Skip to content

[Aikido] Fix security issue in kotlin-stdlib via major version upgrade from 1.9.25 to 2.1.0 in agent_api - #331

Open
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/AIK-18170-update-packages-82925224-p3fs
Open

[Aikido] Fix security issue in kotlin-stdlib via major version upgrade from 1.9.25 to 2.1.0 in agent_api#331
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/AIK-18170-update-packages-82925224-p3fs

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Aug 6, 2026

Copy link
Copy Markdown

Upgrade kotlin-stdlib to fix insecure temporary file permissions vulnerability allowing unauthorized data access and directory listing.

⚠️ Breaking changes analysis not available for: org.jetbrains.kotlin:kotlin-stdlib

✅ 1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2026-550292
MEDIUM
[kotlin-stdlib] In JetBrains Kotlin, a vulnerable Java API is used for temporary file and folder creation. An attacker is able to read data from such files and list directories due to insecure permissions.
🔗 Related Tasks

@codecov

codecov Bot commented Aug 6, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants