| Timeline is interesting Timeline: 02/27/2025: vulnerability reported to the maintainers (specifying that only versions between 12.0.0 and 12.0.7 were vulnerable, which was our understanding at the time) 03/01/2025: second email sent explaining that all versions were ultimately vulnerable, including the latest stable releases 03/05/2025: initial response received from the Vercel team explaining that versions 12.x were no longer supported/maintained (probably hadn’t read the second email/security advisory template indicating that all were vulnerable) 03/05/2025: another email sent so that the team could quickly take a look at the second email/security advisory template 03/11/2025: another email sent to find out whether or not the new information had been taken into account 03/17/2025: email received from the Vercel team confirming that the information had been taken into account 03/18/2025: email received from the Vercel team: the report had been accepted, and the patch was implemented. Version 15.2.3 was released a few hours later, containing the fix (+backports) 03/21/2025: publication of the security advisory |
That doesn't mean they shouldn't issue an alert to developers still running those versions advising them to upgrade ASAP.