Skip to content

Fix security issue in brace-expansion via minor version upgrade from 1.1.11 to 1.1.12#150

Merged
janb87 merged 2 commits intomainfrom
fix/aikido-security-update-packages-4887280-htoW
Jul 2, 2025
Merged

Fix security issue in brace-expansion via minor version upgrade from 1.1.11 to 1.1.12#150
janb87 merged 2 commits intomainfrom
fix/aikido-security-update-packages-4887280-htoW

Conversation

@aikido-autofix
Copy link
Copy Markdown
Contributor

This PR will resolve the following CVEs:

CVE ID Severity Description
CVE-2025-5889
LOW
A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. Th...

cursor[bot]

This comment was marked as outdated.

@janb87 janb87 merged commit 7a7baec into main Jul 2, 2025
8 checks passed
@janb87 janb87 deleted the fix/aikido-security-update-packages-4887280-htoW branch July 2, 2025 15:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant