Skip to content

Security Vulnerability: CVE-2025-27789 in rc-mentions@^2.19.1 (via @babel/runtime@^7.22.5) #292

Description

@phattanapisit

Hello,

I would like to report a security vulnerability (CVE-2025-27789) found in rc-mentions@^2.19.1, which depends on @babel/runtime@^7.22.5.

Issue Details:
Affected Package: rc-mentions@^2.19.1
Vulnerable Dependency: @babel/runtime@^7.22.5
CVE: CVE-2025-27789 (Add a reference link if available)
Impact: (Describe the risk—e.g., "This vulnerability may allow XSS attacks or remote code execution.")
Suggested Fix:
Upgrade @babel/runtime to a secure version if available.
If rc-mentions has a newer release that addresses this issue, please consider upgrading.
Could you confirm if there is a planned fix for this issue? Thank you.

Best regards,

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions