Skip to content

[GHSA-xgwh-cgv9-783v] @tryghost/members-csv: use the package's own version 2.0.1 instead of Ghost's 5.82.0 - #9799

Open
zyl71 wants to merge 1 commit into
github:zyl71/advisory-improvement-9799from
zyl71:fix/GHSA-xgwh-cgv9-783v
Open

zyl71 wants to merge 1 commit into
github:zyl71/advisory-improvement-9799from
zyl71:fix/GHSA-xgwh-cgv9-783v

Conversation

@zyl71

@zyl71 zyl71 commented Sep 26, 2026

Copy link
Copy Markdown

Updates

  • Affected products

Comments
The range gives Ghost's product version (patched 5.82.0) for the npm package @tryghost/members-csv, whose own versions are 1.x and 2.x, so every members-csv release, including those that contain the fix, is reported as affected. The fix (commit de668e7950a019a204b2df0c84596ea0fa32cce6, which adds escapeFormulae: true in lib/unparse.js) first appears in the published package in @tryghost/members-csv 2.0.1 (npm, 2025-05-12), and every later release (2.0.2-2.0.7) contains it. This change sets the patched version to 2.0.1.

@github-actions
github-actions Bot changed the base branch from main to zyl71/advisory-improvement-9799 September 26, 2026 20:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant