Skip to content

Conversation

@psimsa
Copy link
Owner

@psimsa psimsa commented Jul 18, 2025

This PR addresses the high-severity vulnerability CVE-2025-26646 by:

  1. Updating Nuke.Common from 8.1.4 to 9.0.4
  2. Adding a direct dependency on Microsoft.Build.Tasks.Core 17.14.8

The vulnerability is related to external control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio, with a CVSS score of 8.0. The fix ensures we use the patched version of Microsoft.Build.Tasks.Core that resolves this security issue.

@sonarqubecloud
Copy link

@psimsa psimsa closed this Jul 18, 2025
@psimsa psimsa deleted the fix-vulnerability-cve-2025-26646 branch July 18, 2025 07:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants