{"api_version":"v1","generated_at":"2026-10-08T10:20:00+00:00","product":{"cve_count":3,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-technical-laohu-mpay-d71ffc3f6242","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/mpay","name":"mpay","next_cursor":null,"observations":[{"affected":"1.2.0; 1.2.1; 1.2.2; 1.2.3; 1.2.4","affected_versions_present":true,"cve_id":"CVE-2026-1153","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-1153","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-23T08:45:38.258Z","patch_url":"","primary_source":"","published":"2026-01-19T12:02:06.218Z"},{"affected":"1.2.0; 1.2.1; 1.2.2; 1.2.3; 1.2.4","affected_versions_present":true,"cve_id":"CVE-2026-1152","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-1152","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-23T08:45:24.624Z","patch_url":"","primary_source":"","published":"2026-01-19T11:32:05.948Z"},{"affected":"1.2.0; 1.2.1; 1.2.2; 1.2.3; 1.2.4","affected_versions_present":true,"cve_id":"CVE-2026-1151","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-1151","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-23T08:45:12.920Z","patch_url":"","primary_source":"","published":"2026-01-19T11:02:05.822Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"technical-laohu"}}
