Security Vulnerability in pbkdf2 Dependency (CVE-2025-6547)
-
I’m reaching out regarding a critical security advisory that may affect your plugin.
The
pbkdf2Node.js package, which appears in your plugin’s/plugins/cookie-law-info/lite/admin/package-lock.json, is affected by a critical vulnerability (CVE-2025-6547). This issue causes the library to silently return static keys when passed aUint8Array, potentially leading to cryptographic weaknesses or forged keys.Relevant advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-6547
Affected versions:
pbkdf2 <= 3.1.2
Fixed in:pbkdf2 >= 3.1.3Could you please let me know:
- If this dependency is actually used at runtime in the plugin?
- Whether you have plans to upgrade
pbkdf2to a secure version? - If an update is expected soon to address this?
You must be logged in to reply to this topic.