pytorch / pytorch/executorch

Vulnerability in the @babel/helpers dependency of ReactNative LLaMA App

Open
#9,179 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

module: reactnative
Dominant language
Python
Stars
5k
Forks
1.2k
Avg merge
2d 10h
Merged PRs (30d)
581

Description

🐛 Describe the bug

Package Dependency

Identifiers

  • GHSA-968p-4wvh-cqc8
  • CVE-2025-27789

References

Versions

.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with examples/demo-apps/react-native/rnllama/yarn.lock and inspect the recorded @babel/helpers version. Update the dependency resolution to version 7.26.10 or later, then verify the lockfile no longer uses an affected version and that the React Native app dependency installation remains consistent.

Written by the indexing model from the issue text.

Assessment

Tech stack
babel, javascript, react-native
Domain
mobile-dev, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
50/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.