{"id":"ECHO-c7cb-a298-143f","upstream":["CVE-2026-9496","GHSA-w4pp-8pjf-rmxw"],"severity":[],"modified":"2026-09-28T00:02:37.993Z","affected":[{"package":{"ecosystem":"Echo:npm","name":"pacote","purl":"pkg:npm/pacote"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.0.2+ds1-1"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-9496"},{"type":"WEB","url":"https://github.com/advisories/GHSA-w4pp-8pjf-rmxw"}]}