Known Vulnerable Dependency: nanoid==5.1.7 — 2 advisory(ies): CVE-2026-67214 (nanoid: non-secure generators can loop indefinitely with negative size); CVE-2026-73086 (nanoid: Integer Overflow or Wraparound)
- Category
- Supply Chain
- Confidence
- 95% confidence
- Finding
The lockfile pins nanoid to version 5.1.7, which the supplied advisory metadata identifies as affected by denial-of-service style flaws involving indefinite looping on negative size inputs and integer overflow/wraparound. Even though nanoid is only a transitive dependency of docx here, vulnerable code in the dependency tree is still present and could be reachable if the library or future code paths pass attacker-influenced sizes into Nano ID generation.
- Content
