{
  "@id": "urn:uuid:c5f1991f-fdf2-4ace-948a-3dea0572d497",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 4,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-30T16:42:07.696248+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27152 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2025-27152"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-58754 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2025-58754"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62718 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2025-62718"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-30T15:22:01.103634+00:00",
      "status_notes": "Vulnerability CVE-2026-101902 affects version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-101902"
      },
      "action_statement": "Vulnerability CVE-2026-101902 affects version 1.7.9-tuxcare.3 of axios."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-30T15:57:50.734473+00:00",
      "status_notes": "Vulnerability CVE-2026-101904 affects version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-101904"
      },
      "action_statement": "Vulnerability CVE-2026-101904 affects version 1.7.9-tuxcare.3 of axios."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-30T16:42:07.696248+00:00",
      "status_notes": "Vulnerability CVE-2026-101908 does not affect version 1.7.9-tuxcare.3 of axios. not_affected \u2014 CVE-2026-101908 describes a prototype pollution gadget where passing user-provided `fetchOptions` as the second argument to fetch() allows inherited properties from `Object.prototype` to override sanitized request headers. The target (axios v1.7.9-tuxcare.4) does NOT have this vulnerable pattern. The target's fetch adapter calls `fetch(request)` with only one argument (line 272), never passing ...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-101908"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-101908 describes a prototype pollution gadget where passing user-provided `fetchOptions` as the second argument to fetch() allows inherited properties from `Object.prototype` to override sanitized request headers. The target (axios v1.7.9-tuxcare.4) does NOT have this vulnerable pattern. The target's fetch adapter calls `fetch(request)` with only one argument (line 272), never passing ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25639 does not affect version 1.7.9-tuxcare.3 of axios. Version 1.7.9 is not vulnerable. Summary: The target repository (axios v1.7.9) is NOT vulnerable to CVE-2026-25639. The target uses Object.assign({}, config1, config2) for key iteration, which does not include __proto__ in Object.keys() results, preventing the DoS crash. The vulnerable code pattern was introduced later in v1.11.0 when the code was refactored to use the spread operator ({...config1, ...config2}). [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25639"
      },
      "impact_statement": "Version 1.7.9 is not vulnerable. Summary: The target repository (axios v1.7.9) is NOT vulnerable to CVE-2026-25639. The target uses Object.assign({}, config1, config2) for key iteration, which does not include __proto__ in Object.keys() results, preventing the DoS crash. The vulnerable code pattern was introduced later in v1.11.0 when the code was refactored to use the spread operator ({...config1, ...config2}). [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40175 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-40175"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42033 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42033"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42034 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42034"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42035 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42036 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42036"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42037 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42037"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42038 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42038"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42039 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42039"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42040 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42040"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42041 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42041"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42042 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42042"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42043 does not affect version 1.7.9-tuxcare.3 of axios. Version 1.7.9 is not vulnerable. Summary: The target version (axios v1.7.9) is NOT vulnerable to CVE-2026-42043 because the vulnerable shouldBypassProxy feature does not exist in this version. The target uses the external 'proxy-from-env' package for proxy handling, whereas the vulnerability exists in axios's own shouldBypassProxy implementation that was only introduced in version 1.15.0. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-42043"
      },
      "impact_statement": "Version 1.7.9 is not vulnerable. Summary: The target version (axios v1.7.9) is NOT vulnerable to CVE-2026-42043 because the vulnerable shouldBypassProxy feature does not exist in this version. The target uses the external 'proxy-from-env' package for proxy handling, whereas the vulnerability exists in axios's own shouldBypassProxy implementation that was only introduced in version 1.15.0. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42044 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42044"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42264 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42264"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44486 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44486"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44487 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44487"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44488 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44488"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44490 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44490"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44492 affects version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44492"
      },
      "action_statement": "Vulnerability CVE-2026-44492 affects version 1.7.9-tuxcare.3 of axios."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44494 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44494"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44495 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44495"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44496 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44496"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67312 affects version 1.7.9-tuxcare.3 of axios, and is fixed in 1.7.9-tuxcare.4.",
      "vulnerability": {
        "name": "CVE-2026-67312"
      },
      "action_statement": "Vulnerability CVE-2026-67312 affects version 1.7.9-tuxcare.3 of axios, and is fixed in 1.7.9-tuxcare.4."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67313 affects version 1.7.9-tuxcare.3 of axios, and is fixed in 1.7.9-tuxcare.4.",
      "vulnerability": {
        "name": "CVE-2026-67313"
      },
      "action_statement": "Vulnerability CVE-2026-67313 affects version 1.7.9-tuxcare.3 of axios, and is fixed in 1.7.9-tuxcare.4."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67316 affects version 1.7.9-tuxcare.3 of axios, and is fixed in 1.7.9-tuxcare.4.",
      "vulnerability": {
        "name": "CVE-2026-67316"
      },
      "action_statement": "Vulnerability CVE-2026-67316 affects version 1.7.9-tuxcare.3 of axios, and is fixed in 1.7.9-tuxcare.4."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67317 affects version 1.7.9-tuxcare.3 of axios, and is fixed in 1.7.9-tuxcare.4.",
      "vulnerability": {
        "name": "CVE-2026-67317"
      },
      "action_statement": "Vulnerability CVE-2026-67317 affects version 1.7.9-tuxcare.3 of axios, and is fixed in 1.7.9-tuxcare.4."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67319 affects version 1.7.9-tuxcare.3 of axios, and is fixed in 1.7.9-tuxcare.4.",
      "vulnerability": {
        "name": "CVE-2026-67319"
      },
      "action_statement": "Vulnerability CVE-2026-67319 affects version 1.7.9-tuxcare.3 of axios, and is fixed in 1.7.9-tuxcare.4."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-42h9-826w-cgv3 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "GHSA-42h9-826w-cgv3"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7q8q-rj6j-mhjq is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "GHSA-7q8q-rj6j-mhjq"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jqh4-m9w3-8hp9 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "GHSA-jqh4-m9w3-8hp9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mmx7-hfxf-jppx is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "GHSA-mmx7-hfxf-jppx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.9-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pmv8-rq9r-6j72 is fixed in version 1.7.9-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "GHSA-pmv8-rq9r-6j72"
      }
    }
  ]
}
