Skip to content

Conversation

@Abraham-Flutterwave
Copy link
Contributor

image

@github-actions
Copy link

github-actions bot commented Sep 18, 2025

Logo
Checkmarx One – Scan Summary & Details583dd2fe-3cfb-4dab-8bb2-96fadb177727

New Issues (5)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
HIGH CVE-2025-58754 Npm-axios-0.21.4
detailsRecommended version: 1.12.0
Description: Axios is a promise based HTTP client for the browser and Node.js. When Axios prior to version 1.12.0 runs on Node.js and is given a URL with the "d...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: %2BVU1XPZv6quMbqggzCzF4SzwLrt8UIU%2FnV%2F6L5lPmxM%3D
Vulnerable Package
HIGH CVE-2025-58754 Npm-axios-0.25.0
detailsRecommended version: 1.12.0
Description: Axios is a promise based HTTP client for the browser and Node.js. When Axios prior to version 1.12.0 runs on Node.js and is given a URL with the "d...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: yhtZPWB%2FUBR%2FNiGimg636oFTkqhbZJ%2FSUq6uXlANfLs%3D
Vulnerable Package
LOW CVE-2025-58751 Npm-sirv-1.0.19
detailsRecommended version: 3.0.2
Description: Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 92KegvPyQ5x%2FRHbE4jAy%2BHODAMKKRANWgHvzjmOv29g%3D
Vulnerable Package
LOW CVE-2025-58751 Npm-vite-4.2.1
detailsRecommended version: 5.4.20
Description: Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: GTDT8JVvDOXm5T1b27xUYdSy06KZgvaDsQMf6k6%2FSiI%3D
Vulnerable Package
LOW CVE-2025-58752 Npm-vite-4.2.1
detailsRecommended version: 5.4.20
Description: Vite is a frontend tooling framework for JavaScript. In Vite versions through 5.4.19, 6.x through 6.3.5, 7.0.x through 7.0.6 and 7.1.x through 7.1....
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Eh1zWFhR%2BibSJ%2BzejqgzC1XlpzQ2byWVp3BEvwvtRNY%3D
Vulnerable Package
Fixed Issues (1)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
MEDIUM CVE-2025-7969 Npm-markdown-it-12.3.2
Policy Management Violations (1)
Policy Name Rule(s) Break Build
Quality Gate - v3 Open Source Vulnerable Package true

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants