Direct Vulnerabilities

Known vulnerabilities in the lerna package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Resource Exhaustion

<9.0.7-r11
  • L
GHSA-5p4m-2wfm-xmqj

<9.0.7-r18
  • L
GHSA-38gx-cfqf-f652

<9.0.7-r11
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<9.0.7-r11
  • L
Improper Input Validation

<9.0.7-r17
  • L
GHSA-mwp4-54f8-5fhr

<9.0.7-r17
  • L
Improper Input Validation

<9.0.7-r17
  • L
GHSA-4xrf-jv44-h6hh

<9.0.7-r17
  • L
Improper Input Validation

<9.0.7-r17
  • L
GHSA-22jq-vg5j-6vgg

<9.0.7-r17
  • L
GHSA-xj6q-8x83-jv6g

<9.0.7-r11
  • L
GHSA-jqh4-m9w3-8hp9

<9.0.7-r11
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

<9.0.7-r11
  • L
GHSA-8x88-c5mf-7j5w

<9.0.7-r11
  • L
GHSA-w8wr-v893-vjvp

<9.0.7-r11
  • L
GHSA-r292-9mhp-454m

<9.0.7-r11
  • L
Algorithmic Complexity

<9.0.7-r11
  • L
GHSA-mmx7-hfxf-jppx

<9.0.7-r11
  • L
GHSA-mwf2-3pr3-8698

<9.0.7-r11
  • L
GHSA-hcpx-6fm6-wx23

<9.0.7-r11
  • L
GHSA-mh99-v99m-4gvg

<9.0.7-r16
  • L
CVE-2026-13149

<9.0.7-r12
  • L
Uncaught Exception

<9.0.7-r11
  • L
GHSA-52cp-r559-cp3m

<9.0.7-r11
  • L
GHSA-gvwx-54wh-qm9j

<9.0.7-r11
  • L
GHSA-42h9-826w-cgv3

<9.0.7-r11
  • L
CVE-2026-14257

<9.0.7-r16
  • L
GHSA-3jxr-9vmj-r5cp

<9.0.7-r12
  • L
Allocation of Resources Without Limits or Throttling

<9.0.7-r11
  • L
GHSA-f4gw-2p7v-4548

<9.0.7-r11
  • L
GHSA-23hp-3jrh-7fpw

<9.0.7-r11
  • L
Incorrect Type Conversion or Cast

<9.0.7-r11
  • L
GHSA-7q8q-rj6j-mhjq

<9.0.7-r11
  • L
GHSA-pmv8-rq9r-6j72

<9.0.7-r11
  • L
GHSA-gcfj-64vw-6mp9

<9.0.7-r11
  • L
GHSA-h67p-54hq-rp68

<9.0.7-r10
  • L
Algorithmic Complexity

<9.0.7-r10
  • L
GHSA-vmf3-w455-68vh

<9.0.7-r10
  • L
GHSA-7c78-jf6q-g5cm

<9.0.7-r9
  • L
GHSA-hmw2-7cc7-3qxx

<9.0.7-r9
  • L
Interpretation Conflict

<9.0.7-r10
  • L
CVE-2026-12143

<9.0.7-r9
  • L
Improper Input Validation

<9.0.7-r9
  • L
GHSA-pjwm-pj3p-43mv

<9.0.7-r7
  • M
HTTP Response Splitting

<9.0.7-r7
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

<9.0.7-r7
  • L
GHSA-35jp-ww65-95wh

<9.0.7-r7
  • L
Server-Side Request Forgery (SSRF)

<9.0.7-r7
  • L
GHSA-898c-q2cr-xwhg

<9.0.7-r7
  • L
GHSA-654m-c8p4-x5fp

<9.0.7-r7
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<9.0.7-r7
  • H
Directory Traversal

<9.0.7-r6
  • L
GHSA-ph9p-34f9-6g65

<9.0.7-r6
  • L
GHSA-r4q5-vmmm-2653

<9.0.7-r5
  • L
GHSA-jxxr-4gwj-5jf2

<9.0.7-r5
  • H
Resource Exhaustion

<9.0.7-r5
  • H
Server-Side Request Forgery (SSRF)

<9.0.7-r4
  • L
GHSA-m7pr-hjqh-92cm

<9.0.7-r4
  • M
Improper Authentication

<9.0.7-r4
  • L
GHSA-vf2m-468p-8v99

<9.0.7-r4
  • L
HTTP Response Splitting

<9.0.7-r4
  • L
Improper Encoding or Escaping of Output

<9.0.7-r4
  • L
GHSA-pf86-5x62-jrwf

<9.0.7-r4
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<9.0.7-r4
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<9.0.7-r4
  • L
GHSA-v2v4-37r5-5v8g

<9.0.7-r4
  • L
GHSA-pmwg-cvhr-8vh7

<9.0.7-r4
  • H
Uncontrolled Recursion

<9.0.7-r4
  • M
Cross-site Scripting (XSS)

<9.0.7-r4
  • L
CRLF Injection

<9.0.7-r4
  • L
GHSA-w9j2-pvgh-6h63

<9.0.7-r4
  • C
Permissive Whitelist

<9.0.7-r4
  • L
GHSA-5c9x-8gcm-mpgx

<9.0.7-r4
  • L
Allocation of Resources Without Limits or Throttling

<9.0.7-r4
  • L
GHSA-xhjh-pmcv-23jw

<9.0.7-r4
  • L
GHSA-6chq-wfr3-2hj9

<9.0.7-r4
  • L
GHSA-445q-vr5w-6q77

<9.0.7-r4
  • L
GHSA-q8qp-cvcw-x6jj

<9.0.7-r4
  • L
Allocation of Resources Without Limits or Throttling

<9.0.7-r4
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<9.0.7-r4
  • L
GHSA-62hf-57xw-28j9

<9.0.7-r4
  • L
GHSA-3w6x-2g7m-8v23

<9.0.7-r4
  • L
Permissive Whitelist

<9.0.7-r4
  • L
GHSA-xx6v-rp6x-q39c

<9.0.7-r4
  • C
Unintended Proxy or Intermediary ('Confused Deputy')

<9.0.7-r3
  • L
GHSA-fvcv-3m26-pcqx

<9.0.7-r3
  • L
GHSA-3p68-rc4w-qgx5

<9.0.7-r3
  • M
HTTP Response Splitting

<9.0.7-r3
  • L
GHSA-3v7f-55p6-f55p

<9.0.7-r2
  • H
Resource Exhaustion

<9.0.7-r2
  • H
Cross-site Scripting (XSS)

<9.0.7-r2
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<9.0.7-r2
  • L
Arbitrary Code Injection

<9.0.7-r2
  • L
Improper Check for Unusual or Exceptional Conditions

<9.0.7-r2
  • L
GHSA-2w6w-674q-4c4q

<9.0.7-r2
  • L
GHSA-3mfm-83xf-c92r

<9.0.7-r2
  • L
GHSA-xhpv-hc6g-r9c6

<9.0.7-r2
  • M
Cross-site Scripting (XSS)

<9.0.7-r2
  • L
Uncontrolled Recursion

<9.0.7-r2
  • L
Inefficient Regular Expression Complexity

<9.0.7-r2
  • L
Arbitrary Code Injection

<9.0.7-r2
  • L
GHSA-9cx6-37pm-9jff

<9.0.7-r2
  • L
GHSA-2qvq-rjwj-gvw9

<9.0.7-r2
  • L
GHSA-xjpj-3mr7-gcpf

<9.0.7-r2
  • L
GHSA-f886-m6hf-6m8v

<9.0.7-r2
  • L
GHSA-c2c7-rcm5-vvqj

<9.0.7-r2
  • L
Arbitrary Code Injection

<9.0.7-r2
  • L
GHSA-48c2-rrv3-qjmp

<9.0.7-r2
  • L
GHSA-442j-39wm-28r2

<9.0.7-r2
  • L
GHSA-7rx3-28cr-v5wh

<9.0.7-r2
  • L
GHSA-qffp-2rhf-9h96

<9.0.7-r1
  • L
GHSA-9ppj-qmqm-q256

<9.0.7-r1
  • M
Directory Traversal

<9.0.7-r1
  • M
Directory Traversal

<9.0.7-r1
  • L
Algorithmic Complexity

<9.0.5-r1
  • L
GHSA-7r86-cg39-jmmj

<9.0.5-r1
  • L
Inefficient Regular Expression Complexity

<9.0.5-r1
  • L
GHSA-23c5-xmqv-rm74

<9.0.5-r1
  • L
GHSA-3ppc-4f35-3m26

<9.0.4-r3
  • L
GHSA-83g3-92jg-28cx

<9.0.4-r3
  • H
Directory Traversal

<9.0.4-r3
  • H
Inefficient Regular Expression Complexity

<9.0.4-r3
  • L
GHSA-43fc-jf86-j433

<9.0.4-r2
  • L
Improper Check for Unusual or Exceptional Conditions

<9.0.4-r2
  • L
Directory Traversal

<9.0.4-r1
  • L
GHSA-34x7-hfp2-rc4v

<9.0.4-r1
  • L
Inefficient Regular Expression Complexity

<9.0.3-r3
  • L
GHSA-7h2j-956f-4vf2

<9.0.3-r3
  • L
GHSA-8qq5-rm4j-mr97

<9.0.4-r0
  • M
Improper Handling of Unicode Encoding

<9.0.4-r0
  • L
GHSA-r6q2-hw4h-h46w

<9.0.4-r0
  • M
Directory Traversal

<9.0.4-r0
  • L
CVE-2025-54371

<8.2.3-r1
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<9.0.1-r1
  • L
GHSA-mh29-5h37-fv8m

<9.0.1-r1
  • L
OS Command Injection

<9.0.1-r1
  • L
GHSA-5j98-mcp5-4vw2

<9.0.1-r1
  • L
Allocation of Resources Without Limits or Throttling

<8.2.4-r2
  • L
GHSA-4hjh-wcwx-xvwj

<8.2.4-r2
  • M
Link Following

<8.2.4-r1
  • L
GHSA-52f5-9888-hmc6

<8.2.4-r1
  • L
GHSA-rm8p-cx58-hcvx

<8.2.3-r1
  • L
Resource Exhaustion

<8.2.2-r2
  • M
Server-Side Request Forgery (SSRF)

<8.2.1-r1
  • L
Inefficient Regular Expression Complexity

<8.2.1-r0
  • L
Inefficient Regular Expression Complexity

<8.2.1-r0
  • L
Inefficient Regular Expression Complexity

<8.2.1-r0
  • L
CVE-2024-21538

<8.1.9-r1
  • M
CVE-2024-4067

<8.1.8-r1
  • H
Server-Side Request Forgery (SSRF)

<8.1.8-r1
  • L
CVE-2024-4068

<8.1.4-r0
  • L
CVE-2024-28863

<8.1.3-r0
  • L
CVE-2024-33883

<8.1.3-r0
  • L
CVE-2024-28849

<8.1.2-r1
  • C
Server-Side Request Forgery (SSRF)

<8.1.2-r1
  • M
Open Redirect

<8.0.2-r0