andrewrk / andrewrk/node-mv

CVE-2026-26996

Đang mở
#37 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
JavaScript
Star
156
Fork
18
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

As per https://github.com/advisories/GHSA-3ppc-4f35-3m26

> minimatch is vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal character that doesn't appear in the test string.

minimatch is included as a sub-dependency of `mv` through the following dependency chain

```
minimatch <10.2.1
Severity: high
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern - https://github.com/advisories/GHSA-3ppc-4f35-3m26
fix available via `npm audit fix`
node_modules/mv/node_modules/minimatch
glob 3.0.0 - 10.5.0
Depends on vulnerable versions of minimatch
node_modules/mv/node_modules/glob
rimraf 2.3.0 - 3.0.2 || 4.2.0 - 5.0.10
Depends on vulnerable versions of glob
node_modules/mv/node_modules/rimraf
mv >=2.1.0
Depends on vulnerable versions of rimraf
node_modules/mv
```

Can this library be updated to support a newer version of `rimraf` which allows for dependency chains to install a patched version of minimatch?

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.