[PR #31515] fix(web): upgrade tanstack devtools to fix seroval RCE vulnerability #33272

Closed
opened 2026-02-21 20:52:59 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/31515

State: closed
Merged: Yes


Summary

  • Upgrade @tanstack/react-devtools 0.9.0 → 0.9.2
  • Upgrade @tanstack/react-form-devtools 0.2.9 → 0.2.12
  • Add solid-js: 1.9.11 override to resolve seroval 1.3.2 → 1.5.0

Fixes CVE-2026-23737 (seroval RCE via JSON deserialization).

Related Dependabot Alerts

**Original Pull Request:** https://github.com/langgenius/dify/pull/31515 **State:** closed **Merged:** Yes --- ## Summary - Upgrade `@tanstack/react-devtools` 0.9.0 → 0.9.2 - Upgrade `@tanstack/react-form-devtools` 0.2.9 → 0.2.12 - Add `solid-js: 1.9.11` override to resolve `seroval` 1.3.2 → 1.5.0 Fixes CVE-2026-23737 (seroval RCE via JSON deserialization). ## Related Dependabot Alerts - https://github.com/langgenius/dify/security/dependabot/153 - https://github.com/langgenius/dify/security/dependabot/154 - https://github.com/langgenius/dify/security/dependabot/155 - https://github.com/langgenius/dify/security/dependabot/156 - https://github.com/langgenius/dify/security/dependabot/159
yindo added the pull-request label 2026-02-21 20:52:59 -05:00
yindo closed this issue 2026-02-21 20:52:59 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#33272