Skip to content

chore(deps): update dependency moment to v2.31.0 [security] j:cdx-227 - #1566

Merged
alexprudhomme merged 1 commit into
masterfrom
renovate/npm-moment-vulnerability
Oct 7, 2026
Merged

alexprudhomme merged 1 commit into
masterfrom
renovate/npm-moment-vulnerability

Conversation

@renovate-coveo

@renovate-coveo renovate-coveo Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
moment devDependencies minor 2.29.4 → 2.31.0

moment vulnerable to Path Traversal via crafted non-string locale name

CVE-2026-17495 / GHSA-4p3w-j4w9-5jqw

More information

Details

Impact

moment before 2.31.0 is vulnerable to path traversal in moment.locale(). When an application passes a non-string, attacker-influenced value to moment.locale(), a specially crafted object can bypass the locale name validation and cause moment to load a file from an attacker-controlled path. This is a further bypass of the validation added in 2.29.2 for CVE-2022-24785.

This affects server-side (npm) users only. Plain string input is not affected: the existing validation correctly rejects strings that contain path separators.

Patches

This issue is patched in moment 2.31.0.

Workarounds

Validate that any user-supplied input is a string before passing it to moment.locale().

Severity

  • CVSS Score: 5.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@renovate-coveo renovate-coveo Bot added the dependencies Pull requests that update a dependency file label Oct 5, 2026
@renovate-coveo
renovate-coveo Bot requested a review from a team as a code owner October 5, 2026 05:16
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Thanks for your contribution @renovate-coveo[bot] !
When your pull-request is ready to be merged, check the box below to merge it

  • Merge! :shipit:

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Pull Request Report

PR Title

✅ Title follows the conventional commit spec.

@alexprudhomme alexprudhomme left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate pass: checks green.

@alexprudhomme
alexprudhomme merged commit fc8cc1a into master Oct 7, 2026
14 checks passed
@alexprudhomme
alexprudhomme deleted the renovate/npm-moment-vulnerability branch October 7, 2026 13:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant