842e657a5b7c", "level": "warning", "message": {"text": "Vulnerable dependency vite 7.3.1: GHSA-v6wh-96g9-6wx3"}, "properties": {"repobilityId": "e94069e1f72ac15f", "scanner": "scanner-primary", "fingerprint": "dd33842e657a5b7c", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v6wh-96g9-6wx3", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/mcp-use-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dbd130a5ba53241f", "level": "warning", "message": {"text": "Vulnerable dependency vite 8.0.3: GHSA-4w7w-66w2-5vf9"}, "properties": {"repobilityId": "f55c88b067eb3406", "scanner": "scanner-primary", "fingerprint": "dbd130a5ba53241f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4w7w-66w2-5vf9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ea793561b342c075", "level": "error", "message": {"text": "Vulnerable dependency vite 8.0.3: GHSA-fx2h-pf6j-xcff"}, "properties": {"repobilityId": "dd78656c33927370", "scanner": "scanner-primary", "fingerprint": "ea793561b342c075", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-fx2h-pf6j-xcff"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b20e9c473a2067f7", "level": "error", "message": {"text": "Vulnerable dependency vite 8.0.3: GHSA-p9ff-h696-f583"}, "properties": {"repobilityId": "991708a48716e9e5", "scanner": "scanner-primary", "fingerprint": "b20e9c473a2067f7", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p9ff-h696-f583"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-743cefa6d647197e", "level": "warning", "message": {"text": "Vulnerable dependency vite 8.0.3: GHSA-v2wj-q39q-566r"}, "properties": {"repobilityId": "10a2c721fff850a8", "scanner": "scanner-primary", "fingerprint": "743cefa6d647197e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-v2wj-q39q-566r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ceaaaff01ad6ebc2", "level": "warning", "message": {"text": "Vulnerable dependency vite 8.0.3: GHSA-v6wh-96g9-6wx3"}, "properties": {"repobilityId": "46ebfb2ca8c990f9", "scanner": "scanner-primary", "fingerprint": "ceaaaff01ad6ebc2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-v6wh-96g9-6wx3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2524fda4bc7e9aba", "level": "warning", "message": {"text": "Vulnerable dependency langchain 1.2.0: GHSA-gr75-jv2w-4656"}, "properties": {"repobilityId": "e65b6c5217607fa5", "scanner": "scanner-primary", "fingerprint": "2524fda4bc7e9aba", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gr75-jv2w-4656"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/agent/pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-07d55afd5f6f7200", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 1.2.16: GHSA-926x-3r5x-gfhw"}, "properties": {"repobilityId": "781faadd96861c67", "scanner": "scanner-primary", "fingerprint": "07d55afd5f6f7200", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-926x-3r5x-gfhw"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fbd048ac41ed90e9", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 1.2.16: GHSA-pjwx-r37v-7724"}, "properties": {"repobilityId": "ad7374ddd4ba391d", "scanner": "scanner-primary", "fingerprint": "fbd048ac41ed90e9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pjwx-r37v-7724"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f76e564dc7eadece", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 1.2.16: GHSA-qh6h-p6c9-ff54"}, "properties": {"repobilityId": "5412eaaef7b1e29f", "scanner": "scanner-primary", "fingerprint": "f76e564dc7eadece", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-qh6h-p6c9-ff54"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2ab60797b4508d2e", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 1.2.16: PYSEC-2026-2193"}, "properties": {"repobilityId": "e98a9ecc968f53cb", "scanner": "scanner-primary", "fingerprint": "2ab60797b4508d2e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2193"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6de7f58fca8fdb46", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 1.2.16: PYSEC-2026-2563"}, "properties": {"repobilityId": "774239353f733347", "scanner": "scanner-primary", "fingerprint": "6de7f58fca8fdb46", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2563"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b5c9716a00053954", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 1.2.16: PYSEC-2026-2564"}, "properties": {"repobilityId": "0136aadfd2c1f0b4", "scanner": "scanner-primary", "fingerprint": "b5c9716a00053954", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2564"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-63fd260abd1047ec", "level": "warning", "message": {"text": "Vulnerable dependency langchain-openai 1.1.9: GHSA-r7w7-9xr2-qq2r"}, "properties": {"repobilityId": "864b0db8d9303581", "scanner": "scanner-primary", "fingerprint": "63fd260abd1047ec", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-r7w7-9xr2-qq2r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4954ac89b0e3becf", "level": "warning", "message": {"text": "Vulnerable dependency langchain-openai 1.1.9: PYSEC-2026-76"}, "properties": {"repobilityId": "b0bc55f57c885e5e", "scanner": "scanner-primary", "fingerprint": "4954ac89b0e3becf", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-76"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-37ef992c979b02fd", "level": "error", "message": {"text": "Vulnerable dependency langsmith 0.6.6: GHSA-3644-q5cj-c5c7"}, "properties": {"repobilityId": "1823177fb316d814", "scanner": "scanner-primary", "fingerprint": "37ef992c979b02fd", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3644-q5cj-c5c7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d1a391a57e2ede2c", "level": "warning", "message": {"text": "Vulnerable dependency langsmith 0.6.6: GHSA-f4xh-w4cj-qxq8"}, "properties": {"repobilityId": "dc8875d210902239", "scanner": "scanner-primary", "fingerprint": "d1a391a57e2ede2c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-f4xh-w4cj-qxq8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7cbce9f5f206fd7f", "level": "warning", "message": {"text": "Vulnerable dependency langsmith 0.6.6: GHSA-rr7j-v2q5-chgv"}, "properties": {"repobilityId": "0da656946e131f00", "scanner": "scanner-primary", "fingerprint": "7cbce9f5f206fd7f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-rr7j-v2q5-chgv"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cf37968f1572ae8a", "level": "warning", "message": {"text": "Vulnerable dependency langsmith 0.6.6: PYSEC-2026-2583"}, "properties": {"repobilityId": "dac17ce4742c17f6", "scanner": "scanner-primary", "fingerprint": "cf37968f1572ae8a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2583"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-603754b5f32709b3", "level": "warning", "message": {"text": "Vulnerable dependency click 8.3.2: PYSEC-2026-2132"}, "properties": {"repobilityId": "3be3f43004e2ed5b", "scanner": "scanner-primary", "fingerprint": "603754b5f32709b3", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2132"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-62a355125ec37cb1", "level": "warning", "message": {"text": "Vulnerable dependency langchain 1.2.15: GHSA-gr75-jv2w-4656"}, "properties": {"repobilityId": "91efc9da6acea41a", "scanner": "scanner-primary", "fingerprint": "62a355125ec37cb1", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gr75-jv2w-4656"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/agent/pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-873041286d84052a", "level": "warning", "message": {"text": "Vulnerable dependency langchain-anthropic 1.4.0: GHSA-gr75-jv2w-4656"}, "properties": {"repobilityId": "3b238720d211c2cd", "scanner": "scanner-primary", "fingerprint": "873041286d84052a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gr75-jv2w-4656"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8ad122675f99df3c", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 1.2.29: GHSA-pjwx-r37v-7724"}, "properties": {"repobilityId": "0e98f708e7091ad2", "scanner": "scanner-primary", "fingerprint": "8ad122675f99df3c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pjwx-r37v-7724"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1219dc9c152abde6", "level": "warning", "message": {"text": "Vulnerable dependency langchain-core 1.2.29: PYSEC-2026-2564"}, "properties": {"repobilityId": "567a52b11a263d1a", "scanner": "scanner-primary", "fingerprint": "1219dc9c152abde6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2564"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-63add6afe5d1e03b", "level": "error", "message": {"text": "Vulnerable dependency langsmith 0.7.31: GHSA-3644-q5cj-c5c7"}, "properties": {"repobilityId": "37ca7c8547743415", "scanner": "scanner-primary", "fingerprint": "63add6afe5d1e03b", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3644-q5cj-c5c7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3dbfe11eaeebbda8", "level": "warning", "message": {"text": "Vulnerable dependency langsmith 0.7.31: GHSA-f4xh-w4cj-qxq8"}, "properties": {"repobilityId": "94a8d34ede261db4", "scanner": "scanner-primary", "fingerprint": "3dbfe11eaeebbda8", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-f4xh-w4cj-qxq8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a8356a4e96f23267", "level": "warning", "message": {"text": "Vulnerable dependency pip 26.0.1: GHSA-58qw-9mgm-455v"}, "properties": {"repobilityId": "6ae0de0bf5edbeb7", "scanner": "scanner-primary", "fingerprint": "a8356a4e96f23267", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-58qw-9mgm-455v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c0f3702558ebe4cb", "level": "warning", "message": {"text": "Vulnerable dependency pip 26.0.1: GHSA-jp4c-xjxw-mgf9"}, "properties": {"repobilityId": "90651863a0e09648", "scanner": "scanner-primary", "fingerprint": "c0f3702558ebe4cb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jp4c-xjxw-mgf9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fcbd008b42fa53ea", "level": "warning", "message": {"text": "Vulnerable dependency pip 26.0.1: GHSA-wf93-45jw-7689"}, "properties": {"repobilityId": "8de4acb4a12b8bde", "scanner": "scanner-primary", "fingerprint": "fcbd008b42fa53ea", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wf93-45jw-7689"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ca3021d1de9eae0d", "level": "warning", "message": {"text": "Vulnerable dependency pip 26.0.1: PYSEC-2026-196"}, "properties": {"repobilityId": "d33f834a742e064d", "scanner": "scanner-primary", "fingerprint": "ca3021d1de9eae0d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-196"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9607ee11b13a72cd", "level": "warning", "message": {"text": "Vulnerable dependency pip 26.0.1: PYSEC-2026-2875"}, "properties": {"repobilityId": "23a4b18336a84be9", "scanner": "scanner-primary", "fingerprint": "9607ee11b13a72cd", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2875"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ed1450e28dd608d7", "level": "warning", "message": {"text": "Vulnerable dependency pip 26.0.1: PYSEC-2026-2876"}, "properties": {"repobilityId": "55dcf2b097e3ffde", "scanner": "scanner-primary", "fingerprint": "ed1450e28dd608d7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2876"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/generative-ui-starter-project/agent/uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cdb994d1530edf58", "level": "warning", "message": {"text": "Dependency @ai-sdk/openai is two or more major versions behind"}, "properties": {"repobilityId": "7e1fa72262477548", "scanner": "scanner-primary", "fingerprint": "cdb994d1530edf58", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-dashboard-canvas-agent/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fcac91b6db817f4f", "level": "note", "message": {"text": "Dependency @ai-sdk/openai is a major version behind"}, "properties": {"repobilityId": "bbcd45e171ec5bca", "scanner": "scanner-primary", "fingerprint": "fcac91b6db817f4f", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "generative_ui_agents/ai-mcp-app-builder/apps/web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2fda694469daaf64", "level": "note", "message": {"text": "124 backend endpoints not called by scanned frontend"}, "properties": {"repobilityId": "3c8e96670c5e1f9f", "scanner": "scanner-primary", "fingerprint": "2fda694469daaf64", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}