Skip to content

UID2-6731: Update flatted to 3.4.0 to fix CVE-2026-32141#180

Closed
swibi-ttd wants to merge 1 commit intomainfrom
swi-UID2-6731-fix-flatted-vuln
Closed

UID2-6731: Update flatted to 3.4.0 to fix CVE-2026-32141#180
swibi-ttd wants to merge 1 commit intomainfrom
swi-UID2-6731-fix-flatted-vuln

Conversation

@swibi-ttd
Copy link
Contributor

@swibi-ttd swibi-ttd commented Mar 15, 2026

Summary

  • Update flatted from 3.3.3 to 3.4.0 to fix CVE-2026-32141 (HIGH severity)
  • Vulnerability: Unbounded recursion DoS in parse() revive phase
  • Affected lockfiles:
    • web-integrations/google-secure-signals/react-client-side/package-lock.json
    • web-integrations/javascript-sdk/react-client-side/package-lock.json

Test plan

  • CI pipeline passes

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@swibi-ttd
Copy link
Contributor Author

This was fixed in #181

@swibi-ttd swibi-ttd closed this Mar 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant