Update dependency @crowdin/crowdin-api-client to v1.33.2 - #4
Security Report
You have successfully remediated 18 vulnerabilities, but introduced 17 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|---|
CVE-941441-362681Path to dependency file: /website/package.json Path to vulnerable library: /website/package.json Dependency Hierarchy: -> core-2.4.0.tgz (Root Library) -> shelljs-0.8.5.tgz -> glob-7.2.3.tgz -> ❌ once-1.4.0.tgz (Vulnerable Library) |
9.8 | Transitive once-1.4.0.tgz |
core-2.4.0.tgz | None | ||
CVE-666308-417910Path to dependency file: /website/package.json Path to vulnerable library: /website/package.json Dependency Hierarchy: -> core-2.4.0.tgz (Root Library) -> babel-plugin-dynamic-import-node-2.3.3.tgz -> object.assign-4.1.5.tgz -> ❌ has-symbols-1.1.0.tgz (Vulnerable Library) |
9.8 | Transitive has-symbols-1.1.0.tgz |
core-2.4.0.tgz | None | ||
CVE-2026-39834Path to dependency file: /v2/go.mod Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@v/v0.23.0.mod Dependency Hierarchy: -> github.com/Go-git/go-git/v5-v5.11.0 (Root Library) -> ❌ golang.org/x/crypto-v0.23.0 (Vulnerable Library) |
9.1 | Transitive golang.org/x/crypto-v0.23.0 |
github.com/Go-git/go-git/v5-v5.11.0 | Transitive v0.52.0 |
None | |
CVE-2026-39831Path to dependency file: /v2/go.mod Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@v/v0.23.0.mod Dependency Hierarchy: -> github.com/Go-git/go-git/v5-v5.11.0 (Root Library) -> ❌ golang.org/x/crypto-v0.23.0 (Vulnerable Library) |
9.1 | Transitive golang.org/x/crypto-v0.23.0 |
github.com/Go-git/go-git/v5-v5.11.0 | Transitive v0.52.0 |
None | |
CVE-2026-44728Path to dependency file: /website/package.json Path to vulnerable library: /website/package.json Dependency Hierarchy: -> core-2.4.0.tgz (Root Library) -> preset-env-7.24.7.tgz -> ❌ plugin-transform-modules-systemjs-7.24.7.tgz (Vulnerable Library) |
8.2 | Transitive plugin-transform-modules-systemjs-7.24.7.tgz |
core-2.4.0.tgz | Transitive 7.29.4 |
None | |
CVE-2026-44973Path to dependency file: /v2/go.mod Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/github.com/go-git/go-billy/v5/@v/v5.5.0.mod Dependency Hierarchy: -> github.com/Go-git/go-git/v5-v5.11.0 (Root Library) -> ❌ github.com/go-git/go-Billy/v5-v5.5.0 (Vulnerable Library) |
8.1 | Transitive github.com/go-git/go-Billy/v5-v5.5.0 |
github.com/Go-git/go-git/v5-v5.11.0 | None | ||
CVE-2026-46599Path to dependency file: /v2/go.mod Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/image/@v/v0.12.0.mod Dependency Hierarchy: -> github.com/leaanthony/winicon-v1.0.0 (Root Library) -> ❌ golang.org/x/image-v0.12.0 (Vulnerable Library) |
7.5 | Transitive golang.org/x/image-v0.12.0 |
github.com/leaanthony/winicon-v1.0.0 | Transitive golang.org/x/image - v0.41.0 |
None | |
CVE-2026-46599Path to dependency file: /v2/go.mod Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/image/@v/v0.12.0.mod Dependency Hierarchy: -> github.com/tc-hib/winres-v0.2.1 (Root Library) -> ❌ golang.org/x/image-v0.12.0 (Vulnerable Library) |
7.5 | Transitive golang.org/x/image-v0.12.0 |
github.com/tc-hib/winres-v0.2.1 | Transitive golang.org/x/image - v0.41.0 |
None | |
CVE-2026-46597Path to dependency file: /v2/go.mod Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@v/v0.23.0.mod Dependency Hierarchy: -> github.com/Go-git/go-git/v5-v5.11.0 (Root Library) -> ❌ golang.org/x/crypto-v0.23.0 (Vulnerable Library) |
7.5 | Transitive golang.org/x/crypto-v0.23.0 |
github.com/Go-git/go-git/v5-v5.11.0 | Transitive v0.52.0 |
None | |
CVE-2026-44740Path to dependency file: /v2/go.mod Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/github.com/go-git/go-billy/v5/@v/v5.5.0.mod Dependency Hierarchy: -> github.com/Go-git/go-git/v5-v5.11.0 (Root Library) -> ❌ github.com/go-git/go-Billy/v5-v5.5.0 (Vulnerable Library) |
6.5 | Transitive github.com/go-git/go-Billy/v5-v5.5.0 |
github.com/Go-git/go-git/v5-v5.11.0 | None | ||
CVE-2026-1229Path to dependency file: /v2/go.mod Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/github.com/cloudflare/circl/@v/v1.3.7.mod Dependency Hierarchy: -> github.com/Go-git/go-git/v5-v5.11.0 (Root Library) -> github.com/ProtonMail/go-crypto-v0.0.0-20230828082145-3c4c8a2d2371 -> ❌ github.com/Cloudflare/circl-v1.3.7 (Vulnerable Library) |
6.5 | Transitive github.com/Cloudflare/circl-v1.3.7 |
github.com/Go-git/go-git/v5-v5.11.0 | None | ||
CVE-2025-27789Path to dependency file: /website/package.json Path to vulnerable library: /website/package.json Dependency Hierarchy: -> core-2.4.0.tgz (Root Library) -> ❌ runtime-corejs3-7.24.7.tgz (Vulnerable Library) |
6.2 | Transitive runtime-corejs3-7.24.7.tgz |
core-2.4.0.tgz | Transitive 7.26.10 |
None | |
CVE-2025-27789Path to dependency file: /website/package.json Path to vulnerable library: /website/package.json Dependency Hierarchy: -> core-2.4.0.tgz (Root Library) -> core-7.24.7.tgz -> ❌ helpers-7.24.7.tgz (Vulnerable Library) |
6.2 | Transitive helpers-7.24.7.tgz |
core-2.4.0.tgz | Transitive 7.26.10 |
None | |
CVE-2025-27789Path to dependency file: /website/package.json Path to vulnerable library: /website/package.json Dependency Hierarchy: -> core-2.4.0.tgz (Root Library) -> ❌ runtime-7.24.7.tgz (Vulnerable Library) |
6.2 | Transitive runtime-7.24.7.tgz |
core-2.4.0.tgz | Transitive 7.26.10 |
None | |
CVE-2026-46598Path to dependency file: /v2/go.mod Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@v/v0.23.0.mod Dependency Hierarchy: -> github.com/Go-git/go-git/v5-v5.11.0 (Root Library) -> ❌ golang.org/x/crypto-v0.23.0 (Vulnerable Library) |
5.3 | Transitive golang.org/x/crypto-v0.23.0 |
github.com/Go-git/go-git/v5-v5.11.0 | Transitive v0.52.0 |
None | |
CVE-2026-33809Path to dependency file: /v2/go.mod Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/image/@v/v0.12.0.mod Dependency Hierarchy: -> github.com/leaanthony/winicon-v1.0.0 (Root Library) -> ❌ golang.org/x/image-v0.12.0 (Vulnerable Library) |
5.3 | Transitive golang.org/x/image-v0.12.0 |
github.com/leaanthony/winicon-v1.0.0 | Transitive v0.38.0 |
None | |
CVE-2026-33809Path to dependency file: /v2/go.mod Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/image/@v/v0.12.0.mod Dependency Hierarchy: -> github.com/tc-hib/winres-v0.2.1 (Root Library) -> ❌ golang.org/x/image-v0.12.0 (Vulnerable Library) |
5.3 | Transitive golang.org/x/image-v0.12.0 |
github.com/tc-hib/winres-v0.2.1 | Transitive v0.38.0 |
None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2026-42039 | axios-1.7.2.tgz |
| CVE-2026-42033 | axios-1.7.2.tgz |
| CVE-2026-25639 | axios-1.7.2.tgz |
| CVE-2026-44487 | axios-1.7.2.tgz |
| CVE-2026-44496 | axios-1.7.2.tgz |
| CVE-2025-7783 | form-data-4.0.0.tgz |
| CVE-2026-44488 | axios-1.7.2.tgz |
| CVE-2026-42264 | axios-1.7.2.tgz |
| CVE-2024-39338 | axios-1.7.2.tgz |
| CVE-2026-42037 | axios-1.7.2.tgz |
| CVE-2025-58754 | axios-1.7.2.tgz |
| CVE-2025-62718 | axios-1.7.2.tgz |
| CVE-2026-42043 | axios-1.7.2.tgz |
| CVE-2026-39865 | axios-1.7.2.tgz |
| CVE-2026-40175 | axios-1.7.2.tgz |
| CVE-2025-27152 | axios-1.7.2.tgz |
| CVE-2026-67316 | axios-1.7.2.tgz |
| CVE-2026-44486 | axios-1.7.2.tgz |
Base branch total remaining vulnerabilities: 132
Base branch commit: null
Total libraries scanned: 1270
Scan token: d330c6e2dc9f412cb7c03b542a30808d