react-component / react-component/mentions

Security Vulnerability: CVE-2025-27789 in rc-mentions@^2.19.1 (via @babel/runtime@^7.22.5)

Open
#292 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
112
Forks
65
Avg merge
28m
Merged PRs (30d)
2

Description

Hello,

I would like to report a security vulnerability (CVE-2025-27789) found in rc-mentions@^2.19.1, which depends on @babel/runtime@^7.22.5.

Issue Details:
Affected Package: rc-mentions@^2.19.1
Vulnerable Dependency: @babel/runtime@^7.22.5
CVE: CVE-2025-27789 (Add a reference link if available)
Impact: (Describe the risk—e.g., "This vulnerability may allow XSS attacks or remote code execution.")
Suggested Fix:
Upgrade @babel/runtime to a secure version if available.
If rc-mentions has a newer release that addresses this issue, please consider upgrading.
Could you confirm if there is a planned fix for this issue? Thank you.

Best regards,

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No file or test is named. Start by verifying CVE-2025-27789 and inspecting the dependency tree for @babel/runtime; determine the affected and secure versions. Done means the vulnerable dependency is resolved and the project’s dependency checks confirm the fix.

Written by the indexing model from the issue text.

Assessment

Tech stack
babel, react, typescript
Domain
build-system, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.