There is 1 open security issue in trixie.
1 issue left for the package maintainer to handle:
- CVE-2026-93687:
(needs triaging)
braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js process with an uncaught RangeError.
You can find information about how to handle this issue in the security team's documentation.