Skip to content

Dependency Security Update: CVE-2025-67030 in plexus-utils #120

@ncoiffier-celonis

Description

@ncoiffier-celonis

Hello,

I would like to report one problem related to high-severity Path Traversal vulnerability (CVE-2025-67030) has been identified in the plexus-utils library, which is a dependency of this project.

plexus-utils version has already been bump by this commit last month, but given the severity of the CVE, would it make sense to release a new version of plexus-resources?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions