Skip to content

Missing advisory: CVE-2025-5890 affects npm @actions/glob but has no GHSA, so it is absent from OSV #10230

Description

@sonukapoor

Summary

CVE-2025-5890 is published in NVD and affects the npm package @actions/glob, but there is no GitHub advisory for it, so it is absent from the GitHub Advisory Database and from OSV. Tools that source npm advisory data from either see nothing for this package.

The CVE

  • CVE-2025-5890, published 2025-06-09, NVD status Deferred
  • NVD description: a ReDoS in globEscape in toolkit/packages/glob/src/internal-pattern.ts, reported against actions toolkit 0.5.0
  • Sourced via VulDB, which is why it appears not to have reached GHSA
  • NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2025-5890

The affected npm package

@actions/glob is the published package for toolkit/packages/glob, the component the CVE names. Published versions: 0.1.0 through 0.7.0.

No fixed version appears to exist

The upstream fix, actions/toolkit#2057, is still open and unmerged as of 2026-10-08, so there does not appear to be a released version that resolves this. I have deliberately not proposed an affected range, since establishing where it starts and whether 0.6.x and 0.7.0 still carry the pattern is a maintainer judgement rather than mine.

Why this is worth recording even without a fix

An advisory with no fixed version is still actionable: consumers can see the exposure and decide, rather than not knowing. At present a commercial scanner that maintains its own advisory data reports this package while anything sourcing from GHSA or OSV reports nothing, which is a visible gap rather than a theoretical one. I found it while reconciling two scanners over the same lockfile.

I am the maintainer of an OSV-based scanner and have no affiliation with the reporter or with VulDB. Happy to supply anything else useful.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions