Skip to content

Fix for tmp CVE-2025-54798#3598

Open
freshtonic wants to merge 1 commit intoartilleryio:mainfrom
freshtonic:patch-1
Open

Fix for tmp CVE-2025-54798#3598
freshtonic wants to merge 1 commit intoartilleryio:mainfrom
freshtonic:patch-1

Conversation

@freshtonic
Copy link

Description

Bump tmp to 0.2.5 (latest at time of commit).

In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / directory write via symbolic link dir parameter. This is fixed in version 0.2.4.

Pre-merge checklist

This is for use by the Artillery team. Please leave this in if you're contributing to Artillery.

  • [no] Does this require an update to the docs?
  • [yes] Does this require a changelog entry?

Bump `tmp` to 0.2.5 (latest at time of commit).

In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / directory write via symbolic link dir parameter. This is fixed in version 0.2.4.
@CLAassistant
Copy link

CLAassistant commented Aug 28, 2025

CLA assistant check
All committers have signed the CLA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants