Skip to content

CVE-2025-22871 @angular/build uses a vulnerable version of "esbuild" - "0.25.1" #30255

@denkerny

Description

@denkerny

Command

build

Is this a regression?

  • Yes, this behavior used to work in the previous version

The previous version in which this bug was not present was

No response

Description

current version of @angular/build: 19.2.10 has dependency of esbuild: 0.25.1, which affected by CVE-2025-22871 (go/stlib: 1.23.7)

and its fine with esbuild: 0.25.2 (go/stlib: 1.23.8) fix #4133: Update go 1.23.7 => 1.23.8 #4134

Minimal Reproduction

No need for steps to reproduce

Exception or Error


Your Environment

Angular CLI: 19.2.10
Node: 22.15.0
Package Manager: npm 10.9.2
OS: macOS 15.1.1 (24B91)

Anything else relevant?

esbuild: 4133

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions