Skip to content

Vulnerable dependency: cJSON affected by CVE-2025-57052 #42

@hizaco

Description

@hizaco

Description

Hello,

While reviewing the dependencies of this project, We noticed that cJSON is being used and is affected by a critical vulnerability:

cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters.

Impact

This vulnerability could potentially allow full compromise (Confidentiality, Integrity, Availability). Given the severity (CVSS 9.8), it is strongly recommended to update or replace the vulnerable dependency as soon as possible.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions