/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-v8qq-4966-8xx5

Published

Last updated

https://images.chainguard.dev/security/CGA-v8qq-4966-8xx5
Package

kibana-8

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2025-54798
  • GHSA-52f5-9888-hmc6

Severity

2.5

Low

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-54798

Updates

Status

Pending upstream fix

Impact

The tmp package version 0.0.33 cannot be directly upgraded to the fixed version 0.2.4 due to breaking changes. Upgrading from 0.0.33 to 0.2.4 requires Node.js > 14 and includes API changes that may break compatibility. Kibana bundles its own specific Node.js version and the upgrade would require upstream Kibana to update their dependencies to use a newer tmp version that is compatible with their bundled Node.js runtime.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing