minimatch <10.2.1
Severity: high
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern - GHSA-3ppc-4f35-3m26
It appears that this application depends on "minimatch" 3.1.2 which is now listed as having a known vulnerability. I did try overriding the package to the fixed version but the API has changed and breaks functionality.
See above for the advisory and CVE: CVE-2026-26996
minimatch <10.2.1
Severity: high
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern - GHSA-3ppc-4f35-3m26
It appears that this application depends on "minimatch" 3.1.2 which is now listed as having a known vulnerability. I did try overriding the package to the fixed version but the API has changed and breaks functionality.
See above for the advisory and CVE: CVE-2026-26996