/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-7jv3-6jcq-47xr

Published

Last updated

https://images.chainguard.dev/security/CGA-7jv3-6jcq-47xr
Package

langfuse

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-54798
  • GHSA-52f5-9888-hmc6

Severity

2.5

Low

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-54798

Updates

Status

Pending upstream fix

Impact

The tmp package version 0.0.33 cannot be directly upgraded to the fixed version 0.2.4 due to breaking changes. Upgrading from 0.0.33 to 0.2.4 requires Node.js > 14 and includes API changes that may break compatibility. The package has already been updated to use pnpm overrides for tmp@^0.2.4 which will fix instances of tmp@0.2.x, but the 0.0.33 instances require upstream dependencies to update their requirements.

Status

Under investigation


Safe Source for Open Source™
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing