Skip to content

[Aikido] Fix security issue in glob via minor version upgrade from 10.3.4 to 10.5.0#23

Merged
daniel-vdp merged 1 commit into
mainfrom
fix/aikido-security-update-packages-17830411-vMRh
Mar 5, 2026
Merged

[Aikido] Fix security issue in glob via minor version upgrade from 10.3.4 to 10.5.0#23
daniel-vdp merged 1 commit into
mainfrom
fix/aikido-security-update-packages-17830411-vMRh

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Mar 2, 2026

Copy link
Copy Markdown
Contributor

Upgrade glob to fix command injection vulnerability (CVE-2025-64756) enabling arbitrary code execution via malicious filenames in CLI operations.

✅ 1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2025-64756
HIGH
[glob] A command injection vulnerability in the CLI's -c/--cmd option allows arbitrary code execution when processing files with malicious names, as matched filenames are passed to a shell with shell metacharacters interpreted.

@aikido-autofix aikido-autofix Bot requested a review from daniel-vdp as a code owner March 2, 2026 03:05
@aikido-autofix aikido-autofix Bot force-pushed the fix/aikido-security-update-packages-17830411-vMRh branch from 5e9e3eb to f626116 Compare March 5, 2026 23:47
@daniel-vdp daniel-vdp merged commit f1bcb60 into main Mar 5, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant