Skip to content

[Snyk] Upgrade contentstack from 3.22.0 to 3.26.3 - #67

Open
RohitKini wants to merge 1 commit into
mainfrom
snyk-upgrade-cd343e077e0eba969882666015b4a9d9
Open

[Snyk] Upgrade contentstack from 3.22.0 to 3.26.3#67
RohitKini wants to merge 1 commit into
mainfrom
snyk-upgrade-cd343e077e0eba969882666015b4a9d9

Conversation

@RohitKini

Copy link
Copy Markdown
Contributor

snyk-top-banner

Snyk has created this PR to upgrade contentstack from 3.22.0 to 3.26.3.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 15 versions ahead of your current version.

  • The recommended version was released a month ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
critical severity Access of Resource Using Incompatible Type ('Type Confusion')
SNYK-JS-PREACT-14897824
639 Proof of Concept
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-QS-14724253
639 Proof of Concept
Release notes
Package name: contentstack from contentstack GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade contentstack from 3.22.0 to 3.26.3.

See this package in npm:
contentstack

See this project in Snyk:
https://app.snyk.io/org/rohitkini/project/***REDACTED***?utm_source=github&utm_medium=referral&page=upgrade-pr
@RohitKini
RohitKini requested a review from a team as a code owner January 16, 2026 15:04
@priyadarshan-khadtale-cstk
priyadarshan-khadtale-cstk force-pushed the snyk-upgrade-cd343e077e0eba969882666015b4a9d9 branch from 887f596 to 5e75b9e Compare August 13, 2026 09:55
@snyk-io

snyk-io Bot commented Aug 13, 2026

Copy link
Copy Markdown

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@github-actions

Copy link
Copy Markdown

🔒 Security Scan Results

ℹ️ Note: Only vulnerabilities with available fixes (upgrades or patches) are counted toward thresholds.

Check Type Count (with fixes) Without fixes Threshold Result
🔴 Critical Severity 0 0 10 ✅ Passed
🟠 High Severity 21 0 25 ✅ Passed
🟡 Medium Severity 32 0 500 ✅ Passed
🔵 Low Severity 6 0 1000 ✅ Passed

⏱️ SLA Breach Summary

⚠️ Warning: The following vulnerabilities have exceeded their SLA thresholds (days since publication).

Severity Breaches (with fixes) Breaches (no fixes) SLA Threshold (with/no fixes) Status
🔴 Critical 0 0 15 / 30 days ✅ Passed
🟠 High 13 0 30 / 120 days ❌ Failed
🟡 Medium 17 0 90 / 365 days ❌ Failed
🔵 Low 0 0 180 / 365 days ✅ Passed

🟠 High Severity - SLA Breached Issues (with fixes)

Showing 13 issue(s) that have exceeded the 30-day SLA threshold:

  1. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15104645
    • Package: next@16.0.10
    • Published: 197 days ago (SLA: 30 days)
    • CVSS Score: 8.2
    • CVE: CVE-2025-59471
  2. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15105315
    • Package: next@16.0.10
    • Published: 197 days ago (SLA: 30 days)
    • CVSS Score: 8.2
    • CVE: CVE-2025-59472
  3. Arbitrary Code Injection

    • ID: SNYK-JS-LODASHES-15869627
    • Package: lodash-es@4.17.21
    • Published: 133 days ago (SLA: 30 days)
    • CVSS Score: 8.6
    • CVE: CVE-2026-4800
  4. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15921797
    • Package: next@16.0.10
    • Published: 128 days ago (SLA: 30 days)
    • CVSS Score: 8.7
    • CVE: CVE-2026-23864
  5. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15954202
    • Package: next@16.0.10
    • Published: 125 days ago (SLA: 30 days)
    • CVSS Score: 8.7
    • CVE: CVE-2026-23869
  6. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-16638674
    • Package: next@16.0.10
    • Published: 93 days ago (SLA: 30 days)
    • CVSS Score: 8.7
    • CVE: CVE-2026-23870
  7. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-16638678
    • Package: next@16.0.10
    • Published: 93 days ago (SLA: 30 days)
    • CVSS Score: 8.7
    • CVE: CVE-2026-44579
  8. Authentication Bypass Using an Alternate Path or Channel

    • ID: SNYK-JS-NEXT-16638679
    • Package: next@16.0.10
    • Published: 93 days ago (SLA: 30 days)
    • CVSS Score: 8.6
    • CVE: CVE-2026-44574
  9. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-16638680
    • Package: next@16.0.10
    • Published: 93 days ago (SLA: 30 days)
    • CVSS Score: 8.2
    • CVE: CVE-2026-44577
  10. Server-side Request Forgery (SSRF)

  • ID: SNYK-JS-NEXT-16638682
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 7.7
  • CVE: CVE-2026-44578
  1. Incorrect Authorization
  • ID: SNYK-JS-NEXT-16638683
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.2
  • CVE: CVE-2026-44573
  1. Authentication Bypass Using an Alternate Path or Channel
  • ID: SNYK-JS-NEXT-16638685
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.7
  • CVE: CVE-2026-44575
  1. Authentication Bypass Using an Alternate Path or Channel
  • ID: SNYK-JS-NEXT-16638686
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.7
  • CVE: CVE-2026-45109

🟡 Medium Severity - SLA Breached Issues (with fixes)

Showing 17 issue(s) that have exceeded the 90-day SLA threshold:

  1. Prototype Pollution

    • ID: SNYK-JS-LODASHES-15053836
    • Package: lodash-es@4.17.21
    • Published: 203 days ago (SLA: 90 days)
    • CVSS Score: 6.9
    • CVE: CVE-2025-13465
  2. Cross-site Scripting (XSS)

    • ID: SNYK-JS-DOMPURIFY-15371376
    • Package: dompurify@3.3.0
    • Published: 161 days ago (SLA: 90 days)
    • CVSS Score: 5.1
    • CVE: CVE-2026-0540
  3. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15674556
    • Package: next@16.0.10
    • Published: 148 days ago (SLA: 90 days)
    • CVSS Score: 6.9
    • CVE: CVE-2026-27980
  4. Cross-site Request Forgery (CSRF)

    • ID: SNYK-JS-NEXT-15674557
    • Package: next@16.0.10
    • Published: 148 days ago (SLA: 90 days)
    • CVSS Score: 5.3
    • CVE: CVE-2026-27978
  5. HTTP Request Smuggling

    • ID: SNYK-JS-NEXT-15674558
    • Package: next@16.0.10
    • Published: 148 days ago (SLA: 90 days)
    • CVSS Score: 6.3
    • CVE: CVE-2026-29057
  6. Cross-site Scripting (XSS)

    • ID: SNYK-JS-DOMPURIFY-15810938
    • Package: dompurify@3.3.0
    • Published: 136 days ago (SLA: 90 days)
    • CVSS Score: 5.3
    • CVE: CVE-2026-65914
  7. Prototype Pollution

    • ID: SNYK-JS-LODASHES-15869621
    • Package: lodash-es@4.17.21
    • Published: 133 days ago (SLA: 90 days)
    • CVSS Score: 6.9
    • CVE: CVE-2026-2950
  8. Prototype Pollution

    • ID: SNYK-JS-DOMPURIFY-15874903
    • Package: dompurify@3.3.0
    • Published: 132 days ago (SLA: 90 days)
    • CVSS Score: 5.3
    • CVE: CVE-2026-65913
  9. Permissive List of Allowed Inputs

    • ID: SNYK-JS-DOMPURIFY-15874905
    • Package: dompurify@3.3.0
    • Published: 132 days ago (SLA: 90 days)
    • CVSS Score: 5.3
    • CVE: CVE-2026-65912
  10. Operator Precedence Logic Error

  • ID: SNYK-JS-DOMPURIFY-16078387
  • Package: dompurify@3.3.0
  • Published: 119 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-41240
  1. Cross-site Scripting (XSS)
  • ID: SNYK-JS-DOMPURIFY-16132234
  • Package: dompurify@3.3.0
  • Published: 112 days ago (SLA: 90 days)
  • CVSS Score: 5.1
  • CVE: CVE-2026-41238
  1. Improper Validation of Specified Index, Position, or Offset in Input
  • ID: SNYK-JS-UUID-16133035
  • Package: uuid@8.3.2
  • Published: 112 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-41907
  1. Cross-site Scripting (XSS)
  • ID: SNYK-JS-POSTCSS-16189065
  • Package: postcss@8.4.31
  • Published: 111 days ago (SLA: 90 days)
  • CVSS Score: 5.3
  • CVE: CVE-2026-41305
  1. Acceptance of Extraneous Untrusted Data With Trusted Data
  • ID: SNYK-JS-NEXT-16638675
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-44572
  1. Interpretation Conflict
  • ID: SNYK-JS-NEXT-16638676
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-44576
  1. Use of Weak Hash
  • ID: SNYK-JS-NEXT-16638677
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-44582
  1. Cross-site Scripting (XSS)
  • ID: SNYK-JS-NEXT-16638681
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 90 days)
  • CVSS Score: 5.1
  • CVE: CVE-2026-44580

❌ BUILD FAILED - Security checks failed

Please review and fix the security vulnerabilities before merging.

1 similar comment
@github-actions

Copy link
Copy Markdown

🔒 Security Scan Results

ℹ️ Note: Only vulnerabilities with available fixes (upgrades or patches) are counted toward thresholds.

Check Type Count (with fixes) Without fixes Threshold Result
🔴 Critical Severity 0 0 10 ✅ Passed
🟠 High Severity 21 0 25 ✅ Passed
🟡 Medium Severity 32 0 500 ✅ Passed
🔵 Low Severity 6 0 1000 ✅ Passed

⏱️ SLA Breach Summary

⚠️ Warning: The following vulnerabilities have exceeded their SLA thresholds (days since publication).

Severity Breaches (with fixes) Breaches (no fixes) SLA Threshold (with/no fixes) Status
🔴 Critical 0 0 15 / 30 days ✅ Passed
🟠 High 13 0 30 / 120 days ❌ Failed
🟡 Medium 17 0 90 / 365 days ❌ Failed
🔵 Low 0 0 180 / 365 days ✅ Passed

🟠 High Severity - SLA Breached Issues (with fixes)

Showing 13 issue(s) that have exceeded the 30-day SLA threshold:

  1. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15104645
    • Package: next@16.0.10
    • Published: 197 days ago (SLA: 30 days)
    • CVSS Score: 8.2
    • CVE: CVE-2025-59471
  2. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15105315
    • Package: next@16.0.10
    • Published: 197 days ago (SLA: 30 days)
    • CVSS Score: 8.2
    • CVE: CVE-2025-59472
  3. Arbitrary Code Injection

    • ID: SNYK-JS-LODASHES-15869627
    • Package: lodash-es@4.17.21
    • Published: 133 days ago (SLA: 30 days)
    • CVSS Score: 8.6
    • CVE: CVE-2026-4800
  4. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15921797
    • Package: next@16.0.10
    • Published: 128 days ago (SLA: 30 days)
    • CVSS Score: 8.7
    • CVE: CVE-2026-23864
  5. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15954202
    • Package: next@16.0.10
    • Published: 125 days ago (SLA: 30 days)
    • CVSS Score: 8.7
    • CVE: CVE-2026-23869
  6. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-16638674
    • Package: next@16.0.10
    • Published: 93 days ago (SLA: 30 days)
    • CVSS Score: 8.7
    • CVE: CVE-2026-23870
  7. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-16638678
    • Package: next@16.0.10
    • Published: 93 days ago (SLA: 30 days)
    • CVSS Score: 8.7
    • CVE: CVE-2026-44579
  8. Authentication Bypass Using an Alternate Path or Channel

    • ID: SNYK-JS-NEXT-16638679
    • Package: next@16.0.10
    • Published: 93 days ago (SLA: 30 days)
    • CVSS Score: 8.6
    • CVE: CVE-2026-44574
  9. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-16638680
    • Package: next@16.0.10
    • Published: 93 days ago (SLA: 30 days)
    • CVSS Score: 8.2
    • CVE: CVE-2026-44577
  10. Server-side Request Forgery (SSRF)

  • ID: SNYK-JS-NEXT-16638682
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 7.7
  • CVE: CVE-2026-44578
  1. Incorrect Authorization
  • ID: SNYK-JS-NEXT-16638683
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.2
  • CVE: CVE-2026-44573
  1. Authentication Bypass Using an Alternate Path or Channel
  • ID: SNYK-JS-NEXT-16638685
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.7
  • CVE: CVE-2026-44575
  1. Authentication Bypass Using an Alternate Path or Channel
  • ID: SNYK-JS-NEXT-16638686
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.7
  • CVE: CVE-2026-45109

🟡 Medium Severity - SLA Breached Issues (with fixes)

Showing 17 issue(s) that have exceeded the 90-day SLA threshold:

  1. Prototype Pollution

    • ID: SNYK-JS-LODASHES-15053836
    • Package: lodash-es@4.17.21
    • Published: 203 days ago (SLA: 90 days)
    • CVSS Score: 6.9
    • CVE: CVE-2025-13465
  2. Cross-site Scripting (XSS)

    • ID: SNYK-JS-DOMPURIFY-15371376
    • Package: dompurify@3.3.0
    • Published: 161 days ago (SLA: 90 days)
    • CVSS Score: 5.1
    • CVE: CVE-2026-0540
  3. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15674556
    • Package: next@16.0.10
    • Published: 148 days ago (SLA: 90 days)
    • CVSS Score: 6.9
    • CVE: CVE-2026-27980
  4. Cross-site Request Forgery (CSRF)

    • ID: SNYK-JS-NEXT-15674557
    • Package: next@16.0.10
    • Published: 148 days ago (SLA: 90 days)
    • CVSS Score: 5.3
    • CVE: CVE-2026-27978
  5. HTTP Request Smuggling

    • ID: SNYK-JS-NEXT-15674558
    • Package: next@16.0.10
    • Published: 148 days ago (SLA: 90 days)
    • CVSS Score: 6.3
    • CVE: CVE-2026-29057
  6. Cross-site Scripting (XSS)

    • ID: SNYK-JS-DOMPURIFY-15810938
    • Package: dompurify@3.3.0
    • Published: 136 days ago (SLA: 90 days)
    • CVSS Score: 5.3
    • CVE: CVE-2026-65914
  7. Prototype Pollution

    • ID: SNYK-JS-LODASHES-15869621
    • Package: lodash-es@4.17.21
    • Published: 133 days ago (SLA: 90 days)
    • CVSS Score: 6.9
    • CVE: CVE-2026-2950
  8. Prototype Pollution

    • ID: SNYK-JS-DOMPURIFY-15874903
    • Package: dompurify@3.3.0
    • Published: 132 days ago (SLA: 90 days)
    • CVSS Score: 5.3
    • CVE: CVE-2026-65913
  9. Permissive List of Allowed Inputs

    • ID: SNYK-JS-DOMPURIFY-15874905
    • Package: dompurify@3.3.0
    • Published: 132 days ago (SLA: 90 days)
    • CVSS Score: 5.3
    • CVE: CVE-2026-65912
  10. Operator Precedence Logic Error

  • ID: SNYK-JS-DOMPURIFY-16078387
  • Package: dompurify@3.3.0
  • Published: 119 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-41240
  1. Cross-site Scripting (XSS)
  • ID: SNYK-JS-DOMPURIFY-16132234
  • Package: dompurify@3.3.0
  • Published: 112 days ago (SLA: 90 days)
  • CVSS Score: 5.1
  • CVE: CVE-2026-41238
  1. Improper Validation of Specified Index, Position, or Offset in Input
  • ID: SNYK-JS-UUID-16133035
  • Package: uuid@8.3.2
  • Published: 112 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-41907
  1. Cross-site Scripting (XSS)
  • ID: SNYK-JS-POSTCSS-16189065
  • Package: postcss@8.4.31
  • Published: 111 days ago (SLA: 90 days)
  • CVSS Score: 5.3
  • CVE: CVE-2026-41305
  1. Acceptance of Extraneous Untrusted Data With Trusted Data
  • ID: SNYK-JS-NEXT-16638675
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-44572
  1. Interpretation Conflict
  • ID: SNYK-JS-NEXT-16638676
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-44576
  1. Use of Weak Hash
  • ID: SNYK-JS-NEXT-16638677
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-44582
  1. Cross-site Scripting (XSS)
  • ID: SNYK-JS-NEXT-16638681
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 90 days)
  • CVSS Score: 5.1
  • CVE: CVE-2026-44580

❌ BUILD FAILED - Security checks failed

Please review and fix the security vulnerabilities before merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants