chore(deps): update dependency express to v4.18.3 #63
Security Report
You have successfully remediated 3 vulnerabilities, but introduced 16 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|---|
CVE-2026-4867Path to dependency file: /app-to-phone-kotlin/package.json Path to vulnerable library: /app-to-phone-kotlin/package.json,/app-to-phone-swift/package.json,/app-to-app-swift/package.json,/phone-to-app-kotlin/package.json Dependency Hierarchy: -> express-4.21.0.tgz (Root Library) -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library) |
7.5 | Transitive path-to-regexp-0.1.10.tgz |
express-4.21.0.tgz | Transitive path-to-regexp - 0.1.13 |
None | |
CVE-2026-4867Path to dependency file: /app-to-phone-kotlin/package.json Path to vulnerable library: /app-to-phone-kotlin/package.json,/app-to-phone-swift/package.json,/app-to-app-swift/package.json,/phone-to-app-kotlin/package.json Dependency Hierarchy: -> express-4.21.1.tgz (Root Library) -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library) |
7.5 | Transitive path-to-regexp-0.1.10.tgz |
express-4.21.1.tgz | Transitive path-to-regexp - 0.1.13 |
None | |
CVE-2026-4867Path to dependency file: /app-to-phone-kotlin/package.json Path to vulnerable library: /app-to-phone-kotlin/package.json,/app-to-phone-swift/package.json,/app-to-app-swift/package.json,/phone-to-app-kotlin/package.json Dependency Hierarchy: -> express-4.20.0.tgz (Root Library) -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library) |
7.5 | Transitive path-to-regexp-0.1.10.tgz |
express-4.20.0.tgz | Transitive path-to-regexp - 0.1.13 |
None | |
CVE-2026-27904Path to dependency file: /app-to-phone-js/package.json Path to vulnerable library: /app-to-phone-js/package.json,/app-to-app-js/package.json,/phone-to-app-js/package.json Dependency Hierarchy: -> client-sdk-2.0.0.tgz (Root Library) -> typedoc-plugin-missing-exports-2.2.0.tgz -> typedoc-0.25.12.tgz -> ❌ minimatch-9.0.3.tgz (Vulnerable Library) |
7.5 | Transitive minimatch-9.0.3.tgz |
client-sdk-2.0.0.tgz | Transitive 9.0.7 |
#72 | |
CVE-2026-27903Path to dependency file: /app-to-phone-js/package.json Path to vulnerable library: /app-to-phone-js/package.json,/app-to-app-js/package.json,/phone-to-app-js/package.json Dependency Hierarchy: -> client-sdk-2.0.0.tgz (Root Library) -> typedoc-plugin-missing-exports-2.2.0.tgz -> typedoc-0.25.12.tgz -> ❌ minimatch-9.0.3.tgz (Vulnerable Library) |
7.5 | Transitive minimatch-9.0.3.tgz |
client-sdk-2.0.0.tgz | Transitive https://github.com/isaacs/minimatch.git - v3.1.3,https://github.com/isaacs/minimatch.git - v4.2.5,https://github.com/isaacs/minimatch.git - v6.2.2,https://github.com/isaacs/minimatch.git - v10.2.3,https://github.com/isaacs/minimatch.git - v5.1.8,https://github.com/isaacs/minimatch.git - v9.0.7,https://github.com/isaacs/minimatch.git - v7.4.8,https://github.com/isaacs/minimatch.git - v8.0.6 |
#72 | |
CVE-2026-26996Path to dependency file: /app-to-phone-js/package.json Path to vulnerable library: /app-to-phone-js/package.json,/app-to-app-js/package.json,/phone-to-app-js/package.json Dependency Hierarchy: -> client-sdk-2.0.0.tgz (Root Library) -> typedoc-plugin-missing-exports-2.2.0.tgz -> typedoc-0.25.12.tgz -> ❌ minimatch-9.0.3.tgz (Vulnerable Library) |
7.5 | Transitive minimatch-9.0.3.tgz |
client-sdk-2.0.0.tgz | Transitive https://github.com/isaacs/minimatch.git - v10.2.1,https://github.com/isaacs/minimatch.git - v5.1.7,https://github.com/isaacs/minimatch.git - v4.2.4,https://github.com/isaacs/minimatch.git - v3.1.3,https://github.com/isaacs/minimatch.git - v8.0.5,https://github.com/isaacs/minimatch.git - v9.0.6,https://github.com/isaacs/minimatch.git - v6.2.1,https://github.com/isaacs/minimatch.git - v7.4.7 |
#72 | |
CVE-2024-52798Path to dependency file: /app-to-phone-kotlin/package.json Path to vulnerable library: /app-to-phone-kotlin/package.json,/app-to-phone-swift/package.json,/app-to-app-swift/package.json,/phone-to-app-kotlin/package.json Dependency Hierarchy: -> express-4.21.0.tgz (Root Library) -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library) |
7.5 | Transitive path-to-regexp-0.1.10.tgz |
express-4.21.0.tgz | Transitive 0.1.12 |
None | |
CVE-2024-52798Path to dependency file: /app-to-phone-kotlin/package.json Path to vulnerable library: /app-to-phone-kotlin/package.json,/app-to-phone-swift/package.json,/app-to-app-swift/package.json,/phone-to-app-kotlin/package.json Dependency Hierarchy: -> express-4.21.1.tgz (Root Library) -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library) |
7.5 | Transitive path-to-regexp-0.1.10.tgz |
express-4.21.1.tgz | Transitive 0.1.12 |
None | |
CVE-2024-52798Path to dependency file: /app-to-phone-kotlin/package.json Path to vulnerable library: /app-to-phone-kotlin/package.json,/app-to-phone-swift/package.json,/app-to-app-swift/package.json,/phone-to-app-kotlin/package.json Dependency Hierarchy: -> express-4.20.0.tgz (Root Library) -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library) |
7.5 | Transitive path-to-regexp-0.1.10.tgz |
express-4.20.0.tgz | Transitive 0.1.12 |
None | |
CVE-2024-45590Path to dependency file: /phone-to-app-swift/package.json Path to vulnerable library: /phone-to-app-swift/package.json Dependency Hierarchy: -> express-4.18.3.tgz (Root Library) -> ❌ body-parser-1.20.2.tgz (Vulnerable Library) |
7.5 | Transitive body-parser-1.20.2.tgz |
express-4.18.3.tgz | Transitive 1.20.3 |
None | |
CVE-2026-33750Path to dependency file: /phone-to-app-js/package.json Path to vulnerable library: /phone-to-app-js/package.json,/app-to-app-js/package.json,/app-to-phone-js/package.json Dependency Hierarchy: -> client-sdk-2.0.0.tgz (Root Library) -> typedoc-plugin-missing-exports-2.2.0.tgz -> typedoc-0.25.12.tgz -> minimatch-9.0.3.tgz -> ❌ brace-expansion-2.0.1.tgz (Vulnerable Library) |
6.5 | Transitive brace-expansion-2.0.1.tgz |
client-sdk-2.0.0.tgz | Transitive https://github.com/juliangruber/brace-expansion.git - v2.0.3,https://github.com/juliangruber/brace-expansion.git - v3.0.2,https://github.com/juliangruber/brace-expansion.git - v5.0.5,https://github.com/juliangruber/brace-expansion.git - v1.1.13 |
#72 | |
CVE-2024-29041Path to dependency file: /phone-to-app-swift/package.json Path to vulnerable library: /phone-to-app-swift/package.json Dependency Hierarchy: -> ❌ express-4.18.3.tgz (Vulnerable Library) |
6.1 | Direct express-4.18.3.tgz |
express-4.18.3.tgz | 4.19.0 | None | |
CVE-2024-47764Path to dependency file: /app-to-app-swift/package.json Path to vulnerable library: /app-to-app-swift/package.json,/phone-to-app-kotlin/package.json,/app-to-phone-swift/package.json Dependency Hierarchy: -> express-4.21.0.tgz (Root Library) -> ❌ cookie-0.6.0.tgz (Vulnerable Library) |
5.3 | Transitive cookie-0.6.0.tgz |
express-4.21.0.tgz | Transitive 0.7.0 |
None | |
CVE-2024-47764Path to dependency file: /app-to-app-swift/package.json Path to vulnerable library: /app-to-app-swift/package.json,/phone-to-app-kotlin/package.json,/app-to-phone-swift/package.json Dependency Hierarchy: -> express-4.20.0.tgz (Root Library) -> ❌ cookie-0.6.0.tgz (Vulnerable Library) |
5.3 | Transitive cookie-0.6.0.tgz |
express-4.20.0.tgz | Transitive 0.7.0 |
None | |
CVE-2024-43796Path to dependency file: /phone-to-app-swift/package.json Path to vulnerable library: /phone-to-app-swift/package.json Dependency Hierarchy: -> ❌ express-4.18.3.tgz (Vulnerable Library) |
5.0 | Direct express-4.18.3.tgz |
express-4.18.3.tgz | 4.20.0 | None | |
CVE-2025-5889Path to dependency file: /phone-to-app-js/package.json Path to vulnerable library: /phone-to-app-js/package.json,/app-to-app-js/package.json,/app-to-phone-js/package.json Dependency Hierarchy: -> client-sdk-2.0.0.tgz (Root Library) -> typedoc-plugin-missing-exports-2.2.0.tgz -> typedoc-0.25.12.tgz -> minimatch-9.0.3.tgz -> ❌ brace-expansion-2.0.1.tgz (Vulnerable Library) |
3.1 | Transitive brace-expansion-2.0.1.tgz |
client-sdk-2.0.0.tgz | Transitive 2.0.2 |
#72 |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2024-43796 | express-4.18.2.tgz |
| CVE-2024-29041 | express-4.18.2.tgz |
| CVE-2024-45590 | body-parser-1.20.1.tgz |
Base branch total remaining vulnerabilities: 25
Base branch commit: null
Total libraries scanned: 363
Scan token: 7d4e791d3aa747eb824e6faa57fe0cea