Skip to content

CVE-2026-13149 (brace-expansion DoS vulnerability) #412

Description

@nov

Your Environment

  • Prettier version: 2.x.x
  • node version: [12.x.x, 14.x.x]
  • package manager: [npm@7, pnpm@6, yarn@2]
  • IDE: [VScode, Webstorm, CLI]

Describe the bug

@trivago/prettier-plugin-sort-imports@6.0.2 requires brace-expansion@^2.0.2 via minimatch@9.0.9

To Reproduce

Expected behavior

minimatch upgrade will solve the issue

Screenshots, code sample, etc

Configuration File (cat .prettierrc, prettier.config.js, .prettier.js)

Error log

Contribute to @trivago/prettier-plugin-sort-imports

  • I'm willing to fix this bug 🥇

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions