Automated remediation exhausted
Devin attempted 2 fix cycles on
PR #486 but HIGH/CRITICAL findings remain.
Remaining findings
frontend/web-app/package-lock.json
- HIGH
CVE-2026-42033: axios 1.15.0 → 1.15.1, 0.31.1 — axios: Axios: HTTP Transport Hijacking via Prototype Pollution
- HIGH
CVE-2026-42035: axios 1.15.0 → 1.15.1, 0.31.1 — axios: Axios: Arbitrary HTTP header injection via prototype pollution
- HIGH
CVE-2026-42043: axios 1.15.0 → 1.15.1, 0.31.1 — axios: Axios: NO_PROXY bypass via crafted URL
- HIGH
CVE-2026-42264: axios 1.15.0 → 1.15.2 — Axios is a promise based HTTP client for the browser and Node.js. From ...
- HIGH
CVE-2026-44486: axios 1.15.0 → 1.16.0, 0.32.0 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects
- HIGH
CVE-2026-44487: axios 1.15.0 → 1.16.0, 0.32.0 — axios: Axios: Information disclosure of proxy credentials via redirect flows
- HIGH
CVE-2026-44488: axios 1.15.0 → 1.16.0 — axios: Axios: Denial of Service due to unenforced request and response size limits
- HIGH
CVE-2026-44492: axios 1.15.0 → 1.16.0, 0.32.0 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
- HIGH
CVE-2026-44494: axios 1.15.0 → 1.16.0 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
- HIGH
CVE-2026-44495: axios 1.15.0 → 1.15.2, 0.31.1 — axios: Axios: Information disclosure due to prototype pollution vulnerability
- HIGH
CVE-2026-44496: axios 1.15.0 → 1.16.0, 0.32.0 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
- HIGH
CVE-2026-12143: form-data 4.0.5 → 2.5.6, 3.0.5, 4.0.6 — form-data is a library for creating readable multipart/form-data strea ...
- HIGH
CVE-2026-44573: next 14.1.3 → 15.5.16, 16.2.5 — next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n
- HIGH
CVE-2026-44578: next 14.1.3 → 15.5.16, 16.2.5 — Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests
- HIGH
GHSA-8h8q-6873-q5fj: next 14.1.3 → 15.5.16, 16.2.5 — Next.js Vulnerable to Denial of Service with Server Components
- HIGH
CVE-2026-48779: ws 6.2.3 → 5.2.5, 6.2.4, 7.5.11, 8.21.0 — ws is an open source WebSocket client and server for Node.js. All vers ...
- HIGH
CVE-2026-48779: ws 8.18.3 → 5.2.5, 6.2.4, 7.5.11, 8.21.0 — ws is an open source WebSocket client and server for Node.js. All vers ...
services/admin-service/Gemfile.lock
- CRITICAL
CVE-2026-33202: activestorage 7.1.6 → ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 — rails: Active Storage: Unintended file deletion via crafted blob keys
- HIGH
CVE-2026-33174: activestorage 7.1.6 → ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 — Rails: Active Storage: Rails Active Storage: Denial of Service via unbounded Range header
- HIGH
CVE-2026-33176: activesupport 7.1.6 → ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 — Rails: Active Support: Activ
Next steps
- Review the findings manually
- Check if the fixes require breaking API changes
- Consider adding justified suppressions to .trivyignore
with proper documentation
Opened automatically by the SAST auto-remediation pipeline.
Automated remediation exhausted
Devin attempted 2 fix cycles on
PR #486 but HIGH/CRITICAL findings remain.
Remaining findings
frontend/web-app/package-lock.json
CVE-2026-42033: axios 1.15.0 → 1.15.1, 0.31.1 — axios: Axios: HTTP Transport Hijacking via Prototype PollutionCVE-2026-42035: axios 1.15.0 → 1.15.1, 0.31.1 — axios: Axios: Arbitrary HTTP header injection via prototype pollutionCVE-2026-42043: axios 1.15.0 → 1.15.1, 0.31.1 — axios: Axios: NO_PROXY bypass via crafted URLCVE-2026-42264: axios 1.15.0 → 1.15.2 — Axios is a promise based HTTP client for the browser and Node.js. From ...CVE-2026-44486: axios 1.15.0 → 1.16.0, 0.32.0 — axios: Axios: Information disclosure of proxy credentials via HTTP redirectsCVE-2026-44487: axios 1.15.0 → 1.16.0, 0.32.0 — axios: Axios: Information disclosure of proxy credentials via redirect flowsCVE-2026-44488: axios 1.15.0 → 1.16.0 — axios: Axios: Denial of Service due to unenforced request and response size limitsCVE-2026-44492: axios 1.15.0 → 1.16.0, 0.32.0 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalizationCVE-2026-44494: axios 1.15.0 → 1.16.0 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype PollutionCVE-2026-44495: axios 1.15.0 → 1.15.2, 0.31.1 — axios: Axios: Information disclosure due to prototype pollution vulnerabilityCVE-2026-44496: axios 1.15.0 → 1.16.0, 0.32.0 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie nameCVE-2026-12143: form-data 4.0.5 → 2.5.6, 3.0.5, 4.0.6 — form-data is a library for creating readable multipart/form-data strea ...CVE-2026-44573: next 14.1.3 → 15.5.16, 16.2.5 — next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18nCVE-2026-44578: next 14.1.3 → 15.5.16, 16.2.5 — Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requestsGHSA-8h8q-6873-q5fj: next 14.1.3 → 15.5.16, 16.2.5 — Next.js Vulnerable to Denial of Service with Server ComponentsCVE-2026-48779: ws 6.2.3 → 5.2.5, 6.2.4, 7.5.11, 8.21.0 — ws is an open source WebSocket client and server for Node.js. All vers ...CVE-2026-48779: ws 8.18.3 → 5.2.5, 6.2.4, 7.5.11, 8.21.0 — ws is an open source WebSocket client and server for Node.js. All vers ...services/admin-service/Gemfile.lock
CVE-2026-33202: activestorage 7.1.6 → ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 — rails: Active Storage: Unintended file deletion via crafted blob keysCVE-2026-33174: activestorage 7.1.6 → ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 — Rails: Active Storage: Rails Active Storage: Denial of Service via unbounded Range headerCVE-2026-33176: activesupport 7.1.6 → ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 — Rails: Active Support: ActivNext steps
with proper documentation
Opened automatically by the SAST auto-remediation pipeline.