Skip to content

minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern #8636

@brendon

Description

@brendon

minimatch that is included in the dependency tree by @tensorflow/tfjs-node via both @mapbox/node-pre-gyp and rimraf has a vulnerability: CVE-2026-26996

Essentially glob needs to be upgraded in rimraf (which is has in the latest version).

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions