CVE-2025-9403

A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Other versions might be affected as well.
References
Link Resource
https://drive.google.com/file/d/1r8m9PhU_rk-QPj6OMcs415FcvWPD-zJY/view?usp=sharing Exploit
https://github.com/jqlang/jq/issues/3393 Exploit Issue Tracking Vendor Advisory
https://vuldb.com/?ctiid.321239 Permissions Required VDB Entry
https://vuldb.com/?id.321239 Third Party Advisory VDB Entry
https://vuldb.com/?submit.633170 Exploit Third Party Advisory VDB Entry
https://github.com/jqlang/jq/issues/3393 Exploit Issue Tracking Vendor Advisory
https://vuldb.com/?submit.633170 Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:jqlang:jq:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-08-25 03:15

Updated : 2025-09-12 20:11


NVD link : CVE-2025-9403

Mitre link : CVE-2025-9403

CVE.ORG link : CVE-2025-9403


JSON object : View

Products Affected

jqlang

  • jq
CWE
CWE-617

Reachable Assertion