Skip to content

Conversation

@cylewaitforit
Copy link

Updates

  • Affected products

Comments
https://x.com/SzymonRybczak/status/1986199665000566848

Copilot AI review requested due to automatic review settings November 6, 2025 22:22
@github-actions github-actions bot changed the base branch from main to cylewaitforit/advisory-improvement-6394 November 6, 2025 22:23
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR corrects the vulnerability version range in a GitHub security advisory by specifying that the vulnerability was introduced in version 18.0.0 rather than affecting all versions from "0". This narrows the scope of affected versions to 18.0.0-19.x.x (fixed in 20.0.0).

Key Changes:

  • Updated the introduced version from "0" to "18.0.0" to accurately reflect when the vulnerability was introduced
  • Updated the modified timestamp to reflect the advisory correction

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@advisory-database advisory-database bot merged commit 3e0f827 into cylewaitforit/advisory-improvement-6394 Nov 6, 2025
10 checks passed
@advisory-database
Copy link
Contributor

Hi @cylewaitforit! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the cylewaitforit-GHSA-399j-vxmf-hjvr branch November 6, 2025 22:36
@shelbyc
Copy link
Contributor

shelbyc commented Nov 6, 2025

Hi @cylewaitforit, I noticed from https://x.com/SzymonRybczak/status/1986199665000566848 that https://github.com/react-native-community/cli has released multiple fixes to address CVE-2025-11953, including 19.1.2, 18.0.1, and 17.0.1. I'm changing the affected version ranges to incorporate these fixed versions. Because you alerted me to the existence of backported fixes, you'll still receive credit on the advisory.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants