Skip to content

[Aikido] Fix 1 security issue in logback-core, logback-classic#8

Open
aikido-autofix[bot] wants to merge 1 commit intomasterfrom
fix/aikido-security-update-packages-15205282-rNyA
Open

[Aikido] Fix 1 security issue in logback-core, logback-classic#8
aikido-autofix[bot] wants to merge 1 commit intomasterfrom
fix/aikido-security-update-packages-15205282-rNyA

Conversation

@aikido-autofix
Copy link

@aikido-autofix aikido-autofix bot commented Feb 1, 2026

Targeted updates to remediate security findings while preserving existing behavior

Upgrade logback dependencies to mitigate remote code execution vulnerability in XML configuration parsing when Janino and Spring are present

✅ 1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2025-10694
MEDIUM
A remote code execution vulnerability in logback configuration parsing allows arbitrary code execution when Janino and Spring are present, if an attacker can modify config files or set malicious environment variables.

@aikido-autofix aikido-autofix bot added the Kroo Label created by Aikido AutoFix label Feb 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Kroo Label created by Aikido AutoFix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants