Skip to content
This repository was archived by the owner on May 22, 2026. It is now read-only.

fix: critical issue in turbo via minor version upgrade from 2.6.3 to 2.9.14#206

Merged
glebedel merged 1 commit into
mainfrom
fix/aikido-security-SEC-1764-update-packages-37544319-u8rm
May 21, 2026
Merged

fix: critical issue in turbo via minor version upgrade from 2.6.3 to 2.9.14#206
glebedel merged 1 commit into
mainfrom
fix/aikido-security-SEC-1764-update-packages-37544319-u8rm

Conversation

@aikido-autofix

Copy link
Copy Markdown
Contributor

Upgrade turbo to fix critical RCE vulnerability in package manager detection that could execute arbitrary code from malicious Yarn configurations.

✅ 1 CVE resolved by this upgrade, including 1 critical 🚨 CVE

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-45772
🚨 CRITICAL
[turbo] Arbitrary code execution vulnerability in package manager detection that executes malicious Yarn configurations from untrusted repositories. An attacker controlling repository contents can achieve RCE when users or CI systems run turbo commands.
🔗 Related Tasks

Copilot AI review requested due to automatic review settings May 21, 2026 08:07

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@glebedel glebedel changed the title [Aikido] Fix critical issue in turbo via minor version upgrade from 2.6.3 to 2.9.14 fix: critical issue in turbo via minor version upgrade from 2.6.3 to 2.9.14 May 21, 2026

@glebedel glebedel left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@glebedel glebedel merged commit a48ab52 into main May 21, 2026
6 of 7 checks passed
@glebedel glebedel deleted the fix/aikido-security-SEC-1764-update-packages-37544319-u8rm branch May 21, 2026 08:31
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants