Skip to content

[🐛 BUG]: CVE-2025-22871 #2166

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
1 task done
Orrison opened this issue Apr 29, 2025 · 1 comment
Closed
1 task done

[🐛 BUG]: CVE-2025-22871 #2166

Orrison opened this issue Apr 29, 2025 · 1 comment
Assignees
Labels
Milestone

Comments

@Orrison
Copy link

Orrison commented Apr 29, 2025

No duplicates 🥲.

  • I have searched for a similar issue in our bug tracker and didn't find any solutions.

What happened?

CVE-2025-22871 is present in the current version of the rr package triggering causing vulnerability and triggering a critical vuln in auditing reports.

Package like esbuild have updated to resolve this issue for reference: evanw/esbuild#4133

Version (rr --version)

2024.3.5

How to reproduce the issue?

The vulnerability is present at all times. No need to reproduce.

Relevant log output

@Orrison Orrison added B-bug Bug: bug, exception F-need-verification labels Apr 29, 2025
@Orrison Orrison mentioned this issue Apr 29, 2025
6 tasks
@rustatian rustatian added this to the v2025.1.0 milestone Apr 29, 2025
@rustatian rustatian moved this to 🏗 In progress in Jira 😄 Apr 29, 2025
@rustatian rustatian added A-other Area: other Y-high Priority: High and removed B-bug Bug: bug, exception labels Apr 29, 2025
@rustatian rustatian mentioned this issue May 1, 2025
6 tasks
@rustatian
Copy link
Member

Fixed in v2025.1

@github-project-automation github-project-automation bot moved this from 🏗 In progress to ✅ Done in Jira 😄 May 1, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
Status: ✅ Done
Development

No branches or pull requests

2 participants