Skip to content

CVE-2026-33671;CVE-2026-33672 - @oclif/plugin-plugins uses a vulnerable version of picomatch via npm #1303

@Amndeep7

Description

@Amndeep7

The npm project is aware of the vulnerability: npm/cli#9162

There is no guarantee of a backport to the 10.x line which is what this project is currently using: https://github.com/npm/cli/wiki/Support-Policy#security-issues--backports

This project will likely need to update to using npm v11.x whenever a fix appears.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions