Root has patched CVE-2025-5889 in the @rootio/brace-expansion package for Root:npm. Multiple fixed versions available.
{ "distro_version": "", "distro": "npm", "severity": "LOW", "source": "Root" }
"https://api.root.io/external/osv/ROOT-APP-NPM-CVE-2025-5889.json"
"1.1.11-root.io.3"
[ "2.0.1-root.io.2", "1.1.11-root.io.2", "2.0.1-root.io.3", "1.1.11-root.io.3" ]
4.0
""
true
[ "2.0.1-aikido.3", "1.1.11-aikido.3" ]
"1.1.11-aikido.3"
2.0