/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-7jv3-6jcq-47xr

Published

Last updated

https://images.chainguard.dev/security/CGA-7jv3-6jcq-47xr
Package

langfuse

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-54798
  • GHSA-52f5-9888-hmc6

Severity

2.5

Low

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-54798

Updates

Status

Pending upstream fix

Impact

The tmp package version 0.0.33 cannot be directly upgraded to the fixed version 0.2.4 due to breaking changes. Upgrading from 0.0.33 to 0.2.4 requires Node.js > 14 and includes API changes that may break compatibility. The package has already been updated to use pnpm overrides for tmp@^0.2.4 which will fix instances of tmp@0.2.x, but the 0.0.33 instances require upstream dependencies to update their requirements.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing