andrewrk / andrewrk/node-mv

CVE-2026-26996

未關閉
#37 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
JavaScript
星號
156
分支
18
PR 合併指標
30 天內沒有已合併 PR

描述

As per https://github.com/advisories/GHSA-3ppc-4f35-3m26

> minimatch is vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal character that doesn't appear in the test string.

minimatch is included as a sub-dependency of `mv` through the following dependency chain

```
minimatch <10.2.1
Severity: high
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern - https://github.com/advisories/GHSA-3ppc-4f35-3m26
fix available via `npm audit fix`
node_modules/mv/node_modules/minimatch
glob 3.0.0 - 10.5.0
Depends on vulnerable versions of minimatch
node_modules/mv/node_modules/glob
rimraf 2.3.0 - 3.0.2 || 4.2.0 - 5.0.10
Depends on vulnerable versions of glob
node_modules/mv/node_modules/rimraf
mv >=2.1.0
Depends on vulnerable versions of rimraf
node_modules/mv
```

Can this library be updated to support a newer version of `rimraf` which allows for dependency chains to install a patched version of minimatch?

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。