SCA: security update for style-dictionary (GHSA-vj5c-m527-mpff)

high Tenable Cloud Security Plugin ID 445415

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution
vulnerability starting in version 4.3.0 and prior to version 5.4.4. Impact users have: direct usage of
`convertTokenData(tokens, { output: 'object' });`; indirect usage, via using Expand API; and/or indirect
usage via SD's transform lifecycle. Impact is high for this when style-dictionary is used as an
integration in a NodeJS server application. Impact is moderate for when style-dictionary is used as an
integration in a Web application. Impact is low for most common cases where the user of style-dictionary
also maintains the tokens, and access is limited via read/write access to the repository/workflows where
it is used. A patch has been published in version `5.4.4`. The only known workaround is to sanitize token
data first. Whether using DTCG format or old Style Dictionary format, check the token data object
recursively for any object keys that include `__proto__`. (CVE-2026-54639)

Solution

Update the style-dictionary library and its related packages to version 5.4.4 or later.

See Also

https://github.com/advisories/GHSA-vj5c-m527-mpff

Plugin Details

Severity: High

ID: 445415

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 7/29/2026

Updated: 7/29/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.23

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-54639

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/28/2026

Vulnerability Publication Date: 6/24/2026

Reference Information

CVE: CVE-2026-54639