CVE-2025-9403: jqlang jq JSON jq_test.c run_jq_tests assertion
A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function runjqtests of the file jqtest.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Other versions might be affected as well.
Other sources
jqlang jq JSON jqtest.c runjqtests assertion
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.6-5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.7.1-7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.7.1-8
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9403?
CVE-2025-9403 has a high severity level due to its potential for local exploitation and assertion failures.
How do I fix CVE-2025-9403?
To fix CVE-2025-9403, upgrade jqlang jq to version 1.7 or later.
What components are affected by CVE-2025-9403?
CVE-2025-9403 affects the JSON Parser component within jqlang jq versions up to 1.6.
Is local access required to exploit CVE-2025-9403?
Yes, exploit of CVE-2025-9403 requires local access to the vulnerable system.
Has CVE-2025-9403 been publicly disclosed?
Yes, CVE-2025-9403 has been publicly disclosed.