Hello Team,
Mend Bolt tool is showing vulnerability in package "path-to-regexp-2.2.1.tgz" with [CVE-2024-45296]
Vulnerability is raised from the path-to-regexp@2.2.1 module which is used as a transitive dependency. The recommended version of this is 8.1.0
Running npm list path-to-regexp returns the following:
└─┬ serve@14.2.3
└─┬ serve-handler@6.1.5
└── path-to-regexp@2.2.1
Could you please upgrade the path-to-regexp transitive dependency to 8.1.0 to fix it at asap.
Regards,
Sridevi G