security issue of dependency flatted package
envgap__log4js-node__log4js-node-1446
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
8f8916d2a37b9fc61ce32a6304f9145a9464f72b- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
log4js-node/log4js-node #1446 · read the original issue
In package.json, we need `flatted`:
```json
"dependencies": {
"date-format": "^4.0.14",
"debug": "^4.3.4",
"flatted": "^3.2.7",
"rfdc": "^1.3.0",
"streamroller": "^3.1.5"
},
```
The version 3.2.7 has the known vulnerability [CVE-2026-32141](https://www.cve.org/CVERecord?id=CVE-2026-32141).
upgrade it to 3.4.2
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]