This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+6 more
Affected surfaces
ReleasePort's take
Moderate signalVersion v25.0.7 fixes an argument injection vulnerability that can be triggered through the repositoryUrl field in package.json.
Why it matters: Addresses a high-severity (95) security flaw affecting package.json handling; deploy v25.0.7 to mitigate risk.
Summary
AI summaryFixes argument injection vulnerability via repositoryUrl in package.json
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes argument injection vulnerability via repositoryUrl in package.json Fixes argument injection vulnerability via repositoryUrl in package.json Source: llm_adapter@2026-07-13 Confidence: high |
— |
Security Fixes
- Fixes argument injection vulnerability via repositoryUrl in package.json
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About semantic-release
package::rocket: Fully automated version management and package publishing
Related context
Related tools
Beta — feedback welcome: [email protected]