| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| Microsoft.Build.Tasks.Core | nuget | = 17.15.0-preview-25277-114 | 18.0.0-preview-25476-107 |
I have determined that the initial vulnerability advisory GHSA-q8g5-rw97-f55h is a duplicate of GHSA-w3q9-fxm7-j8fq. My initial attempts to find information on GHSA-w3q9-fxm7-j8fq and the associated CVE CVE-2025-55247 (which appears to be a placeholder) were unsuccessful. The provided information does not contain any links to source code, commits, or pull requests that would allow me to perform a detailed analysis of the code changes and identify the specific vulnerable functions. Without access to the security patches, I cannot determine the exact functions that were modified to address the "Improper Link Resolution Before File Access" vulnerability. Therefore, I cannot confidently provide the names of the vulnerable functions.
Ongoing coverage of React2Shell