Security: Vulnerable dependency minimatch@3.1.2 [SNYK-JS-MINIMATCH-15309438, CVE-2026-26996]

Open
#533 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
javascript
Domain
security

Research direction

Start by inspecting the dependency tree for ember-cli-babel@8.3.1, especially the listed broccoli, walk-sync, rimraf, glob, and babel-plugin-module-resolver paths. Check which compatible upgrades remove minimatch 3.1.2, 8.0.4, and 9.0.5, then verify the dependency tree against the Snyk advisory. Done means no vulnerable minimatch versions remain without breaking the package.

Written by the indexing model from the issue text.

Description

Summary

ember-cli-babel@8.3.1 depends on multiple vulnerable versions of minimatch (3.1.2, 8.0.4, 9.0.5), which are vulnerable to Regular Expression Denial of Service (ReDoS) (High severity).

Vulnerability Details

Affected versions of minimatch are vulnerable to ReDoS in the AST class, caused by catastrophic backtracking when an input string contains many * characters in a row followed by an unmatched character.

Example Affected Dependency Paths

minimatch is pulled in through 21 paths in ember-cli-babel@8.3.1. Key paths grouped by vulnerable version:

# Dependency Path
1 ember-cli-babelbabel-plugin-module-resolver@5.0.2glob@9.3.5minimatch@8.0.4
2 ember-cli-babelbroccoli-funnel@3.0.8minimatch@3.1.2
3 ember-cli-babelbroccoli-funnel@3.0.8walk-sync@2.2.0minimatch@3.1.2
few more...

Potential Remediation

  1. Fix has been given in minimatch to version 10.2.1 or higher. Upgrade transitive dependencies that pull in vulnerable minimatch versions — broccoli-funnel, broccoli-plugin, broccoli-persistent-filter, broccoli-debug, walk-sync, rimraf, glob, and babel-plugin-module-resolver — to versions that depend on minimatch@>=10.2.1

References

Dominant language
JavaScript
Stars
152
Forks
115
Avg merge
23h 22m
Merged PRs (30d)
4

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from emberjs/ember-cli-babel

All issues in emberjs/ember-cli-babel

Similar issues

More JavaScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.