Blazing fast and accurate glob matcher written in JavaScript, with no dependencies and full support for standard and extended Bash glob features, including braces, extglobs, POSIX brackets, and regular expressions.
83%
Total Score
64
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-33672 picomatch is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 4.0.0 - 4.0.4, 3.0.0 - 3.0.2 and 0.0.0 - 2.3.2. | 0.0.0 - 2.3.23.0.0 - 3.0.24.0.0 - 4.0.4 | Medium |
CVE-2026-33671 picomatch is vulnerable to Inefficient Regular Expression Complexity in versions 4.0.0 - 4.0.4, 3.0.0 - 3.0.2 and 0.0.0 - 2.3.2. | 0.0.0 - 2.3.23.0.0 - 3.0.24.0.0 - 4.0.4 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant