Skip to content

[stable5.7] fix(deps): Update symfony/process#12747

Merged
kesselb merged 1 commit intostable5.7from
fix/deps/symfony-process-msys2-escaping-stable5.7
Apr 16, 2026
Merged

[stable5.7] fix(deps): Update symfony/process#12747
kesselb merged 1 commit intostable5.7from
fix/deps/symfony-process-msys2-escaping-stable5.7

Conversation

@ChristophWurst
Copy link
Copy Markdown
Member

Backport of #12746.

…erability

symfony/process v5.4.46 contained incorrect argument escaping under MSYS2/Git Bash
that could lead to destructive file operations on Windows. Updated to v6.4.33 which
includes the fix for CVE-2026-24739.

AI-assisted: OpenCode (Claude Haiku 4.5)
Signed-off-by: Christoph Wurst <1374172+ChristophWurst@users.noreply.github.com>
@ChristophWurst ChristophWurst force-pushed the fix/deps/symfony-process-msys2-escaping-stable5.7 branch from 3d00336 to ca7663d Compare April 16, 2026 08:01
@ChristophWurst ChristophWurst changed the title [stable5.7] fix(deps): Update symfony/process to fix MSYS2 argument escaping vuln… [stable5.7] fix(deps): Update symfony/process Apr 16, 2026
@kesselb kesselb merged commit aaedc0a into stable5.7 Apr 16, 2026
42 checks passed
@kesselb kesselb deleted the fix/deps/symfony-process-msys2-escaping-stable5.7 branch April 16, 2026 15:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants