CVE-2025-9403

A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Other versions might be affected as well.
References
Link Resource
https://drive.google.com/file/d/1r8m9PhU_rk-QPj6OMcs415FcvWPD-zJY/view?usp=sharing Exploit
https://github.com/jqlang/jq/issues/3393 Exploit Issue Tracking Vendor Advisory
https://vuldb.com/?ctiid.321239 Permissions Required VDB Entry
https://vuldb.com/?id.321239 Third Party Advisory VDB Entry
https://vuldb.com/?submit.633170 Exploit Third Party Advisory VDB Entry
https://github.com/jqlang/jq/issues/3393 Exploit Issue Tracking Vendor Advisory
https://vuldb.com/?submit.633170 Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:jqlang:jq:*:*:*:*:*:*:*:*

History

12 Sep 2025, 20:11

Type Values Removed Values Added
CPE cpe:2.3:a:jqlang:jq:*:*:*:*:*:*:*:*
First Time Jqlang
Jqlang jq
References () https://drive.google.com/file/d/1r8m9PhU_rk-QPj6OMcs415FcvWPD-zJY/view?usp=sharing - () https://drive.google.com/file/d/1r8m9PhU_rk-QPj6OMcs415FcvWPD-zJY/view?usp=sharing - Exploit
References () https://github.com/jqlang/jq/issues/3393 - () https://github.com/jqlang/jq/issues/3393 - Exploit, Issue Tracking, Vendor Advisory
References () https://vuldb.com/?ctiid.321239 - () https://vuldb.com/?ctiid.321239 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.321239 - () https://vuldb.com/?id.321239 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.633170 - () https://vuldb.com/?submit.633170 - Exploit, Third Party Advisory, VDB Entry

25 Aug 2025, 20:24

Type Values Removed Values Added
Summary
  • (es) Se detectó una vulnerabilidad en jqlang (hasta la versión 1.6). La función run_jq_tests del archivo jq_test.c del componente JSON Parser se ve afectada. La manipulación puede generar una aserción accesible. El ataque requiere acceso local. Se ha hecho público el exploit y puede que sea utilizado. Otras versiones también podrían verse afectadas.
References () https://github.com/jqlang/jq/issues/3393 - () https://github.com/jqlang/jq/issues/3393 -
References () https://vuldb.com/?submit.633170 - () https://vuldb.com/?submit.633170 -

25 Aug 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-25 03:15

Updated : 2025-09-12 20:11


NVD link : CVE-2025-9403

Mitre link : CVE-2025-9403

CVE.ORG link : CVE-2025-9403


JSON object : View

Products Affected

jqlang

  • jq
CWE
CWE-617

Reachable Assertion