Skip to content

[Bug] CVE-2025-27789: DOS Vulnerability in BabelΒ #3232

Open
@jorlando-elucid

Description

@jorlando-elucid

Bug description

vtk.js depends on "@babel/runtime": "7.22.11"

Versions of @babel < 7.26.10 are vulnerable to CVE-2025-27789, a DOS condition due to improper handling of regex's.

Steps to reproduce

Inspect the package-lock.json file for the version of babel.

https://github.com/Kitware/vtk-js/blame/307ce4497ca0698b8934e79716db2c5a33f3a9a7/package-lock.json#L13

Detailed Behavior

No response

Expected Behavior

Update babel to remediate vulnerability

Environment

All

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions