Skip to content

[Aikido] Fix security issue in requests via minor version upgrade from 2.32.3 to 2.33.0#150

Open
aikido-autofix[bot] wants to merge 1 commit intodevelopfrom
fix/aikido-security-update-packages-21161149-iuuq
Open

[Aikido] Fix security issue in requests via minor version upgrade from 2.32.3 to 2.33.0#150
aikido-autofix[bot] wants to merge 1 commit intodevelopfrom
fix/aikido-security-update-packages-21161149-iuuq

Conversation

@aikido-autofix
Copy link
Copy Markdown

Upgrade requests to fix local privilege escalation via predictable temp file extraction in zip handling.

✅ 1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-25645
MEDIUM
[requests] A predictable filename vulnerability in the extract_zipped_paths() utility function allows local attackers to pre-create malicious files in the temp directory that would be loaded instead of legitimate ones, enabling arbitrary code execution.

@github-actions
Copy link
Copy Markdown
Contributor

Docker Images

Commit: 0f586520aa150fc07d36deaaedd8c3470710b40f

Tag
610829907584.dkr.ecr.ap-southeast-2.amazonaws.com/gitops:test-0f58652

@toshke toshke requested a review from uptickmetachu March 30, 2026 03:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant