Package
langfuse-fips-3-worker
Component
braces
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable component is the braces npm package, resolved at 3.0.3 as a transitive dependency in the upstream lockfile. GHSA-vfj7-8cjw-p6xm lists all versions up to and including 3.0.3 as affected and no patched version has been published; 3.0.3 is the latest release on npm. Until braces publishes a fixed release that is adopted by the upstream dependency chain, this vulnerability cannot be remediated with a dependency pin.
References: https://nvd.nist.gov/vuln/detail/CVE-2026-93687 https://github.com/advisories/GHSA-vfj7-8cjw-p6xm
Status