Skip to content

fix(deps): CVE-2026-102276 (high) + CVE-2026-102278 (high) — bump brace-expansion override to ^5.0.11 - #1928

Merged
mishushakov merged 1 commit into
mainfrom
devin/1790924781-brace-expansion-cve-2026-102276-102278
Oct 2, 2026
Merged

mishushakov merged 1 commit into
mainfrom
devin/1790924781-brace-expansion-cve-2026-102276-102278

Conversation

@devin-ai-integration

@devin-ai-integration devin-ai-integration Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

pnpm audit flags brace-expansion@5.0.9. The SDK pulls it in at runtime through e2b → glob → minimatch@10.2.5 → brace-expansion. glob is a runtime dependency of packages/js-sdk: template/utils.ts dynamically imports it to expand user-supplied Template.copy() source patterns, so published code can reach it.

Advisory Severity Issue Fixed in (5.x)
CVE-2026-102276 / GHSA-6j4f-fj2g-mc7p high DoS via uncontrolled recursion in parseCommaParts 5.0.10
CVE-2026-102278 / GHSA-qhr7-859c-m2p7 high DoS via uncontrolled recursion on nested brace groups 5.0.11
CVE-2026-102277 / GHSA-q2hr-2g5m-vwhr moderate Quadratic-time {a},b} rewrite 5.0.12
 # pnpm-workspace.yaml overrides
-  brace-expansion@>=4.0.0 <5.0.9: ^5.0.9
+  brace-expansion@>=4.0.0 <5.0.11: ^5.0.11
 # pnpm-lock.yaml
-brace-expansion 5.0.9
+brace-expansion 5.0.12

One PR for both high CVEs: the smallest override that clears CVE-2026-102276 (^5.0.10) already resolves to 5.0.12. That version clears all three advisories, so two separate PRs would have identical lockfiles and conflict on the same override line. The floor is ^5.0.11, the lowest version that clears both highs. 5.0.10–5.0.12 were published 2026-09-14, outside the 3-day minimumReleaseAge window.

No changeset: this follows earlier override-only bumps (#1869, #1851). The workspace override and lockfile aren't published. e2b keeps depending on glob ^13.0.6, and no released minimatch requires a patched brace-expansion floor, so fresh installs of e2b already resolve to 5.0.12 through ^5.0.x.

Not covered here (dev-only): brace-expansion@1.1.18 (via npm-run-all) and @2.1.4 (via openapi-typescript → @redocly/openapi-core). Both come only from js-sdk devDependencies used for codegen and scripts, and published code can't reach them.

Verified locally:

  • pnpm audit no longer reports the 5.x path.
  • The tests/template/utils vitest suite passes (81 passed, 3 skipped). It includes the glob-based getAllFilesInPath tests.
  • pnpm --dir packages/js-sdk run typecheck passes.

Link to Devin session: https://app.devin.ai/sessions/ee1f1bed5d9d479aa6092da48034989b
Open in Devin Desktop: https://app.devin.ai/desktop/session/ee1f1bed5d9d479aa6092da48034989b?variant=devin


Devin Review

…VE-2026-102278)

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@cla-bot cla-bot Bot added the cla-signed label Oct 2, 2026
@changeset-bot

changeset-bot Bot commented Oct 2, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: d7e22cd

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TASTE.md review: complies — 0 violations. The PR only changes the brace-expansion override in pnpm-workspace.yaml and pnpm-lock.yaml; it touches no public SDK surface in packages/js-sdk or packages/python-sdk, so none of the TASTE.md rules (T-1–T-74) apply.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Package Artifacts

Built from 8d4d518. Download artifacts from this workflow run.

JS SDK (e2b@2.52.1-devin-1790924781-brace-expansion-cve-2026-102276-102278.0):

npm install ./e2b-2.52.1-devin-1790924781-brace-expansion-cve-2026-102276-102278.0.tgz

CLI (@e2b/cli@2.21.1-devin-1790924781-brace-expansion-cve-2026-102276-102278.0):

npm install ./e2b-cli-2.21.1-devin-1790924781-brace-expansion-cve-2026-102276-102278.0.tgz

Code Interpreter JS SDK (@e2b/code-interpreter@2.8.1-devin-1790924781-brace-expansion-cve-2026-102276-102278.0):

npm install ./e2b-code-interpreter-2.8.1-devin-1790924781-brace-expansion-cve-2026-102276-102278.0.tgz

Desktop JS SDK (@e2b/desktop@2.4.1-devin-1790924781-brace-expansion-cve-2026-102276-102278.0):

npm install ./e2b-desktop-2.4.1-devin-1790924781-brace-expansion-cve-2026-102276-102278.0.tgz

Python SDK (e2b==2.52.0+devin.1790924781.brace.expansion.cve.2026.102276.102278):

pip install ./e2b-2.52.0+devin.1790924781.brace.expansion.cve.2026.102276.102278-py3-none-any.whl

Code Interpreter Python SDK (e2b-code-interpreter==2.10.1+devin.1790924781.brace.expansion.cve.2026.102276.102278):

pip install ./e2b_code_interpreter-2.10.1+devin.1790924781.brace.expansion.cve.2026.102276.102278-py3-none-any.whl

Desktop Python SDK (e2b-desktop==2.6.0+devin.1790924781.brace.expansion.cve.2026.102276.102278):

pip install ./e2b_desktop-2.6.0+devin.1790924781.brace.expansion.cve.2026.102276.102278-py3-none-any.whl

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, straightforward dependency pin bump.

What was reviewed: confirmed the only changes are the brace-expansion override range/target bump (<5.0.9: ^5.0.9 to <5.0.11: ^5.0.11) in pnpm-workspace.yaml and the matching pnpm-lock.yaml update (resolution hash and minimatch@ 10.2.5's dependency reference both moved from 5.0.9 to 5.0.12, consistent with the override). No application code, scripts, or other dependencies changed.

Extended reasoning...

The diff touches only pnpm-workspace.yaml and pnpm-lock.yaml, raising a transitive brace-expansion override from 5.0.9 to 5.0.11+ (lockfile resolves to 5.0.12) to address known CVEs; no security-sensitive application code is touched directly, only a dependency pin. The change is small, mechanical, and internally consistent (override and lockfile match), with no outstanding objections in the timeline, so a human does not need to review this.

@mishushakov
mishushakov merged commit a9c58ab into main Oct 2, 2026
48 checks passed
@mishushakov
mishushakov deleted the devin/1790924781-brace-expansion-cve-2026-102276-102278 branch October 2, 2026 10:28
mishushakov pushed a commit that referenced this pull request Oct 2, 2026
…ions (CVE-2026-102276/77/78) (#1929)

## Summary

The Dependabot security-update job on `main`
([run](https://github.com/e2b-dev/E2B/actions/runs/36995679736/job/110801731144))
fails because the lockfile still pins vulnerable
`brace-expansion@1.1.18` (and `2.1.4`).
#1928 only bumped the 5.x line; the
same advisories also cover the 1.x/2.x/3.x lines, and the pnpm override
floors (`^1.1.18`, `^2.1.4`) keep Dependabot from resolving a fix:

```
INFO The latest possible version of brace-expansion that can be installed is 1.1.18
INFO The earliest fixed version is 1.1.21.
| security_update_not_possible | "dependency-name": "brace-expansion", "latest-resolvable-version": "1.1.18", "lowest-non-vulnerable-version": "1.1.21" |
```

Raise every `brace-expansion` override floor to the first version
patched against all three advisories (GHSA-6j4f-fj2g-mc7p,
GHSA-qhr7-859c-m2p7, GHSA-q2hr-2g5m-vwhr):

```diff
-  brace-expansion@<1.1.18: ^1.1.18
-  brace-expansion@>=2.0.0 <2.1.4: ^2.1.4
-  brace-expansion@>=3.0.0 <3.0.6: ^3.0.6
-  brace-expansion@>=4.0.0 <5.0.11: ^5.0.11
+  brace-expansion@<1.1.21: ^1.1.21
+  brace-expansion@>=2.0.0 <2.1.7: ^2.1.7
+  brace-expansion@>=3.0.0 <3.0.9: ^3.0.9
+  brace-expansion@>=4.0.0 <5.0.12: ^5.0.12
```

Lockfile: `1.1.18 → 1.1.21`, `2.1.4 → 2.1.7`, `5.0.12` unchanged. All
versions were published 2026-09-14, so they clear `minimumReleaseAge`.
After the change, `pnpm audit` reports no `brace-expansion` advisories;
`pnpm install --frozen-lockfile` and `pnpm run lint` pass. There's no
changeset because only the workspace lockfile/overrides change, not the
published package dependencies (same as
#1928).

Link to Devin session:
https://app.devin.ai/sessions/148d963bf68a484bb74d1c4eb9d8e332
Open in Devin Desktop:
https://app.devin.ai/desktop/session/148d963bf68a484bb74d1c4eb9d8e332?variant=devin
<!-- devin-review-badge-begin -->

---

<a href="https://app.devin.ai/review/e2b-dev/e2b/pull/1929"
target="_blank"><picture><source media="(prefers-color-scheme: dark)"
srcset="https://static.devin.ai/assets/gh-devin-review-dark.svg?v=4"><img
src="https://static.devin.ai/assets/gh-devin-review-light.svg?v=4"
alt="Devin Review"></picture></a>
<!-- devin-review-badge-end -->

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant