Skip to content

Comments

Fix CVE-2025-5889: Update brace-expansion to 1.1.12#168

Open
mihirukongahage wants to merge 1 commit intodevfrom
fix-cve-2025-5889
Open

Fix CVE-2025-5889: Update brace-expansion to 1.1.12#168
mihirukongahage wants to merge 1 commit intodevfrom
fix-cve-2025-5889

Conversation

@mihirukongahage
Copy link
Owner

Security Fix for CVE-2025-5889\n\n### Summary\nThis PR fixes the vulnerability CVE-2025-5889 in the brace-expansion package.\n\n### Changes\n- Added npm override in package.json to force brace-expansion to version 1.1.12\n- Updated package-lock.json to reflect the patched version\n\n### Vulnerability Details\n- Package: brace-expansion\n- Vulnerable Version: 1.1.11\n- Fixed Version: 1.1.12\n\n### Testing\n- Run npm install --legacy-peer-deps to install dependencies with the security fix

Security fix for CVE-2025-5889 - brace-expansion vulnerability.
Added npm override to force brace-expansion to version 1.1.12 which
contains the security patch.

Co-authored-by: openhands <openhands@all-hands.dev>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants