Skip to content

fix: update jsonpath-plus for CVE-2025-1302#3609

Merged
hassy merged 1 commit intoartilleryio:mainfrom
JonathanSmithSkipton:fix-vulnerability
Dec 12, 2025
Merged

fix: update jsonpath-plus for CVE-2025-1302#3609
hassy merged 1 commit intoartilleryio:mainfrom
JonathanSmithSkipton:fix-vulnerability

Conversation

@JonathanSmithSkipton
Copy link
Contributor

@JonathanSmithSkipton JonathanSmithSkipton commented Sep 11, 2025

Description

Followup fix for vulnerability CVE-2024-21534 previous addressed in #3369

See: https://nvd.nist.gov/vuln/detail/CVE-2025-1302

Pre-merge checklist

This is for use by the Artillery team. Please leave this in if you're contributing to Artillery.

  • Does this require an update to the docs?
  • Does this require a changelog entry?

@CLAassistant
Copy link

CLAassistant commented Sep 11, 2025

CLA assistant check
All committers have signed the CLA.

@JonathanSmithSkipton JonathanSmithSkipton changed the title fix: update jsonpath-plus to recommended 10.3.0 fix: update jsonpath-plus for CVE-2025-1302 Sep 11, 2025
@JonathanSmithSkipton
Copy link
Contributor Author

@hassy anything you need from me on this? very interested in getting this RCE vulnerability closed off from a security point of view

@JonathanSmithSkipton
Copy link
Contributor Author

@hassy do we have an eta on when this would likely be merged? getting alot of alerts raised from this due to its nature as a critical vulnerability

@TonyF111
Copy link

Can this be bumped up in urgency please?

@hassy hassy merged commit 7d7719e into artilleryio:main Dec 12, 2025
37 of 42 checks passed
@hassy
Copy link
Member

hassy commented Dec 12, 2025

merged now, thank you @JonathanSmithSkipton & apologies for the delay.

btw this is unlikely to have affected any installations of Artillery, since the dependency only pins the major version, so v10.3.0 of the package would be installed on npm install artillery.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants