Skip to content

minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern #8636

@brendon

Description

@brendon

minimatch that is included in the dependency tree by @tensorflow/tfjs-node via both @mapbox/node-pre-gyp and rimraf has a vulnerability: CVE-2026-26996

Essentially glob needs to be upgraded in rimraf (which is has in the latest version).

Metadata

Metadata

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions