fix(deps): update dependency rollbar to v2.26.5 [security] #293
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.26.0->2.26.5GitHub Vulnerability Alerts
CVE-2025-57325
Impact
Prototype pollution potential with the utility function
rollbar/src/utility.set(). No impact when using the published public interface.If application code directly imports
setfromrollbar/src/utilityand then callssetwith untrusted input in the second argument, it is vulnerable to prototype pollution.POC:
Patches
Fixed in version 2.26.5 and 3.0.0-beta5.
Workarounds
If application code directly imports
setfromrollbar/src/utility, ensure that the second argument does not receive untrusted input.References
https://github.com/rollbar/rollbar.js/issues/1333#issuecomment-3353720946
CVE-2025-62517
Impact
Prototype pollution vulnerability in merge(). If application code calls
rollbar.configure()with untrusted input, prototype pollution is possible.Patches
Fixed in 2.26.5 and 3.0.0-beta5.
Workarounds
Ensure that values passed to
rollbar.configure()do not contain untrusted input.References
Fixed in https://github.com/rollbar/rollbar.js/pull/1394 (2.26.x) and https://github.com/rollbar/rollbar.js/pull/1390 (3.x)
Release Notes
rollbar/rollbar.js (rollbar)
v2.26.5Compare Source
Prototype pollution prevention, #1394
v2.26.4Compare Source
v2.26.3Compare Source
URLobject infetch/XHRtelemetry, #1118v2.26.2Compare Source
v2.26.1Compare Source
Fixes
objecttype defs with dictionary type, #1079thisto closure, #1081Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.