Skip to content

@angular-devkit/build-angular 18.2.19 affected by CVE-2025-46565 #30364

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
1 task
steven-j-park opened this issue May 21, 2025 · 1 comment
Closed
1 task

Comments

@steven-j-park
Copy link

steven-j-park commented May 21, 2025

Command

build

Is this a regression?

  • Yes, this behavior used to work in the previous version

The previous version in which this bug was not present was

No response

Description

CVE-2025-46565 details a vulnerability with vite v5.4.18 which is present in @angular/cli version 18.2.19. Recommend updating to vite v5.4.19

Minimal Reproduction

No reproduction steps

Exception or Error


Your Environment

Angular CLI: 18.2.19
Node: 20.19.2
Package Manager: npm 10.8.2
OS: win32 x64

Anything else relevant?

No response

@steven-j-park steven-j-park changed the title @angular-devkit/build-angular 18.2.9 affected by CVE-2025-46565 @angular-devkit/build-angular 18.2.19 affected by CVE-2025-46565 May 21, 2025
@alan-agius4
Copy link
Collaborator

alan-agius4 commented May 21, 2025

Version 18 uses ~5.4.17, which resolves to version 5.4.19. Please update your lock file accordingly. See:

@alan-agius4 alan-agius4 closed this as not planned Won't fix, can't repro, duplicate, stale May 21, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants