Measured is vulnerable to Path Traversal attacks during class initialization
Description
Published to the GitHub Advisory Database
Jul 15, 2025
Reviewed
Jul 15, 2025
Last updated
Jul 15, 2025
Impact
A path traversal vulnerability exists where an attacker with access to manipulate inputs when initializing the
Measured::Cache::Json class
would be able to instruct the library to read arbitrary files.Patches
Users should update to the latest version.
References