Skip to content

fix(security): remediate linkify-it vulnerability - #243

Closed
GioDavid wants to merge 4 commits into
mainfrom
security/linkify-it-5.0.2
Closed

GioDavid wants to merge 4 commits into
mainfrom
security/linkify-it-5.0.2

Conversation

@GioDavid

@GioDavid GioDavid commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Summary

Resolves CVE-2026-59887 / GHSA-v245-v573-v5vm in linkify-it (quadratic CPU use in the mailto: validator, fixed in 5.0.2). The installed 5.0.1 copy is a docs-only transitive dependency of TypeDoc and is not part of the React Native runtime.

Dependency path

package (devDependency)
  → typedoc@0.28.19
    → markdown-it@14.2.0
      → linkify-it@5.0.1

Immediate parent: markdown-it. High-level parent: typedoc. One installed version, requested as linkify-it@^5.0.1.

CVE-2026-48801 / GHSA-22p9-wv53-3rq4 (<= 5.0.0, fixed in 5.0.1) does not apply to the installed 5.0.1 release.

Package-only investigation

yarn up -R linkify-it can resolve linkify-it@5.0.2 inside the existing ^5.0.1 range and changes only the linkify-it lockfile entry. It leaves markdown-it at 14.2.0.

Parent investigation

markdown-it@14.3.2 is a non-breaking update inside TypeDoc's existing markdown-it@^14.1.1 range. It requires linkify-it@^5.0.2.

markdown-it@15 was not used. It is a major release (linkify-it 6, entities 8, argparse 3, removed internal exports). typedoc@0.28.20 was not required; its range already allows 14.3.2, and that TypeDoc release includes unrelated feature work.

yarn up -R markdown-it resolved markdown-it@14.3.2 and linkify-it@5.0.2. entities stays at 4.5.0. Only yarn.lock changed.

This parent update also moves markdown-it past GHSA-253c-mchw-3w2r (< 14.3.1) and includes the 14.3.2 security backport. Those fixes are in markdown-it's own linkify path, separate from CVE-2026-59887.

Final remediation

Lockfile-only update:

  • markdown-it 14.2.0 → 14.3.2
  • linkify-it 5.0.1 → 5.0.2

Why

Both strategies fix CVE-2026-59887 and touch only yarn.lock. The parent update is smaller in risk than a TypeDoc or markdown-it 15 upgrade, and it also clears the related quadratic linkify issue that a linkify-it-only bump would leave in markdown-it@14.2.0.

Validation

  • yarn install --immutable
  • yarn why linkify-it → 5.0.2 via markdown-it@14.3.2
  • yarn test (22 tests passed)
  • yarn lint
  • yarn docs (TypeDoc markdown generation)
  • yarn npm audit -A -R no longer reports linkify-it or markdown-it

Scope

Limited to this linkify-it remediation. Other audit findings are unchanged and are not part of this PR.

Test plan

  • Confirm yarn why linkify-it shows 5.0.2 only
  • yarn test
  • yarn lint
  • yarn docs
  • Dependency audit no longer reports CVE-2026-59887

Made with Cursor

typedoc already allows markdown-it 14.3.2, which requires the patched linkify-it release and includes the related linkify denial-of-service fixes.

Co-authored-by: Cursor <cursoragent@cursor.com>
@GioDavid

GioDavid commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator Author

solved using dependabots

@GioDavid GioDavid closed this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant