Details
-
Fix
-
Status: Released (View Workflow)
-
Minor
-
Resolution: Fixed
-
2.7.5
-
None
-
None
-
CVE-2025-27789
Description
Current Stuation
Currently JS7 JOC-Cockpit ships with @babel/runtime 7.25.0 which is affected by CVE-2025-27789.
We rate the impact to our software asĀ low as there is no direct impact to our software as we do not expose @babel/runtime functionality to end users.
Desired Behavior
JS7 should use @babel/runtime version 7.28.4 which solves the issue.