{"api_version":"v1","generated_at":"2026-10-07T21:10:00+00:00","product":{"cve_count":2,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-semantic-release-semantic-release-101a940f8553","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/semantic-release","name":"semantic-release","next_cursor":null,"observations":[{"affected":">= 17.0.4, < 19.0.3","affected_versions_present":true,"cve_id":"CVE-2022-31051","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-31051","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T18:17:20.711Z","patch_url":"https://github.com/semantic-release/semantic-release/commit/58a226f29c04ee56bbb02cc661f020d568849cad","primary_source":"","published":"2022-06-09T20:05:12.000Z"},{"affected":"< 6.1.5","affected_versions_present":true,"cve_id":"CVE-2020-26226","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-26226","fixed":"17.2.3.","last_modified":"2024-08-04T15:56:03.009Z","patch_url":"https://github.com/semantic-release/semantic-release/commit/ca90b34c4a9333438cc4d69faeb43362bb991e5a","primary_source":"","published":"2020-11-18T21:35:14.000Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"semantic-release"}}
