foxx-cli
Chainguard
2.5
CVSS V3
Status
Impact
The vulnerable tmp package is a transitive dependency through inquirer@8.2.6 → external-editor@3.1.0 → tmp@0.0.33. The fix requires upgrading inquirer from ^8.0.0 to ^12.9.0, which is a major version upgrade that may introduce breaking changes to the CLI functionality. inquirer 12.x has been rewritten and no longer uses external-editor/tmp dependencies. This change requires thorough testing of all CLI interactions and user prompts to ensure compatibility.
Status