Skip to content

[audit] high: CVE-2026-13149 in brace-expansion@2.1.1 #1

Description

@github-actions

Severity: high
CVE: CVE-2026-13149
Package: brace-expansion @ 2.1.1
Vulnerable range: >=2.0.0 <2.1.2
Patched in: >=2.1.2
Dep paths:

  • lib__api-spec>orval>typedoc>minimatch>brace-expansion

brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups

Reference: GHSA-3jxr-9vmj-r5cp
Filed automatically by .github/workflows/pnpm-audit.yml. The fix
work for this CVE belongs in its own task; see
docs/security-audit-public-2026-04.md §11 limitation 4 for the
policy. Either bump the affected dep (closes this issue on the next
scheduled run) or add an entry to scripts/audit/ignore-list.json
with a written reachability rationale and a re-evaluation date.

Metadata

Metadata

Assignees

No one assigned

    Labels

    audit:cveAutomated pnpm audit finding

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions