Skip to content

Update dependency @crowdin/crowdin-api-client to v1.33.2#4

Open
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/crowdin-crowdin-api-client-1.x-lockfile
Open

Update dependency @crowdin/crowdin-api-client to v1.33.2#4
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/crowdin-crowdin-api-client-1.x-lockfile

Update dependency @crowdin/crowdin-api-client to v1.33.2

0917ee4
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Jun 23, 2026 in 3m 17s

Security Report

You have successfully remediated 8 vulnerabilities, but introduced 6 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-941441-362681

Path to dependency file: /website/package.json

Path to vulnerable library: /website/package.json

Dependency Hierarchy:

-> core-2.4.0.tgz (Root Library)

   -> shelljs-0.8.5.tgz

     -> glob-7.2.3.tgz

       -> ❌ once-1.4.0.tgz (Vulnerable Library)

Critical 9.8 Transitive once-1.4.0.tgz core-2.4.0.tgz None
CVE-666308-417910

Path to dependency file: /website/package.json

Path to vulnerable library: /website/package.json

Dependency Hierarchy:

-> core-2.4.0.tgz (Root Library)

   -> babel-plugin-dynamic-import-node-2.3.3.tgz

     -> object.assign-4.1.5.tgz

       -> ❌ has-symbols-1.1.0.tgz (Vulnerable Library)

Critical 9.8 Transitive has-symbols-1.1.0.tgz core-2.4.0.tgz None
CVE-2026-44728

Path to dependency file: /website/package.json

Path to vulnerable library: /website/package.json

Dependency Hierarchy:

-> core-2.4.0.tgz (Root Library)

   -> preset-env-7.24.7.tgz

     -> ❌ plugin-transform-modules-systemjs-7.24.7.tgz (Vulnerable Library)

High 8.2 Transitive plugin-transform-modules-systemjs-7.24.7.tgz core-2.4.0.tgz Transitive 7.29.4 None
CVE-2025-27789

Path to dependency file: /website/package.json

Path to vulnerable library: /website/package.json

Dependency Hierarchy:

-> core-2.4.0.tgz (Root Library)

   -> ❌ runtime-corejs3-7.24.7.tgz (Vulnerable Library)

Medium 6.2 Transitive runtime-corejs3-7.24.7.tgz core-2.4.0.tgz Transitive 7.26.10 None
CVE-2025-27789

Path to dependency file: /website/package.json

Path to vulnerable library: /website/package.json

Dependency Hierarchy:

-> core-2.4.0.tgz (Root Library)

   -> ❌ runtime-7.24.7.tgz (Vulnerable Library)

Medium 6.2 Transitive runtime-7.24.7.tgz core-2.4.0.tgz Transitive 7.26.10 None
CVE-2025-27789

Path to dependency file: /website/package.json

Path to vulnerable library: /website/package.json

Dependency Hierarchy:

-> core-2.4.0.tgz (Root Library)

   -> core-7.24.7.tgz

     -> ❌ helpers-7.24.7.tgz (Vulnerable Library)

Medium 6.2 Transitive helpers-7.24.7.tgz core-2.4.0.tgz Transitive 7.26.10 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2026-40175 axios-1.7.2.tgz
CVE-2026-25639 axios-1.7.2.tgz
CVE-2025-27152 axios-1.7.2.tgz
CVE-2025-7783 form-data-4.0.0.tgz
CVE-2024-39338 axios-1.7.2.tgz
CVE-2025-58754 axios-1.7.2.tgz
CVE-2025-62718 axios-1.7.2.tgz
CVE-2026-39865 axios-1.7.2.tgz

Base branch total remaining vulnerabilities: 87
Base branch commit: null


Total libraries scanned: 1272

Scan token: f1d8aea8bc604e84a7c839c777f3e010