Skip to content

fix(security): remediate baseline-browser-mapping vulnerability - #247

Closed
GioDavid wants to merge 3 commits into
mainfrom
security/baseline-browser-mapping-2.11.27
Closed

GioDavid wants to merge 3 commits into
mainfrom
security/baseline-browser-mapping-2.11.27

Conversation

@GioDavid

@GioDavid GioDavid commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Resolves CVE-2026-45819 / GHSA-w5vr-8v7q-w6rv (CWE-705, moderate) in transitive baseline-browser-mapping 2.10.37.
  • Versions before 2.11.0 call process.exit() on invalid or conflicting library inputs, which terminates the Node process. 2.11.0 and later throw instead.
  • The installed copy is now 2.11.27. This pull request does not change browserslist or any other package.

Dependency path

baseline-browser-mapping is not a direct dependency. One version is installed, and every path goes through browserslist@4.28.2 (baseline-browser-mapping@^2.10.12):

  • example → @babel/core → @babel/helper-compilation-targets → browserslist → baseline-browser-mapping
  • example and react-native-spotlight-tour → @react-native/babel-preset / Metro → @babel/core or core-js-compat → browserslist → baseline-browser-mapping

Immediate parent: browserslist@4.28.2.
Higher-level parents: @babel/helper-compilation-targets@7.29.7 and core-js-compat@3.49.0.

Role: build-time Babel/Metro tooling. It is not a runtime dependency of the published library. browserslist calls getCompatibleVersions() only for baseline queries. Attacker-controlled parameters are not part of normal library use; the package was still inside the affected range.

Package-only investigation

browserslist@4.28.2 already allows baseline-browser-mapping@^2.10.12, which includes 2.11.27.

yarn up -R baseline-browser-mapping

Result: 2.10.37 → 2.11.27, with browserslist still at 4.28.2. Only yarn.lock changed.

Parent investigation

yarn up -R browserslist resolves the latest version allowed by the existing ranges (^4.24.0 and ^4.28.1): browserslist@4.29.3, which depends on baseline-browser-mapping@^2.11.26 and installs 2.11.27.

That update is a non-breaking minor and does fix this advisory. It also changes caniuse-lite, electron-to-chromium, node-releases, and update-browserslist-db, and it moves browserslist off 4.28.2. That browserslist release is a separate remediation for CVE-2026-73088 and CVE-2026-73089, already covered by security/browserslist-4.29.3.

Updating Babel, Metro, or React Native was not tested. Their current ranges already accept browserslist@4.28.2, so they do not change this package unless browserslist itself moves. Those upgrades would be toolchain changes.

browserslist@4.28.9 (latest 4.28 patch) also requires baseline-browser-mapping@^2.11.20, but yarn up -R cannot pin that older release, and it would still upgrade browserslist for a different advisory.

Final remediation

Lockfile-only update of baseline-browser-mapping from 2.10.37 to 2.11.27.

The parent update was not selected because the existing range already reaches a fixed release, the lockfile change is limited to this package, and the parent update would also remediate a different browserslist advisory.

Validation

  • yarn install --immutable
  • yarn why baseline-browser-mapping → browserslist@4.28.2 → baseline-browser-mapping@2.11.27
  • OSV query for 2.11.27: no advisories
  • yarn npm audit: baseline-browser-mapping is not reported
  • yarn compile
  • yarn lint
  • yarn test:ci (22 tests passed)
  • Changed files: yarn.lock only

Scope

Limited to CVE-2026-45819 in baseline-browser-mapping. Other audit findings are unchanged.

Test plan

  • yarn install --immutable
  • Confirm yarn why baseline-browser-mapping resolves 2.11.27 and no 2.10.x copy remains
  • yarn compile
  • yarn lint
  • yarn test:ci
  • CI on this pull request

Made with Cursor

Resolve CVE-2026-45819 by moving the browserslist dependency off 2.10.37, which exits the process on invalid input.

Co-authored-by: Cursor <cursoragent@cursor.com>
@GioDavid
GioDavid requested a review from suany0805 October 2, 2026 15:22
@GioDavid

GioDavid commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator Author

resolved using dependabots

@GioDavid GioDavid closed this Oct 2, 2026
@GioDavid
GioDavid deleted the security/baseline-browser-mapping-2.11.27 branch October 2, 2026 18:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant