chore(deps): update dependency nexmo to v2 (main) #26
Security Report
You have successfully remediated 14 vulnerabilities, but introduced 6 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Exploit Maturity | EPSS | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|---|---|
CVE-2025-7783Path to dependency file: /package.json Path to vulnerable library: /node_modules/form-data/package.json Dependency Hierarchy: -> nexmo-2.9.1.tgz (Root Library) -> request-2.88.2.tgz -> ❌ form-data-2.3.3.tgz (Vulnerable Library) |
8.7 | Not Defined | 0.1% | Transitive form-data-2.3.3.tgz |
nexmo-2.9.1.tgz | Transitive 2.5.4 |
None | ||
CVE-2023-26136Path to dependency file: /package.json Path to vulnerable library: /node_modules/tough-cookie/package.json Dependency Hierarchy: -> nexmo-2.9.1.tgz (Root Library) -> request-2.88.2.tgz -> ❌ tough-cookie-2.5.0.tgz (Vulnerable Library) |
6.5 | Proof of concept | 6.4% | Transitive tough-cookie-2.5.0.tgz |
nexmo-2.9.1.tgz | Transitive 4.1.3 |
None | ||
CVE-2022-23540Path to dependency file: /package.json Path to vulnerable library: /node_modules/jsonwebtoken/package.json Dependency Hierarchy: -> nexmo-2.9.1.tgz (Root Library) -> ❌ jsonwebtoken-8.5.1.tgz (Vulnerable Library) |
6.4 | Not Defined | 0.0% | Transitive jsonwebtoken-8.5.1.tgz |
nexmo-2.9.1.tgz | Transitive 9.0.0 |
None | ||
CVE-2023-28155Path to dependency file: /package.json Path to vulnerable library: /node_modules/request/package.json Dependency Hierarchy: -> nexmo-2.9.1.tgz (Root Library) -> ❌ request-2.88.2.tgz (Vulnerable Library) |
6.1 | Not Defined | 0.6% | Transitive request-2.88.2.tgz |
nexmo-2.9.1.tgz | Transitive @cypress/request - 3.0.0 |
None | ||
CVE-2022-23539Path to dependency file: /package.json Path to vulnerable library: /node_modules/jsonwebtoken/package.json Dependency Hierarchy: -> nexmo-2.9.1.tgz (Root Library) -> ❌ jsonwebtoken-8.5.1.tgz (Vulnerable Library) |
5.9 | Not Defined | 0.1% | Transitive jsonwebtoken-8.5.1.tgz |
nexmo-2.9.1.tgz | Transitive 9.0.0 |
None | ||
CVE-2022-23541Path to dependency file: /package.json Path to vulnerable library: /node_modules/jsonwebtoken/package.json Dependency Hierarchy: -> nexmo-2.9.1.tgz (Root Library) -> ❌ jsonwebtoken-8.5.1.tgz (Vulnerable Library) |
5.0 | Not Defined | 0.1% | Transitive jsonwebtoken-8.5.1.tgz |
nexmo-2.9.1.tgz | Transitive 9.0.0 |
None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2024-43796 | express-4.18.2.tgz |
| CVE-2024-29041 | express-4.18.2.tgz |
| CVE-2020-36604 | hoek-2.16.3.tgz |
| CVE-2025-65945 | jws-3.2.2.tgz |
| CVE-2022-23539 | jsonwebtoken-7.4.3.tgz |
| CVE-2026-2391 | qs-6.11.0.tgz |
| CVE-2022-23541 | jsonwebtoken-7.4.3.tgz |
| CVE-2024-47764 | cookie-0.5.0.tgz |
| CVE-2024-52798 | path-to-regexp-0.1.7.tgz |
| CVE-2025-15284 | qs-6.11.0.tgz |
| CVE-2022-23540 | jsonwebtoken-7.4.3.tgz |
| CVE-2024-45590 | body-parser-1.20.1.tgz |
| CVE-2024-45296 | path-to-regexp-0.1.7.tgz |
| CVE-2026-4867 | path-to-regexp-0.1.7.tgz |
Base branch total remaining vulnerabilities: 14
Base branch commit: null
Total libraries scanned: 127
Scan token: 9eeb7c05b49643d9bfddfa416fe4273f