conductor-oss / conductor-oss/javascript-sdk

[GHSA-mw96-cpmx-2vgc] rollup@4.52.0: Arbitrary File Write via Path Traversal

Open
#112 1 comment 0 reactions 0 assignees View on GitHub
security vulnerability
Dominant language
TypeScript
Stars
58
Forks
20
Avg merge
1d 13h
Merged PRs (30d)
7

Description

## Vulnerability Report

| CVE | Library | Installed | Fixed |
|-----|---------|-----------|-------|
| GHSA-mw96-cpmx-2vgc | rollup | 4.52.0 | 4.59.0 |

### Summary
Rollup 4 has Arbitrary File Write via Path Traversal.

### References
- [GHSA-mw96-cpmx-2vgc](https://osv.dev/vulnerability/GHSA-mw96-cpmx-2vgc)

Contributor guide

No contributing guide indexed for this repository

Research direction

No source file or test is named. Locate the project’s dependency declaration for rollup, review how the installed version is recorded, and confirm the affected 4.52.0 version is replaced by the stated fixed 4.59.0 release; done means the dependency is updated and the reported vulnerability is no longer present.

Written by the indexing model from the issue text.

Assessment

Tech stack
rollup, typescript
Domain
build-system, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.