Skip to content

Security: Update minimatch to fix vulnerability CVE-2026-26996 #478

@paras-raba

Description

@paras-raba

Hi team,

I am opening this issue to report that the current version of minimatch used in this project is vulnerable to a Regular Expression Denial of Service (ReDoS) attack.

Context:
Our organization uses this extension in a production Web IDE environment. Our security policies require us to patch or file exceptions for all High/Critical CVEs. While I understand the extension is well-maintained, we are currently blocked by this specific dependency.

Reference to Previous PR:
I previously opened a PR #477 to address this via npm update, but it was closed. I would be happy to re-open a more targeted PR or help test a fix if you have a specific contribution guideline I should follow!!

Also apologies from my end, I should have opened the issue or discussed this first, before raising the PR.

Question:
Is there a planned release on the roadmap that will address these security dependencies? If not, would you be open to a PR that specifically targets the minimatch upgrade?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions