Intel

AIKIDO-2025-10848

slack-incoming-webhook-plugin is vulnerable to Dependency on Vulnerable Third-Party Component

Dependency on Vulnerable Third-Party ComponentCVE-2025-48924

20

Low Risk

This Affects:

JAVAslack-incoming-webhook-plugin
0.0.1 - 1.3.6
Fixed in 1.3.7
Are you affected? Scan for Free

TL;DR

Affected versions of this package import the vulnerable commons-lang package (CVE-2025-48924), which is vulnerable to Uncontrolled Recursion when processing long or deeply nested inputs. The patch replaces the vulnerable package with commons-lang3 version 3.18.0.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

slack-incoming-webhook-plugin is vulnerable to Dependency on Vulnerable Third-Party Component in versions 0.0.1 - 1.3.6.

How to fix this

Upgrade the org.rundeck.plugins:slack-incoming-webhook-plugin library to a patch version.