Repository navigation
Conversation
Resolve CVE-2026-45819 by moving the browserslist dependency off 2.10.37, which exits the process on invalid input. Co-authored-by: Cursor <cursoragent@cursor.com>
Collaborator
Author
|
resolved using dependabots |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
baseline-browser-mapping2.10.37.process.exit()on invalid or conflicting library inputs, which terminates the Node process. 2.11.0 and later throw instead.browserslistor any other package.Dependency path
baseline-browser-mappingis not a direct dependency. One version is installed, and every path goes throughbrowserslist@4.28.2(baseline-browser-mapping@^2.10.12):example→@babel/core→@babel/helper-compilation-targets→browserslist→baseline-browser-mappingexampleandreact-native-spotlight-tour→@react-native/babel-preset/ Metro →@babel/coreorcore-js-compat→browserslist→baseline-browser-mappingImmediate parent:
browserslist@4.28.2.Higher-level parents:
@babel/helper-compilation-targets@7.29.7andcore-js-compat@3.49.0.Role: build-time Babel/Metro tooling. It is not a runtime dependency of the published library.
browserslistcallsgetCompatibleVersions()only forbaselinequeries. Attacker-controlled parameters are not part of normal library use; the package was still inside the affected range.Package-only investigation
browserslist@4.28.2already allowsbaseline-browser-mapping@^2.10.12, which includes 2.11.27.Result:
2.10.37→2.11.27, withbrowsersliststill at 4.28.2. Onlyyarn.lockchanged.Parent investigation
yarn up -R browserslistresolves the latest version allowed by the existing ranges (^4.24.0and^4.28.1):browserslist@4.29.3, which depends onbaseline-browser-mapping@^2.11.26and installs 2.11.27.That update is a non-breaking minor and does fix this advisory. It also changes
caniuse-lite,electron-to-chromium,node-releases, andupdate-browserslist-db, and it movesbrowserslistoff 4.28.2. Thatbrowserslistrelease is a separate remediation for CVE-2026-73088 and CVE-2026-73089, already covered bysecurity/browserslist-4.29.3.Updating Babel, Metro, or React Native was not tested. Their current ranges already accept
browserslist@4.28.2, so they do not change this package unlessbrowserslistitself moves. Those upgrades would be toolchain changes.browserslist@4.28.9(latest 4.28 patch) also requiresbaseline-browser-mapping@^2.11.20, butyarn up -Rcannot pin that older release, and it would still upgradebrowserslistfor a different advisory.Final remediation
Lockfile-only update of
baseline-browser-mappingfrom 2.10.37 to 2.11.27.The parent update was not selected because the existing range already reaches a fixed release, the lockfile change is limited to this package, and the parent update would also remediate a different
browserslistadvisory.Validation
yarn install --immutableyarn why baseline-browser-mapping→browserslist@4.28.2→baseline-browser-mapping@2.11.27yarn npm audit:baseline-browser-mappingis not reportedyarn compileyarn lintyarn test:ci(22 tests passed)yarn.lockonlyScope
Limited to CVE-2026-45819 in
baseline-browser-mapping. Other audit findings are unchanged.Test plan
yarn install --immutableyarn why baseline-browser-mappingresolves 2.11.27 and no 2.10.x copy remainsyarn compileyarn lintyarn test:ciMade with Cursor