Security advisory
Flags a vulnerable dependency with its CVE, affected versions and the upgrade command.
Subject line: Critical vulnerability in form-parser-lite affects 2 of your projects. Designed for Stackwise, a fictional developer tools brand. Swap the logo, colors and images for yours. Replace each {{variable}} with your own value.
Advisory
Red topped card with severity badges, version table, affected projects and the command.
Bulletin
Dark bulletin with a severity scale, before and after version tiles and a disclosure timeline.
Variables
| Variable | Example | Description |
|---|---|---|
cve_id | CVE-2026-41873 | CVE identifier. |
package_name | form-parser-lite | Vulnerable package. |
patched_version | 2.4.3 | First patched version. |
logo_url | https://assets.ui.sh/marks/1.svg?text=Stackwise&color=%2322d38a&textColor=%230a0a0a&font=space-grotesk | Stackwise logo for light backgrounds. |
logo_dark_url | https://assets.ui.sh/marks/1.svg?text=Stackwise&color=%2322d38a&textColor=%23fafafa&font=space-grotesk | Stackwise logo for dark backgrounds. |
severity | Critical | Severity label. |
cvss_score | 9.1 | CVSS base score. |
vulnerability_summary | A crafted multipart request can write files outside the upload directory, which allows remote code execution on servers that execute uploaded paths. | One sentence summary of the vulnerability. |
affected_versions | >=2.0.0 <2.4.3 | Affected version range. |
advisory_id | SWA-2026-017 | Stackwise advisory identifier. |
published_at | Sep 24, 2026 | When the advisory was published. |
project_1 | acme-storefront | First affected project. |
project_1_version | 2.3.1 | Version detected in the first project. |
project_2 | acme-api | Second affected project. |
project_2_version | 2.1.0 | Version detected in the second project. |
upgrade_command | npm install form-parser-lite@2.4.3 | Command that installs the patched version. |
projects_url | https://stackwise.dev/acme/security | Link to the affected projects. |
advisory_url | https://stackwise.dev/security/SWA-2026-017 | Link to the full advisory. |
team_name | Acme Engineering | Name of the team that owns the resource. |
notification_settings_url | https://stackwise.dev/account/notifications | Link to the notification preferences. |
company_address | Stackwise Inc., 548 Market Street, San Francisco, CA 94104 | Postal address of the sender. |
reported_at | Sep 18, 2026 | When the issue was reported. |
patched_at | Sep 22, 2026 | When the fix was released. |