Skip to content

chore(security): fix CVEs (2026-07-23) - #90

Open
Kevintjuhz wants to merge 2 commits into
developfrom
cve-fixes-2026-07-23
Open

chore(security): fix CVEs (2026-07-23)#90
Kevintjuhz wants to merge 2 commits into
developfrom
cve-fixes-2026-07-23

Conversation

@Kevintjuhz

Copy link
Copy Markdown
Member

Security & dependency fixes — 2026-07-23

Automatically applied by /cve-fix. Patch and minor bumps only.

Security CVE fixes

Severity Package From To CVE GHSA Summary
high svgo 4.0.1 4.0.2 GHSA-2p49-hgcm-8545 SVGO removeScripts plugin leaves some executable scripts intact
medium tar 7.5.16 7.5.18 CVE-2026-59871 GHSA-w8wr-v893-vjvp node-tar: Process crash via PAX numeric path type confusion
high shell-quote 1.8.4 1.9.0 CVE-2026-13311 GHSA-395f-4hp3-45gv shell-quote: Quadratic-complexity Denial of Service in parse() (CWE-407)

Dependabot version bumps

Package From To Summary
tar 7.5.16 7.5.21 chore(deps-dev): bump tar from 7.5.16 to 7.5.21
shell-quote 1.8.4 1.10.0 chore(deps-dev): bump shell-quote from 1.8.4 to 1.10.0
svgo 4.0.1 4.0.2 chore(deps-dev): bump svgo from 4.0.1 to 4.0.2

Major bumps requiring manual review are listed in the CVE manual review report.

- [high] svgo 4.0.1 → 4.0.2 (-, GHSA-2p49-hgcm-8545)
- [medium] tar 7.5.16 → 7.5.18 (CVE-2026-59871, GHSA-w8wr-v893-vjvp)
- [high] shell-quote 1.8.4 → 1.9.0 (CVE-2026-13311, GHSA-395f-4hp3-45gv)
- [bump] tar 7.5.16 → 7.5.21 (-, -)
- [bump] shell-quote 1.8.4 → 1.10.0 (-, -)
- [bump] svgo 4.0.1 → 4.0.2 (-, -)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant