Skip to content

Dependency Security Update: CVE-2025-67030 in plexus-utils #120

Description

@ncoiffier-celonis

Hello,

I would like to report one problem related to high-severity Path Traversal vulnerability (CVE-2025-67030) has been identified in the plexus-utils library, which is a dependency of this project.

plexus-utils version has already been bump by this commit last month, but given the severity of the CVE, would it make sense to release a new version of plexus-resources?

Metadata

Metadata

Assignees

Labels

dependenciesPull requests that update a dependency filepriority:majorMajor loss of function

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions