CVE-2026-6321 & CVE-2026-6322 reported
Given the latest development of vulnerabilities, we believe this should be addressed accordingly.
## Audit Report
### High — `fast-uri` vulnerable to path traversal via percent-encoded dot segments
| Field | Details |
|---------------|---------|
| **Package** | `fast-uri` |
| **Patched in** | `>=3.1.1` |
| **Dependency of** | `@commitlint/cli` |
| **Path** | `@commitlint/cli` → `@commitlint/load` → `@commitlint/config-validator` → `ajv` → `fast-uri` |
| **Path (alt)** | `@commitlint/cli` → `@commitlint/load` → `@commitlint/resolve-extends` → `@commitlint/config-validator` → `ajv` → `fast-uri` |
| **More info** | https://www.npmjs.com/advisories/1117870 |
---
### High — `fast-uri` vulnerable to host confusion via percent-encoded authority delimiters
| Field | Details |
|---------------|---------|
| **Package** | `fast-uri` |
| **Patched in** | `>=3.1.2` |
| **Dependency of** | `@commitlint/cli` |
| **Path** | `@commitlint/cli` → `@commitlint/load` → `@commitlint/config-validator` → `ajv` → `fast-uri` |
| **Path (alt)** | `@commitlint/cli` → `@commitlint/load` → `@commitlint/resolve-extends` → `@commitlint/config-validator` → `ajv` → `fast-uri` |
| **More info** | https://www.npmjs.com/advisories/1117884 |
关闭于 2026-05-26 1 条评论