# node-forge 1.4.0 via @anthropic-ai/mcpb 2.1.2 (CI bundle tooling only).
# Signature-forgery advisory; the tool creates signatures for our own
# artifacts and never verifies untrusted input, so the exposure does not
# apply. No fixed node-forge release exists yet (latest is the affected
# 1.4.0); revisit on the next dependency refresh.
CVE-2026-85393 exp:2027-01-01
