{"id":"CGA-cgxv-gpf6-cq7f","modified":"2026-09-09T16:33:12.608717477Z","published":"2026-09-09T12:17:38Z","upstream":["CVE-2020-15095","GHSA-93f3-23rq-pjfp"],"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4OOYAMJVLLCLXDTHW3V5UXNULZBBK4O6/"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00023.html"},{"type":"ADVISORY","url":"https://github.com/npm/cli/blob/66aab417f836a901f8afb265251f761bb0422463/CHANGELOG.md#6146-2020-07-07"},{"type":"ADVISORY","url":"https://github.com/npm/cli/security/advisories/GHSA-93f3-23rq-pjfp"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202101-07"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00011.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00015.html"},{"type":"FIX","url":"https://github.com/npm/cli/commit/a9857b8f6869451ff058789c4631fadfde5bbcbc"}],"affected":[{"package":{"name":"commercial-gitlab-rails-ee-assets-fips-19.3","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/commercial-gitlab-rails-ee-assets-fips-19.3?arch=aarch64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"ecosystem_specific":{"components":[{"component_name":"npm","component_version":"1.0.1","component_type":"npm","component_location":"/srv/gitlab/public/assets/webpack/gitlab-web-ide-vscode-workbench-0.0.1-dev-20260106142046/vscode/extensions/npm/package.json","component_purl":"pkg:npm/npm@1.0.1","latest_event_status":"pending_upstream_fix","latest_event_timestamp":"2026-09-09T12:17:47Z"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-cgxv-gpf6-cq7f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N"}]}