Back to advisories
GHSA-j86p-76g3-4vcv Critical

Vulnerable Dependencies

BraveCMS 2.0 ships with a large set of out-of-date third-party libraries across both its PHP (Composer/Packagist) and JavaScript (npm) dependency trees. Multiple Critical and High severity vulnerabilities are present in the bundled versions, including the Laravel framework itself, Symfony components, Babel, Webpack, lodash, axios, and core cryptography packages.

Affected: BraveCMS 2.0 Vendor: BraveCMS Discovered: Reported: Apr 4, 2026 Patched: Apr 4, 2026 Reporter: Stefan Mitocaru

Details

The advisory inventories the project's pinned dependencies and flags every package whose pinned version is known to be vulnerable in the GitHub Advisory Database. Because BraveCMS 2.0 is built on Laravel 8 with a Webpack/Mix front-end pipeline, the affected surface spans both the runtime PHP stack (framework, HTTP foundation, process handling, Carbon, CommonMark) and the build/dev-tooling JavaScript stack (Webpack, Babel, lodash, axios, dev-server middleware, transitive cryptographic primitives).

The advisory carries no CVE assignment by design. Per the upstream note, vulnerable-dependency rollups are treated as informational and do not require a dedicated CVE record because each underlying issue is already tracked in the GitHub Advisory Database under its own identifier.

Impact

The practical consequences depend on which subset of the dependency tree is reachable in production versus only at build/development time, but the overall posture is concerning:

Runtime exposure via Laravel and Symfony: laravel/framework 8.83.23, symfony/http-foundation 5.4.12, symfony/process 5.4.11, symfony/http-kernel 5.4.12, league/commonmark 2.3.5, nesbot/carbon 2.62.1, and guzzlehttp/psr7 2.4.1 are all loaded at request time. Issues in these packages can translate into request-handling, header parsing, markdown rendering, and process-execution weaknesses that affect the live application. Build- and dev-time exposure: Webpack, Babel, Loader-Utils, Terser, PostCSS, SVGO, and the webpack-dev-server / webpack-dev-middleware family are involved when assets are compiled or when developers run the dev server. Critical-rated issues in webpack, @babel/traverse, and loader-utils have historically been exploited to compromise developer machines and CI pipelines, and to inject malicious content into produced bundles. Cryptographic primitives: elliptic 6.5.4, pbkdf2 3.1.2, sha.js 2.4.11, cipher-base 1.0.4, node-forge 1.3.0, and browserify-sign 4.2.1 ship known vulnerabilities affecting signature verification, hashing, and key handling. Wherever they are used as transitive dependencies of front-end tooling that operates on tokens, JWTs, or signed payloads, the impact can extend to the running application. Network and parsing primitives: axios 0.21.4, ws 8.5.0, body-parser 1.19.2, qs 6.9.7, follow-redirects 1.14.9, path-to-regexp 0.1.7, http-proxy-middleware 2.0.4, and express 4.17.3 cover HTTP clients, WebSocket servers, and request parsers. Exploitable issues in these layers commonly result in SSRF, prototype pollution, denial of service, or request-smuggling style attacks.

Start securing your codebase today

Connect your repositories and let AI agents handle continuous scanning, research, and triage.

Have questions? Get in touch →