Skip to content

CVE-2025-66293: Document affected versions and patch workflow-tests#60

Draft
Copilot wants to merge 3 commits intomasterfrom
copilot/check-cve-2025-66293-issue
Draft

CVE-2025-66293: Document affected versions and patch workflow-tests#60
Copilot wants to merge 3 commits intomasterfrom
copilot/check-cve-2025-66293-issue

Conversation

Copy link
Contributor

Copilot AI commented Feb 6, 2026

CVE-2025-66293 is an out-of-bounds read in libpng < 1.6.52. Main repo was already patched (1.6.54 since Jan 2026), but workflow-tests remained vulnerable and no historical analysis existed.

Historical Impact Analysis

Traced git history to identify affected periods:

Development environment (pixi.lock):

  • Jun 2025 - Nov 2025: libpng 1.6.47 (commits 37f5d14 to fcd9069)
  • Nov 2025 - Jan 2026: libpng 1.6.50 (commits cf0f5a8 to ee11f38)
  • Jan 2026+: libpng 1.6.54 ✓

Workflow tests (workflow-tests/test-extension/pixi.lock):

  • Sep 2025 - Feb 2026: libpng 1.6.50 (commit adbd584 onwards)
  • Feb 2026+: libpng 1.6.54 ✓ (this PR)

Changes

  • SECURITY-ADVISORY-CVE-2025-66293.md: Timeline of affected versions, risk assessment, remediation steps
  • workflow-tests/test-extension/: Updated libpng 1.6.50 → 1.6.54, added libpng >= 1.6.52 constraint
  • README.md: Added security section reference

Risk Profile

High: Processing untrusted PNG files
Medium: Dev/test environments with trusted input
Low: No PNG processing

Developers who cloned Jun 2025 - Feb 2026 should rebuild environments: pixi clean && pixi install


💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

Co-authored-by: HedgehogCode <6631116+HedgehogCode@users.noreply.github.com>
Copilot AI changed the title [WIP] Investigate repository for CVE-2025-66293 impact Fix CVE-2025-66293: Update libpng to 1.6.54 in workflow-tests Feb 6, 2026
Copilot AI requested a review from HedgehogCode February 6, 2026 13:23
Co-authored-by: HedgehogCode <6631116+HedgehogCode@users.noreply.github.com>
Copilot AI changed the title Fix CVE-2025-66293: Update libpng to 1.6.54 in workflow-tests CVE-2025-66293: Document affected versions and patch workflow-tests Feb 6, 2026
@sonarqubecloud
Copy link

sonarqubecloud bot commented Feb 6, 2026

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants