Summary
CVE-2025-5890 is published in NVD and affects the npm package @actions/glob, but there is no GitHub advisory for it, so it is absent from the GitHub Advisory Database and from OSV. Tools that source npm advisory data from either see nothing for this package.
The CVE
- CVE-2025-5890, published 2025-06-09, NVD status
Deferred
- NVD description: a ReDoS in
globEscape in toolkit/packages/glob/src/internal-pattern.ts, reported against actions toolkit 0.5.0
- Sourced via VulDB, which is why it appears not to have reached GHSA
- NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2025-5890
The affected npm package
@actions/glob is the published package for toolkit/packages/glob, the component the CVE names. Published versions: 0.1.0 through 0.7.0.
No fixed version appears to exist
The upstream fix, actions/toolkit#2057, is still open and unmerged as of 2026-10-08, so there does not appear to be a released version that resolves this. I have deliberately not proposed an affected range, since establishing where it starts and whether 0.6.x and 0.7.0 still carry the pattern is a maintainer judgement rather than mine.
Why this is worth recording even without a fix
An advisory with no fixed version is still actionable: consumers can see the exposure and decide, rather than not knowing. At present a commercial scanner that maintains its own advisory data reports this package while anything sourcing from GHSA or OSV reports nothing, which is a visible gap rather than a theoretical one. I found it while reconciling two scanners over the same lockfile.
I am the maintainer of an OSV-based scanner and have no affiliation with the reporter or with VulDB. Happy to supply anything else useful.
Summary
CVE-2025-5890 is published in NVD and affects the npm package
@actions/glob, but there is no GitHub advisory for it, so it is absent from the GitHub Advisory Database and from OSV. Tools that source npm advisory data from either see nothing for this package.The CVE
DeferredglobEscapeintoolkit/packages/glob/src/internal-pattern.ts, reported against actions toolkit 0.5.0The affected npm package
@actions/globis the published package fortoolkit/packages/glob, the component the CVE names. Published versions: 0.1.0 through 0.7.0.No fixed version appears to exist
The upstream fix, actions/toolkit#2057, is still open and unmerged as of 2026-10-08, so there does not appear to be a released version that resolves this. I have deliberately not proposed an affected range, since establishing where it starts and whether 0.6.x and 0.7.0 still carry the pattern is a maintainer judgement rather than mine.
Why this is worth recording even without a fix
An advisory with no fixed version is still actionable: consumers can see the exposure and decide, rather than not knowing. At present a commercial scanner that maintains its own advisory data reports this package while anything sourcing from GHSA or OSV reports nothing, which is a visible gap rather than a theoretical one. I found it while reconciling two scanners over the same lockfile.
I am the maintainer of an OSV-based scanner and have no affiliation with the reporter or with VulDB. Happy to supply anything else useful.