Jonschlinkert maintains a focused collection of JavaScript utility libraries—including picomatch, braces, and micromatch—that perform pattern matching, string parsing, and configuration file handling in Node.js and browser environments. The durable signal across these libraries centers on input-handling and resource-consumption weaknesses: prototype pollution, inefficient regular expression evaluation, and uncontrolled algorithmic complexity that can arise when parsing untrusted patterns or configuration data. Defenders should review dependencies on these parsing utilities for exposure to malformed or adversarial input; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jonschlinkert over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33671HIGH Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted ext | Mar 26, 2026 | 7.5 | 31 | NO | NO |
CVE-2025-57328HIGH toggle-array is a package designed to enables a property on the object at the specified index, while disabling the property on all other objects. A Prototype Pollution vulnerabilit | Sep 24, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-4068HIGH The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious u | May 14, 2024 | 7.5 | 25 | NO | NO |
CVE-2026-33672MEDIUM Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` obje | Mar 26, 2026 | 5.3 | 24 | NO | NO |
CVE-2025-25975HIGH An issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys function | Mar 12, 2025 | 7.5 | 20 | NO | NO |
CVE-2024-4067MEDIUM The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because t | May 14, 2024 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jonschlinkert.
Media articles that mention a CVE ID that affects a product developed by Jonschlinkert — matched by CVE ID, not by vendor name.