Skip to content

fix(deps): update dependency moment to v2.31.0 [security] - #613

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate-npm-moment-vulnerability
Sep 30, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate-npm-moment-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
moment 2.30.1 → 2.31.0 age confidence

moment vulnerable to Path Traversal via crafted non-string locale name

CVE-2026-17495 / GHSA-4p3w-j4w9-5jqw

More information

Details

Impact

moment before 2.31.0 is vulnerable to path traversal in moment.locale(). When an application passes a non-string, attacker-influenced value to moment.locale(), a specially crafted object can bypass the locale name validation and cause moment to load a file from an attacker-controlled path. This is a further bypass of the validation added in 2.29.2 for CVE-2022-24785.

This affects server-side (npm) users only. Plain string input is not affected: the existing validation correctly rejects strings that contain path separators.

Patches

This issue is patched in moment 2.31.0.

Workarounds

Validate that any user-supplied input is a string before passing it to moment.locale().

Severity

  • CVSS Score: 5.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (in timezone Europe/Zurich)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

Copy link
Copy Markdown

This PR will trigger a patch release when merged.

@codecov

codecov Bot commented Sep 30, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@renovate
renovate Bot merged commit 1b6632e into main Sep 30, 2026
8 checks passed
@renovate
renovate Bot deleted the renovate-npm-moment-vulnerability branch September 30, 2026 21:53
github-actions Bot pushed a commit that referenced this pull request Sep 30, 2026
## [6.4.47](v6.4.46...v6.4.47) (2026-09-30)

### Bug Fixes

* **deps:** update dependency moment to v2.31.0 [security] ([#613](#613)) ([1b6632e](1b6632e))
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 6.4.47 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants