Skip to content

semantic-release

v25.0.7 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 14d Artifact Management
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

automation changelog package publish release release-automation
+6 more
release-workflow semantic-release semantic-version semver semver-release version

Affected surfaces

rce_ssrf breaking_upgrade

ReleasePort's take

Moderate signal
editorial:auto 13d

Version v25.0.7 fixes an argument injection vulnerability that can be triggered through the repositoryUrl field in package.json.

Why it matters: Addresses a high-severity (95) security flaw affecting package.json handling; deploy v25.0.7 to mitigate risk.

Summary

AI summary

Fixes argument injection vulnerability via repositoryUrl in package.json

Changes in this release

Security Critical

Fixes argument injection vulnerability via repositoryUrl in package.json

Fixes argument injection vulnerability via repositoryUrl in package.json

Source: llm_adapter@2026-07-13

Confidence: high

Full changelog

25.0.7 (2026-07-13)

Bug Fixes

  • argument Injection via repositoryUrl in package.json (#4245) (c46dbda)

Security Fixes

  • Fixes argument injection vulnerability via repositoryUrl in package.json

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track semantic-release

Get notified when new releases ship.

Sign up free

About semantic-release

package::rocket: Fully automated version management and package publishing

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]